Mac OS X Server User Managment

Total Page:16

File Type:pdf, Size:1020Kb

Mac OS X Server User Managment Mac OS X Server User Management Version 10.6 Snow Leopard K Apple Inc. Apple, the Apple logo, AirPort, AppleShare, Bonjour, © 2009 Apple Inc. All rights reserved. FireWire, iCal, iTunes, Mac, Mac OS, MacBook, Macintosh, QuickTime, SuperDrive, Xgrid, Xsan, and Xserve are The owner or authorized user of a valid copy of trademarks of Apple Inc., registered in the U.S. and other Mac OS X Server software may reproduce this countries. Apple Remote Desktop, Extensions Manager, publication for the purpose of learning to use such Finder, iWork, and Safari are trademarks of Apple Inc. software. No part of this publication may be reproduced Mac is a service mark of Apple Inc. or transmitted for commercial purposes, such as selling copies of this publication or for providing paid-for Adobe and PostScript are trademarks of Adobe Systems support services. Incorporated. Every effort has been made to ensure that the The Bluetooth® word mark and logos are registered information in this manual is accurate. Apple Inc. is not trademarks owned by the Bluetooth SIG, Inc. and any responsible for printing or clerical errors. use of such marks by Apple is under license. Apple Java and all Java-based trademarks and logos 1 Infinite Loop are trademarks or registered trademarks of Sun Cupertino, CA 95014-2084 Microsystems, Inc. in the U.S. and other countries. 408-996-1010 www.apple.com UNIX is a registered trademark of The Open Group. Use of the “keyboard” Apple logo (Option-Shift-K) for Other company and product names mentioned herein commercial purposes without the prior written consent are trademarks of their respective companies. Mention of Apple may constitute trademark infringement and of third-party products is for informational purposes unfair competition in violation of federal and state laws. only and constitutes neither an endorsement nor a recommendation. Apple assumes no responsibility with regard to the performance of these products. 019-1415/2009-08-01 Contents 13 Preface: About This Guide 13 What’s New in Workgroup Manager 14 What’s in This Guide 15 Using Onscreen Help 16 Documentation Map 17 Viewing PDF Guides Onscreen 17 Printing PDF Guides 18 Getting Documentation Updates 18 Getting Additional Information 19 Chapter 1: User Management Overview 19 Tools for User Management 19 Workgroup Manager 20 Server Admin 21 Server Preferences 21 Command-Line Tools 21 Accounts 22 Administrator Accounts 23 User Accounts 24 Group Accounts 25 Computer Accounts 25 Computer Groups 25 The User Experience 25 Authentication and Identity Validation 27 Information Access Control 28 SIDs and Windows Interoperability 29 Chapter 2: Getting Started with User Management 29 Setup Overview 32 Planning Strategies for User Management 32 Analyzing Your Environment 33 Identifying Directory Services Requirements 33 Determining Server and Storage Requirements 3 35 Choosing a Home Folder Structure 36 Devising a Home Folder Distribution Strategy 36 Identifying Groups 37 Determining Administrator Requirements 38 Chapter 3: Getting Started with Workgroup Manager 38 Configuring the Administrator’s Computer and Account 38 Setting Up an Administrator Computer 39 Creating a Directory Administrator Account 40 Using Workgroup Manager 40 Using Mac OS X Server v10.6 to Administer Earlier Versions of Mac OS X 40 Connecting and Authenticating to Directory Domains in Workgroup Manager 41 Major Workgroup Manager Tasks 42 Modifying Workgroup Manager Preferences 43 Finding and Listing Accounts 43 Working with Account Lists in Workgroup Manager 44 Listing Accounts in the Local Directory Domain 44 Listing Accounts in Search Policy Directory Domains 45 Listing Accounts in Available Directory Domains 46 Refreshing Account Lists 46 Finding Specific Accounts in a List 47 Using Advanced Search 47 Sorting Users and Groups 48 Shortcuts for Working with Accounts 48 Using Presets 48 Editing Multiple Accounts Simultaneously 50 Importing and Exporting Account Information 51 Chapter 4: Setting Up User Accounts 51 About User Accounts 51 Where User Accounts Are Stored 52 Predefined User Accounts 53 Administering User Accounts 53 Creating User Accounts 57 Creating Augmented User Records 58 Editing User Account Information 59 Editing User Account Information from the Command Line 59 Working with Read-Only User Accounts 60 Working with Guest Users 60 Working with Windows User Accounts 61 Deleting a User Account 62 Disabling a User Account 63 Working with Presets 4 Contents 63 Creating a Preset for User Accounts 64 Using Presets to Create Accounts 64 Renaming Presets 64 Editing Presets 65 Deleting a Preset 65 Working with Basic Settings 65 Modifying User Names 66 Modifying Short Names 67 Choosing Stable Short Names 68 Avoiding Duplicate