<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Integrating Leopard Server With UNIX LDAP</title>
	<atom:link href="http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/</link>
	<description>Apple Certified Mac Consulting</description>
	<lastBuildDate>Mon, 09 Jan 2012 22:29:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Integrating Snow Leopard Server with Unix LDAP and NFS &#124; # zpool create &#8230;</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-3026</link>
		<dc:creator>Integrating Snow Leopard Server with Unix LDAP and NFS &#124; # zpool create &#8230;</dc:creator>
		<pubDate>Sat, 15 Jan 2011 04:28:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-3026</guid>
		<description>[...] what would be necessary to make SLS talk to OpenDS, I came across Brent Kearney&#8217;s excellent Integrating Leopard Server With UNIX LDAP blog posts. His work is built on top of a previous post by Rajeev Karamchedu that does something [...]</description>
		<content:encoded><![CDATA[<p>[...] what would be necessary to make SLS talk to OpenDS, I came across Brent Kearney&#8217;s excellent Integrating Leopard Server With UNIX LDAP blog posts. His work is built on top of a previous post by Rajeev Karamchedu that does something [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2643</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Tue, 02 Nov 2010 20:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2643</guid>
		<description>No, I haven&#039;t.  A quick search suggests that the altSecurityIdentities attribute is a Windows attribute, so perhaps your server does not load the Samba schemas...</description>
		<content:encoded><![CDATA[<p>No, I haven&#8217;t.  A quick search suggests that the altSecurityIdentities attribute is a Windows attribute, so perhaps your server does not load the Samba schemas&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2642</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Tue, 02 Nov 2010 20:18:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2642</guid>
		<description>Brent,

Actually I am finally getting the Sun diradmin to extend his schema just to test out further.   I gave him the 92ldif file but he ran into this issue when trying to extend:


Bootstrap config  - conn=-1 op=-1 msgId=-1 - System error  The entry cn=schema  in file /var/Sun/mps/slapd-vorik_test/config/schema/92apple.ldif is invalid (error 21: Invalid syntax) - object class apple-user: Unknown allowed attribute type &quot;altSecurityIdentities&quot;.


Have you come across this at all?

Thanks,

Don</description>
		<content:encoded><![CDATA[<p>Brent,</p>
<p>Actually I am finally getting the Sun diradmin to extend his schema just to test out further.   I gave him the 92ldif file but he ran into this issue when trying to extend:</p>
<p>Bootstrap config  &#8211; conn=-1 op=-1 msgId=-1 &#8211; System error  The entry cn=schema  in file /var/Sun/mps/slapd-vorik_test/config/schema/92apple.ldif is invalid (error 21: Invalid syntax) &#8211; object class apple-user: Unknown allowed attribute type &#8220;altSecurityIdentities&#8221;.</p>
<p>Have you come across this at all?</p>
<p>Thanks,</p>
<p>Don</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2641</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Wed, 27 Oct 2010 18:30:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2641</guid>
		<description>So to follow up Brent there seems to be an issue between 10.6 compared to 10.5 server.   I can create augmented records fine on 10.5 without to much problem.   Still looking into what may be the issue on a 10.6 server.</description>
		<content:encoded><![CDATA[<p>So to follow up Brent there seems to be an issue between 10.6 compared to 10.5 server.   I can create augmented records fine on 10.5 without to much problem.   Still looking into what may be the issue on a 10.6 server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2637</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Wed, 20 Oct 2010 20:10:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2637</guid>
		<description>Brent,

I will follow up on that and keep you posted.   Thanks!

Don</description>
		<content:encoded><![CDATA[<p>Brent,</p>
<p>I will follow up on that and keep you posted.   Thanks!</p>
<p>Don</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2636</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Wed, 20 Oct 2010 18:05:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2636</guid>
		<description>According to the book, it is not necessary to extend the schema to create augmented user records. But then again, the book also mentions that augmented records are only supported with Active Directory.

The best way to figure out what is going wrong is probably to increase the logging verbosity on the Sun DS, and watch the query logs as you try to add users to OD.  I bet it&#039;s looking for some authentication related attribute which it&#039;s not finding.  Possibly something relating to Kerberos.

