Chapter 3: Using Open Directory - 9 Questions Flashcards
What’s the main function of directory services?
Directory services provide a central repository for information about the computers, applications, and users in an organization.
What standard is used for data access with Open Directory? What version and level of support is provided for this standard?
Open Directory uses OpenLDAP and the Lightweight Directory Access Protocol (LDAP) standard to provide a common language for directory access. Open Directory uses LDAPv3 to provide read and write access to the directory data.
In terms of Open Directory, what four roles can Lion Server play?
Lion Server can be an Open Directory master, a standalone server, connected to a directory system, and an Open Directory replica.
What are the two methods of applying password policies, and where are they located?
Per-user policies are defined in Workgroup Manager, and global policies are defined in Server Admin or the Server app.
When you create an Open Directory archive, is the sparse image created on the server that hosts the Open Directory service or on the administrator computer from which you run Server Admin?
The archive is created on the server that hosts the Open Directory service.
What criteria determines the Open Directory locale with which a Lion Open Directory client associates?
If a Lion computer’s IPv4 address is in the range of a subnet associated with an Open Directory locale, that computer should use any of the Open Directory servers associated with that locale. Otherwise, it will use the default locale.
What log shows successful and failed attempts to authenticate against the password service?
Password Service Server Log, located at /Library/Logs/ PasswordService/ApplePasswordServer.Server.log, shows successful and failed attempts to authenticate.
What tool can you use to confirm forward and reverse DNS records?
You should use Network Utility to confirm forward and reverse DNS records before configuring as an Open Directory master or replica, or binding to another directory service.
What tool can you use to check the ability to obtain a Kerberos ticket?
Ticket Viewer is in /System/Library/CoreServices, and you can use it to confirm the ability to obtain a Kerberos ticket.