Skip to main content
Question

Best Practices for Integrating OS X with Active Directory - Yosemite

  • December 8, 2014
  • 6 replies
  • 32 views

Forum|alt.badge.img+24

We've released a refresh of the AD integration technical document here: http://training.apple.com/pdf/wp_integrating_active_directory_yosemite.pdf.

6 replies

dlondon
Forum|alt.badge.img+14
  • Honored Contributor
  • December 9, 2014

Hi Jared,

Thanks for that. Do you or anyone else know why it says "To properly support Kerberos, both forward and reverse Domain Name System (DNS) records should be accurate for Kerberized servers".

What is it about reverse DNS that is important? If you don't have it, what will break/not work?

Regards,

David London


Forum|alt.badge.img+8
  • Contributor
  • June 6, 2016

@jarednichols I know this is an old topic.
But perhaps you or someone else has made a best practice for El Capitan?

The link provided for Yosemite is not working anymore.

Regards,

Ronald


bpavlov
Forum|alt.badge.img+18
  • Esteemed Contributor
  • June 7, 2016

Are you running into a particular issue with El Capitan?


Forum|alt.badge.img+8
  • Contributor
  • June 7, 2016

@bpavlov

No, I am currently working on a script (bash) to read out the expiry date and sent a notification to the user.


Forum|alt.badge.img+5
  • New Contributor
  • June 7, 2016

The latest whitepaper is for 10.10: on this page
direct: link

Ronald: for password expire dates I can recommend this ADPassMon tool, and similar KerbMinder.


Forum|alt.badge.img+8
  • Contributor
  • June 8, 2016

@mjsanders

Thanks for the link.

As far as Password Expiry Notifications I have seen ADPassMon. But I have create a bash script which will tell the user via CacaoDialog there password is expiring..

Still finetuning the script but a preview can be found here: link

I do have an update on this script but not fully tested it. In the new script I read out the Exact date for Password Expiry. (Just like ADPassMon does)