My Xserve is an AD client using the golden triangle approach, so it’s currently an OD master. The AD server doesn’t have the unix attributes enabled, so UID’s are really large numbers. I’d like to take advantage of a separate OpenLDAP server for unix attributes to keep them the same throughout our workplace. I have the Xserve already joined to the OpenLDAP server and I can see my account via Workgroup Manager, but when I type “id” in the Terminal, I still get the AD attributes. The server is still running the Open Directory services, but I have the OpenLDAP server set above Open Directory in Directory Access Authentication. Do I need to turn Open Directory off? If I do, will I mess up the AD binding?
Comments are closed