Home › Forums › OS X Server and Client Discussion › Active Directory › A few problems (AD/OD integration)
- This topic has 3 replies, 3 voices, and was last updated 20 years, 4 months ago by
afp548contributor.
-
AuthorPosts
-
November 26, 2004 at 8:13 pm #360003
szumlins
ParticipantOkay, I now have a working AD/OD setup. Hooray! Users can auth via the AD server and then get their managed settings from OD groups. I also have network home directories working and mounting properly. I am running into a couple of problems/issues however and was wondering if anyone had any ideas.
1) The group folder attempts to mount on startup via the Group Folder directive on the OD server, but it doesn’t seem to be kerberized (ie, users are prompted to authenticate to the server the instant they log in)
2) We currently do not use a managed environment for our users and all files are stored locally. The only issue I foresee going to the networked home directory method is music. Our users have lots of music on their local machines. 99% of the time the users are on their own machines, so moving from box to box isn’t the issue. I DON’T want that music on the network server. I figure most of our users have between 500MB and 1GB of their own music on their machine. Times that by the 100+ users I manage…well, you get the idea. Is it possible to symlink or move the iTunes default folder pre-setup?
3) About 40% of our users are laptop users. I can’t find a good explanation of how to make sure their network home directory IS synced locally so when they walk away and plug back in on Monday morning everything hops back to being A-OK. Any ideas.
A bit long winded for a first post, eh? Thanks for any input you guys/gals might have.
November 29, 2004 at 7:03 pm #360023szumlins
Participant[QUOTE BY= MacTroll] 1) This is because you have not integrated the AFP server on the OSXS into the AD kerberos realm. Once you do this the authentication will be done over kerberos, but right now your users are getting a TGT from AD which is useless against the OSXS.
[/QUOTE]I’m assuming I do this by using /System/Library/CoreServices/Kerberos.app on the OSXS. I got new tickets on the server and everything but the client still asks for authentication upon login to get to the group share. Maybe I’m doing it wrong?
[QUOTE BY= MacTroll]
2) You can try using a symlink, not an alias so you’ll need to do this from the CLI, from the network home “music” folder to a local path, like /Library/LocalMusic/
[/QUOTE]Symlink seemed to work okay so far on my testing across two machines. The odd side affect is that the iTunes library file is local too, so you get whoever’s music library that machine belongs to no matter who you log in as. I’m expanding people’s aural horizons and I’m not even trying.
[QUOTE BY= MacTroll]
3) Tiger
[/QUOTE]
Doh! -
AuthorPosts
- You must be logged in to reply to this topic.
Comments are closed