Posts Tagged ‘authentication

On Mac OS X v10.6-based systems, the LDAP server specified via DHCP option 95 is no longer added to the search base by default.  This reduces the possibility of an unauthorized DHCP server being used to add an LDAP directory domain to the authentication search path on a client.  The new behavior locates LDAP servers via Bonjour and then places any DHCP-supplied LDAP servers at the top of the list of servers available for binding.

Important: Follow the instructions in the Upgrade and Migration administration guide. The below article supplements, but does not replace, those instructions. Some Wiki service server settings may not be automatically preserved when migrating or upgrading Mac OS X Server v10.5 to Mac OS X Server v10.6. These include: Clear Text Authentication (enableClearTextAuth) may not be enabled. Web Calendar may not be enabled.

In certain cases, it may be desirable to rebuild the Kerberos Key Distribution Center (KDC) on a 10.5 server in a manner that retains the existing databases for LDAP and PasswordServer.  The steps outlined in this article will accomplish this. Note: You must have at least one of the “Recoverable Authentication Methods” (WebDAV-Digest and/or APOP) checked in the Policy tab under Settings for the Open Directory service in Server Admin, otherwise passwords will not be recreated properly.   Important: Be sure to back up the files mentioned in the steps below prior to editing or deleting them.

Filed under: Software , Security Thursby Software is a longtime Mac development firm (since 1986) that has always had a mission: integrating Macs as full players in mixed-OS environments. While Mac OS X has gone a long way toward improving the situation of Mac users in predominantly Microsoft environments, there are still situations where third-party software may be required


About this blog

The outside of the box said "Windows base machine or better", so I bought a Mac.

Specials

Stay Tuned! To our daily articles to help you get the most out of your Mac.


Your Ad Here Your Ad Here