Apple Mac OS X Server Installationsanleitung Seite 1

Stöbern Sie online oder laden Sie Installationsanleitung nach PC / Workstation Barebones Apple Mac OS X Server herunter. Apple Mac OS X Server Installation guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 197
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Mac OS X Server

Mac OS X ServerAdvanced Server AdministrationVersion 10.6 Snow Leopard

Seite 2

10 Contents

Seite 3 - Contents

Installing Locally from the Installation DiscYou can install Mac OS X Server directly onto a computer with a display, a keyboard, and a DVD drive atta

Seite 4 - 4 Contents

Chapter 5 Installation and Deployment 101After installation is complete, the target server restarts and you can perform initial server setup. Ch

Seite 5 - Contents 5

3 Select the target server from the list of servers waiting for installation.If neither the target server nor the list appear, make sure the target

Seite 6 - 6 Contents

Chapter 5 Installation and Deployment 103For detailed instructions for connecting to a computer running from an Install DVD, see “Remotely Acces

Seite 7 - Contents 7

sudo shutdown -r now# Method 2sudo systemsetup -liststartupdiskssudo systemsetup -setstartupdisk <path to disk root>Using the installer Command-

Seite 8 - 8 Contents

Chapter 5 Installation and Deployment 105 4 If you haven’t already done so, prepare the disks for installation.For more information about prepa

Seite 9 - 191 Index

Installing Multiple ServersMost Ecient Methods of InstallationThe most ecient method of installation would be completely automated. Opening the Term

Seite 10 - 10 Contents

Chapter 5 Installation and Deployment 107Upgrading a Computer from Mac OS X to Mac OS X ServerThis is not supported in Mac OS X Server v10.6. Pe

Seite 11 - About This Guide

108Basic characteristics of your Mac OS X Server are established during server setup. The server can operate in three dierent congurations: advanc

Seite 12 - Using Onscreen Help

Chapter 6 Initial Server Setup 109If you’re setting up a server without a keyboard or display, you can enter the following in the Terminal appli

Seite 13 - Document Road Map

11This guide provides a starting point for administering Mac OS X Server v10.6 using its advanced administration tools. It contains information ab

Seite 14 - Printing PDF Guides

Default SSH and Apple Remote Desktop state is enabled. ÂNetwork interfaces (ports) are congured. ÂTCP/IP and Ethernet settings are dened for each po

Seite 15 - Getting Documentation Updates

Chapter 6 Initial Server Setup 111 Â Import Users and GroupsThis setting connects the server to an existing Open Directory or Active Directory s

Seite 16 - Standards

Even if you want to change the server’s directory setup, selecting “Congure Manually” is the safest option, especially if you’re considering changing

Seite 17

Chapter 6 Initial Server Setup 11 3To interactively connect to an additional directory server: 1 Open the Accounts pane of System Preferences o

Seite 18 - What’s New in Server Admin

The following illustration shows target servers on the same subnet as the administrator computer in one scenario and target servers on a dierent subn

Seite 19

Chapter 6 Initial Server Setup 11 5If the computer you want to congure doesn’t appear in the list, you can add it manually by clicking the Add

Seite 20 - Supported Standards

The automatic approach is useful when you:Have more than a few servers to set up ÂWant to prepare for setting up servers that aren’t yet available ÂWa

Seite 21

Chapter 6 Initial Server Setup 11 7You can dene generic setup data that can be used to set up any server. For example, you can dene generic se

Seite 22

Using Encryption with Setup Data FilesSaved setup data can be encrypted for extra security. Before a server sets itself up using encrypted setup data,

Seite 23

Chapter 6 Initial Server Setup 11 9If setup data is encrypted, the server needs the correct passphrase before setting itself up. You can use Ser

Seite 24 - Planning Server Usage

12 Preface About This GuideUsing Onscreen HelpYou can get task instructions onscreen in Help Viewer while you’re managing Mac OS X Server v10

