I'm sure this is a scenario that a lot of you will have encountered before. Consider the following:
- Mac is bound to Active Directory
- An Active Directory user has previously successfully logged on to the Mac
- The user changes/has their password changed elsewhere (most commonly because they forgot it or it expired)
- The user tries to log on to the Mac
- The user receives a cryptic dialogue box about not being able to unlock the keychain. Not being familiar with what a keychain is or why they should care, the user clicks Continue Log In
- The user then receives constant requests for a "keychain password" which they have no idea what it is and they just want to get on with their work
For reference, we are mainly using OS X 10.10.5 although we do still have some 10.9 and 10.8 machines which we are hoping to update to 10.10 during the summer. We are also on Casper 9.82 with plans to update to 9.92 at or before summer.
I've seen the following workarounds/solutions to this problem:
- Simply telling the users to delete their login keychain. While this does get the messages to go away (as the login keychain is recreated using the new user password) it's a heck of a lot of faff for users to go through.
- Keychain Minder. I tried installing this for testing purposes, but it did not seem to activate when confronted with a test version of the scenario described above. Reading the documentation it seems like it's only used for screensaver unlocking and preference pane unlocking? Is there a version that works for the regular login screen? I uninstalled it after this test
- ADPassMon. I tried installing this for testing purposes and setting its Preferences to be added to the login items and to check the keychain at launch. It did load on login, but didn't activate its password update dialog automatically; if I then went into the Preferences and clicked Test Settings it worked, but obviously I'd want it to do it automatically.
It's also worth noting that none of these solutions seem to be able to replace the original system-generated dialogue that has the message about keychains and the three buttons. I appreciate it might not be possible to disable that but if it is possible I'd definitely want to do it.
What solution do you use? Is there some extra configuration that I have missed?
