Hands-on: Using Net Info domains for single sign-on to many servers
Computerworld - In a series of articles written by Yuval Kossovsky, manager of digital media systems at Hunter College's Department of Film and Media Studies in New York, Computerworld is following the school's integration of new Apple Computer Inc. hardware and software. This is the fifth of those articles, which are intended to offer a hands-on view of integrating Macintosh computers and Apple software in what's largely an Intel and Windows world.
The phrase often used is "single sign-on," and it means relief from multiple passwords for each server that an end user accesses. The theory goes something like this: In the old days of computing, every server an end user accessed required a new log-on. Since the servers were often managed by different computing groups, the hapless corporate end user ended up with numerous log-ons and passwords. The domain and directory service architecture is supposed to provide relief for this by bringing all of the servers under one roof. A primary server acts as the authorization agent, and all the other servers query it for an OK when a user attempts to access a resource.
The domain model greatly simplifies the lives of both the end user and the administrator.
Fast-forward to the OSX Open Directory model now available. Because Apple endowed its system with the ability to understand many protocols, the domain catalog can be maintained natively in two major formats: Net Info and Lightweight Directory Access Protocol. The server can also work as part of a Microsoft Active Directory domain, but only as a member server -- not as the primary authenticator. For this discussion, we will leave out Active Directory, since the OSX machine will act as the primary server.
To set up single sign-on for all of your servers, first you must set up the primary server.
I used my X-Serve for this purpose. To begin, run the Open Directory Assistant, and make the selections as outlined in the accompanying screenshots. First, the server must have a fixed IP (see Figure 1).

On the next screen, choose "provide directory information to other computers" for the primary server and "get directory information from an existing system" for all of the other servers in your domain (see Figure 2). 
Keep in mind that if you have already set up users in the servers, they will be wiped out when rerunning the Open Directory Assistant. Be sure to export your catalog so it can be reimported after the process is finished. Also, if you had previously set up


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Mac OS White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Live Webcast
A Geek's Guide to Presenting to Business People - Live Webcast: Wednesday, June 20th at 1:00 PM EDT
Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to... - Live Webcast
Today's NAS: A Solution Beyond Old Limits - Date: Tuesday, July 17, 2012 2:00 PM EDT
Traditional NAS systems don't scale beyond fixed limits. Proliferation of NAS systems leads to management... - Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Mac OS Webcasts