Solved

OD Replicating to AD.  OSX Server 10.6 and Server 2008

Posted on 2011-03-07
6
885 Views
Last Modified: 2012-05-11
So I have a unique and PITA situation here.
I have a school that is running Snow Leopard Server and Windows Server 2008.  They are 99% MAC Based in their workstations, but have a couple PCs.  They have file shares on both servers.  The are adamant about not removing the windows server from the network.
What they want to do is have the OSX Server be the master and replicate the user info (just Login Name, User Name, and Password) to AD so that file sharing and such won't be a problem regardless of the platform they are using.
My issue is getting the Two server to talk to eachother.  I have replicated a similar network in my office where I have a Snow Leo Server and Window Server 2k8 running on the same test network.  The win2k8 server is setup on domain dns.lan the OSX server is setup on DNS.lan as well.
The OSX server is called "server.dns.lan"
The Win2k8 server is called "winsrv.dns.lan"
when I go into Directory Utility and enable Active Directory then go into the settings to bind it I am leaving the Active Directory Forest set at " - Automatic - "
Active Directory Domain I input "dns.lan"
Computer ID I leave with the default which is "server"
I then click Bind and it brings up the Network Administrator Required field.
I put in the Username and password for the windows Server and Click OK and I get the attached error. Bind Error
So I turn to the experts that have been oh so helpful in the past.
they are also wanting this live in 2 weeks, even though I was originally told it wasn't happening until May.  -.-

Thanks in advance for any help!
0
Comment
Question by:dnetsol
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 11

Expert Comment

by:gmbaxter
ID: 35062630
I think you'll struggle here. You cant replicate between OSX and Windows AD. OS X runs an outdated version of samba 3, itself which is based around NT4.

Your mac server isn't running a PDC role is it?

To bind it in, check that your mac server can resolve the name of the windows server ( set mac servers DNS server to the AD one) then bind it in via directory utility > Active DIrectory

Still don't see how this is going to assist you as previously stated. How about running AD/DNS/DHCP on the windows server, and using the OS X server bound to the domain as a member server as a file server?

You can then add another small windows box to the mix to add some redundancy.
0
 

Author Comment

by:dnetsol
ID: 35062736
Hi gmbaxter - Basically what they are trying to accomplish is having the same user accounts on either box w/o having to manually enter them twice.
To be honest I don't care which box they enter them on, but if (for example) they enter it on the Windows Server at least the name, shortname (login name) and password needs to be replicated over to the MAC Server so that they can then use the MAC Administration stuff for privilege restrictions and such on the MACs in the enviroment.

I don't know what their MAC server is running (in regards to PDC) the one I started I did from scratch and have just set it up as an open directory master but I can switch that.  The issue though is going to be I am pretty sure that the majority of their user accounts is on their MAC server currently.


Hopefully this didn't muddy the waters more...
0
 

Author Comment

by:dnetsol
ID: 35128608
So I have set the test bed up where OD it pulling its Data from AD, OD is not a PDC, and AD is doing the DNS, DHCP etc.
My biggest issue for what the client needs is that now I can not administer any of the preferences in Workgroup Manager for the people using MACs.
This functionality of being able to administer the settings for MAC Users, Groups and workstations via Work group manager is crucial.

Does anyone know how to make this work while still replicating the AD and OD to each other?
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 11

Expert Comment

by:gmbaxter
ID: 35130325
This its usually achieved by making the OD server a member of the domain and nesting AD groups into OD groups which you can then apply managed preferences to.
0
 

Author Comment

by:dnetsol
ID: 35131148
Can I get some help on how to do that then?
I'll try to figure it out but I am not 100% sure on how to make it happen.
0
 
LVL 11

Accepted Solution

by:
gmbaxter earned 500 total points
ID: 35132535
Setup your domain controller to host AD and DNS.
Your OD server should be in standalone mode - not an open directory master, with AD as its DNS server.
Check DNS has A and PTR records for the OD server
Check OD server can resolve AD and vice-versa
Join the OD server into the AD domain using the AD plugin in directory utility in the /System/Library/Core Services
open terminal and type: sudo dsconfigad -enableSSO (this will join the OD server into AD's kerberos realm)
Reboot the OD server
Open Server Admin, and add open directory as a service in server admin
Select change role
Select remain connected and setup open directory master
Ignore error about kerberos being unavailable - you are using AD for kerberos
Reboot server
Open Server Admin, select Open Directory > Overview
You should have:

Open Directory is: Open Directory Master

LDAP Server is: Running
Password Server is: Running
Kerberos is: Stopped

Kerberos Realm: YOUR.AD.DOMAIN

Now create an AD group with some users in, eg Finance Users
Open Workgroup Manager and authenticate as the directory administrator
Create a similar group in OD, eg Finance User Management Group
Select the group
Select "Members"
Select +
In the slide out pane where it says "Directory:", click the drop down arrow and select Active Directory.
Add your AD group.

You now have a magic/golden triangle AD-OD setup.


0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question