Want OD authentication for logins, but need home folders stored locally

Real quick...
How does one configure Open Directory to allow for users to login to their computers using a network/LDAP authentication, but have their home folders stored locally on their computers. I know how to do this when bound to AD, but can't figure it out using OS X's OD.
Would I set it up the server role to "Standalone Server"? Do the computers need to be bound to AD in order to create "mobile accounts? I don't want them to be able to move from computer to compouter, so I don't need synchronization, just to enforce password policies
Thanks!
T

Hi
@ Templeton
You may find this useful as this is what I have done before in the past. It’s worked for me. There may be other methods that can be used?
Create an admin account on the client computer and then create an account in the LDAP node in WGM with same name and password. If the account already exists on the client computer then all you need do is the latter. Don’t create a Home Folder as this will be created automatically later on. Launch Directory Access and bind to the server.
It seems to work better if the Server is running DHCP Services although it works OK using static. I have seen authentication problems where an AD Server is providing DHCP Services so bear that in mind – in theory it should work – as ever it depends on how well DNS Services are configured.
As soon as you bind the edu.mit.Kerberos file is created in /Library/Preferences. AS_REQ and ISSUE has done its business and as far as the server is concerned the client is intially authenticated. It will request further pre-authentication later on. You should see this feedback if you consult the kdc.log. If the client connects to the server to access a server based service using the normal methods he/she will receive the Kerberos login window prompt. The user name and Realm will already be filled in. Supply the password and you should then be presented with a list of shares you can access including the home folder. If you select the home folder it will mount on the local desktop and be automatically populated with the usual folders. Of course you don’t have to do this if you don’t want to. That’s it the client has its day ticket for the day and can use the local home folder as normal.
@ Mike
This can be a tricky thing to administer and keep track of, especially if local client account names and passwords don’t match what is on the Server. For 300 Users or more its a lot of work. I had a similar experience myself and as usual cursed myself for not anticipating this need when the server was first deployed. Perhaps Apple may build something into Leopard that can facilitate this need?
Tony

Similar Messages

  • No Authentication for application but need to be authorized for few pages

    Hi,
    I am new to the security concepts of APEX. Could you please assist me if my below requirement could be acheived, if so how?
    My application has 'No Login Authentication' schema selected which makes it open for any user, and this is as per our requirement. I have few pages which have to be accessed only by
    * Administrator
    * Higher Management team
    * Some pages where any enduser need to login (for instance, for posting any query, I would require to know the owner of the query for which I require the user to be authenticated and further have email communications)
    Any assistance in this regard is much appreciated.
    Thanks & regards,
    Anasuya

    Anasuya,
    You need to select an appropriate authentication scheme based on how you want to authenticate users and then make all pages "public" except for those that require authenticated access. For those authenticated pages, you can then assign authorization scheme to limit which authenticated users are authorized for each page.
    Scott

  • In Hongkong. I want to buy new iMac, But need to sell old one first. Where is good for sell??

    Please help me.
    Please give me a suggestion.
    I want to buy new iMac, but need to sell old one.
    About following the info.
    How much can sell and where is good for sell?
    Processor  2.93 GHz Intel Core i7
    Total Number of Cores:          4
    Processor Interconnect Speed: 4.8 GT/s
    Memory  8 GB 1333 MHz DDR3
    Graphics  ATI Radeon HD 5750 1024 MB
    Software  OS X 10.8.3 (12D78)
    1TB harddisk
    Warranty to 02/Aug/2013
    Thank you for your help.

    When you sell your iMac, please remember that if you bought Mountain Lion upgrade at the app store, the license is not transferable and you need to erase the drive and reinstall the original system (which was most likely Snow Leopard?). If you don't do that, the buyer can never reinstall Mountain Lion because the license is tied to your Apple ID forever.

  • TS4185 I have a I Mac in my office & a mac lap top at home. Now I have the same e-mail address. I want the Facetime for my mac at home. 10.5.8 how can I get it?

    I have a I Mac in my office & a mac lap top at home. Now I have the same e-mail address. I want the Facetime for my mac at home. 10.5.8 how can I get it?

    Addition to above...
    I need this on iCloud. anyone know where to find it?