Brent</description>
		<content:encoded><![CDATA[<p>According to the book, it is not necessary to extend the schema to create augmented user records. But then again, the book also mentions that augmented records are only supported with Active Directory.</p>
<p>The best way to figure out what is going wrong is probably to increase the logging verbosity on the Sun DS, and watch the query logs as you try to add users to OD.  I bet it&#8217;s looking for some authentication related attribute which it&#8217;s not finding.  Possibly something relating to Kerberos.</p>
<p>Brent</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2635</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Wed, 20 Oct 2010 14:05:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2635</guid>
		<description>Brent,

Yes I have tried WGM on a client computer as well as the server.  I get the same results on both when trying to use the Server menu &quot;New Augmented User Records&quot; where WGM crashes or if I try to use the plus to add LDAP external user to and OD group.   

In the testing environment I am connecting to of the Sun Directory there are no groups set for me to test that I can see.   Maybe this is part of the problem?   I will check with diradmin for the S.D. and see if I don&#039;t have read access to every attribute.   Also since we were going to use the external directory to only authenticate and not store data for MCX I did not have him extend his schema.

Is that absolutely necessary if trying to attempt this?


Thanks,

Don</description>
		<content:encoded><![CDATA[<p>Brent,</p>
<p>Yes I have tried WGM on a client computer as well as the server.  I get the same results on both when trying to use the Server menu &#8220;New Augmented User Records&#8221; where WGM crashes or if I try to use the plus to add LDAP external user to and OD group.   </p>
<p>In the testing environment I am connecting to of the Sun Directory there are no groups set for me to test that I can see.   Maybe this is part of the problem?   I will check with diradmin for the S.D. and see if I don&#8217;t have read access to every attribute.   Also since we were going to use the external directory to only authenticate and not store data for MCX I did not have him extend his schema.</p>
<p>Is that absolutely necessary if trying to attempt this?</p>
<p>Thanks,</p>
<p>Don</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2634</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Tue, 19 Oct 2010 21:35:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2634</guid>
		<description>Hi Don,

The members tab + globe icon is the right way to do it.  You don&#039;t need write privileges on the external LDAP server.

Are you running WGM on a client computer instead of on the OS X Server?  That is the recommended way to do it for this purpose.  Have you tried dragging a &lt;em&gt;group&lt;/em&gt;, instead of user records, from the external LDAP into a group on your OD master?  Also, in Workgroup Manager, under the Server menu, there is a new option, &quot;New Augmented User Records&quot;.  Try that.

The book is ambiguous about support for augmenting user records from external LDAP servers which are not Active Directory or OD. Surely there is away; what&#039;s so special about AD?  Kerberos?

Brent</description>
		<content:encoded><![CDATA[<p>Hi Don,</p>
<p>The members tab + globe icon is the right way to do it.  You don&#8217;t need write privileges on the external LDAP server.</p>
<p>Are you running WGM on a client computer instead of on the OS X Server?  That is the recommended way to do it for this purpose.  Have you tried dragging a <em>group</em>, instead of user records, from the external LDAP into a group on your OD master?  Also, in Workgroup Manager, under the Server menu, there is a new option, &#8220;New Augmented User Records&#8221;.  Try that.</p>
<p>The book is ambiguous about support for augmenting user records from external LDAP servers which are not Active Directory or OD. Surely there is away; what&#8217;s so special about AD?  Kerberos?</p>
<p>Brent</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2633</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Mon, 18 Oct 2010 16:20:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2633</guid>
		<description>Brent,

I have followed the set up per my Sun&#039;s directory admins instructions where I am now able to to see lists of users from the external directory in WGM.   This all looks fine and dandy until I either try to add an external user to an OD group, or try to augment a user record and select an external user.

Actually WGM will crash if I try to augment.   If I try to add an external user to an OD group by clicking the members tab for the group and hitting the plus icon then using the globe to select the external DS, I see the list of users but when I drag a user over to the group I get a green plus icon while dragging but when I release the mouse in the members pane that user just never shows up at all.

