What You ve Learned


What You've Learned

  • Complex passwords play a very important role in a secure computing environment.

  • The various types of passwords used by Mac OS X and Mac OS X Server include shadowhash and Open Directory.

  • Use the Password Assistant to identify insecure password types.

  • Because you can leverage both SASL and Kerberos implementations, it is important to have more than one password type when using an Open Directory master.

  • You can use the AccessControls records to restrict access to your OpenLDAP directory data.

  • Use the Keychain application or its command-line equivilants, security and certtool, to manage certificates in Mac OS X.

References

Administration Guides

"Mac OS X Server Getting Started": http://images.apple.com/server/pdfs/Getting_Started_v10.4.pdf

"Upgrading and Migrating to Mac OS X Server v10.4 Tiger": http://images.apple.com/server/pdfs/Migration_v10.4.pdf

"Open Directory Administration": http://images.apple.com/server/pdfs/Open_Directory_v10.4.pdf

"Mac OS X Server Command-Line Administration": http://images.apple.com/server/pdfs/Command_Line_v10.4.pdf

Apple Knowledge Base Documents

The following Knowledge Base documents (located at www.apple,com.support) provide further information about secure authentication.

LDAP

Document 107242: "Mac OS X Server: How to Get More Than 500 Returns from LDAP Server."

Authentication

Document 107543: "Mac OS X Server 10.2, 10.3: Password Authentication Options for Networked Environments."

Document 107875: "Mac OS X Server 10.3: Upgrading Password Server Users to Kerberos and Single Sign-On."

Kerberos

Document 107702: "Mac OS X Server 10.3: Kerberos Authentication May Not Work After Changing to LDAP Master or Replica, or Kerberizing a Particular Service."

Books

Carter, Gerald. LDAP System Administration (O'Reilly, 2003).

Garman, Jason. Kerberos: The Definitive Guide (O'Reilly, 2003).

URLs

Massachusetts Institute of Technology Kerberos release: http://web.mit.edu/kerberos/www

"Designing an Authentication System: a Dialogue in Four Scenes": http://web.mit.edu/kerberos/www/dialogue.html




Apple Training Series. Mac OS X System Administration Reference, Volume 1
Apple Training Series: Mac OS X System Administration Reference, Volume 1
ISBN: 032136984X
EAN: 2147483647
Year: 2005
Pages: 258
Authors: Schoun Regan

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net