Solved

Can't join OS X (10.6.6) to AD domain...

Posted on 2011-02-25
10
1,054 Views
Last Modified: 2012-05-11
I'm trying to join a OS X server to my 2008 AD domain but I'm having some issues...

I have enabled the Active Directory utility on the mac and then I've double-clicked it and filled in the domain and even given it a 'preferred' DC to contact. Then I've given it the enterprise admin account and click bind, but when I do that I get:

"unable to access domain controller. This computer is unable to access the domain controller for an unknown reason"

DNS is working well on the Mac and I can ping the domain controller by IP and FQDN, and vice versa.

I don't see anything in the log about this either.

Can anyone tell me how to get past this so that I can take advantage of AD groups and users on the Mac server?
0
Comment
Question by:willlandymore
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 34987899
0
 
LVL 1

Expert Comment

by:orbistechnology
ID: 34987907
Just for clarification, on your Mac, is your DNS set to be the domain controller - and *only* the domain controller?
0
 
LVL 11

Expert Comment

by:gmbaxter
ID: 34988795
Have you tried:

Not specifying a DC

Binding into another CN or OU
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34988856
have you tried the short domain name and the FQDN for the domain ? try not specifying a specific DC, whats in the OSX logs when you try to join (use console viewer).
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34997300
tried it with:
-domain and domain.com
-with and without specifying the DC
-it only uses the 1st and 2nd DC for DNS
-same results when binding to another OU
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 20

Expert Comment

by:woolnoir
ID: 34997769
and there is nothing in either the AD event log, or the directory log under OSX for the time the join is taking place ?
0
 
LVL 11

Expert Comment

by:gmbaxter
ID: 34998867
Are the clocks in sync ?

Can you repair permissions on the mac server and try again?

0
 
LVL 1

Expert Comment

by:orbistechnology
ID: 34999325
Good point baxter.  Clocks must not be out of sync by more than 5 minutes or Kerberos will break.
0
 
LVL 1

Author Comment

by:willlandymore
ID: 35020854
sorry for the delay. Clock is in sync to the second.
0
 
LVL 1

Author Comment

by:willlandymore
ID: 35217995
never could find an answer to this one.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The error "There was an error performing the update" occurred on a Mac OS X client workstation running  Symantec AntiVirus for Mac (http://www.symantec.com/business/products/purchasing.jsp?pcid=pcat_security&pvid=825_1) - the Enterprise product vers…
Information security is a multi-billion dollar industry. Just as lucrative is the black market industry which trades stolen identities, credit card numbers and software exploits all over the world. Nothing is hack-proof. The best one can do is make …
This is a video describing the growing solar energy use in Utah. This is a topic that greatly interests me and so I decided to produce a video about it.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now