  • Password works for login but not for the Adobe CC Desktop application

    Password works for login but not for the Adobe CC Desktop application

    Please refer to http://helpx.adobe.com/creative-cloud/kb/troubleshoot-cc-installation-download.html
    ou can try deleting OPM.DB from steps below and try again.
    Mac OS: You can locate the OPM.db file in the \User\\Library\Application Support\Adobe\OOBE folder. To access the hidden user Library folder, see Access hidden user library files | Mac OS 10.7 Lion. - http://helpx.adobe.com/x-productkb/global/access-hidden-user-library-f iles.html
    Windows: You can locate the OPM.db file in the :\Users\\AppData\Local\Adobe\OOBE folder.  To view the hidden AppData folder, see Show hidden files, folders, filename extensions | Windows XP, Vista, Windows 7. -http://helpx.adobe.com/x-productkb/global/show-hidden-files-folders-ex tensions.html
    3) update to the latest version of the Creative Cloud app.
    Also we would like few more details:
    When has this issue started occurring, was this after installation of any specific adobe product.
    On which platform are you seeing this.
    Also we would like to know if after above steps this issue occurs ever again in future.
    You can refer to http://forums.adobe.com/thread/1239510
    Regards,
    Rajshree

  • I want to purchase for store, but the game underworld empire says it can not be completed

    I want to purchase for store, but the game underworld empire says it can not be completed

    You can contact the seller and ask if they wish to make an exception but not all items are available to all places. It is sometimes the decision of the seller and other times law. 

  • I have created a version of my website with muse for tablet but the home/index page is not centered

    I have created a version of my website with muse for tablet but the home/index page is not centered (leave some space on the right ) when see it on my ipdad which is weird as the other pages are centered .Please help!
    thanks

    See my post here <http://forums.adobe.com/message/5410674#5410674>

  • How do you setup a user mobile account, with the home directory stored locally and not synced to the server?

    I want to be able to setup a user mobile account, with the home directory stored locally and not synced to the server.  What is the best way to do this? I am running Server 10.6 with 10.6 clients.  Open Directory will be used to authenticate and manage preferences.   Also, this one account will be used simultaneosly in a computer lab setting, so files will be stored locally in the client, hence the need to NOT sync to the server.  Any Ideas? 

    currofelix wrote:
    So what does WGM Look like in the Home Tab? afp://servername.domainname/Users? or afp://Users?
    The attached screen shots should help you:
    You will only have to do this step once. Obviously you want to use the user's shortname here.
    Then, you will see this as an option in WGM:

  • I want to setup multiple numbers but need a way to...

    I want to setup multiple numbers but I need a way to identify which number was called when it comes in. I have a SkypeIn account with an online number that I'm using. I'm planning on setting up a 2nd online number so I can track calls from brochures but I need to make sure theres a way to identify that a call is coming from skypephone#2
    I need to get this figured out urgently so any help at all would be greatly appreciated.
    Thanks!

    Dear,
    your question sound powerful.
    I am curious to know also. I am having the same problem right now. I can not even identify which skype number is being called so that we can know the language we use for the customers. Believe me, if the setting does not work, then is the effort getting skype number in vain and partially useless. Please can some one help? Question: How to set up 2 different skype numbers for us to know which of the numbers a customer called.
    Thank you in advance!

  • Old computer crashed - have iPhone 4, want to update to iOS5, but need help.

    I'm hoping someone can help me. My old computer crashed, and had to get a new one. I lost my iTunes, and didn't have a back-up. The only place I have the data is on the phone itself. I had to re-install iTunes on my new computer, and I want to update to iOS5, but I'm worried I'll lose everything on my iPhone, as I don't have a back-up. How do I take the data (pictures, contacts, email, etc.) from my phone and put it on my computer, so I can update to iOS5, and have a back-up in case I lose it? I already transferred the purchases, so I have all of my apps on my new iTunes, but I don't want to lose any other data. I have Windows XP and an iPhone 4.
    Thanks for any help or advice - I appreciate it!

    Copying from iPod to Computer threads...
    http://discussions.apple.com/thread.jspa?threadID=776996&tstart=0
    http://discussions.apple.com/thread.jspa?threadID=805256&tstart=0
    http://discussions.apple.com/thread.jspa?messageID=797432&#797432
    Also these useful internet articles...
    http://www.engadget.com/2004/11/02/how-to-get-music-off-your-ipod/
    http://playlistmag.com/help/2005/01/2waystreet/
    iPod: Frequently Asked Questions
    http://docs.info.apple.com/article.html?artnum=60920
    Patrick

  • Two factor authentication for login

    Can you tell me when Verizon online will implement 2 factor authentication for logging into web and email?
    Thanks!

    Uh, never.  I doubt its even on their radar.

  • I need Home directories on local machines, not on server

    I'm setting up 10.5 server and OD. I have 10 mac workstations (all 10.4), each with established users and home directories. I have set up new users on the server, in the directory domain the exact same as they are set up on the local workstations (same long name, short name, and password. Obviously they have different UIDs and GIDs). I have user home folder paths set to None, accept the diradmin folder, which is set to /Users.
    When I log in as a OD user other than diradmin from a workstation, I see my home folder as "99". I'm not sure why this is, but it appears to create this home folder locally. I don't like this.
    When I log in as diradmin from a workstation, it creates a folder home folder called "diradmin" on the local mac. This is better.
    Ideally, what I'd like is the home folder always be located on the workstation, even if logging in from a different machine, so preferences, email, tunes, etc. are there. I DON'T want home directories on the server due to bandwidth limitation of our network. I want home directories to say as-is ((on local machines) and just change how users log onto their workstations (using LDAP instead of NetInfo).
    Questions:
    1. Can I have the same long/short name and password on the workstation, and in the shared directory? If not, will just changing the long name be enough to differentiate, or does the short name also need to change?
    2. Is it possible to have my home folders set up as described (living on the local workstation and shared in logging in from a different mac)? If so, how? I've read the apple docs and nothing seems to clearly describe how to do this.
    Thanks much.

