Similar documents
Integrating Mac OS X 10.6 with Active Directory. 1 April 2010

Charles Firth Managing Macs in a Windows World

Apple Technical White Paper Best Practices for Integrating OS X with Active Directory

Creating Home Directories for Windows and Macintosh Computers

Best Practices: Integrating Mac OS X with Active Directory. Technical White Paper April 2009

Macintosh Clients and Windows Print Queues

Best Practices: Integrating Mac OS X with Active Directory. Technical White Paper September 2007

Installation Logon Recording Basis. By AD Logon Name AD Logon Name(recommended) By Windows Logon Name IP Address

CENTRIFY TRAINING CLASS Centrify Suite Standard Edition - Mac OS X Training Course Details. Format: 100% lecture including demonstrations.

Centralized Mac Home Directories On Windows Servers: Using Windows To Serve The Mac

Other documents in this series are available at: servernotes.wazmac.com

Active Directory 2008 Implementation Guide Version 6.3

Presto User s Manual. Collobos Software Version Collobos Software, Inc!

Instructions for Adding a MacOS 10.4.x Server to ASURITE for File Sharing. Installation Section

Wazza s QuickStart 1. Leopard Server - Install & Configure DNS

Computer Science and Engineering MacOS Cisco VPN Client Installation and Setup Guide

Apple Technical White Paper Best Practices for Integrating OS X with Active Directory

DeployStudio Server Quick Install

ACS 5.x and later: Integration with Microsoft Active Directory Configuration Example

Active Directory Compatibility with ExtremeZ-IP. A Technical Best Practices Whitepaper

Active Directory Compatibility with ExtremeZ-IP

Configuring the Active Directory Plug-in

Centrify Identity Service and Mac - Online Training

VMware vcenter Support Assistant 5.1.1

Working Together - Your Apple Mac and Microsoft Windows

Univention Corporate Server. Operation of a Samba domain based on Windows NT domain services

Configuring and Using the TMM with LDAP / Active Directory

Wazza s QuickStart 10. Leopard Server - Managing Preferences

The question becomes, How does the competent Windows IT professional open up their print server to their Mac clients?

How to configure Mac OS X Server

Smart Card Setup Guide

Wazza s QuickStart 17. Leopard Server - Blogs & Wikis

How To Set Up A Macintosh With A Cds And Cds On A Pc Or Macbook With A Domain Name On A Macbook (For A Pc) For A Domain Account (For An Ipad) For Free

Wazza s QuickStart 13. Leopard Server - Windows Domain

Migration Strategies and Tools for the HP Print Server Appliance

Xerox 700 Digital Color Press with Integrated Fiery Color Server. Printing from Mac OS

Group Policy Objects: What are They and How Can They Help Your Firm?

SonicWALL Mobile Connect. Mobile Connect for OS X 3.0. User Guide

Configuring Active Directory Binding for OS X (10.4.x) within Miami Dade Schools

What s New in Propalms VPN 3.5?

Thecus N2100 FAQ. 1. NAS Management

Apple Technical White Paper Best Practices for Integrating OS X with Active Directory

1 Introduction. Ubuntu Linux Server & Client and Active Directory. Page 1 of 14

Other documents in this series are available at: servernotes.wazmac.com

Presto User s Manual. Collobos Software Version Collobos Software, Inc

Setting Up Scan to SMB on TaskALFA series MFP s.

EMR Link Server Interface Installation

Mac OS X and Directory Services Integration

Active Directory 2008 Implementation. Version 6.410

qliqdirect Active Directory Guide

SINGLE SIGN-ON FOR MTWEB

Instructions for Adding a MacOS 10.4.x Client to ASURITE

Setup guide. TELUS AD Sync

BlackBerry Enterprise Service 10. Universal Device Service Version: Administration Guide

Managing Users, Computers, & Groups

Binding an OS X computer to Active Directory at NEIU (Existing User)

How-to: Single Sign-On

6) Click the lock in the lower left corner of the Directory Utility Window and authenticate with the local administrator account s credentials.

Installing and Configuring Remote Desktop Connection Client for Mac

NETWORK SERVICES AND SHARING IN MAC

OFFICE OF KNOWLEDGE, INFORMATION, AND DATA SERVICES (KIDS) DIVISION OF ENTERPRISE DATA

AD Integration & Home Folders

Creating the Conceptual Design by Gathering and Analyzing Business and Technical Requirements

Creating Custom Nameservers Contents

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

Mac OS X Secure Wireless Setup Guide

Mail 8.2 for Apple OSX: Configure IMAP/POP/SMTP

CAC/PIV PKI Solution Installation Survey & Checklist

R4: Configuring Windows Server 2008 Active Directory

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

Connected Data. Connected Data requirements for SSO

Iomega Home Media Network Hard Drive

Professional Mailbox Software Setup Guide

How to connect to the DGL Practice Manager Cloud Server from an Apple Mac

Frequently Asked Questions

8 NETWORK SERVERS AND SERVICES FUNDAMENTALS

Office 365 deploym. ployment checklists. Chapter 27

1 Introduction. Windows Server & Client and Active Directory.

Configuring Sponsor Authentication

Windows" 7 Desktop Support

Installing and Configuring vcenter Support Assistant

Automating client deployment

Enabling Backups for Windows and MAC OS X

CONFIGURING ACTIVE DIRECTORY IN LIFELINE

Operating System Installation Guide

Xerox 700 Digital Color Press with Integrated Fiery Color Server. Utilities

Field Description Example. IP address of your DNS server. It is used to resolve fully qualified domain names