Seite 25 - Setting Up a Planning Team

To use setup data from a le remotely: 1 Create the folder for the setup le on the remote server. a Connect to the remote server.ssh root@<serve

Seite 26 - Identifying Servers to Set Up

Chapter 6 Initial Server Setup 121Handling Setup ErrorsWhen a server encounters a setup problem, Server Assistant shows a description of the set

Seite 27

Setting Up ServicesAfter installation and initial startup, the rst time you open Server Admin, you see any services that were congured during server

Seite 28 - Migrating from Windows

Chapter 6 Initial Server Setup 12 3Setting Up Open DirectoryUnless your server must be integrated with another vendor’s directory system or the

Seite 29

12 4This chapter shows you how to complete ongoing management for your systems, including setting up administrator computers, designating administra

Seite 30

Chapter 7 Ongoing System Management 12 5In the following illustration, the arrows originate from administrator computers and point to servers th

Seite 31

Using the Administration ToolsInformation about administration tools can be found on the pages indicated in the following table.Use this application o

Seite 32

Chapter 7 Ongoing System Management 12 7You can use Workgroup Manager on a v10.6 server to manage Mac OS X clients running the latest Mac OS X v

Seite 33 - Understanding Backup Types

Server Admin BasicsYou use Server Admin to administer services on Mac OS X Server computers. Server Admin also lets you specify settings that support

Seite 34 - Understanding Restores

Chapter 7 Ongoing System Management 12 9If a server in the Servers list appears gray, double-click the server or click the Connect button in the

Seite 35

Preface About This Guide 13Document Road MapMac OS X v10.6 has a suite of guides which can cover management of individual services. Each service

Seite 36

IP address ÂOS version ÂTo create a server smart group: 1 Under the Server list at the bottom of the Server Admin window, click the Add (+) button. 2

Seite 37

Chapter 7 Ongoing System Management 131The following table contains a summary of what you nd for each button:Toolbar button ShowsOverview Info

Seite 38 - Administration Tools

Server-side le tracking for mobile home-sync is a feature of mobile home folders. For information about when to enable this feature, see the online h

Seite 39 - Server Admin Interface

Chapter 7 Ongoing System Management 133The following sections give guidance regarding the types of changes will be necessary for a name or IP ad

Seite 40

Your network conguration might have other domains, computers, and record types that are impacted by a server’s IP address change (SRV records, for in

Seite 41 - Server Assistant

Chapter 7 Ongoing System Management 13 5Changing the DNS name of the directory server requires that all bound machines be rebound to the new dir

Seite 42 - Workgroup Manager

VPNVPN servers allocate IP address ranges to VPN clients and mediate DNS queries of VPN clients. Any of these can be aected by a change to the VPN se

Seite 43 - Workgroup Manager Interface

Chapter 7 Ongoing System Management 137MySQLIn general, MySQL is not aected by changing an IP address or DNS name. However, none of the data in

Seite 44 - Server Monitor

For the most part, changing the network address or DNS name of a le server has no internal aect on le services. The le service processes monitor n

Seite 45

Chapter 7 Ongoing System Management 13 9IMAP and POPDovecot, the IMAP and POP service, loads the fully-qualied domain name at startup and cong

Seite 46

14 Preface About This GuideViewing PDF Guides OnscreenWhile reading the PDF version of a guide onscreen:Show bookmarks to see the guide’s outl

Seite 47 - Media Streaming Management

Address Book ServiceChanging the IP address of an Address Book server does not aect new connections to the server; however, it can disconnect existin

Seite 48 - RAID Admin

Chapter 7 Ongoing System Management 141Certicates for Collaboration ServicesAddressBook, iCal, and iChat servers that use SSL will need new cer

Seite 49 - Xgrid Admin

To change the IP address of the Podcast Producer computer: 1 Stop the Xgrid job queue when empty (or stop and empty it). 2 Recongure DNS, Open Dire

