TweetFollow Us on Twitter

Mac OS X Server 10.4

Volume Number: 21 (2005)
Issue Number: 8
Column Tag: Programming

Patch Panel

Mac OS X Server 10.4: Part Two Of Our Overview Of Mac OS X 10.4 Server

by John C. Welch

Last time, we took a long look at Mac OS X 10.4 Server from the Server Admin point of view, and concentrated mainly on server setup, features, and some management. Now, we're going to look at Mac OS X 10.4 Server from the Workgroup Manager point of view, or the tools and new features that Mac OS X 10.4 Server provides so you can better manage your network.

Workgroup Manager

Workgroup Manager is the tool you use to manage your overall Mac OS X network. Where Server Admin works with one server at a time, and only servers, Workgroup Manager works with multiple servers, client machines and client users. It's the primary tool for:

  • Setting sharepoints and access policies for those sharepoints
  • Setting client machines and client machine groups, their access policies and preferences
  • Setting users and user groups, their access policies and preferences
  • Manual manipulation of Open Directory data

Workgroup Manager is also the way you handle directory data from multiple directory systems. If you have multiple systems defined via the Directory Access application, then Workgroup Manager can work with those systems.

Directory Access in Mac OS X 10.4.x

One important point here is that you don't have to run Workgroup Manager on the server your using it with. You can also run Directory Access against a remote Mac OS X Server box via the cmd-K option, and this allows for what is called "directory mode", accessed via the "View Directories" option, or cmd-D in Workgroup Manager. In directory mode, you run Workgroup Manager from a remote administration Mac, that can be bound, via Directory Access to different directory systems than the server you're managing. This allows, for example, an Open Directory Master to integrate data from Active Directory without having to be itself bound to Active Directory. This allows for a great deal of flexibility, although my personal experience with directory mode has been inconsistent.

This does bring to mind one annoyance with directory service handling in Mac OS X in general, and that is how dependent it is on search order. If the search order in Directory Access is incorrect, you're in a world of hurt. As well, from what I can tell, if you have two external directory systems defined, and you try to authenticate, and the first one can't authenticate you, the directory services code won't fall through to the next one, and you can't authenticate. This is just a little annoying.

However, when directory mode in Workgroup Manager is working, and you have your authentication paths set right, it's neat as heck to use.

New Features

Since this is an article about Mac OS X 10.4 Server, I'm obviously going to concentrate on the new features that are in Mac OS X 10.4 Server that relate to Workgroup Manager. This isn't really a Workgroup Manager review; I'm just using that product as a framework. One change has to do with the new "Directory Admin" user concept. This just allows you to set up a Server so that the local machine administrator is not, by default the directory administrator, and in fact, the local administrator account that you first set up is a NetInfo only account, not an LDAP account. A second new feature is the Search button in the Workgroup Manager toolbar that allows you to search the Open Directory database by a number of items, such as UserID, Real Name, Comment, etc. If you have thousands of records in your Open Directory domain, that's a right handy feature to have.

User Accounts

The first obvious changes are due to the ACLs in Mac OS X 10.4. The old 16-group limits are gone, and there's support for inherited groups. As I said in July's article on this, ACLs give you great power, but you have to be careful, especially if you're talking about combined Active Directory and Open Directory networks. Careless application of ACLs will create security holes the likes of which you've never seen. Setting up groups for a user is still the same, although there's a new option for seeing inherited groups. This is for ACL usage, since you can have explicit and inherited permissions and groups. Mail and Print setup hasn't changed, although with the improvements to Mac OS X 10.4 Server's print architecture, the existing features probably work much better.

A new feature in Mac OS X 10.4 Server's client management is the Info tab for user accounts. This allows you to directly enter personal information on a user such as name, address, IM handle, etc. This is not a requirement for the account to work, but is a convenience for those using Open Directory as a shared address book. You could do this in Mac OS X 10.3 Server, but you had to directly edit the directory information, and it didn't always work correctly.

