beautypg.com

Using a local directory search policy – Apple Mac OS X Server (version 10.2.3 or later) User Manual

Page 89

background image

Directory Services

89

Note: Make sure the computer has been configured to access the LDAP servers, Active
Directory servers, NetInfo domains, and BSD configuration files that you want to add to the
search policy. For instructions, see the subsequent sections of this chapter.

To define a custom search policy for the computer:

1

In Directory Access, click the Authentication tab or the Contacts tab.

Click Authentication to configure the search policy used for authentication and most other
administrative data.

Click Contacts to configure the search policy used for contact information in some mail,
address book, and personal information manager applications.

2

If the lock icon is locked, click it and type the name and password of a server administrator.

3

Choose “Custom path” from the Search pop-up menu.

4

Click Add.

5

Select from the list of available directories and click Add.

To add multiple directories, select more than one and click Add.

6

Change the order of the listed directory domains as needed, and remove listed directory
domains that you don’t want in the search policy.

Move a listed directory domain by dragging it up or down.

Remove a listed directory domain by selecting it and clicking Remove.

7

Click Apply.

Using a Local Directory Search Policy

If you want to limit the access that a computer has to authentication information and other
administrative data, you can restrict the computer’s authentication search policy to the local
directory domain. If you do this, users without local accounts on the computer will be unable
to log in or authenticate for any services it provides. You can configure a computer to use
only its local directory domain by using the Directory Access application on the computer.

To restrict a computer to its local directory domain:

1

In Directory Access, click the Authentication tab or the Contacts tab.

Click Authentication to configure the search policy used for authentication and most other
administrative data.

Click Contacts to configure the search policy used for contact information in some mail,
address book, and personal information manager applications.

2

If the lock icon is locked, click it and type the name and password of a server administrator.

3

Choose “Local directory” from the Search pop-up menu, then click Apply.

LL0395.Book Page 89 Wednesday, November 20, 2002 11:44 AM