Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
Help please
OSX Server 4, fresh install on mac mini.

Trying to configure Open Directory for my home use. Theoretically all is working fine, but I have some options grayed out - see example below from users list (I cannot edit password policy etc.)

I could access all of those before turning on Open Directory.

Any idea what is wrong?
 

Attachments

  • Screen Shot 2014-12-03 at 23.45.17.png
    Screen Shot 2014-12-03 at 23.45.17.png
    394.2 KB · Views: 646

Altemose

macrumors G3
Mar 26, 2013
9,189
488
Elkton, Maryland
Help please
OSX Server 4, fresh install on mac mini.

Trying to configure Open Directory for my home use. Theoretically all is working fine, but I have some options grayed out - see example below from users list (I cannot edit password policy etc.)

I could access all of those before turning on Open Directory.

Any idea what is wrong?

That user is a local user and not a network user.
 

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
Yes I know - just used it for the screenshot.
The same is with the network users - options grayed out :(
 

gavinstubbs09

macrumors 65816
Feb 17, 2013
1,386
256
NorCal boonies ~~~by Reno sorta
I'm experiencing the same issue. Last week I upgraded a lab from yosemite to Mavericks and my OD was ruined so I had to add all the users back manually. What worked for me was to load the server app up on another machine and connect to the server from there. Then press the unlock in the corner of the user window and sign in with your diradmin account.

Kind of a pita but it works, and going back to MV would put the lab out another week which I can't have.
 

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
.. Then press the unlock in the corner of the user window and sign in with your diradmin account.

sorry - I'm trying to follow-up your solution, but don't understand.
Which user window are you referring to?
In server.app users window there is no unlock ...
 

gavinstubbs09

macrumors 65816
Feb 17, 2013
1,386
256
NorCal boonies ~~~by Reno sorta
sorry - I'm trying to follow-up your solution, but don't understand.
Which user window are you referring to?
In server.app users window there is no unlock ...

Ok. I have a client iMac, and I copied the server.app off the server and ran it on iMac.

Open it, and connect to the server through the app, go to users on the side, and in the bottom left corner next to the +/- button should be a lock if you are not using the server. Unlock that with diradmin and you can edit users/add/delete them again.
 

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
Well - in my case I have no lock (running form server or from external machine in my case is the same).

I believe that our problems are slightly different - I can add/remove users. I do not have all rights as soon as I turn on open directory. I tried to loging with server admin, with OD admin (diradmin), I even activated root and logged with it - no change.

It is really frustrating
I started over, format my macmini, reinstalled yosemite OS, installed server 4 - still the same.
As soon as I turn on open directory I am blocked with some admin activities (eg I cannot define password policies for users).

See below - right screenshoot - OD disabled - I have all rights (including advanced options), left screenshot - OD enabled - I have limmitted rights :(

anybody? any idea - what can be wrong?
 

Attachments

  • p1.png
    p1.png
    380.7 KB · Views: 442
  • p2.png
    p2.png
    249.5 KB · Views: 383

chrfr

macrumors G5
Jul 11, 2009
13,709
7,280
Well - in my case I have no lock (running form server or from external machine in my case is the same).

I believe that our problems are slightly different - I can add/remove users. I do not have all rights as soon as I turn on open directory. I tried to loging with server admin, with OD admin (diradmin), I even activated root and logged with it - no change.

What's the output of
Code:
sudo changeip -checkhostname
in a terminal window?
 

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
thanks for the replay
I'm not at my machine now, but I tested it before and got "success"
 

am2am

macrumors regular
Original poster
Oct 15, 2011
223
103
OK - solved it.
The solution is .. simple.

I have been wondering why I don's see lock mentioned by gavinstubbs09
I have also read discussions about similar problems on apple forum and found a hint there.

I have always been accessing users screen in server app with "All Users" selected. At least in my case with this view I have limited rights.
As soon as I select "Local Users" or "Local Network Users" (where I finally found the lock icon :) ) I have access to all functions including password reset and templates.

I believe it is the result of admin and diradmin rights separation.

Anyhow - problem solved. Thank you all who tried to help.
 

gavinstubbs09

macrumors 65816
Feb 17, 2013
1,386
256
NorCal boonies ~~~by Reno sorta
OK - solved it.
The solution is .. simple.

I have been wondering why I don's see lock mentioned by gavinstubbs09
I have also read discussions about similar problems on apple forum and found a hint there.

I have always been accessing users screen in server app with "All Users" selected. At least in my case with this view I have limited rights.
As soon as I select "Local Users" or "Local Network Users" (where I finally found the lock icon :) ) I have access to all functions including password reset and templates.

I believe it is the result of admin and diradmin rights separation.

Anyhow - problem solved. Thank you all who tried to help.

Actually I was on the server and noticed this myself, where I had to be under Local Network Users instead of All Users.

Next problem: time to figure out why some people can log in and others can't. Figured Profile Manager out too (not pushing out settings, I had to delete a certificate), that was a nightmare.
 

gavinstubbs09

macrumors 65816
Feb 17, 2013
1,386
256
NorCal boonies ~~~by Reno sorta
Fixed it.

On a few accounts I had to go to "Edit Access to Services..." and some accounts only had Calender and File Sharing checked. If I check all of them they can log in just fine and get to the point where they can sign in with iCloud.

Weird.
 

Attachments

  • Screen Shot 2014-12-08 at 12.12.27 PM.png
    Screen Shot 2014-12-08 at 12.12.27 PM.png
    36.9 KB · Views: 303
  • Screen Shot 2014-12-08 at 12.06.45 PM.png
    Screen Shot 2014-12-08 at 12.06.45 PM.png
    44.8 KB · Views: 276
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.