Workgroup Manager's Info Tab

The Windows settings for User accounts is unchanged, and the Inspector tab has only minor changes, such as showing the size of each entry in the user's record. One thing that hasn't changed from Mac OS X 10.3, and I really wish would, is the pane management in Workgroup Manager. You can't resize the panes in Workgroup Manager to show more info. You need to see the full Generated UID number? Changing the size of the window only increases the size of the account listing on the left. The data display on the right cannot be grown or shrunk depending on your needs, so get to scrolling. Shades of Windows 3.X! For a company that gets UI right far more than most, when they get it wrong, it's doubly frustrating.

Adding new users is unchanged, and still as kludgy as ever. Apple really needs to step up its sysadmin automation capabilities here. With regard to individual user preferences, there are a few updates here. The login prefs have some new features, such as "Add network home share point" and "Merge with user's items (Mac OS X 10.4 and later). The first one is how you make sure the user's network home share point always mounts. The second one, from what I can tell, is to merge the user's personal startup items and the ones you select for them so they all start up on login. I say, "from what I can tell", because this checkbox is pretty much undocumented. Apple's PDF and discussions group don't have anything on it, (at least not as of this writing, which is about a month before you read it) and searching the Apple Knowledge Base for that item gave me no results. Spotty documentation for a user is bad. Spotty sysadmin documentation is unacceptable. If they can take the time to code the function and the UI access for it, then Apple must take the time to document its basic function. Login Items is the only preference that you can manage for users or groups in the Workgroup Manager login preferences.

This gives me an opening to bring up a point about Workgroup Manager and the MCX (Managed Client OS X) here. There are three levels of management in MCX: User, Group, Machine. Most, but not all prefs can be set at all three levels. If you have contradictory settings, you may not get the results you want and you'll have great agony. You want to be very careful about setting the same preference on multiple levels, and do so as little as possible. Simple planning before you set will help here. Along these lines, Apple including a "Settings Check" function that would, if nothing else, highlight possible conflicts would be quite useful and very welcome.

The Media Access prefs haven't changed, but I wanted to point them out. If you have a need to limit how people can use removable media, this is an important setting. It allows you to lock down access to removable media at whatever level you require, with decent granularity. In today's SOX/GLB/HIPAA environment, being able to not allow copying of data to, or even from, removable media is an important feature, and I'm glad that Apple makes setting this up as easy as they do.

The Mobility setting is the biggest change to user management in OS X, and one that's been a long time in coming. With Mac OS X 10.3 Server, you could have "mobile" accounts, but all that did was deal with domain authentication. It did nothing for data synchronization. So, if you had a mobile account on one machine, and went to another machine, you didn't have any access to your home directory data on the first machine. Mobile accounts under Mac OS X 10.3 really only allowed you to log into the machine in situations where you were disconnected from the Open Directory network. In Mac OS X 10.4 Server, that's changed, and you now have (almost) full home directory synchronization. You can choose the items you want, or don't want to sync, and how. So, for example, you can have some directories sync on login and logout, (this would be the Windows Roaming Profile model), or have them sync in the background anywhere from once every 5 minutes to once an hour. You probably want to sync as little as possible to avoid network capacity problems. This means that if you have to switch machines a lot, you can have an almost uniform home directory setup, something that will be a major boon to mobile users, or schools, where a student may log into multiple machines throughout the day and then take a laptop home. There is one exception: Your home Library directory. That does not sync, even if you tell Workgroup Manager to sync it. This is primarily because you have some application and OS settings that use absolute hard coded paths that could break on different machines. Switching machines a lot will also make your ByHost preference management a lot more complicated. There is a workaround for this, at story=20050601101436323, but be warned, forcing that sync can cause problems, so be careful. However, even with that caveat, this is a feature that many have needed for a few years, and finally having it, even in this imperfect form, is a welcome change.

Portable Home Directory Sync setup

The Network preferences are a new feature, allowing administrators to set proxy preferences at the domain level, so that users can't bypass them. The Software Update prefs, also new in Mac OS X 10.4 Server, allow you to specify a local software update server you wish your users to use.

Group Accounts

At the group level, most of the account changes are wrapped around ACLs, so you can have groups within groups, etc. There are some other minor tweaks, like a group picture feature, and a comment for the group. Outside of preference features that don't exist at all in Mac OS X 10.3 Server, group preferences are unchanged.

