Mobile users unable to log in using Open Directory (OD) credentials when not on company LAN

Recently did a clean installation of Mac OS X Server 10.6.7 and configured Open Directory to manage user accounts/access and permissions. Also created several Computer accounts using Workgroup Manager and added their Hardware UUIDs.

Also set-up a Group in Workgroup Manager called 'mobile' and established preferences in Workgroup Manager -> Preferences -> Mobility to create the users Home folder on the server but to keep a sync copy on the local machine.

Also set up DNS on the same server correctly as from what I read before creating this post, improper DNS settings can wreak havoc with OD.

The problem is that when a user that is a member of the 'mobile' group takes their MacBook Pro home, they are unable to log in using their OD credentials.

Coming from a Windows world, it is clear that the user's login credentials are not stored locally in the event that the OD server is not accessible.

Therefore my questions is . . .

How do I allow mobile users to log in when they are away from the office but then sync when they reconnect to the office network?
boomtowncioAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

roylongCommented:
You should be prompted at first log on to create a mobile account.  Did you get that prompt?
There is a setting, I believe it's when you bind to the directory, to prompt for mobile account creation.  This is separate from synced home folders.

I use this setting with our AD users on the macs and it works great.

If you already have a local user folder with the name of the OD user then this may cause you problems and you may have to save the current user folder, create a new one, copy items back from old one.
boomtowncioAuthor Commented:
I have set the preference in Workgroup Manager -> Preferences -> Mobility -> Account Creation -> Creation to always create the mobile account for Users that are a member of the 'mobile' group. I have set the "Manage" option to "Always" perform this action and not to prompt the user (therefore a mobile account is created in all instances).

I have also verified that there is no local account on the MacBook Pro in question with the same user name as the OD account.
lloydforth1Commented:
Before troublshooting the server i'd Open System preferences on the Client machine, click accounts and check the user account has the word mobile beneath it


Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

boomtowncioAuthor Commented:
lloydforth1 - Yes indeed  I have validated that when logged in the user account is listed as type "Mobile" in the manner that you specify.

Where does OS X store the cached OD credentials in the event that the OD server is unavailable? In the User's Home folder?
boomtowncioAuthor Commented:
Comment: In other OD deployments I have observed both "Mobile" and "Managed" appear under a user account.

In the current deployment that I am describing the word "Managed" does not appear. Could that be part of the problem?
lloydforth1Commented:
Indeed i have seen the same.

Can you log in as a admin and check the logs, you would need to check the /var/log  - secure log
boomtowncioAuthor Commented:
Yes however I will have to do that tomorrow as the laptop in question is no longer accessible.

How do I make a User profile both 'mobile' and 'managed'?
marookCommented:
Hi,

If the User is not prompted, is the user Home folder created under /Users ???
If not, there is your problem!

Remove the limitation not to promt for local user creation - make sure you create a Mobile User when logging in, and the the user account is under /Users (or where ever you allow it to store it) !!

Otherwise the user is booted over the network and nothing is local on the Mac.

When you are logged in as the user, you can also Cmd-Click on the foldername in the window and see the path to the folder - should be local. See screenshot.
path-to-folder.PNG
boomtowncioAuthor Commented:
Yes I have validates that the users Home folder is on the local machine
Screen-shot-2011-03-30-at-4.24.0.png
marookCommented:
Hmm, strange then.

And - just to make sure:
Does the login screen shake, or does it just take like 2 min. to auhenticate?
You can test by simply disconnecting the network(s)
boomtowncioAuthor Commented:
It shakes as though the password is incorrect
marookCommented:
"How do I make a User profile both 'mobile' and 'managed'?"

Mobile: A Directory user that is loacl on the Mac.
Managed: MCX preferences has been set from the Directory

Do you have a local admin account on the Mac?
If so, log in to that and check the logs in Console (/Applications/Utilities)
The All Messages should show some entries regarding the login (failure).

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
boomtowncioAuthor Commented:
Thanks marook!

I have looked at the logs via console but to tell you the truth my expertise in reviewing system events is much better in Windows.

Can you tell me what type of event I should be looking for to help me sift through the data (there is a lot!)?
boomtowncioAuthor Commented:
Still a huge delay in on login when off network
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Mac OS X

From novice to tech pro — start learning today.