Securing LAN Connected Devices in Industrial Sites with TLS and Multicast DNS

v7.8.2 Release Notes for Websense Content Gateway

Windows Clients and GoPrint Print Queues

How To Use 1Bay 1Bay From Awn.Net On A Pc Or Mac Or Ipad (For Pc Or Ipa) With A Network Box (For Mac) With An Ipad Or Ipod (For Ipad) With The

Upgrade Guide BES12. Version 12.1

Joining a workstation to the TAMU IT Domain and Profile Migration

User Migration Tool. Note. Staging Guide for Cisco Unified ICM/Contact Center Enterprise & Hosted Release 9.0(1) 1

Using Mac OS X 10.7 Filevault with Centrify DirectControl

Dual Bay Home Media Store. User Manual

MS SQL Server Database Management

Transcription:

1

2

3

4

5

6

7

8

9

Multichannel Retailer selling bedding, towels, clothing, kid stuff (the huge bear is called Ralph) and home stuff for making your outside area look like that 10

5 years of doing Mac support in Windows environments 3 of those being a 1 st line newb deleting plists, resetting keychains etc 11

Literally hitler.local only on private networks Each computer knows its own name and responds to requests for that name automatically via IP multicast which is cool for home. But it means no DNS/DHCP server(s) required; doesn t work in an Enterprise; come onto that later. Bonjour is on OSX and ios out of the box; some printers use it, can install an agent on Windows Caused issues in 2002 by being called Rendezvous and Apple had a lawsuit filed against it (in 2003). From the documentation I can find on Apple.com, they have changed how Bonjour works every version from 10.4 onwards (all host names that ended with.local were resolved by default with mdns needed to be added to search domain, 10.5 added hostnames containing two or more labels are resolved using server but changes may have needed to be added to search list, 10.6 worked fine as long as you had a functioning DNS server. mdnsresponder swapped with discoveryd 12

Additionally, Mac OS X v10.6 automatically detects when the local network operator has set up a name server that will answer name requests for a domain ending in ".local". It does this by checking to see if there is a Start Of Authority (SOA) record for the top level domain "local", which is how a DNS server indicates that it claims to have authority over a part of the DNS namespace. As long as the DNS server is properly configured with the required SOA record, Mac OS X v10.6 will detect this SOA record and automatically use this server to look up all host names in the domain. 1 st November 2015 is when Certificate Authorities stop issuing certificates for.local and all CA issued.local certificates will at the latest expire on that date. 13

Although the underscore character is valid in hostnames, it is not a valid component in a DNS domain name. If the Active Directory domain being bound to contains an underscore in the domain name, binding and services will not function as expected (i.e. it won t bind). RFC1123 from 1989 states as much but I suspect the domain was created in the Windows 2000 days where underscore was allowed. 14

15

Small project to get Macs managed properly Needed to allow users to log into their Mac using domain credentials rather than having a different password for local login and server login We can t bind to LDN_TWC.local using the Apple AD plugin; and the Apple AD plugin doesn t support cross domain trust relationships so we can t put them on the new domain New storage platform as part of that project New servers are being bound to TWC.local so needs to support cross domain trust 16

Centrify plugin allows binding to an underscore It supports cross domain trust relationships so we can authenticate against TWC for the storage server We can script it And it s is free Thanks to Greg Neagle for the suggestion; I think he just wanted to shut me up 17

Script we used in binding via deploystudio This will tell the Centrify agent to use the same UID generation algorithm as the Apple plugin (Rather than use the traditional Centrify method of calculating it off of the user's SID). This way your existing AD users can continue logging into their Mac systems without any further configuration needed when we swap from Centrify to Apple AD. Networksetup to add domain to search domains (we don t have local set as a SOA). 18

Bound the Mac server doing the sharing to ldn_twc.local or twc.local, and the SMB service just crashes and requires a restart. Confirmed issue with Centrify, but using Express so it would have to be a forum post. Setup temporarily a single user with access to the storage bad but best we can do in short term Users don t understand the keychain despite documentation being sent their way; so ADPassMon to the rescue: https://yourmacguy.wordpress.com/adpassmon/ Windows computers couldn t connect to the mac server; we had a over eager GPO setup to restrict NTLM authentication types for the Computer OU in AD; created a new OU and moved all PCs that needed access to the server to that OU (temporary while we move domains and create new GPOs for the new domain). Centrify has a line in its conf that controls password expiry, if the AD account has password never expire enabled then it will ask to update the password and then muck up the keychain by updating network passwords. Fixed by disabling that setting for all users 19

Plans for Mac environment at TWC Script the adleave and join process to join twc.local Figure out a way to script UID using dscl or whether it s better just to create new accounts Install ESXi on the Mac Pro we have as the server; install drivers needed for the Pegasus RAID boxes to work with ESXi and then migrate all the things to linux/docker Make software install hands off with Salt + ServiceNow i.e. User requests software on ServiceNow, ServiceNow uses Salt to add the software to their manifest and then tell Munki to update on the Mac 20

21

22