We maintain passwords via a larger AD userbase, and I am now thinking I might like to see Keychain Access disabled for good. Meaning yes, lab and public workstation users would have to enter every password they need for every website they need one for-- every time. This would be great for computer labs like ours where computers often are abandoned. It appears as if the AD plugin in the post-10.7 OS's is slowly becoming unglued and increasingly buggy, IMHO. Computer lab users inevitably misunderstand or are baffled by the choices that the OSX AD-plugin Keychain GUI demands they make every time there is a domain account password change for the user.
It is my understanding that this is impossible given OSX's underpinnings, but I wanted to ask whether anyone has made this approach work for public or kiosk workstations. We have access to Profile Manager and its settings choices-- as well as the ability to deploy scripts and commands of every conceivable kind.
Thanks for any advice or wisdom on this. Keychain and AD have been the one item for us that consistently gets in the way of a smooth end-user experience. Users having to remember website passwords would be much preferable to all the outcomes we have seen with local login Keychain and the convenience they were originally intended to provide.
I have seen ADPassMon and a few other approaches to this, but I am becoming more interested in some more fundamental approach to circumventing the Keychain login db for good for an AD user.