Mac OS X 10.2: LDAP Users Cannot Log In, Computer Stops Responding at Login Window

When you click a user name in the Login Window of an LDAP client computer, it may briefly appear to be logging in. However, the computer becomes unresponsive (a "hang") at the progress bar, and the user is not logged in. LDAP accounts cannot log in in this circumstance.
Symptom

When you click a user name at the Login Window, it skips the password dialog and briefly appears to be logging in. The window shakes (which normally indicates incorrect password), and the system stays at the progress bar. To be able to log in as a local user after this occurs, you must force the computer to restart by pressing the power button, reset button, or appropriate keyboard shortcut as applicable to the computer model.


Solution

This happens specifically when the computer is an LDAP client and the attribute for the LDAP directory service being used is not mapped. Some LDAP servers do not store the user password in Directory Services. If the password attribute for users is not mapped, login is tried without a password and thus cannot succeed.

Follow the steps below at each affected client computer. To log in to an affected computer, select a local administrator account at the Login Window, not an LDAP user account. After logging in, follow these steps:
Published Date: Feb 17, 2012