Part 3: Hunter College: Setting up a Netinfo/LDAP catalog
Computerworld - In a series of articles written by Yuval Kossovsky, manager of digital media systems at Hunter College's Department of Film and Media Studies, Computerworld is following the school's integration of new Apple hardware and software. This is the third of those articles, which are designed to offer a hands-on view of integrating Macs and Apple software in what is largely an Intel and Windows world.
The first question to ask in a situation like this is: "Why do I want a central catalog?" The answer is obvious to anyone who has tried to maintain more than one identity on 10 or more machines.
When setting up a large number of user identities in an enterprise or lab environment, it is nearly impossible to visit every machine and set up an identical profile for each new user. And what do you do when an account is deleted, or the password is changed in one place? Centralizing the catalog allows an administrator to keep all user information in one place.
While Mac OS X integrates with industry-standard methods such as Microsoft's Active Directory and Sun's Open LDAP, my focus is on managing a purely OS X environment. Much like the enterprise administrator tool in the Windows world, the Workgroup Manager (WGM) tool in OS X enables the administrator to completely control an end user's experience. With WGM you can manage specific machine, group and user preferences.
The first step in building a net info directory is Planning, with a capital P! I made the mistake of not planning my first implementation and had to scrap it part of the way through. You'll need to consider how many users and potential groups you have now, and how many there will be in the future. What is the naming convention for users? How many IDs will you require? In the Unix world, the user identity (UID) is the most important piece of data: It is a unique identifier for an account, and all privileges and permissions are given to that unique number. If there are duplicate ID numbers, you've got a big problem.
For people, it helps to have that UID number mean something -- and this is where a conflict usually arises. For example, I set aside UIDs 1001-1099 for user accounts and 1101-1199 for administrators. What happens when I have 100 users? Do I use an admin number or jump to another range? Either way, the neat mapping I had is now all mucked up. Lesson learned: Give yourself some room to



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Mac OS White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Mac OS Webcasts