Computer Accounts

This section has received more than a little work in Mac OS X 10.4 Server. In the Access tab, you have Mac OS X 10.4 - only options for Local - Only accounts picking workgroups from the list of groups allowed to access the machines in a computer list, and that computer administrators can disable management.

However, the specific machine information for Macs in a Computer List has grown by quite a bit. In Mac OS X 10.3 Server, about all you could do was set the computer list for a given machine, give it a name for use in Workgroup Manager, and a comment. In Mac OS X 10.4 Server, there are some new features here that work with the managed Network views. (I'll be getting to those later). So you can specify what Network view a machine can use, and the URLs that can be used to reach the computer based on what services it offers that you want used. So you can specify AFP, SMB, etc. When we go over managed Network views, you'll see how powerful this can be.

In the preferences, again, there aren't many changes that aren't Mac OS X 10.4 specific. The Login preferences are a little different for machines, in that you not only have features that only apply to the computer level, but you can now specify login and logout scripts that run instead of, or in addition to Login/LogoutHook scripts. This is a powerful, and potentially dangerous feature, so it only works if you enable this feature for root's loginwindow defaults AND you are using trusted binding to an Open Directory domain. This makes sense, as without that precaution, you could create a rogue server that would run 'bad' scripts on Macs that you shouldn't have control over. That would be A Bad Thing. And scripts have to be 30KB in size or smaller.

All Records

This (optional) tab hasn't changed in any noticeable way for Mac OS X 10.4 Server, and while that's good from a familiarity point of view, it perpetuates one of the worst design decisions ever made, and that is the decision to hide the structure of the directory from the humans. With almost any other Directory Service, such as Active Directory, you can see the tree view of the directory, and easily manipulate the data directly. So you can drag and drop items between OUs, groups, containers, etc. Workgroup Manager still doesn't allow you to do this, which is a shame, because even with Mac OS X 10.4 Server's rudimentary OU support, being able to handle those objects easily would make directory setup and administration far easier. I get that a lot of K-12 administrators don't want or need this kind of feature, but almost every other segment does want and need it. In the Enterprise Space, Workgroup Manager is one of the weakest directory management tools on the market, and things like this are a big part of it. Apple needs to, at least for Leopard; preferable well before, let the administrators who need this ability have access to it via Apple's own tools. Otherwise, you'll never be able to really scale Open Directory past a relatively smallish size.

Managed Network Views

This is a brand new feature for Mac OS X 10.4 Server, accessed, by clicking the Network button in Workgroup Manager, and in the short version, allows you to manage what your users see when they click on the Network icon in the Mac OS X 10.4 Finder. One of the problems with the Network view in Mac OS X 10.3 is that restricting what any Mac saw was quite hard, even effectively impossible. With Mac OS X 10.4 and Mac OS X 10.4 Server, you can now manage what neighborhoods and what machines any given client in an Open Directory domain can see. If you have a small network, this is not a big issue for you. If you have a few thousand clients on multiple subnets, this is a real help in controlling spurious browsing and its associated traffic.

There are three main kinds of views:

Named View: This is a network view that is visible only on those computers that you explicitly allow access for.

Default View: This is used for managed computers if there's no Named View.

Public View: This is used in lieu of the other two. If there's no Public View, but there is a Default View, that's used instead.

Within a Network View, you can have one or more of the following objects:

Network Neighborhood: This is a collection, (with a name stolen right from Windows, yeah, both sides do that), which can contain any of the three object types listed here. So it can contain individual computers, other Neighborhoods, or dynamic lists. It's a catchall that you can use as a root container type.

Computer: This is well, a computer. Specifically, it's a computer that Workgroup Manager knows about. You can add computers directly to a View, or to a Neighborhood. This allows you to better partition your browsing traffic, so you could, for example, have a Named View called "Directory Servers" and have only your Open Directory primaries and replicas listed there, and another Named View called "File Servers" which could contain Neighborhoods like "SMB Servers", "AFP Servers", etc.

Dynamic List: This is a collection of resources that is created on the fly when you access it in the Finder. Unlike the other two, you can only create a dynamic list from existing network structures, as seen below:

Dynamic View selection

Dynamic Lists are useful when you want to limit browsing and already have service discovery structures in place. Note that you can neither manually add nor remove items from a Dynamic List. You can however, put a Dynamic List in a Neighborhood and manage access in that fashion.

