AD-2k3 & SSO in Mac Rich Environment

AD-2k3 & SSO in Mac Rich Environment

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
AD-2k3 & SSO in Mac Rich Environment SunWatch 08-15-2005
Posted by on August 15, 2005, 11:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hey, I am a college student currently employed as an infrastructure
consultant for a young small business, and I am looking for some advice
regarding Microsoft Active Directory and Single Sign On.

The problem is, over 60% of the workstations in the company are Macs
(PowerBooks running OS 10.2 or 10.3), and almost all of the
workstations are personally owned laptops or laptops that belong to
consultants that come in and out of the company periodically. And the
Backbone is all Windows Server 2003. One of the lead goals of our
infrastructure change is to achieve Single Sign On but as you can see
this is not going to be an easy task. For the Macs I was hoping to
achieve this through Open Directory, for the PC's we cannot use the
initial login as these are pre-configured laptops.

Right now I am looking at some sort of SSO client (key-ring,
authentication client, or simple password entering program) that will
work with both the PC's and Mac's. I have looked at many of the
commercial options out there, such as Novell's entry, CA's option
and the like, but most of them are either out of our budget, or meant
to be used with a larger environment.

Is there any Open Source/Freeware/Cheap option to help us bring SSO to
our AD setup?

Also, does anyone have experience with the NT Authentication of
Timbuktu Pro, as it currently seems to be flakey at best?



Posted by Scott Lowe on August 16, 2005, 12:12 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On 2005-08-15 14:46:05 -0400, SunWatch@gmail.com said:

> Hey, I am a college student currently employed as an infrastructure
> consultant for a young small business, and I am looking for some advice
> regarding Microsoft Active Directory and Single Sign On.
>
> The problem is, over 60% of the workstations in the company are Macs
> (PowerBooks running OS 10.2 or 10.3), and almost all of the
> workstations are personally owned laptops or laptops that belong to
> consultants that come in and out of the company periodically. And the
> Backbone is all Windows Server 2003. One of the lead goals of our
> infrastructure change is to achieve Single Sign On but as you can see
> this is not going to be an easy task. For the Macs I was hoping to
> achieve this through Open Directory, for the PC's we cannot use the
> initial login as these are pre-configured laptops.
>
> Right now I am looking at some sort of SSO client (key-ring,
> authentication client, or simple password entering program) that will
> work with both the PC's and Mac's. I have looked at many of the
> commercial options out there, such as Novell's entry, CA's option
> and the like, but most of them are either out of our budget, or meant
> to be used with a larger environment.
>
> Is there any Open Source/Freeware/Cheap option to help us bring SSO to
> our AD setup?
>
> Also, does anyone have experience with the NT Authentication of
> Timbuktu Pro, as it currently seems to be flakey at best?

Have you looked at having the Macs bind to Active Directory? While I
personally haven't tried it, I have heard from others that it works
reasonably well and can even cache the domain credentials for logons
while they are away from the office (just like a Windows box). It is
also my understanding that one you do have the Macs bind to AD, they
can take advantage of the AD Kerberos Key Distribution Center (KDC) for
automatic access to file servers in the domain (with no additional
passwords).

HTH.

--
Scott Lowe



Similar ThreadsPosted
Managing SSL Certificates in large environment. May 5, 2008, 12:36 pm
REVIEW: "Application Security in the ISO27001 Environment", Vinod Vasudevan et al November 20, 2008, 12:38 pm
SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege August 30, 2005, 9:42 pm
SSRT051004 rev.1 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege October 6, 2005, 11:44 am
[security bulletin] SSRT051052 rev.0 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access October 19, 2005, 8:02 pm
[security bulletin] SSRT051052 rev.1 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access October 21, 2005, 6:23 pm

The site map in XML format XML site map

Contact Us | Privacy Policy