Names 69 Modifying User IDs 70 Assigning a Password to a User 71 Assigning Administrator Privileges for a Server 72 Choosing a User’s Login Picture 73 Working with Privileges 73 Removing Administrative Privileges from a User 74 Giving a User Limited Administrative Capabilities 75 Giving a User Full Administrative Capabilities 76 Working with Advanced Settings 76 Enabling a User’s Calendar 77 Allowing a User to Log In to More Than One Computer at a Time 77 Choosing a Default Shell 78 Choosing a Password Type and Setting Password Options 79 Creating a Master List of Keywords 80 Applying Keywords to User Accounts 80 Editing Comments 81 Working with Group Settings 81 Choosing a User’s Primary Group 82 Reviewing a User’s Group Memberships 82 Adding a User to a Group 83 Removing a User from a Group 84 Working with Home Settings 84 Working with Mail Settings 84 Enabling Mail Service Account Options 85 Disabling a User’s Mail Service 85 Forwarding a User’s Mail 86 Working with Print Quota Settings 86 Enabling a User’s Access to All Available Print Queues 86 Enabling a User’s Access to Specific Print Queues 87 Removing a Print Quota for a Queue 88 Resetting a User’s Print Quota 88 Disabling a User’s Access to Print Queues That Enforce Quotas 89 Working with Info Settings Contents 5 89 Working with Windows Settings 90 Changing a Windows User’s Profile Location 91 Changing a Windows User’s Login Script Location 91 Changing a Windows User’s Home Folder Drive Letter 92 Changing a Windows User’s Home Folder Location 92 Working with GUIDs 92 Viewing GUIDs 93 Chapter 5: Setting Up Group Accounts 93 About Group Accounts 93 How Group Accounts Track Membership 94 Where Group Accounts Are Stored 94 Predefined Group Accounts 96 Administering Group Accounts 96 Creating Group Accounts 98 Creating a Preset for Group Accounts 98 Editing Group Account Information 99 Creating Hierarchical Groups 102 Upgrading Legacy Groups 102 Working with Read-Only Groups 103 Deleting a Group 103 Working with Basic Settings for Groups 103 Naming a Group 104 Defining a Group ID 105 Choosing a Group’s Login Picture 106 Enabling a Group’s Web Services When Connecting to Mac OS X Server v10.5 107 Working with Member Settings for Groups 107 Adding Users or Groups to a Group 109 Removing Group Members 111 Working with Group Folder Settings 111 Specifying No Group Folder 112 Creating a Group Folder 114 Designating a Group Folder for Use by Multiple Groups 115 Chapter 6: Setting Up Computers and Computer Groups 115 About Computer Accounts 116 Creating Computer Accounts 117 Working with Guest Computers 118 Working with Windows Computers 118 About Computer Groups 118 Differences Between Computer Groups and Computer Lists 119 Administering Computer Groups 119 Creating a Computer Group 6 Contents 120 Creating a Preset for Computer Groups 121 Using a Computer Group Preset 121 Adding Computers or Computer Groups to a Computer Group 122 Removing Computers and Computer Groups from a Computer Group 122 Deleting a Computer Group 123 Upgrading Computer Lists to Computer Groups 124 Chapter 7: Setting Up Home Folders 124 About Home Folders 125 Hosting Home Folders for Mac OS X Clients 125 Hosting Home Folders for Other Clients 126 Distributing Home Folders Across Multiple Servers 127 Administering Share Points 127 Setting Up a Share Point 128 Setting Up an Automountable AFP Share Point for Home Folders 129 Setting Up an Automountable NFS Share Point for Home Folders 130 Setting Up an SMB Share Point 132 Administering Home Folders 132 Specifying No Home Folder 133 Creating a Home Folder for a Local User 134 Creating a Network Home Folder 136 Creating a Custom Location for Home Folders 138 Setting Up a Home Folder for a Windows User 140 Setting Disk Quotas 141 Setting Disk Quotas for Windows Users to Avoid Data Loss 142 Using Presets to Choose Default Home Folders 142 Moving Home Folders 142 Deleting Home Folders 143 Chapter 8: Managing Portable Computers 143 About Mobile Accounts 144 About Portable Home Directories 145 Logging In to Mobile Accounts 146 Resolving Sync Conflicts 146 About External Accounts 147 Logging In to External Accounts 148 Considerations and Strategies for Deploying Mobile Accounts 148 Advantages of Using Mobile Accounts 149 Considerations for Using Mobile Accounts 151 Strategies for Syncing Content 152 Setting Up Mobile Accounts for Use on Portable Computers 152 Configuring Portable Computers 153 Managing Mobile Clients Without Using Mobile Accounts Contents 7 153 Unknown Mac OS X Portable Computers 154 Using Mac OS X Portable Computers with One Primary Local User 154 Using Mac OS X Portable Computers with Multiple Users 156 Securing Mobile Clients 157 Optimizing the File Server for Mobile Accounts 158 Chapter 9: Client Management Overview 159 Using Network-Visible Resources 160 Customizing the User Experience
