image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
LinkBack Thread Tools
  #1  
Old February 4th, 2009, 03:52 PM
Registered User
 
Join Date: Feb 2009
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
macotec is on a distinguished road
Authenticating OS X Tiger to AD

I am trying to correcting an ailing implementation of Tiger to authenticate user credentials against Active Directory.

Question 1: Should I have the slapd service running?
Question 2: Do I need both AD and LDAPv3 plugins?

Question 3: Are the mappings below correct for LDAPv3?
Default Attribute Types
RecordName = cn

Users
organizationalPerson
user
cn=Users, DC-star, DC=lcc, DC=edu, 'all subtrees'

RecordName
sAMAccountName

UniqueID
uSNCreated

RealName
displayName

Password

PrimaryGroupID
#20


Question 4: Do I need the authentication Distinguished Name: under LDAPv3, Configure, Edit entry, Security to be just the name of the user authentication into the directory or cn=, ou=, dc=, dc=, dc= form.

Question 5: Do I need the Open Directory -> Protocols -> LDAP Settings , Search Base and Database settings assigned or is that only if the machine is supplying it's own LDAP services. NOTE: this servers role is "connected to a Directory System".


Thanks for help.
Reply With Quote
  #2  
Old March 2nd, 2009, 01:57 AM
Michael Dhaliwal, ACSA
 
Join Date: Mar 2003
Location: Chicago, IL
Posts: 1,071
Thanks: 0
Thanked 3 Times in 3 Posts
Go3iverson is on a distinguished road
Questions 1 & 2 - depends on what you're trying to do. If you're trying to vend MCX settings from an OD supplementing the AD schema, then you should have slapd running and both plugins. If you are just trying to authenticate your server against AD or your client machines against OD, you don't need to run the Open Directory service on Mac OS X Server, just bind directly against the AD

Question 3 - Looks OK, but that's dependent on your environment

Question 4 & 5 - You usually want to leave these as the default settings supplied from the AD when you bind the Mac OS X Server to the AD domain itself.

Do you have any other specifics on what you are trying to accomplish with this setup, besides just authentication? Are you trying to allow certain services on OS X use AD authentication?

Michael
__________________
Michael Dhaliwal
ACSA, Xsan Certified, etc, etc...
District13 Computing
Reply With Quote
Reply

Bookmarks

Tags
active directory, ldapv3, mapping ldapv3 to ad, osx

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 03:07 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.