Home › Forums › OS X Server and Client Discussion › Active Directory › Switching to managed users under 10.4 server
- This topic has 4 replies, 2 voices, and was last updated 18 years, 8 months ago by
afp548contributor.
-
AuthorPosts
-
August 10, 2006 at 12:13 pm #366786
Anonymous
GuestHello,
I am currently playing with Mac OS X Tiger Server and I am stuck. We have an XServe that was used as a file server only and we have several macs with local admin accounts.
ToDo:
1. Make all the users to authenticate against server, not locally.
2. Make all users "managed" (change their preferences server-side) but leave their home folders local.
3. Set up a Software Update Server (done) and with Workgroup Manager make all users to use it instead of Apple’s.
4. As all the macs are in the working environment we need to preserve existing users, just convert them to "managed".What I tried (my G5 workstation was chosen for testing):
1. Started Open Directory service.
2. Made it an Open Directory Master.
3. Started Workgroup Manager and authenticated to LDAPv3 directory.
4. Created a user with the same name and password as my local G5 admin user.
5. Changed dock preferences for this user to quickly notice if it works.
6. On my G5 I started Directory Access, enabled LDAPv3 and added a server checking "use for authentication".
7. Binded this computer to server.
8. Changed to Authentication -> Cutom path and added a directory domain from the list.What I achieved:
1. Nothing (I rebooted and logged in but the dock behavior didn’t change, although the DirectoryService.server.log showed the successful connection).
2. When I created another user in Workgroup Manager and logged in as him to my local G5 everything worked as I expected to. There was a new home folder with default settings created although this user is not listed in the local accounts list. This is more or less acceptable but I’d prefer not to start from scratch but use existing accounts.What am I doing wrong?
Thank you!
August 10, 2006 at 12:20 pm #366787friendly
ParticipantJust registered. The above posting is mine.
August 14, 2006 at 2:07 pm #366810friendly
Participant[QUOTE][u]Quote by: macshome[/u]
I have a really old article on converting local accounts to mobile accounts if you aren’t doing network homes here. The article gives you the idea of how it works, but now I wouldn’t mess with the folder re-naming stuff. I would just login as local admin, delete the user using Netinfo Manager, chown the home folder, and have them login.
[/QUOTE]
This looks like a very promising solution to me. Could you explain that Netinfo stuff a bit deeper? Should I delete an appropriate group as well? Who is going to be the new home owner?
Thank you very much!
-
AuthorPosts
- You must be logged in to reply to this topic.
Comments are closed