Seite 50 - Apple Remote Desktop

Chapter 7 Ongoing System Management 143Software Update Service ÂXgrid ÂAfter Software Update changes the DNS name or IP address, a number of cha

Seite 51 - Enhancing Security

Changing the IP Address of a ServerYou can change the IP address of a server using the Network pane of System Preferences or the networksetup tool.Do

Seite 52 - About Network Security

Chapter 7 Ongoing System Management 145You can use the scutil command-line tool to set the local hostname and local hostname. For more informati

Seite 53 - MAC Filtering

Adding and Removing Services in Server AdminServer Admin can only show you the services you are administering, hiding all other service conguration p

Seite 54 - Payload Encryption

Chapter 7 Ongoing System Management 147Controlling Access to ServicesYou can use Server Admin to congure which users and groups can use service

Seite 55 - About File Security

Using SSL for Remote Server AdministrationYou can control the level of security of communications between Server Admin and remote servers by choosing

Seite 56 - Secure Delete

Chapter 7 Ongoing System Management 149The following is the File Sharing conguration pane in Server Admin.Tiered Administration PermissionsIn p

Seite 57

Preface About This Guide 15Getting Documentation UpdatesPeriodically, Apple posts revised help pages and new editions of guides. Some revised he

Seite 58 - Single Sign-On

Server Admin updates to reect what operations are possible for a user’s permissions. For example, some services are hidden or the Settings pane is di

Seite 59 - Public and Private Keys

Chapter 7 Ongoing System Management 151The following topics describe general Workgroup Manager usage. Instructions for conducting specic admini

Seite 60 - Certicates

The following is a sample user record conguration pane in Workgroup Manager: Initially, accounts listed are those stored in the last directory node o

Seite 61 - About Intermediate Trust

Chapter 7 Ongoing System Management 153Dening Managed PreferencesTo work with managed preferences for user accounts, group accounts, or compute

Seite 62

Working with Directory DataTo work with raw directory data, use Workgroup Manager’s Inspector.The following is the record Inspector pane in Workgroup

Seite 63

Chapter 7 Ongoing System Management 155Service Conguration AssistantsServer Admin has conguration assistants to guide you through setting up s

Seite 64 - Readying Certicates

Address Book ServiceFile type LocationConguration les /etc/cardavd/cardavd.plistData /Library/AddressBookServer/Documents/iCal ServiceFile type Loca

Seite 65

Chapter 7 Ongoing System Management 157Mail—AmavisdFile type LocationConguration les /etc/amavisd.confData: (default locations) /var/amavis/M

Seite 66

NoticationsFile type LocationConguration les /etc/emond.d//etc/emond.d/rules//Library/Keychains/System.keychainOpenDirectory ServiceThe entire Open

Seite 67

Chapter 7 Ongoing System Management 159Web ServiceFile type LocationConguration les /etc/apache2/* (for Apache 2.2)/etc/httpd/* (for Apache 1.

Seite 68

16Mac OS X Server gives you everything you need to provide standards-based workgroup and Internet services — delivering a world-class UNIX server so

Seite 69 - Managing Certicates

Some single points of failure include:Computer system ÂHard disk ÂPower supply ÂAlthough it is almost impossible to eliminate all single points of fai

Seite 70 - Deleting a Certicate

Chapter 7 Ongoing System Management 161Using Backup PowerIn the architecture of a server solution, power is a single point of failure. If power

Seite 71 - Using Certicates

The automatic restart options are: Â Restart automatically after a power failure. The power management unit automatically starts up the server after a

Seite 72 - SSH and SSH Keys

Chapter 7 Ongoing System Management 163Link AggregationAlthough not common, the failure of a switch, cable, or network interface card can cause

Seite 73

About the Link Aggregation Control Protocol (LACP)IEEE 802.3ad Link Aggregation denes a protocol called Link Aggregation Control Protocol (LACP) that

Seite 74 - Administration Level Security

Chapter 7 Ongoing System Management 165Computer to SwitchIn this scenario shown in the following illustration, you connect your server to a swit

