speckytecky Posted July 1, 2010 Posted July 1, 2010 We have a Server 2008 domain and I have been asked today to join a new Mac to it - never done anything like this before is there a muppet guide anyone could p[oint me toward please?
sidewinder Posted July 1, 2010 Posted July 1, 2010 A sticky just a few posts above http://www.edugeek.net/forums/mac/15199-active-directory-authentication-how.html 1
dhicks Posted July 1, 2010 Posted July 1, 2010 We have a Server 2008 domain and I have been asked today to join a new Mac to it I've not used it on a Mac, but have on Linux: Likewise Open Source Software that Authenticates Linux, Unix, and Mac systems with Microsoft Active Directory Don't forget you still need to buy a Windows server CAL. -- David Hicks 1
Sean-OC04 Posted July 1, 2010 Posted July 1, 2010 You don't need a CAL to bind a Mac to AD or to use Exchange Services, you will only need one to access Terminal Services on the Windows Server.....
dhicks Posted July 1, 2010 Posted July 1, 2010 You don't need a CAL to bind a Mac to AD Not a TS CAL, but I understood you still needed a device/user CAL for any device that autheticated against Active Directory - same as you need a CAL for each workstation (or user) that you join to your AD domain. -- David Hicks
Sean-OC04 Posted July 1, 2010 Posted July 1, 2010 Not a TS CAL, but I understood you still needed a device/user CAL for any device that autheticated against Active Directory - same as you need a CAL for each workstation (or user) that you join to your AD domain. -- David Hicks Nope... you don't need CAL to Authenticate/Bind or even connect Mac OS X 10.6 to an Exchange Server, only if you were connecting to Terminal Services 1
dhicks Posted July 1, 2010 Posted July 1, 2010 Nope... you don't need CAL to Authenticate/Bind or even connect Mac OS X 10.6 to an Exchange Server, only if you were connecting to Terminal Services Okay, thanks, handy to know - is this something just holds for Mac OS X 10.6, or previous versions of Mac OS X too? -- David Hicks
Sean-OC04 Posted July 1, 2010 Posted July 1, 2010 Okay, thanks, handy to know - is this something just holds for Mac OS X 10.6, or previous versions of Mac OS X too? -- David Hicks Yes if all you doing are binding them to AD, bear in mind though that the AD plug in wasn't as stable before Mac OS X 10.5.6. Also bear in mind that if you want to connect the Mac to other Windows services eg.Terminal you will then need a CAL 1
dhicks Posted July 1, 2010 Posted July 1, 2010 Also bear in mind that if you want to connect the Mac to other Windows services eg.Terminal you will then need a CAL So how is this sorted out - does the price of Mac OS X include a Windows CAL, then? -- David Hicks
speckytecky Posted July 1, 2010 Author Posted July 1, 2010 Haven't cracked it yet but I have downloaded Likewise Open Source Software that Authenticates Linux, Unix, and Mac systems with Microsoft Active Directory and sussed versions etc so thanks folks for the very useful answers - it's now a job for next week.
leco Posted July 1, 2010 Posted July 1, 2010 Thanks for this it's what I need as well. Also a job for next week, cheers 1
AntonioRocco Posted July 1, 2010 Posted July 1, 2010 Hi "So how is this sorted out?" Nothing to be sorted. Bind the workstation to Active Directory. That's it. The platform has no requirement for a CAL let alone a Microsoft one. "Does the price of Mac OS X include a Windows CAL, then?" How can a Windows CAL work with any other operating system other than Windows? Additionally Apple does not support Windows. Apple do however provide an environment (via BootCamp) for anyone to install Windows OS if they wanted to. BootCamp is not the Windows OS. You would still need a licence to install Windows because once you go beyond the Mac OS the hardware is effectively a PC and you would treat the same as any other PC. Antonio Rocco (ACSA)
speckytecky Posted July 2, 2010 Author Posted July 2, 2010 Thanks Leco for trying to bring the thread back on to topic:) Like - how do you join a Mac to Windows 2008 AD rather than about CAL's:rolleyes: I'd be very interested to hear how you get on - I'm not making my attempt till Thursday. Thanks for this it's what I need as well. Also a job for next week, cheers
HodgeHi Posted July 2, 2010 Posted July 2, 2010 I've just looked at the likewise software and I'm not too sure what it does that the Directory utility doesn't. For simplicity's sake I would personally prefer to remove any software that could complicate things and just use what's there. Unless there is an issue with the dir util in general with 2008 AD and OS X. I would perhaps try those 2 together first rather than confusing matters even more with additional software. Or did I miss something, very is very likely If you aren't sure of the process of binding a mac to the AD then give me a shout and I will club together a guide for you. 2
leco Posted July 2, 2010 Posted July 2, 2010 Thanks HodgeHi - my problem/challenge/issue is that the MAC keeps 'losing' it's connection/binding or whatever it is. I've done the rebinding a couple of times now but have to go back to square one each time. The last time it went I just gave the user a local account ie on the MAC, which he was happy with since all the stuff he was doing was on the MAC anyway. Now however, I've been asked by my boss why he can't get to the Network folders. So I have to address the issue again, which I was hoping to avoid to be honest as I have lots of other things to do. Any help you can give would be much appreciated - I'm a Windows Network Tech not a MAC tech.