Once you have created your view types and the objects they contain, you can now manage their visibility, by either having the various views add to the unmanaged Finder Network Views, or replacing the standard Finder Network view entirely. This is a powerful tool if you need to limit access to various computers on your network, such as not allowing random access to the accounting servers, etc. It is also a good way to ensure that every computer isn't trying to browse entire network structures that they may have no need for. Limiting this kind of traffic helps enhance overall network performance, not just for the administrators, but for the users as well. If a user only needs access to four file servers, making them wait while an unmanaged browser view enumerates 150 machines is a waste of their time, not to mention bandwidth.


ACLs are, again, the main source of changes here. In the All tab, you have the option to enable ACLs on a given volume. Note that this can only be done at the volume level, and outside of Workgroup Manager, you can only do this via fsaclctl. Once that's done, you can then apply ACLs to specific folders and files within that volume at your discretion. This can be done outside of any sharing you may implement for a folder, and unlike sharing you can set ACLs on files too. Remember that I've been saying be careful with ACLs a lot? This is why:

Workgroup Manager ACL settings dialog

ACLs give you a lot of capabilities, but setting them willy-nilly, and not watching how you set groups within groups, or tracking who is in what group for which ACL entry will, not can, but will cause you problems. One benefit of Apple's implementation is that if you do get into trouble you can, as a last resort, turn ACLs off and start over again. I know Windows Admins who would love to do that, because they accidently created an ACL for a folder that not only keeps everyone out, but won't even let them delete it without reformatting the drive or other very drastic action.

I don't want to scare you away from ACLs, but you need to give them a lot of respect. As the disclaimer says, not intended for amateurs.

Outside of ACLs, sharing hasn't changed much. There's some improvement to the strict locking for SMB shares, (Note: You should only enable oplocks on shares that will only be touched by Windows clients.), but from the Workgroup Manager point of view, sharing's pretty much the same as it was in Mac OS X 10.3 Server, you just have juicy ACL goodness.


That's it for part two of this series. It's quite a bit shorter than the Server Admin part was, but then Server Admin is the basis for most of what Workgroup Manager does, so there's not as much change to talk about. The final part of this series will show up next month, and cover, well, everything else.

Bibliography and References

As with the first article in this series, almost everything in this article can be found in Apple's Server Documentation, at What little isn't there, I pried from the ridiculously busy brains of people like Schoun Regan of I.T. Instruction, Michael Bartosh of 4am Media, and Joel Rennich of Schoun and Michael are the authors of the two best books on Mac OS X Server available, the Visual Quickstart Guide to Mac OS X Server, and Essential Mac OS X Server Administration, respectively. Buy them both, they're great books. If you read any of my columns and don't regularly read, then you're missing out on a fantastic resource. All three of these guys, Schoun, Michael, and Joel are Apple Trainers too, a great reason to take the Apple courses if you haven't yet. Those courses are taught by the best folks in the Mac market, and well worth their cost.

John Welch is an IT Staff Member for Kansas City Life Insurance, a Technical Strategist for Provar, ( and the Chief Know-It-All for TackyShirt, He has over fifteen years of experience at making Macs work with other computer systems. John specializes in figuring out ways in which to make the Mac do what nobody thinks it can, showing that the Mac is a superior administrative platform, and teaching others how to use it in interesting, if sometimes frightening ways. He also does things that don't involve computertry on occasion, or at least that's the rumor. w


Community Search:
MacTech Search:

