After a few missteps, I have successfully set up Open Directory on our customers network (3 Xserves running 10.3, ~15 clients, all but one is a mac running 10.3). The client wanted Open Directory as a way of implementing an enforcible, centralized password policy. What is the best way to actually implement this? Right now, the clients each have local accounts, and the users connect to the servers to access the file server and email. Is there a good way to force the users to synchronize their local and network passwords? Should I modify /etc/authorization to make them get kerberos tickets? What about road warrriors?
Comments are closed