I was wondering,   do I need higher privileges to the external DS other than read only when binding to it?   I wouldn&#039;t think that the case but as of now that is all I have and thought that might be an issue.

Thanks,

Don</description>
		<content:encoded><![CDATA[<p>Brent,</p>
<p>I have followed the set up per my Sun&#8217;s directory admins instructions where I am now able to to see lists of users from the external directory in WGM.   This all looks fine and dandy until I either try to add an external user to an OD group, or try to augment a user record and select an external user.</p>
<p>Actually WGM will crash if I try to augment.   If I try to add an external user to an OD group by clicking the members tab for the group and hitting the plus icon then using the globe to select the external DS, I see the list of users but when I drag a user over to the group I get a green plus icon while dragging but when I release the mouse in the members pane that user just never shows up at all.</p>
<p>I was wondering,   do I need higher privileges to the external DS other than read only when binding to it?   I wouldn&#8217;t think that the case but as of now that is all I have and thought that might be an issue.</p>
<p>Thanks,</p>
<p>Don</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/27/integrating-leopard-server-with-unix-ldap/comment-page-1/#comment-2632</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Sat, 16 Oct 2010 21:40:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/27/integrating-leopard-server-with-sun-one-ldap/#comment-2632</guid>
		<description>The &lt;a href=&quot;http://images.apple.com/server/macosx/docs/User_Management_v10.6.pdf&quot; rel=&quot;nofollow&quot;&gt;User Management v10.6&lt;/a&gt; PDF has instructions for setting up augmented user accounts from a 3rd party LDAP server.  Page 57-58:

&lt;blockquote&gt;
&lt;strong&gt;To create an augmented user record:&lt;/strong&gt;
&lt;ol&gt;
&lt;li&gt;Make sure the directory services of the Mac OS X Server computer you’re using are configured to access the directory domain containing the original accounts and the directory domain where the augmented user records will reside. For instructions, see &lt;a href=&quot;http://images.apple.com/server/macosx/docs/Open_Directory_Admin_v10.6.pdf&quot; rel=&quot;nofollow&quot;&gt;Open Directory Administration&lt;/a&gt;. &lt;/li&gt;
&lt;li&gt;In Workgroup Manager, connect to the server that you’re importing augmented records to.&lt;/li&gt;
&lt;li&gt;Click Accounts. Click the globe icon and choose the domain you’re importing augmented records to.&lt;/li&gt;
&lt;li&gt;To authenticate, click the lock and enter the name and password of a directory administrator of the directory domain you chose in the previous step.&lt;/li&gt;
&lt;li&gt;Choose Server &gt; New Augmented User Records.&lt;/li&gt;
&lt;li&gt;Select the user records you want to import. If you select a group, all members of that group are imported. &lt;/li&gt;
&lt;li&gt;Click Create, and then click Done.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>The <a href="http://images.apple.com/server/macosx/docs/User_Management_v10.6.pdf" rel="nofollow">User Management v10.6</a> PDF has instructions for setting up augmented user accounts from a 3rd party LDAP server.  Page 57-58:</p>
<blockquote><p>
<strong>To create an augmented user record:</strong></p>
<ol>
<li>Make sure the directory services of the Mac OS X Server computer you’re using are configured to access the directory domain containing the original accounts and the directory domain where the augmented user records will reside. For instructions, see <a href="http://images.apple.com/server/macosx/docs/Open_Directory_Admin_v10.6.pdf" rel="nofollow">Open Directory Administration</a>. </li>
<li>In Workgroup Manager, connect to the server that you’re importing augmented records to.</li>
<li>Click Accounts. Click the globe icon and choose the domain you’re importing augmented records to.</li>
<li>To authenticate, click the lock and enter the name and password of a directory administrator of the directory domain you chose in the previous step.</li>
<li>Choose Server > New Augmented User Records.</li>
<li>Select the user records you want to import. If you select a group, all members of that group are imported. </li>
<li>Click Create, and then click Done.</li>
</ol>
</blockquote>
]]></content:encoded>
	</item>
</channel>
</rss>