Software Updates via MacUpdate

Microsoft Office 2016 16.11 - Popular pr...
Microsoft Office 2016 - Unmistakably Office, designed for Mac. The new versions of Word, Excel, PowerPoint, Outlook, and OneNote provide the best of both worlds for Mac users - the familiar Office... Read more
Adobe Photoshop CC 2018 19.1.2 - Profess...
Photoshop CC 2018 is available as part of Adobe Creative Cloud for as little as $19.99/month (or $9.99/month if you're a previous Photoshop customer). Adobe Photoshop CC 2018, the industry standard... Read more
Adobe Dreamweaver CC 2018 -...
Dreamweaver CC 2018 is available as part of Adobe Creative Cloud for as little as $19.99/month (or $9.99/month if you're a previous Dreamweaver customer). Adobe Dreamweaver CC 2018 allows you to... Read more
Adobe Flash Player - Plug-in...
Adobe Flash Player is a cross-platform, browser-based application runtime that provides uncompromised viewing of expressive applications, content, and videos across browsers and operating systems.... Read more
Drive Genius 5.2.0 - $79.00
Drive Genius features a comprehensive Malware Scan. Automate your malware protection. Protect your investment from any threat. The Malware Scan is part of the automated DrivePulse utility. DrivePulse... Read more
MegaSeg 6.0.6 - Professional DJ and radi...
MegaSeg is a complete solution for pro audio/video DJ mixing, radio automation, and music scheduling with rock-solid performance and an easy-to-use design. Mix with visual waveforms and Magic... Read more
ffWorks 1.0.7 - Convert multimedia files...
ffWorks (was iFFmpeg), focused on simplicity, brings a fresh approach to the use of FFmpeg, allowing you to create ultra-high-quality movies without the need to write a single line of code on the... Read more
Dash 4.1.5 - Instant search and offline...
Dash is an API documentation browser and code snippet manager. Dash helps you store snippets of code, as well as instantly search and browse documentation for almost any API you might use (for a full... Read more
Evernote 7.0.3 - Create searchable notes...
Evernote allows you to easily capture information in any environment using whatever device or platform you find most convenient, and makes this information accessible and searchable at anytime, from... Read more
jAlbum Pro 15.3 - Organize your digital...
jAlbum Pro has all the features you love in jAlbum, but comes with a commercial license. You can create gorgeous custom photo galleries for the Web without writing a line of code! Beginner-friendly... Read more

Latest Forum Discussions

See All

Around the Empire: What have you missed...
Oh hi nice reader, and thanks for popping in to check out our weekly round-up of all the stuff that you might have missed across the Steel Media network. Yeah, that's right, it's a big ol' network. Obviously 148Apps is the best, but there are some... | Read more »
All the best games on sale for iPhone an...
It might not have been the greatest week for new releases on the App Store, but don't let that get you down, because there are some truly incredible games on sale for iPhone and iPad right now. Seriously, you could buy anything on this list and I... | Read more »
Everything You Need to Know About The Fo...
In just over a week, Epic Games has made a flurry of announcements. First, they revealed that Fortnite—their ultra-popular PUBG competitor—is coming to mobile. This was followed by brief sign-up period for interested beta testers before sending out... | Read more »
The best games that came out for iPhone...
It's not been the best week for games on the App Store. There are a few decent ones here and there, but nothing that's really going to make you throw down what you're doing and run to the nearest WiFi hotspot in order to download it. That's not to... | Read more »
Death Coming (Games)
Death Coming Device: iOS Universal Category: Games Price: $1.99, Version: (iTunes) Description: --- Background Story ---You Died. Pure and simple, but death was not the end. You have become an agent of Death: a... | Read more »
Hints, tips, and tricks for Empires and...
Empires and Puzzles is a slick match-stuff RPG that mixes in a bunch of city-building aspects to keep things fresh. And it's currently the Game of the Day over on the App Store. So, if you're picking it up for the first time today, we thought it'd... | Read more »
What You Need to Know About Sam Barlow’s...
Sam Barlow’s follow up to Her Story is #WarGames, an interactive video series that reimagines the 1983 film WarGames in a more present day context. It’s not exactly a game, but it’s definitely still interesting. Here are the top things you should... | Read more »
Pixel Plex Guide - How to Build Better T...
Pixel Plex is the latest city builder that has come to the App Store, and it takes a pretty different tact than the ones that came before it. Instead of being in charge of your own city by yourself, you have to work together with other players to... | Read more »
Fortnite Will Be Better Than PUBG on Mob...
Before last week, if you asked me which game I prefer between Fortnite Battle Royale and PlayerUnknown’s Battlegrounds (PUBG), I’d choose the latter just about 100% of the time. Now that we know that both games are primed to hit our mobile screens... | Read more »
Siege of Dragonspear (Games)
Siege of Dragonspear 2.5.12 Device: iOS Universal Category: Games Price: $9.99, Version: 2.5.12 (iTunes) Description: Experience the Siege of Dragonspear, an epic Baldur’s Gate tale, filled with with intrigue, magic, and monsters.... | Read more »

