Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: 10.2 Win2K LDAP authentication



At 9:25 AM +1200 9/10/02, Bruce Webster wrote:
Yes - was that using LDAPv2 or v3?
I'll investigate the Kerberos option.

Both (I've been doing a lot of Jaguar testing)


I copied all LDAPv2 Directory Access settings from a working 10.1.5 setup to 10.2.
On login, the 10.2 client dumps you to a full-screen console where you can login and get your home dir! I think this is a bug in OSX 10.2 LDAPv2 1.5

That Windowserver crashes when authentication is broken is a bug- but I wouldn't expect 10.1.5's preference files to work in Jaguar.

I wasn't clear. By 'copy' I mean I had the two machines side-by-side and entered identical settings into Jaguar.

Ah.


I tried LDAPv3 too and so far it hasn't worked at all - the login screen just shakes.

How did you mak attributes?

I started with the 'Active Directory' mappings and set connection authentication like the working LDAPv2 setup. The mappings looked OK, but I may need to change something.

have you tried tracing things with lookupd -d?

Can an OSX user change their AD password?

Good question. v2 no.

v3... theoretically. The Dir Srv v3 plugin is read / write. Provided you were autheticated to said directory... maybe. That said, I have not been able to get the v3 plugin to work with any sort of acls (self-write, for instance, which is generally used to allow users to change their passwd).

--
http://www.4am-media.com
Mac OS X Consulting and Training
Michael Bartosh
email@hidden
303.517.0272
Denver, CO


"The surest way to corrupt a youth is to instruct him to hold in higher
regard those who think alike than those who think differently."

- -- Nietzsche
Think Different.
_______________________________________________
maclabmanager mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/maclabmanager
Do not post admin requests to the list. They will be ignored.
References: 
 >Re: 10.2 Win2K LDAP authentication (From: Bruce Webster <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.