Seite 75 - Service Level Security

For example, you can connect two links to the master switch and the remaining links to the backup switch. As long as the master switch is active, the

Seite 76 - Security Best Practices

Chapter 7 Ongoing System Management 167The interface name bond<num> assigned by the system is dierent from the name you give to the link

Seite 77 - Password Guidelines

Load BalancingOne factor that can cause services to become unavailable is server overload. A server has limited resources and can service a limited nu

Seite 78 - Creating Complex Passwords

Chapter 7 Ongoing System Management 169Daemon OverviewBy the time a user logs in to a Mac OS X system, a number of processes are running. Many o

Seite 79 - Installation and Deployment

Chapter 1 System Overview and Supported Standards 17What’s New in Mac OS X Server v10.6Mac OS X Server v10.6 oers major enhancements in several

Seite 80

The launchctl utility is the command-line tool used to control launchd. It can:Load and unload daemons ÂStart and stop launchd controlled jobs ÂGet sy

Seite 81

171Eective monitoring allows you to detect potential problems before they occur and gives you early warning when they occur.Detecting potential p

Seite 82 - About the Server Install Disc

Several factors can be considered for a monitoring response:What are relevant response methods? In other words, how will the response take Âplace?Wha

Seite 83

Chapter 8 Monitoring Your System 173A green status indicator shows the component is OK, a yellow status indicator notes a warning, and a red sta

Seite 84 - Before Starting Up

df -HlFilesystem Size Used Avail Capacity Mounted on/dev/disk0s9 40G 38G 2.1G 95% /In this example, the hard disk is almost full with only 2.1 GB left

Seite 85

Chapter 8 Monitoring Your System 175If you detect an unusual number of requests coming from the same source, use Firewall service to block trac

Seite 86

The following shows a sample Overview pane for a single server.This overview shows basic hardware, operating system versions, active services, and gr

Seite 87

Chapter 8 Monitoring Your System 177When a server kernel panics it abruptly halts all normal system operations. Usually, a kernel process named

Seite 88

Setting Up a Core Dump ServerYou can use any Mac OS X v10.5 or later computer to be a core dump server that ts the following criteria. The core dump

Seite 89

Chapter 8 Monitoring Your System 179Setting Up a Core Dump ClientA core dump client sends its kernel panic debug information to the core dump se

Seite 90

OpenCL support ÂMac OS X Server v10.6 supports OpenCL and makes it possible for developers to use the GPU for general computational tasks.What’s New i

Seite 91 - Destination

Conguring Common Core Dump OptionsBy default, core dumps happen using UDP port 1069 over the built-in Ethernet (en0) interface, and the resulting le

Seite 92

Chapter 8 Monitoring Your System 181SNMPv2 is the default access protocol and the default read-only community string is “public.”Enabling SNMP r

Seite 93 - Choosing a File System

To enable and congure SNMP:Use the /usr/bin/snmpconf command, which takes you through a basic text-based msetup assistant for conguring the communi

Seite 94

Chapter 8 Monitoring Your System 183Step 3: Collect SNMP information from the hostTo get the SNMP-available information you added, execute this

Seite 95

There are two main notication daemons: syslogd and emond. Â syslogd: The syslogd daemon is a standard UNIX method of monitoring systems. It logs mes

Seite 96 - JournaledHFS+ DataStore 50%

Chapter 8 Monitoring Your System 185LoggingMac OS X Server maintains standard UNIX log les and Apple-specic process logs. Logs for the OS can

Seite 97

Syslog Conguration FileThe Syslog conguration le can be found at /etc/syslog.conf. Each line has the following format:<facility>.<loglevel

Seite 98

Chapter 8 Monitoring Your System 187To run slapd in debugging mode: 1 Stop and remove slapd from launchd’s watch list:launchctl unload /System/

Seite 99

188Provide increased server responsiveness to clients and reduce server load with Push Notication Server.Mac OS X Server v10.6 uses an XMPP Pubsub

