Binding to AD during imaging

catfeetstop
Contributor II

Binding to AD during the imaging process has always been iffy for me. Sometimes it works, sometimes it doesn't. I can't figure out any rhyme or reason as to why this is happening. I want to be able to log into an AD account immediately after imaging. I have a first boot script that is run during the imaging process. The end of that script pauses for 2 minutes and reboots itself when complete. At one point I thought that might help the AD binding process finish. Do you guys have any ideas how I can fix this?

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

2 ACCEPTED SOLUTIONS

catfeetstop
Contributor II

Thanks for all the help you guys. I'm going to try removing the AD binding from the imaging configuration and I'm going to add a manual policy trigger for the AD binding in the firstboot script to see what happens.

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

View solution in original post

catfeetstop
Contributor II

I wanted to say thanks to everyone for all their help on this issue. After upgrading the JSS and removing old computer records from AD I'm able to bind during imaging just fine. Thanks again!

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

View solution in original post

17 REPLIES 17

Matt
Valued Contributor

Try using a smart group. I have a smart group that finds all computers that aren't bound and bind them on the any trigger.
--
Matt Lee, CCA/ACA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

catfeetstop
Contributor II

For some reason I'm not even able to bind once I boot up, open Terminal and use a manual binding trigger. It appears as if the policy works but then when I look in Directory Utility I am not bound nor can I log in to AD user accounts. I am able to bind manually through Directory Utility though.

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

catfeetstop
Contributor II

I'm still running Casper 8.22. I wonder if the newer versions are better at binding Lion machines to AD?

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

Matt
Valued Contributor

10.7.2 + the newest JSS version will most likely fix the issue.
--
Matt Lee, CCA/ACA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

ernstcs
Contributor III

So you aren't using the AD binding capabilities within Casper? Or are you?

Craig E

catfeetstop
Contributor II

I am. In the imaging configuration there is a step to use an AD directory binding.

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

ernstcs
Contributor III

On systems that have failed have you dug into the Directory Services logs or into the JAMF log to see what it says happens during that step during imaging?

catfeetstop
Contributor II

Here's what the jamf.log says:

jamf [1236]: Binding jhstu-0001 to domain.net<http://domain.net>
jamf [1236]: Bound to Active Directory (domain.net<http://domain.net>)
jamf [1303]: Running Script CommonSettings.sh...

According to that it worked. I wonder if I should put a pause at the beginning of the CommonSettings.sh? I can't find the DirectoryServices.log, where is that in Lion?

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

nessts
Valued Contributor II

just out of curiosity are you using a 10.7.2 lion base image?
AD binding was very broken in previous versions…
--
Todd Ness
Technology Consultant/Non-Windows Services
Americas Regional Delivery Engineering
HP Enterprise Services

catfeetstop
Contributor II

It is 10.7.2. I had this same issue with 10.6 machines too. I'm going to put a little break at the beginning of the script and see what happens.

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

bentoms
Release Candidate Programs Tester

Works fine for me on 10.6 & 10.7.

Does it work when manually bound? Are any settings different?

Regards,

Ben.

ernstcs
Contributor III

I actually didn't dig much into Lion for AD, I waited until 10.7.2 and things worked OK.

It appears the log may have changed and uses the name opendirectoryd.log instead of Directory Services. I'd have to look it up otherwise. What wasn't helpful before was that you didn't always get enough detail in the log until you put it into a higher logging/debug mode.

I wish I had more time to help today...

Craig E

bentoms
Release Candidate Programs Tester

Rather than directory services being under different versions of the app. They are now plugins, so during the transistion I guess they've not tidied up the logs.

Regards,

Ben.

catfeetstop
Contributor II

Thanks for all the help you guys. I'm going to try removing the AD binding from the imaging configuration and I'm going to add a manual policy trigger for the AD binding in the firstboot script to see what happens.

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

catfeetstop
Contributor II

Excellent, I'll upgrade tomorrow. Thanks to you all for all your help!

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

catfeetstop
Contributor II

I wanted to say thanks to everyone for all their help on this issue. After upgrading the JSS and removing old computer records from AD I'm able to bind during imaging just fine. Thanks again!

Jamie Bell
Apple Technology Specialist
The Westminster Schools
Ph: 404-609-6345

Matt
Valued Contributor

Thats great!
--
Matt Lee, CCA/ACA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group