Directory Services Methods
I am at a little stopping point and could use some asistance...
I am configuring remoted management for our various systems. I utimately need to only allow certain users to "ard_interact" on certain machine and other users to "ard_manage" / "ard_admins" on other machines. IE... I don't want all my editros to be able to interact with my servers.
Ideal would be to set specific "ard_admins / manage / interact" on a certain COMPUTER GROUP.
I have been reading the methods described here:
http://docs.info.apple.com/article.html?path=RemoteDesktop/3.0/en/ARDC55.html
Method 2 has me creating the users groups on OD call "ard_admin..." and so forth. I can them add users to this groups. I can have my editors as "interact", but they would still be able to interact on servers. I have this working fine with just admins...being admins.
BUT, Method 1 would be ideal as it seams to be a way to apply these setting from a compuer group basis.
Method 1 shows us to apple the xml data as a new line in the MCXSetting for a computer groups. I have been trying this with no success. My steps:
1. Changes Client to allow "Directory Authentication"
--- this worked as I can get method 2 to work.
2. I have NO ard_XXX groups in OD, as to not create confusion.
3. I create an XML, and test the plist with xcode that states the differenct usergroups for ard_admins and ard_interact.
4. I open the directory editor (lion) or inspector in snow, locate the computer group in the LDAP, find the existing MCSSettings.
5. I "+" add a value and then paste the xml code in"
6. After reboots, the macs in the group will not let me manage (testing using screen share is easiest).
So...I'm trying to firgure out where I went wrong in the past fews days or where I misunderstood..
One thing that is very unclear in the documentation is where and whice MCXSettings are we suppossed to append? Compuer Groups, Computer Lists? Forgive my ignorance here as I try these out.
Method 2 will work, but, I really need to open it up to my non-admins and get method 1 to work giving me different ARD settigns for different computer groups.
-mt