dhicks Posted July 5, 2010 Posted July 5, 2010 How can a Windows CAL work with any other operating system other than Windows? Sorry, some Windows-related confusion here: Windows Server requires a license (a Client Access License, CAL) for each client that connects to it. This is seperate from the license for Windows (or any any other operating system), and has nothing to do with any kind of serial number. There is no software mechanism in place to check on the number of CALs used, this is the kind of thing that would have to be checked by an audit of some kind. I understood you needed a CAL for every device (or user) that authenticated against an active directory server - even your printers, if they have an AD integration feature. -- David Hicks
HodgeHi Posted July 5, 2010 Posted July 5, 2010 As far as I am aware this is correct. The mac guys are probably unfamiliar with the rip-off that are CALs. With a Mac Server CALs are not needed. I just explain CALs as a tax on the network cable that joins the 2, Windows (and other OS Clients) and AD Server, together. For example A Windows 2003 server has 10 Clients accessing services on the AD Server. 5 Xp, 5 OS X 10.6. The total amount of CALs needed would be 10. Even though 5 are not Windows clients they still access the services on the AD Server. There's even more confusion when you have multiple services on one AD Server. I think you then need more than 1 CAL for each client for each service being accessed on 1 AD Server.
dhicks Posted July 5, 2010 Posted July 5, 2010 I think you then need more than 1 CAL for each client for each service being accessed on 1 AD Server. No, you need one Windows Server CAL for each client (of whatever OS) that authenticates against your Active Directory server. That covers that client connecting to as many servers in your domain as you like - one client can connect to half-a-dozen Windows file servers, if you like. Some services are seperatly chargable - you need separate CALs for Terminal Services and SQL Server. Terminal Services will actually track CAL usage, unlike plain Server CALs. There's a whole forum for this topic around here somewhere, we should probably move this part of the discussion over there. -- David Hicks
HodgeHi Posted July 5, 2010 Posted July 5, 2010 I was under the impression that you need to use CALs for file sharing services, print services amongst others. Does this mean that you would only need one CAL for these types of services since they all reside on 1 server? There's a whole forum for this topic around here somewhere, we should probably move this part of the discussion over there. Agreed
dhicks Posted July 5, 2010 Posted July 5, 2010 Does this mean that you would only need one CAL for these types of services since they all reside on 1 server? Yes, you would just need the one Windows Server CAL (£5-ish or whatever it is each) per client, that would cover you for file sharing, printing, etc. Actually, it would cover you if you (sensibly) split each of those services on to a separate server, or multiple servers, even. You do, hwoever, need to upgrade your Windows Server CALs if you upgrade your Domain Controller - move from 2003 to 2008 and you have to re-buy CALs. You need seperate CALs for some services - Terminal Services, SQL Server, etc. The Wikipedia article might make a decent starting point: http://en.wikipedia.org/wiki/Client_Access_License -- David Hicks 1
HodgeHi Posted July 5, 2010 Posted July 5, 2010 Thanks for the clarification. Will remember that in the future. I have also split the services across multiple servers. This should save use some money. Thanks for the link also.
sidewinder Posted July 8, 2010 Posted July 8, 2010 (edited) I think what Antonio is saying is correct - you dont need a CAL to authenticate/bind to AD. You do need a CAL if you connect to any file shares on Windows Server, but you can easily have the home shares on an OS X server, which is what we do. I mean what about a open source NAS distro that can authenticate against AD for ACL's. Would you buy a CAL for that? I wouldnt...whether thats wrong I dont know, but I dont see why you would have to Edited July 8, 2010 by sidewinder
Marci Posted July 8, 2010 Posted July 8, 2010 Thanks HodgeHi - my problem/challenge/issue is that the MAC keeps 'losing' it's connection/binding or whatever it is. I've done the rebinding a couple of times now but have to go back to square one each time. The last time it went I just gave the user a local account ie on the MAC, which he was happy with since all the stuff he was doing was on the MAC anyway. Now however, I've been asked by my boss why he can't get to the Network folders. So I have to address the issue again, which I was hoping to avoid to be honest as I have lots of other things to do. Any help you can give would be much appreciated - I'm a Windows Network Tech not a MAC tech. If it keeps needing to be rebound to AD, check that you've set the timeserver source on the Mac to the same source as used for your Windows Clients.
leco Posted July 8, 2010 Posted July 8, 2010 Time source on the windows clients is the windows 2008R2 DC - can the mac synchronize to/from that?
Marci Posted July 9, 2010 Posted July 9, 2010 Yep, click on clock on the mac, Open Date & Time, and type in the IP or DNS of your DC in the "Set Date & Time Automatically:" box. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now