    I had the same question and had some very helpful responses in this thread.
    http://discussions.apple.com/thread.jspa?threadID=1334079&tstart=0

  • Mobile Accounts not copying home folders to local machine

    Having recently upgraded my MacBook to 10.5 (and having a 10.5 server) I have noticed an error with mobile accounts. My account has not synced for a couple of weeks and I have checked all the directory settings and cannot see any errors.
    I've removed all directory services and rebooted, put them back and it will create a mobile account but nothing is being copied to the local hdd. So basically it is functioning like a network account rather than a mobile one.
    This works fine on our 10.4 clients but having tried different users on my 10.5 system it does the same....creates the account, mounts the server but does nothing else.
    This means when you sync it says its complete but does nothing...its like its lost permissions to the folder on the server but that seems very odd.
    Anyone else had issues with 10.5? We have an AD server with our users and a 10.5 server with OD replicating AD and holding the home folders.

    Are you still ahving this issue?
    Would you do like geekinit in this thread and post some partial screen grabs (although is problem included Windows server Active Directory and profile Manager which I will get up to soon.)
    Unable to deploy home folder mobility settings through an Apple MDM server
    Did you create a fileshare for Local Network accounts to put their stuff
    If so where is OS X server?
    Did you tell the user in OD to use that fileshare?
    Here's a screen grab example
    Francois.

  • Want to use ipad for work but need to measure foot candles??

    Is there anytype of app for reading/measuring foot candles on the iPad? My job is interested in buying these for our fieldworkers but we need to know if theres a way we can measure foot candles.  I've searched all over the internet without finding anything and was really curious to see if I really hit a dead end. PLEASE HELP!!

    I just downloaded Pocket Light Meter.  After I turn on the additional settings, I can see foot candles , however when I compare it to my actual light meter to check the validity of the Pocket Light Meter, they are way off.    Any idea how to calibrate it or to check if possibly I am doing something wrong??

  • Want to upgrade to SL, but need IMOVIE 06

    Hi all...Okay... I am using OS X (10.4.11), I know I need to upgrade and want to upgrade to Snow Leopar. Here's my problem..I am transferring 8mm films to my digital camcorder,then importing to IMOVIE08, then to IDVD to burn onto a dvd. The quality of the 8mm films are very poor because of the age of the films. I want to be creative when editing these 8mm home movies and IMOVIE 09 will allow me to do that by adding a theme. It will also reduce the unsteadiness which is throughout the films. After reading the threads it seems I would be better off installing IMOVIE 06 because of the quality it will produce when burned onto a dvd. So...if I upgrade to Snow Leopar, which will give me IMOVIE 09, can I also install IMOVIE 06? Is it still available to purchase? Will having IMOVIE 06,08 and 09 screw up my computer? Any comments will be helpful..thanks
    LN

    Hi
    iLife 6 - not fore sale any more. Only second handed on eg e-bay
    I would if I could use Snow Leopard take a look on FinalCut Express.
    Very different - but when learned a tremendous freedom.
    Yours (no intel) Bengt W

Maybe you are looking for

  • IPhone 2G voice mic not working

    Has anyone come across iPhone 2G voice mic not working (not being heard by the other person) but works fine on speaker phone and bluetooth headset. It has been working fine so far and suddenly developed this problem! Any help is highly appreciated-.

  • How do I edit forwarded iCalendar (from Outlook 2010)?

    I love the iPhone but sometimes, little bitty issues can be infuriating. Grrr... Because there is NO WAY I am able to sync my iPhone's calendar to my work account, I found that I can forward important meetings to my phone via Outlook's "Forward as iC

  • Mac OSX Server error message in console

    Hi, I have the following error message having recently bought and configured (for the first time) a MacMini Server with Mac OSX Server 10.6.n. 1/26/11 1:38:11 PM org.dovecot.dovecotd[8582] Fatal: Invalid configuration in /private/etc/dovecot/dovecot.

  • CS6 does not show on my Adobe account.  Has my registration been lost?

    CS6 does not show on my Adobe account.  Has my registration been lost?

  • Can we precompute a value based dimension ?

    Hi, I do not know how to precompute/summarize a value based dimension in AWM 10g. One of my value based dimension in AWM 10 g (10.2.0.3A) showed pre-compute already done , but the aggmap of the cube did not show any precompute clause in relation stat