The Mac Observer

Skip navigational links

Featured Article: Editorial - Mac's Market Share and the Cascade Failure of Windows

Tips for Securing Apple's Open Directory

by , 12:30 PM EDT, August 31st, 2007

Apple's Open Directory for Mac OS X Server is a powerful, capable directory services system that uses open standards like Open LDAP and Kerberos. Despite its capabilities, there are still some methods to secure it over and above the default settings, according to Ryan Faas at Computerworld on Friday.

Mr. Fass, who has written an informative series on Apple's Open Directory system, noted, "For administrators, employing a robust directory services application that supports all their clients is only part of the equation. Directory servers manage user authentication and maintain significant amounts of information about users, groups, servers, workstations and network configurations. This makes securing directory servers a paramount concern for any network admin."

Some of the things that were noted include:

  1. Use open Directory not crypt passwords.
  2. Rely on Kerberos at every opportunity
  3. Disable unused authentication mechanisms
  4. Require SSL for all communication
  5. Use Trusted Binding introduced in Mac OS X 10.4
  6. Secure relevant ports via firewall

Mr. Faas reminded administrators that frequent inspection of the Password Service Server log will reveal failed login attempts and is worthy of attention.

The article, one more in a notable series of articles by the Mr. Fass, is a good refresher for Apple network administrators to make sure they've taken all possible measures to secure their Apple network and do it correctly.

Observer Comments

Show: Subjects Only | Full Comments
Comment on this Article

Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, July 4th, 2008

Fri., 7:30 AM
Happy Fourth of July!
Thu., 4:50 PM
Apple Slashes $400 from SSD Drive in MacBook Air
4:05 PM
It's Official - Firefox Sets Guinness Record for Downloads
3:30 PM
Apple Files Patent for a Multi-touch Gesture Language
2:20 PM
Editorial - Mac's Market Share and the Cascade Failure of Windows
1:35 PM
iPodObserver - Apple Slurps Up Samsung's NAND Flash for iPhone 3G
1:05 PM
WSJ: Tips for Switching from Windows to Mac
12:05 PM
iPodObserver - Google Intros Google Talk for iPhone
11:35 AM
iPO Just a Thought - iPod nano Versus iPhone: Decisons, Decisions...
10:55 AM
YouTube Ordered to Turn Over All User Records to Viacom
10:10 AM
Hot Forum Topic - Apple vs. Cell Carriers: Who's Winning the Game
9:25 AM
iPodObserver - Rumor: Best Buy, Radio Shack to Sell iPhone 3G
8:45 AM
.Mac Bookmark Sync Deadline Extended to July 6
8:10 AM
Adobe Reader 9 Hits the Streets
 

The Mac Observer Reader Specials

  • Special Report: WWDC 2008
  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!
  • New Media Expo 2008

Apple Stock Quote

  • AAPL: $170.12. Change Today: +1.94.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Apple iTunes

Top Deals From DealsOnTheWeb