Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OS X - AD integration tentative solution?



At 9:39 PM +0100 4/30/03, email@hidden wrote:
On Thursday, January 1, 1970, at 01:45 am, Michael Bartosh said goodbye to the 60's, and wrote:

In a correct configuration, the server knows it offers kerb auth, and the client gets an afpserver/email@hidden service ticket, which the server then doesn't consider valid. I haven't been able to get it to work, though (specifically with AD).
So, where am i broken? Does the server's offering kerb depend on correct config of the service principal? I used


Not sure.


ktpass -princ afpserver/email@hidden -mapuser afp -pass password -out krb5.keytab


That looks right. Do you have a tgt before you try to connect? After you try to connect, what does klist say? (klist on the Mac)


where afp is a valid user in the Users cn in the domain. (Just for reference, since there's a bug).

To overcome this, i set the home directories on the Xserve to mount via NFS, which seems to work fine - does this have any negative impact?

Security. Performance. Otherwise, no.

Just means i can go back when AFP works and say " now i'll make it faster AND more secure, for a nominal fee" ;-)



So, i now have to import all the users from AD into Open Directory (pretty simple), create their Mac homedirs (createhomedir -a) and keep them synched (some not too painful scripting). I end up with one set of users, one point of authentication, and two sets of homedirs - not necessarily a bad thing at many of my sites, where the goal is to keep the Macs mostly separate.

Why not simply use smb home dirs?

Where, on the W2K servers?

Yes on the win2k servers

how does this automount on the client?

The same way an afp automount does. You need a mount object and then the user needs a home_loc that points to an smb (rather than an afp) server.




.


still guru pestering

matt jenns


--

http://www.4am-media.com
Mac OS X Consulting and Training
Michael Bartosh
email@hidden
303.517.0272
Denver, CO


"The surest way to corrupt a youth is to instruct him to hold in higher
regard those who think alike than those who think differently."

- -- Nietzsche
Think Different.
_______________________________________________
macos-x-server mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/macos-x-server
Do not post admin requests to the list. They will be ignored.
References: 
 >Re: OS X - AD integration tentative solution? (From: email@hidden)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.