There are two ways to do this.
Option1: if you do not have an xServe, this is OK. You can use Centrify(http:www.centrify
I use this product and can only sing it praises.
Option2: you could work on creating the golden triangle but I have found that you have to pay Apple quite a bit of money for an Engineer's time. Also, since 10.4.11, the AD plugin has not worked as well as it could. Also, with this option, you would need to have an xServe to make the Golden triangle work. Google the prhase "afp48.com golden trianle". You will get a pdf on some implentation steps. While this is a bit dated, its fundamentals for implemtation pretty much remains the same.
Main Topics
Browse All Topics





by: hborisPosted on 2009-09-15 at 01:43:47ID: 25332949
Yes, this is indeed possible. The setup is called the "Magic Triangle" where user accounts are stored in Active Directory, but the Open Directory on the OS X Server holds the so-called augmented records with attributes not supported by Active Directory schema, as well as service locators. It is unfortunately to big of a topic to fit in an EE question so I suggest you get an Apple certified tech to help you with the setup. Just a note - the whole environment must be fully kerberized and for that to work the DNS service must be set up and working correctly.
Boris Herman, ACSA