设为首页 收藏本站
查看: 711|回复: 0

[经验分享] Mac OS X:Configuring Access to an Active Directory Domain

[复制链接]

尚未签到

发表于 2016-5-16 10:47:40 | 显示全部楼层 |阅读模式
Server Admin 10.6 Help
Configuring Access to an Active Directory Domain

Using the Active Directory connector listed in Directory Utility, you can configure MacOSX to access basic user accountinformation in an Active Directory domain on a Windows server.
The Active Directory connector generates all attributes required for MacOSX authentication. No changes to the Active Directoryschema are required.
The Active Directory connector detects and accesses standard MacOSX record types and attributes (such as the attributesrequired for MacOSX client management), if the Active Directory schema has been extended to include them.
WARNING:Withthe advanced options of the Active Directory connector, you can map to the MacOSX unique user ID (UID), primary groupID (GID), and group GID attribute to the correctattributes that have been added to the Active Directory schema. If you changethe setting of these mapping options later, users might lose access to previously created files.

Important:If your computer name contains a hyphen you might not be able to join or bind to a Directory Domain such as LDAP or ActiveDirectory. To establish binding, use a computer name that does not contain a hyphen.


To configure access to an Active Directory domain:


  • Open System Preferences and click Accounts.
  • If the lock icon is locked, unlock it by clicking it and entering the name and password of an administrator.
  • Click Login Options, then click Join or Edit.
  • Click Open Directory Utility.
  • If the lock icon is locked, unlock it by clicking it and entering the name and password of an administrator.
  • Click Services.
  • In the list of services, select Active Directory and click the Edit (/) button.
  • Enter the DNS name of the Active Directory domain you want to bind to the computer you’re configuring.
    The administrator of the Active Directory domain can tell you the DNS name to enter.
  • If necessary, edit the Computer ID.
    The Computer ID is the name the computer is known by in the Active Directory domain, and it’s preset to the name of the computer.You might change this to conform to your organization’s established scheme for naming computers in the Active Directory domain.If you’re not sure, ask the Active Directory domain administrator.
  • (Optional) Set advanced options.
    If the advanced options are hidden, click Show Advanced Options and set options in the User Experience, Mappings, and Administrativepanes. You can also change advanced option settings later.
    For more information about advanced options, see:

    • Setting Up Mobile User Accounts in Active Directory
    • Setting Up Home Folders for Active Directory User Accounts
    • Setting a UNIX Shell for Active Directory User Accounts
    • Mapping the UID to an Active Directory Attribute
    • Mapping the Primary Group ID to an Active Directory Attribute
    • Mapping the Group ID in Group Accounts to an Active Directory Attribute
    • Specifying a Preferred Active Directory Server
    • Changing the Active Directory Groups That Can Administer the Computer
    • Controlling Authentication from All Domains in the Active Directory Forest

  • Click Bind, use the following to authenticate as a user who has rights to bind a computer to the Active Directory domain,select the search policies you want Active Directory added to (see below), and click OK:

    • Username and Password: Youmight be able to authenticate by entering the name and password of yourActive Directory user account, or the Active Directorydomain administrator might need to provide a name and password.
    • Computer OU: Enter the organizational unit (OU) for the computer you’re configuring.
    • Use for authentication: Use to determine whether Active Directory is added to the computer’s authentication search policy.
    • Use for contacts: Use to determine whether Active Directory is added to the computer’s contacts search policy.
    When you click OK, Directory Utility sets up trusted binding between the computer you’re configuring and the Active Directoryserver. The computer’s search policies are set according to the options you selected when you authenticated, and Active Directoryis enabled in Directory Utility’s Services pane.
    With the default settings for Active Directory advanced options, the Active Directory forest is added to the computer’s authenticationsearch policy and contacts search policy if you selected “Use for authentication” or “Use for contacts.”
    However, if you deselect “Allow authentication from any domain in the forest” in the Administrative advanced options panebefore clicking Bind, the nearest Active Directory domain is added instead of the forest.
    You can change search policies later by adding or removing the Active Directory forest or individual domains. For more information,see Defining Custom Search Policies.

  • (Optional) Join the server to the Active Directory Kerberos realm:

    • On the server or an administrator computer that can connect to the server, open Server Admin and select Open Directory forthe server.
    • Click Settings, then click General.
    • Click Join Kerberos, then choose the Active Directory Kerberos realm from the pop-up menu and enter credentials for a localadministrator on this server.


For more information, see Joining a Server to a Kerberos Realm.

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-217700-1-1.html 上篇帖子: mac os terminal hot key 下篇帖子: Mac OS X: Launchd执行程序的一个例子
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表