Seite 100 - Terminal application

Chapter 9 Push Notication Server 189Starting and Stopping Push NoticationWhen you start push notication on a server, the service broadcasts i

Seite 101 - Subnet 2

Chapter 1 System Overview and Supported Standards 19The following table highlights the capabilities of each conguration tool.Service Set in ini

Seite 102

Changing a Service’s Push Notication ServerIf push notication is congured on the server, it is listed in the location on the service’s settings pan

Seite 103 - --setBoot

AaccessACLs 55, 75IMAP 13 9IP address restrictions 52Keychain Access Utility 66LDAP 21, 58Mac address 53, 90remote installation 84, 88, 90, 101

Seite 104 - Software

192 Indexpreparing 64private keys 59public keys 59renewing 71requesting 63, 64, 65root 66self-signed 61, 65Server Admin 62, 148services us

Seite 105

Index 193Eemail. See mail serviceemond daemon 184encryption 54, 55, 59, 11 8See also SSLEthereal packet sning tool 175Ethernet 53, 109, 166exp

Seite 106 - Installing Multiple Servers

19 4 Indexserver 14 4static 82See also identityIPv6 addressing 22Jjournaling, le system 93junk mail screening 13 9KKerberos 21, 57, 58, 13 4

Seite 107 - How to Keep Current

Index 195See also Open DirectoryOpenCL 18OpenLDAP 21OpenSSL 54operating environment requirements 162PPackageMaker 47packets, data, ltering of

Seite 108 - Initial Server Setup

19 6 IndexServer Adminaccess control 147as administration tool 12 8authentication 38certicates 62, 148conguration methods 18customizing 40n

Seite 109

Index 197UUDP (User Datagram Protocol) 52, 180UNIX 23updating software 107upgradingfrom previous server versions 25, 28saved setup data 11 7vs

Seite 110

Apple Inc. K© 2009 Apple Inc. All rights reserved.The owner or authorized user of a valid copy of Mac OS X Server software may reproduce this publicat

Seite 111 - Â Congure Manually

Service Set in initial server setupServer Preferences Server AdminOpen Directory master (user accounts and other data)Optional Optional Yes Podcast P

Seite 112

Chapter 1 System Overview and Supported Standards 21A standards-based directory services architecture oers centralized management of network re

Seite 113

 Web Technologies: Mac OS X Server is a complete AMP stack (a bundle of integrated Apache-MySQL-PHP/Perl/Python software). Mac OS X Server web tech

Seite 114

Chapter 1 System Overview and Supported Standards 23 Â XMPP: Extensible Messaging and Presence Protocol (XMPP) is an open XML-based messaging p

Seite 115 - Using Automatic Server Setup

24Before installing and setting up Mac OS X Server do a little planning and become familiar with your options.The major goals of the planning phase

Seite 116

Chapter 2 Planning Server Usage 25During the planning stage, you’ll also decide which installation and server setup options best suit your needs

Seite 117

If you’ve been planning to replace a Windows NT computer, consider using Mac OS X Server with its extensive built-in support for Windows clients. Make

Seite 118

Chapter 2 Planning Server Usage 27Home folders for network users can be consolidated onto one server or distributed Âamong various servers. Alt

Seite 119

Dening a Migration StrategyIf you’re using Mac OS X Server v10.4–10.5 or a Windows-based server, examine the opportunities for moving data and settin

Seite 120

Chapter 2 Planning Server Usage 29The rst aspect primarily involves directory services integration. Identify which Mac OS X Server computers wi

Seite 121 - Handling Setup Errors

11 Preface: About This Guide11 What’s in This Guide12 Using Onscreen Help13 Document Road Map14 Viewing PDF Guides Onscreen14 Printing PDF Gui

Seite 122 - Setting Up Services

For example, if you use Mac OS X Server to provide DHCP, network time, or BootP services to other servers, you should set up the servers that provide