Recommended publications
  • OS X Server Essentials 10.10 Exam Preparation Guide
    OS X Server Essentials 10.10 Exam Preparation Guide OS X Server Essentials 10.10 Exam Preparation Guide Updated February 2015 !1 OS X Server Essentials 10.10 Exam Preparation Guide Contents About This Guide ..............................................................................................................3 Becoming an Apple Certified Support Professional ...........................................3 Exam Details .......................................................................................................................4 Recommended Exam Preparation .............................................................................4 Part One: Configuring and Monitoring OS X Server ...........................................6 Part Two: Configuring Accounts .................................................................................11 Part Three: Managing Devices with Configuration Profiles .............................16 Part Four: Sharing Files ...................................................................................................18 Part Five: Implementing Deployment Solutions ..................................................21 Part Six: Providing Network Services ........................................................................25 Part Seven: Using Collaborative Services ................................................................28 TM and © 2015 Apple Inc. All rights reserved. Other product and company names mentioned herein may be trademarks of their respective companies. Mention of third-party
    [Show full text]
  • Xserve Technology Overview January 2008 Technology Overview  Xserve
    Xserve Technology Overview January 2008 Technology Overview Xserve Contents Page 4 Introduction Page 5 Product Overview Key Features Page 7 Performance Overview Java Server Performance Processor Performance Memory Performance Storage Performance File Server Performance Page 1 Quad-Core Intel Xeon Processors Enhanced Intel Core Microarchitecture 12MB On-Die L2 Cache Dual Independent System Buses Reduced Idle Power High-Performance Floating-Point Division Enhanced 128-Bit SSE4 SIMD Engine Page 14 High-Bandwidth Server Architecture Dual Independent 1600MHz Frontside Buses Advanced FB-DIMM Memory Technology High-Performance PCI Express Expansion Industry-Standard Connectivity Page 18 Flexible Storage Options SATA Drive Technology SAS Drive Technology Apple Drive Modules Software and Hardware RAID Options Fibre Channel Page 22 Integrated Lights-Out Remote Management Anywhere, Anytime Monitoring and Control Dedicated Monitoring Hardware Server Monitor Software Innovative Remote Management Apple Remote Desktop Technology Overview Xserve Page 6 Mac OS X Server v10.5 Leopard UNIX Certified Foundation Optimized for Multicore Intel Processors 64-Bit Computing Advanced Networking Architecture Comprehensive Built-in Services Powerful Workgroup Management Services Innovative Collaborative Services Software Development with Xcode 3 Page 1 Service, Support, and Training Options AppleCare Premium Service and Support Plan AppleCare Service Parts Kit Apple Maintenance Program Mac OS X Server Software Support Training and Certification Programs Page 33
    [Show full text]
  • Apple Certified Technical Coordinator ACTC V10.6
    APPLE CERTIFIED TECHNICAL COORDINATOR V10.6 MARCO AT MARCOMC DOT COM Apple Certified Technical Coordinator ACTC v10.6 NOTEBOOK APPLE CERTIFIED TECHNICAL COORDINATOR V10.6 MARCO AT MARCOMC DOT COM Apple Certified Technical Coordinator v10.6 15 Disclaimer 15 Installing and Configuring Mac OS X Server 16 1. Identify the minimum hardware requirements for installing Mac OS X Server 16 2. List the computer specific details that you will need From a Mac computer in order to perform a remote installation of Mac OS X Server on the computer 16 3. List the volume formats which can be used for a Mac OS X Server boot volume 16 4. Describe how installing Mac OS X Server on a multiple-partition drive simplifies the task of keeping operating system files separate from server data 16 5. List the possible passwords to use to access a remote Mac computer with Server Assistant when configuring a new installation on Mac OS X Server 16 6. Describe how to install the Mac OS X Server administration software on a Mac OS X client computer 17 7. Describe how to install Mac OS X Server on a head-less computer 17 8. Identify the packages that are installed by Server Assistant when Easy Install is selected 17 9. Describe four procedures for installing Mac OS X Server on a headless Xserve that has no optical drive 17 10. Describe how to use the Installer Log file from a Mac with Mac OS X Server newly installed to verify that the installation was successful 17 11.