Price Scanner via

Sunday Sales: $200 off 13″ Touch Bar MacBook...
Amazon has new 2017 13″ 3.1GHz Touch Bar MacBook Pros on sale this weekend for $200 off MSRP, each including free shipping: – 13″ 3.1GHz/256GB Space Gray MacBook Pro (MPXV2LL/A): $1599.99 $200 off... Read more
B&H drops prices on 15″ MacBook Pros up t...
B&H Photo has dropped prices on new 2017 15″ MacBook Pros, now up to $300 off MSRP and matching Adorama’s price drop yesterday. Shipping is free, and B&H charges sales tax for NY & NJ... Read more
Apple restocks Certified Refurbished 2017 13″...
Apple has restocked Certified Refurbished 2017 13″ 2.3GHz MacBook Pros for $200-$230 off MSRP. A standard Apple one-year warranty is included with each MacBook, models receive new outer cases, and... Read more
13″ Space Gray Touch Bar MacBook Pros on sale...
Adorama has new 2017 13″ Space Gray Touch Bar MacBook Pros on sale for $150 off MSRP. Shipping is free, and Adorama charges sales tax in NY & NJ only: – 13″ 3.1GHz/256GB Space Gray MacBook Pro (... Read more
Best deal of the year on 15″ Apple MacBook Pr...
Adorama has New 2017 15″ MacBook Pros on sale for up to $300 off MSRP. Shipping is free, and Adorama charges sales tax in NJ and NY only: – 15″ 2.8GHz Touch Bar MacBook Pro Space Gray (MPTR2LL/A): $... Read more
Save $100-$150+ on 13″ Touch Bar MacBook Pros...
B&H Photo has 13″ Touch Bar MacBook Pros on sale for $100-$150 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 13″ 3.1GHz/256GB Space Gray MacBook Pro... Read more
Current deals on 27″ Apple iMacs, models up t...
B&H Photo has 27″ iMacs on sale for up to $150 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 27″ 3.8GHz iMac (MNED2LL/A): $2149 $150 off MSRP – 27″ 3... Read more
Thursday Deal: 13″ 2.3GHz MacBook Pro for $11...
B&H Photo has the 13″ 2.3GHz/128GB Space Gray MacBook Pro on sale for $100 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 13-inch 2.3GHz/128GB Space... Read more
How to save $100-$190 on 10″ & 12″ iPad P...
Apple is now offering Certified Refurbished 2017 10″ and 12″ iPad Pros for $100-$190 off MSRP, depending on the model. An Apple one-year warranty is included with each model, and shipping is free: –... Read more
Silver 12″ 1.3GHz MacBook on sale at B&H...
B&H Photo has the 2017 12″ 1.3GHz Silver MacBook on sale for $1399.99 including free shipping plus sales tax for NY & NJ residents only. Their price is $200 off MSRP, and it’s the lowest... Read more

Jobs Board

*Apple* Genius - Technical Customer Service...
Job Description:Job SummaryAs a Genius at the Apple Store, you maintain customers' trust in Apple as the skilled technical customer service expert, Read more
*Apple* Endpoint Administrator - Massachuset...
Reporting to the Director of Client Services (DCS), the Apple Endpoint Administrator serves as a member of the Client Services team, which provides technical support Read more
Franchise Operations Advisor- *APPLE* Exper...
UFG, Inc. Franchise Operations Advisor - MUST HAVE APPLE OR WINDOWS EXPERIENCE (Outside Sales / Business Development / Customer Service / Full Time) Top Five Reasons Read more
Engineering- Platform- *Apple* Enterprise P...
…& RESPONSIBILITIES You are responsible for creating and supporting our next-gen Apple Platform Installers from ground-up. We use Jamf Composer tool along with Read more
*Apple* OS X Server Administrator (Active Se...
Apple OS X Server Administrator \(Active Secret Clearance\) Description Come be a part of a top notch team, apply today\!\! Tuva TUVA provides turnkey solutions that Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.