Apple OS X Mountain Lion v10.8
2
OS X Active Directory Mac Mac Active Directory Mac Windows Apple OS X Active Directory Apple Open Directory Open Directory OS X OS X OS X Server Open Directory LDAP Kerberos SASL Apple Open Directory OS X Active Directory Active Directory OS X OS X Active Directory OS X Active DirectoryOS X Windows Mac Active Directory Kerberos Active Directory Active Directory OS X Server Active Directory OS X Server OS X ServerWindows Active Directory wiki OS X Server OS X Server 3
OS X Server Windows OS X LDAP Mac Active Directory Mac Active Directory LDAP Active Directory Active Directory ichat OS X Active Directory Active Directory E E Microsoft Active Directory OS X Active Directory Mac Active Directory NetBoot Active Directory Mac Active Directory Mac DNS Active Directory Active Directory ID Mac Mac Active Directory Active Directory ID Active Directory Mac LocalHostName 4
Mac Active Directory UNC Mac Dock smb afp UNIXOS X /usr/bin/bash OS X Active DirectoryUID GID UID GID Active Directory OS X Active Directory Mac OS X Mac Active Directory Active Directory 5
Windows Server Mac Active Directory Windows Server 2000 2003 2003 R2 2008 2008 R2 OS X dsconfigad Active Directory dsconfigad -preferred ads01.example.com -a COMPUTERNAME domain example.com -u administrator -p "password" dsconfigad Directory Access dsconfigad -alldomains enable -groups domain admins@example.com, enterprise admins@example.com dsconfigad Active Directory Mac Active Directory Mac Active Directory odutil set log debug Active Directory /var/log/opendirectoryd.log odutil set log default /usr/sbin/dsconfigad -packetencrypt disable /usr/sbin/dsconfigad -packetencrypt allow UDP 53 TCP 88 - DNS - Kerberos 6
TCP 389 TCP/UDP 464 TCP 3268 - LDAP - KerberosKPasswd - LDAP Ethernet capture.out tcpdump tcpdump K -i en0 -s 0 -w capture.out port 88 or port 464 or port 53 or port 389 or port 3268 Wireshark OS X Open Directory Active Directory DNS Active Directory Mac Active Directory Open Directory DNS Active Directory DNS SRV Mac WindowsDNS Mac DNS dig example.com Active Directory DNS dig -t SRV _ldap._tcp.example.com IP MacDNS Active Directory DNS OS X Active Directory A PTRDNS OS X Kerberos Active Directory Mac OS X Mac Active Directory 24 Mac Active Directory 14 dsconfigad 7
Apple Microsoft Kerberos Active Directory OS X KerberosNTLMv1 NTLMv2 Microsoft NT LAN Manager NTLM Mac Active Directory OS X Server Active Directory MacActive Directory Kerberos Ticket Granting Ticket TGT Kerberos TGT Mac Kerberos klist / / /CoreServices/.app Kerberos OS X Active Directory dsconfigad 1 Windows \ Open Directory Active DirectoryLDAP OS X Server Message Block SMB Mac LDAP LDAP over SSL Secure Sockets Layer SSL Open Directory SSL /usr/sbin/dsconfigad -packetencrypt ssl SSL / / security 8
/usr/bin/security add-trusted-cert -d -p basic -k /Library/ Keychains/System.keychain < > 802.1X VPN S/MIME OS X Microsoft OS X 10.8 Mountain Lion DCE/RPC UI 1 Active Directory Microsoft AD 802.1X EAP-TLS Windows OS X Mac Active Directory GPO Apple Active Directory Open Directory OS X Mac Windows Active Directory OS X OS X Mac Open Directory Active Directory Active Directory Mac Mac 9
Active Directory Mac Mac Mac Absolute AirWatch JAMF Software MobileIron Active Directory Beyond Trust Centrify Thursby Quest IT Active Directory Windows Active Directory OS X Active Directory Active Directory OS X DFS OS X DFS UNC SMB DFS AFP afp:// URL Active Directory URL UNC Mac SMB AFP Directory Services Apple Active Directory Active Directory Mac Active Directory Windows \\server\share\user URL Mac Active Directory Active Directory mb://server.ad.domain/share/ user URL URL //server/share/user //server.userad.domain/share/home Mac 10
Windows Mac AFP SMB OS X Server Windows OS X Server OS X Windows AFP Mac SMB Windows OS X Active Directory Mac Mac Active Directory Mac Windows OS X Windows OS X xml Active Directory OS X Active Directory AppleApple 11
A Apple Mac OS X Active Directory - http://support.apple.com/kb/ts1532?viewlocale=ja_jp OS X Server Active Directory SSL http://support.apple.com/kb/ht4730?viewlocale=ja_jp DCE RPC Active Directory Microsoft http://support.apple.com/kb/ht5357?viewlocale=ja_jp ADCertificatePayloadPlugin Microsoft http://support.apple.com/kb/ht4784?viewlocale=ja_jp 12
B DFS GPO Apple GroupLogic ExtremeZ-IP www.grouplogic.com Windows Apple AFP Mac Windows Centrify DirectControl www.centrify.com Active Directory OS X Active Directory GPO PowerBroker Identity Services Enterprise Edition www.beyondtrust.com Active Directory OS X Active Directory GPO Thursby ADmitMac www.thursby.com Active Directory SMB DFS Objective Development Sharity www.obdev.at/products/sharity SMB DFS Quest Authentication Services www.quest.com Active Directory OS X Active Directory GPO 13
Apple Inc. 2013 Apple Inc. All rights reserved. Apple Apple AppleCare FileVault Finder FireWire ichat Mac Mac OS OS X Apple Inc. UNIX Open Group OS X Mountain Lion v10.8 Open Brand UNIX 03 2013 1 15 14