    [Show full text]
  • Mac OS X Server
    Mac OS X Server Version 10.6 Snow Leopard Product Overview August 2009 Product Overview 2 Mac OS X Server Contents Page 3 Quick Look at Snow Leopard Server Page 5 Easy Setup and Management Page 8 Built-in Services File Sharing Mail Server Address Book Server iCal Server iChat Server Web Hosting Wiki Server Podcast Producer Remote Access Firewall Time Machine Backups Page 19 64-Bit Performance High-Performance Networking Performance Benchmarks Page 22 Test-Drive Mac OS X Server Page 28 Product Details Installing Mac OS X Server Setting Up Mac OS X Server Managing the Server Monitoring the Server Exploring Mac OS X Server as a User Page 30 Additional Resources Product Overview 3 Mac OS X Server Quick Look at Snow Leopard Server During the past ten years, Apple has rapidly delivered new versions of Mac OS X Server, the world’s easiest-to-use server operating system. The introduction of Mac OS X Server version 10.6 Snow Leopard brings dramatic performance improvements and innovative new capabilities to Apple’s open standards–based server platform—making it both fast and easy for your organization to collaborate, communicate, and share information. And for ready access to all those advantages, Apple now off ers a single aff ordable edition of Snow Leopard Server with licenses for an unlimited number of clients. Snow Leopard Server is a full 64-bit operating system designed to take advantage of Mac OS X Server version 10.6 multicore processors and address massive amounts of memory. With a new 64-bit kernel Snow Leopard Server is the seventh and teamed with the latest Xserve or Mac Pro system, Snow Leopard Server can easily release of Apple’s award-winning server handle the most demanding server operations—including fi le sharing, mail services, operating system.
    [Show full text]
  • Mail Service Administration Version 10.6 Snow Leopard Kkapple Inc
    Mac OS X Server Mail Service Administration Version 10.6 Snow Leopard K Apple Inc. Java™ and all Java-based trademarks and logos © 2009 Apple Inc. All rights reserved. are trademarks or registered trademarks of Sun Microsystems, Inc. in the U.S. and other countries. Under the copyright laws, this manual may not be copied, in whole or in part, without the written consent PowerPC™ and the PowerPC logo™ are trademarks of Apple. of International Business Machines Corporation, used under license therefrom. The Apple logo is a trademark of Apple Inc., registered in the U.S. and other countries. Use of the “keyboard” UNIX® is a registered trademark of The Open Group. Apple logo (Option-Shift-K) for commercial purposes without the prior written consent of Apple may Other company and product names mentioned herein constitute trademark infringement and unfair are trademarks of their respective companies. Mention competition in violation of federal and state laws. of third-party products is for informational purposes only and constitutes neither an endorsement nor a Every effort has been made to ensure that the recommendation. Apple assumes no responsibility with information in this manual is accurate. Apple is not regard to the performance or use of these products. responsible for printing or clerical errors. The product described in this manual incorporates Apple copyright protection technology that is protected 1 Infinite Loop by method claims of certain U.S. patents and other Cupertino, CA 95014-2084 intellectual property rights owned by Macrovision 408-996-1010 Corporation and other rights owners. Use of this www.apple.com copyright protection technology must be authorized by Macrovision Corporation and is intended for home Apple, the Apple logo, AppleScript, FireWire, Keychain, and other limited viewing uses only unless otherwise Leopard, Mac, Mac OS, Quartz, Safari, Snow Leopard, authorized by Macrovision Corporation.
