Lesson 10: Managing Local Network Accounts Flashcards

Configure local network accounts; Import local network accounts; Describe authentication types; Understand basic Kerberos infrastructure; Configure global password policy

1
Q

What tool can you use to check the ability to obtain a Kerberos ticket?

A

Ticket Viewer is in /System/Library/CoreServices, and you can use it to confirm the ability to obtain a Kerberos ticket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you import local network users from a text file with a properly formatted header line?

A

Choose Manage > Import Accounts from File, select the text file, choose Local Network Accounts in the pop-up menu, provide directory administrator credentials, and click Import.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some reasons that a client computer might not be able to use Kerberos authentication to access a service?

A
  • The client computer might not be bound to a directory service that provides Kerberos
  • The system time between the client computer and the server computer might be off by more than five minutes
  • There could be a DNS configuration issue
  • The service might not be configured to use Kerberos
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In addition to authentication, what else can Kerberos provide?

A

Kerberos provides identification and authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How can you disable a local network user account so that it cannot be used to access services or log in on a bound Mac?

A

In the User pane of the Server app, double-click the user to edit the user, and deselect the checkbox “Allow user to log in.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some examples of global password policies that you can apply to users that apply the next time they change their password?

A

Some examples include:

  • Passwords must differ from account name
  • Contain at least one letter
  • Contain both uppercase and lowercase letters
  • Contain at least one numeric character
  • Contain a character that isn’t a letter or number
  • Contain at least a given number of characters
  • Differ from the last given number of passwords used
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are some examples of global password policy you can configure to disable login after certain events occur?

A

Some examples include that login will be disabled:

  • On a specific date
  • After using it for a given number of times
  • After inactive for a given number of days
  • After a user makes a given number of failed attempts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does a user obtain a Kerberos service ticket?

A

Once a user has a ticket-granting ticket, OS X automatically attempts to obtain a service ticket when a user attempts to connect to a Kerberized service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly