Quantcast
Channel: StudioSysAdmins Message Board
Viewing all articles
Browse latest Browse all 3749

Mac Can't Retrieve Group GID's

$
0
0
Mac Can't Retrieve Group GID's
posted by Jeff Yana on Dec. 26, 2013, 5:20 p.m. (1 day ago)
Are you using any 3rd party AD add-ons or custom GPOs? If so be sure take those out of the equation.

You might want to start by enabling directory services debugging on the Mac client to troubleshoot your issue. Then observe what is happening when unbinding and rebinding to AD:

To enable:
odutil set log debug
To diable:
odutil set log default
On odutil(1), you will find a more detailed explanation here: 


Additionally, while it does not go into any great detail about your specific issue, you might find this white paper helpful:


Along with running odutil, I would suggest doing a packet capture. I would also check AD Event Logs to see if anything interesting appears there as well. Be sure to place all of your Macs into the default Computers container using only the default domain GPO. Default event logging on the Windows side is usually anemic so you should see if you can crank up verbosity there, just cannot remember how off-hand

Good luck!


On Dec 26, 2013, at 8:00 AM, studiosysadmins-discuss-request@studiosysadmins.com wrote:


I've got a bunch of Mac OS X 10.8 and 10.9 bound to Active Directory. They authenticate just fine.

I have not installed SFU. I do not want to use NIS. AD 2012 has the RFC 2307 attributes already in place.

In Active Directory, I have manually entered UID's and GID's in to User objects.  The Mac clients retrieve User UID's and GID's from the user objects just fine based on the "Mappings" window in the Directory Utility. 

The problem I'm having is that 

I found that if I map the "Map group GID" option to the AD attribute "gidNumber", then NO group membership is retrieved from Active Directory 2102 "Member of"  tab. 
 
If I do NOT map "Map group GID to attribute", then group membership IS retrieved from AD,  except the Primary Group  "Domain Users".
 
But if I leave the item unmapped and the Mac's retrieve the group memberships, the Mac's do not retrieve the GID's I allocated to the Group Objects. They are apparently hashing some value and  deriving their own numeric identifier for the groups of which the user is a member.
 
Then this value is getting stamped onto a shared file system. Because this is a Mac-generated value, this will be a problem in a multi-platform environment.
 
Has anyone out there seen this issue? Resolved it some how? I can't seem to find any documentation on it anywhere.

Thread Tags:
  discuss-at-studiosysadmins 

0 Responses   0 Plus One's   0 Comments  
 
Are you using any 3rd party AD add-ons or custom GPOs? If so be sure take those out of the equation.

You might want to start by enabling directory services debugging on the Mac client to troubleshoot your issue. Then observe what is happening when unbinding and rebinding to AD:

To enable:
odutil set log debug
To diable:
odutil set log default
On odutil(1), you will find a more detailed explanation here: 


Additionally, while it does not go into any great detail about your specific issue, you might find this white paper helpful:


Along with running odutil, I would suggest doing a packet capture. I would also check AD Event Logs to see if anything interesting appears there as well. Be sure to place all of your Macs into the default Computers container using only the default domain GPO. Default event logging on the Windows side is usually anemic so you should see if you can crank up verbosity there, just cannot remember how off-hand

Good luck!


On Dec 26, 2013, at 8:00 AM, studiosysadmins-discuss-request@studiosysadmins.com wrote:


I've got a bunch of Mac OS X 10.8 and 10.9 bound to Active Directory. They authenticate just fine.

I have not installed SFU. I do not want to use NIS. AD 2012 has the RFC 2307 attributes already in place.

In Active Directory, I have manually entered UID's and GID's in to User objects.  The Mac clients retrieve User UID's and GID's from the user objects just fine based on the "Mappings" window in the Directory Utility. 

The problem I'm having is that 

I found that if I map the "Map group GID" option to the AD attribute "gidNumber", then NO group membership is retrieved from Active Directory 2102 "Member of"  tab. 
 
If I do NOT map "Map group GID to attribute", then group membership IS retrieved from AD,  except the Primary Group  "Domain Users".
 
But if I leave the item unmapped and the Mac's retrieve the group memberships, the Mac's do not retrieve the GID's I allocated to the Group Objects. They are apparently hashing some value and  deriving their own numeric identifier for the groups of which the user is a member.
 
Then this value is getting stamped onto a shared file system. Because this is a Mac-generated value, this will be a problem in a multi-platform environment.
 
Has anyone out there seen this issue? Resolved it some how? I can't seem to find any documentation on it anywhere.


Viewing all articles
Browse latest Browse all 3749

Trending Articles