    [Show full text]
  • Mac OS X Server Advanced Server Administration Version 10.6 Snow Leopard % Apple Inc
    Mac OS X Server Advanced Server Administration Version 10.6 Snow Leopard % Apple Inc. Finder, QuickTime Broadcaster are trademarks of © 2009 Apple Inc. All rights reserved. Apple Inc. The owner or authorized user of a valid copy of This product includes BSD (4.4 Lite) developed by Mac OS X Server software may reproduce this the University of California, Berkeley, FreeBSD, Inc., publication for the purpose of learning to use such The NetBSD Foundation, Inc., and their respective software. No part of this publication may be reproduced contributors. or transmitted for commercial purposes, such as selling copies of this publication or for providing paid-for Intel, Intel Core, and Xeon are trademarks of Intel Corp. support services. in the U.S. and other countries. 'XGT[GÒQTVJCUDGGPOCFGVQGPUWTGVJCVVJG OpenSSL is software developed by the OpenSSL information in this manual is accurate. Apple is not Project for use in the OpenSSL Toolkit responsible for printing or clerical errors. (http://www.openssl.org/). Apple UNIX® is a registered trademark of The Open Group. +P°PKVG.QQR X Window System is a trademark of the Massachusetts Cupertino, CA 95014-2084 Institute of Technology. www.apple.com Other company and product names mentioned herein The Apple logo is a trademark of Apple Inc., registered are trademarks of their respective companies. Mention in the U.S. and other countries. Use of the “keyboard” of third-party products is for informational purposes Apple logo (Option-Shift-K) for commercial purposes only and constitutes neither an endorsement nor a without the prior written consent of Apple may recommendation. Apple assumes no responsibility with constitute trademark infringement and unfair regard to the performance or use of these products.
    [Show full text]
  • DHCP Option Numbers
    569 Appedix A DHCP Option Numbers DHCP uses what are referred to as options to extend the functionality. You can learn more about what the options can do for you in Chapter 6. They’re identified numerically, and each number corresponds to the services that they provide. 0: Pad 1: Subnet Mask 3: Router 4: Time Server 5: Name Server 6: Domain Name Server 7: Log Server 8: Quotes Server 9: LPR Server 10: Impress Server 11: Resource Location Server 12: Host Name 13: Boot File Size 14: Merit Dump File 15: Domain Name 16: Swap Server 17: Root Path 18: Extensions Path 19: IP Forwarding 20: WAN Source Routing 569 570 APPENDIX A: DHCP Option Numbers 21: Policy Filter 22: Maximum Datagram Reassembly Size 23: Default IP Time-to-Live 24: Path MTU Aging Timeout 25: Path MTU Plateau Table 26: Interface MTU Size 27: All Subnets are Local 28: Broadcast Address 29: Perform Mask Discovery 30: Mask Supplier 31: Perform Router Discovery 32: Router Solicitation Address 33: Static Routing Table 34: Trailer Encapsulation 35: ARP Cache Timeout 36: Ethernet Encapsulation 37: Default TCP TTL 38: TCP Keep-Alive Interval 39: TCP Keep-Alive Garbage 40: Network Information Service Domain 41: Network Information Servers 42: NTP Servers 43: Vendor-Specific Information 44: NetBIOS Over TCP/IP Name Server 45: NetBIOS Over TCP/IP Datagram Distribution Server 46: NetBIOS Over TCP/IP Node Type 47: NetBIOS Over TCP/IP Scope 48: X Window System Font Server 49: X Window System Display Manager 50: Requested IP Address 51: IP Address Lease Time APPENDIX A: DHCP Option Numbers
    [Show full text]
  • Mac OS X Server Web Technologies Administration Version 10.6 Snow Leopard Kkapple Inc
    Mac OS X Server Web Technologies Administration Version 10.6 Snow Leopard K Apple Inc. Apple, the Apple logo, ColorSync, Final Cut Pro, Mac, © 2009 Apple Inc. All rights reserved. Macintosh, Mac OS, QuickTime, Xgrid, and Xserve are trademarks of Apple, Inc., registered in the U.S. and The owner or authorized user of a valid copy of other countries. Finder and Safari are trademarks of Mac OS X Server software might reproduce this Apple, Inc. publication for the purpose of learning to use such software. No part of this publication might be Adobe and PostScript are trademarks of Adobe Systems reproduced or transmitted for commercial purposes, Incorporated. such as selling copies of this publication or for providing paid-for support services. UNIX is a registered trademark of The Open Group. Every effort has been made to guarantee that the Other company and product names mentioned herein information in this manual is correct. Apple Inc., is not are trademarks of their respective companies. Mention responsible for printing or clerical errors. of third-party products is for informational purposes only and constitutes neither an endorsement nor a Apple recommendation. Apple assumes no responsibility with 1 Infinite Loop regard to the performance or use of these products. Cupertino, CA 95014-2084 408-996-1010 019-1424/2009-08-01 www.apple.com The Apple logo is a trademark of Apple Inc., registered in the U.S. and other countries. Use of the “keyboard” Apple logo (Option–Shift–K) for commercial purposes without the prior written consent of Apple might constitute trademark infringement and unfair competition in violation of federal and state laws.
    [Show full text]