Seite 123 - Setting Up All Other Services

Chapter 2 Planning Server Usage 31Making Sure Required Server Hardware Is AvailableYou might want to postpone setting up a server until all its

Seite 124 - Ongoing System Management

Understanding Backup and Restore PoliciesThere are many reasons to have a backup and restore policy. Your data is subject to failure because of failed

Seite 125 - Mac OS X

Chapter 2 Planning Server Usage 33Your organization must determine the following:What must be backed up? ÂWhat should not be backed up (as per o

Seite 126

Understanding Backup SchedulingBacking up les requires time and resources. Before deciding on a backup plan, consider the following questions:How muc

Seite 127 - Ports Open By Default

Chapter 2 Planning Server Usage 35Consider the following questions:How long will it take to restore data at each level of granularity? ÂFor exam

Seite 128 - Server Admin Basics

 Capacity. If you back up only a small amount of data, low-capacity storage media can do the job. But if you need to back up large amounts of data,

Seite 129 - Grouping Servers Manually

Chapter 2 Planning Server Usage 37For example, Time Machine doesn’t back up user and group directory records, email, DNS records, Address Book s

Seite 130

38Manage Mac OS X Server using graphical applications or command-line tools.Mac OS X Server v10.6 administration applications must be run from eithe

Seite 131

Chapter 3 Administration Tools 39Server Admin InterfaceThe Server Admin interface is shown here, with each element explained in the following ta

Seite 132 - Identity

4 Contents33 Understanding Backup Types34 Understanding Backup Scheduling34 Understanding Restores35 Other Backup Policy Considerations36 Co

Seite 133 - Infrastructure Services

DMain Work Area: Shows status and conguration options. This looks dierent for each service and for each context button selected.EAvailable servers:

Seite 134

Chapter 3 Administration Tools 41Server AssistantServer Assistant is used for:Remote server installations ÂInitial setup of a local server ÂInit

Seite 135

Server PreferencesServer Preferences is the simplied administration application you need for managing Mac OS X Server v10.6. You can use Server Prefe

Seite 136 - Wiki Services

Chapter 3 Administration Tools 43Workgroup Manager InterfaceThe Workgroup Manager interface is shown here, with each element explained in the fo

Seite 137 - Services

Customizing the Workgroup Manager EnvironmentThere are several ways to tailor the Workgroup Manager environment:To open Workgroup Manager Preferences,

Seite 138

Chapter 3 Administration Tools 45To identify the Xserve computer to monitor, click Add Server, identify the server, and enter user name and pass

Seite 139 - Collaboration Services

iCal Service UtilityiCal Service Utility gives users access to shared information about locations and resources. Users can use iCal Service Utility to

Seite 140

Chapter 3 Administration Tools 47System Image ManagementYou can use the following Mac OS X Server applications to set up and manage NetBoot and

Seite 141 - Producer

Command-Line ToolsIf you’re an administrator who prefers to work in a command-line environment, you can do so with Mac OS X Server.From the Terminal

Seite 142

Chapter 3 Administration Tools 49Podcast Capture, Composer, and ProducerPodcast Capture takes audio and video from a local or remote camera, cap

Seite 143

Contents 558 Single Sign-On59 About Certicates, SSL, and Public Key Infrastructure59 Public and Private Keys60 Certicates60 About Certicate

Seite 144

Apple Remote DesktopApple Remote Desktop (ARD), which you can optionally purchase, is an easy-to-use network-computer management application. It simpl

Seite 145 - Administering Services

51By vigilantly adhering to security policies and practices, you can minimize the threat to system integrity and data privacy.Mac OS X Server is b

Seite 146

About Network SecurityNetwork security is as important to data integrity as physical security. Although someone might immediately see the need to lock

Seite 147

Chapter 4 Enhancing Security 53This allows an organization to provide services to the external network while protecting the internal network fro

Seite 148 - Managing Sharing

In theory, MAC ltering allows a network administrator to permit or deny network access to hosts and devices associated with the MAC address, although

