Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OS X - AD integration - Kerberos question



>> So, i now have to import all the users from AD into Open Directory
>> (pretty simple), create their Mac homedirs (createhomedir -a) and
>> keep them synched (some not too painful scripting).

in setting up Kerberos auth against AD (so that a kerb account is req for
login success), this is the one thing I don't understand: do you really need
to maintain a copy of all the AD users in OD as well?

and which attributes need to be present in the OD domain to allow this? just
shortname and UID? what approaches are people taking to accomplish the
import of AD data to OD?

I want the security of Kerberos but am wary of importing thousands of users
into Netinfo...

thanks,

justin.


--
Justin Krisko
Apple Support
Knowledge & IT Services Centre

Edith Cowan University
Perth, Western Australia
http://www.ecu.edu.au
_______________________________________________
macos-x-server mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/macos-x-server
Do not post admin requests to the list. They will be ignored.



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.