Active Directory Woes on 10.5 Server

noah_swanson
New Contributor

Yesterday our Mac Server lost partial DNS. I can still access it through its IP and DNS name, but when I tag our domain onto it <server>.<domain>.<company>.com I get no response. I went to unbind and rebind to the domain and Directory Utility locked up the server and required a force reboot. If I open Directory Utility it says the connection is good however, there's no computer account in AD anymore. I then tried to use the dsconfigad command in Terminal only to have Terminal lock up.

Has anyone seen this or know of a way I can unbind without locking up again?

Noah Swanson
Imaging Specialist
Enterprise Desktop Services
Phone: 309-765-3153
SwansonNoah at johndeere.com

7 REPLIES 7

Kedgar
Contributor

Try daconfigad -rf

This should force a removal from the domain.

Sent from Ken's iPhone

noah_swanson
New Contributor

Worked great. However, when I tried to rebind, it locked up again. I’m guessing there’s a corrupt plist or cache somewhere…Anyone know the exact files I should trash before attempting to rebind?

Not applicable

When this happens to one of my Mac servers I delete the Directory Service folder, empty trash and reboot then rebind:

MacHD > Library > Preferences> DirectoryService

tlarkin
Honored Contributor

Did you fully unbind first?

noah_swanson
New Contributor

Yep. Full unbind, removed the account from AD even.

tlarkin
Honored Contributor

Look at the dsconfigldap command to fully force unbind and to clear all
caches

Not applicable

If you just can't get the server to bind, create the computer object in AD first (with the server's name) and rebind.

Tony S. Wu
tonyswu.mac at gmail.com