Seite 149

Chapter 4 Enhancing Security 55Most transport encryption requires the participation of both parties in the transaction. Some services (such as S

Seite 150 - Workgroup Manager Basics

 Secure VM: Secure VM encrypts system virtual memory (memory data temporarily written to the hard disk), not user les. It improves system security

Seite 151 - Administering Accounts

Chapter 4 Enhancing Security 57In Mac OS X Server, users trying to access services (like logging in to a directory-aware workstation, or trying

Seite 152

Web Service (Apache via the SPNEGO Simple and Protected GSS-API Negotiation ÂMechanism protocol)Xgrid  ÂStoring passwords in user accounts. This app

Seite 153 - Dening Managed Preferences

Chapter 4 Enhancing Security 59Kerberos also provides a single sign-on environment where users must authenticate only once a day, week, or other

Seite 154 - Working with Directory Data

6 Contents84 About Starting Up for Installation84 Before Starting Up85 Starting Up from the Install DVD85 Starting Up from an Alternate Parti

Seite 155

Web, mail, and directory services use the public key with SSL to negotiate a shared key for the duration of the connection.For example, a mail server

Seite 156

Chapter 4 Enhancing Security 61About IdentitiesIdentities are a certicate and a private key, together. The certicate identies the user, and t

Seite 157

Several keychains can hold certicates: Â SystemRootCerticates: This keychain holds root certicates that ship with Mac OS X. The certicates alread

Seite 158

Chapter 4 Enhancing Security 63The Server Admin interface is shown below, with Certicates selected.Certicate Manager provides integrated manag

Seite 159

When certicates and keys are imported via Certicate Manager, they are put in the /etc/certicates/ directory. The directory contains four PEM format

Seite 160

Chapter 4 Enhancing Security 65Creating a Self-Signed CerticateA self-signed certicate is generated at server setup. Although it is available

Seite 161 - Using Backup Power

4 Click the Action button below the certicates list and choose “Generate Certicate Signing Request (CSR).”Certicate manager creates the signing r

Seite 162

Chapter 4 Enhancing Security 67 5 If you override the defaults, provide the following information in the next few screens:A unique serial numbe

Seite 163 - Link Aggregation

Using a CA to Create a Certicate for Someone ElseYou can use your CA certicate to issue a certicate to someone else. By doing so you are stating yo

Seite 164 - Link Aggregation Scenarios

Chapter 4 Enhancing Security 69 7 Click the Import button.If prompted, enter the private key passphrase.Managing CerticatesAfter you create an

Seite 165

Contents 7124 Chapter 7: Ongoing System Management124 Computers You Can Use to Administer a Server124 Setting Up an Administrator Computer125 U

Seite 166

For instructions on how to do this, see “Replacing an Existing Certicate” on page 71.Distributing a CA Public Certicate to ClientsIf you’re using se

Seite 167

Chapter 4 Enhancing Security 71 5 Click Save.Renewing an Expiring CerticateCerticates have an expiration date and must be renewed periodicall

Seite 168 - Load Balancing

SSH and SSH KeysSSH is a network protocol that establishes a secure channel between your computer and a remote computer. It uses public-key cryptograp

Seite 169 - Daemon Overview

Chapter 4 Enhancing Security 73The -b ag sets the length of the keys to 1,024-bits, -t indicates to use the RSA hashing algorithm, -f sets the

Seite 170 - Set environment settings Â

$count = @{[$_ =~ /$match/g]};if($count > 0) {$flag = 1;}}close SBUFF;if($flag == 1) {"ssh $server -x -o batchmode=yes shutdown -r now"}}

Seite 171 - Monitoring Your System

Chapter 4 Enhancing Security 75You can determine which services other admin group users can modify. To do this, the administrator making the de

Seite 172 - Using Server Monitor

Security Best PracticesServer administrators must make sure that adequate security measures are implemented to protect a server from attacks. A compro

