I have a shiny new Xserve running 10.4.2 and Open Directory. Everything is working fine (remote login, preference management, etc) but I’m stuck on one final topic: Administrators stored in the OD are not counted as admins of the individual computer.
For example: I have an iBook that is bound to the OD and allows me to login using an account that exists only in the OD server. It syncs with a mobil account on the server just fine. But if I go into a system preference that requires admin level rights, I can only use local admins; not server-side admins.
Is there a way to create an account on the server that will have rights to change high level stuff like system preferences? Is there also a way to create an account that can only admin other computers but not the server (for a department with a student technician that isn’t trusted with full access to the server)?
Comments are closed