Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > authenticating 10.4 off ldap client - almost...

authenticating 10.4 off ldap client - almost...
Thread Tools
Fresh-Faced Recruit
Join Date: Nov 2009
Status: Offline
Reply With Quote
Nov 24, 2009, 01:06 PM
 
I've set up various Macs to authenticate off LDAP, so I get the general idea, but I've hit a problem I've never seen before, and I'm hoping someone else can offer suggestions.

The client is running OS 10.4.11, and the connection is set up through Directory Access. I can authenticate OK using the usual command line tools - dscl, dirt, lookupd - but when I try at the actual login window, I fail with the shaking login box. Even /usr/bin/login works to authenticate an LDAP user and gives a command shell.

It's a secure LDAP connection, which I haven't done before, but I think I have the certificate authority set up right, since I can login at the command line, get the record with dscl, etc. The connection also uses an authentication login, but I assume that works for the same reason.

Could it be my attribute mappings? Looks like /usr/bin/login and the login window request a slightly different list, according to DirectoryService.debug.log. I wasn't sure if I need AuthenticationAuthority and what to put for a value. Also, it requests two that I don't even see available in the Directory Access mapping list: CopyTimestamp and OriginalNodeName

If the problem is attributes, which ones does 10.4 even need? I don't need any on the client, I just want to know if the username/password is right and log a user in.

Thanks for any insights.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 04:39 PM.
All contents of these forums © 1995-2009 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.4 © 2000-2009, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2