Seite 173 - Using Disk Monitoring Tools

Chapter 4 Enhancing Security 77Do not use administrator (UNIX “admin” group) accounts for daily use. ÂRestrict the use of administration privile

Seite 174

Creating Complex PasswordsUse the following tips to create complex passwords:Use a mix of alphabetic (upper and lower case), numeric, and special char

Seite 175

79Whether you install Mac OS X Server on a single server or a cluster of servers, there are tools and processes to help the installation and deplo

Seite 176

8 Contents159 Eliminating Single Points of Failure160 Using Xserve for High Availability161 Using Backup Power161 Setting Up Your Server for

Seite 177

Step 3: Set up the environmentIf you are not in complete control of the network environment (DNS servers, DHCP server, rewall, and so forth) coordina

Seite 178 - Setting Up a Core Dump Server

Chapter 5 Installation and Deployment 81“ Â Installing Remotely with Server Assistant” on page 101“ Â Installing Remotely with Screen Sharing an

Seite 179 - Setting Up a Core Dump Client

Setting Up Network ServicesBefore you can install, you must set up the following for your network service: Â DNS: You must have a fully qualied doma

Seite 180

Chapter 5 Installation and Deployment 83Mac OS X Server Install DiscThe Install Disc has a Documentation folder with Getting Started, Installati

Seite 181 - Conguring snmpd

When you install and set up Mac OS X Server on a computer that has a display and keyboard, it’s already an administrator computer. To make a computer

Seite 182 - /usr/sbin/snmpd

Chapter 5 Installation and Deployment 85Starting Up from the Install DVDThis is the simplest method of starting the computer, if you have physic

Seite 183 - Tools to Use with SNMP

However, if you are reinstalling regularly, or if you are creating an external Firewire drive-based installation to take to various computers, or if y

Seite 184

Chapter 5 Installation and Deployment 87 4 Select File > New > Disk Image from <device>. 5 Give the image a name; select Read-only

Seite 185

Tip: ∏ You can use asr to restore a disk over a network, multicasting the blocks to client computers. Using the multicast server feature of asr, you

Seite 186 - Open Directory Logging

Chapter 5 Installation and Deployment 89This is usually the rst eight characters of the server’s built-in hardware serial number.For more infor

Seite 187 - Additional Monitoring Aids

Contents 9188 Chapter 9: Push Notication Server188 About Push Notication Server189 Starting and Stopping Push Notication190 Changing a Servi

Seite 188 - Push Notication Server

2 Identify the target server.If you don’t know the IP address and the remote server is on the local subnet, you can nd servers using the comannd l

Seite 189 - # on the notification server

Chapter 5 Installation and Deployment 91You can use the dns-sd tool to identify computers on the local subnetwhere you can install server softwa

Seite 190

Step 1: Create a NetInstall image from the Install DVDThis step doesn’t need to be done on the target computer. It can be done on an administrator com

Seite 191

Chapter 5 Installation and Deployment 93If you’re using an installation disc for Mac OS X Server v10.6, you can perform these tasks from another

Seite 192 - 192 Index

A case-sensitive volume is supported as a start volume format. An HFSX le system for Mac OS X Server must be specically selected when erasing a volu

Seite 193 - Index 193

Chapter 5 Installation and Deployment 95Partitioning a DiskYou can use the Installer to open Disk Utility and then use Disk Utility to partition

Seite 194 - 19 4 Index

Additional information about diskutil and other uses can be found in Introduction to Command-Line Administration. For complete command syntax for disk

Seite 195 - Index 195

Chapter 5 Installation and Deployment 97You can combine RAID sets to combine their benets. For example, you can create a RAID set that combines

Seite 196 - 19 6 Index

5 Drag the disks to the window. 6 Follow the instructions in the window to set parameters. 7 Click Create.You can nd instructions for partitionin

Seite 197 - Index 197

Chapter 5 Installation and Deployment 99Erasing a Disk or PartitionYou have several options for erasing a disk, depending on your preferred tool

Kommentare zu diesen Handbüchern

Keine Kommentare