Apple Mac OS X Server Instalační příručka

Procházejte online nebo si stáhněte Instalační příručka pro Barebones pro PC / pracovní stanice Apple Mac OS X Server. Apple Mac OS X Server Installation guide Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 197
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - Mac OS X Server

Mac OS X ServerAdvanced Server AdministrationVersion 10.6 Snow Leopard

Strany 2

10 Contents

Strany 3 - Contents

Installing Locally from the Installation DiscYou can install Mac OS X Server directly onto a computer with a display, a keyboard, and a DVD drive atta

Strany 4 - 4 Contents

Chapter 5 Installation and Deployment 101After installation is complete, the target server restarts and you can perform initial server setup. Ch

Strany 5 - Contents 5

3 Select the target server from the list of servers waiting for installation.If neither the target server nor the list appear, make sure the target

Strany 6 - 6 Contents

Chapter 5 Installation and Deployment 103For detailed instructions for connecting to a computer running from an Install DVD, see “Remotely Acces

Strany 7 - Contents 7

sudo shutdown -r now# Method 2sudo systemsetup -liststartupdiskssudo systemsetup -setstartupdisk <path to disk root>Using the installer Command-

Strany 8 - 8 Contents

Chapter 5 Installation and Deployment 105 4 If you haven’t already done so, prepare the disks for installation.For more information about prepa

Strany 9 - 191 Index

Installing Multiple ServersMost Ecient Methods of InstallationThe most ecient method of installation would be completely automated. Opening the Term

Strany 10 - 10 Contents

Chapter 5 Installation and Deployment 107Upgrading a Computer from Mac OS X to Mac OS X ServerThis is not supported in Mac OS X Server v10.6. Pe

Strany 11 - About This Guide

108Basic characteristics of your Mac OS X Server are established during server setup. The server can operate in three dierent congurations: advanc

Strany 12 - Using Onscreen Help

Chapter 6 Initial Server Setup 109If you’re setting up a server without a keyboard or display, you can enter the following in the Terminal appli

Strany 13 - Document Road Map

11This guide provides a starting point for administering Mac OS X Server v10.6 using its advanced administration tools. It contains information ab

Strany 14 - Printing PDF Guides

Default SSH and Apple Remote Desktop state is enabled. ÂNetwork interfaces (ports) are congured. ÂTCP/IP and Ethernet settings are dened for each po

Strany 15 - Getting Documentation Updates

Chapter 6 Initial Server Setup 111 Â Import Users and GroupsThis setting connects the server to an existing Open Directory or Active Directory s

Strany 16 - Standards

Even if you want to change the server’s directory setup, selecting “Congure Manually” is the safest option, especially if you’re considering changing

Strany 17

Chapter 6 Initial Server Setup 11 3To interactively connect to an additional directory server: 1 Open the Accounts pane of System Preferences o

Strany 18 - What’s New in Server Admin

The following illustration shows target servers on the same subnet as the administrator computer in one scenario and target servers on a dierent subn

Strany 19

Chapter 6 Initial Server Setup 11 5If the computer you want to congure doesn’t appear in the list, you can add it manually by clicking the Add

Strany 20 - Supported Standards

The automatic approach is useful when you:Have more than a few servers to set up ÂWant to prepare for setting up servers that aren’t yet available ÂWa

Strany 21

Chapter 6 Initial Server Setup 11 7You can dene generic setup data that can be used to set up any server. For example, you can dene generic se

Strany 22

Using Encryption with Setup Data FilesSaved setup data can be encrypted for extra security. Before a server sets itself up using encrypted setup data,

Strany 23

Chapter 6 Initial Server Setup 11 9If setup data is encrypted, the server needs the correct passphrase before setting itself up. You can use Ser

Strany 24 - Planning Server Usage

12 Preface About This GuideUsing Onscreen HelpYou can get task instructions onscreen in Help Viewer while you’re managing Mac OS X Server v10

Strany 25 - Setting Up a Planning Team

To use setup data from a le remotely: 1 Create the folder for the setup le on the remote server. a Connect to the remote server.ssh root@<serve

Strany 26 - Identifying Servers to Set Up

Chapter 6 Initial Server Setup 121Handling Setup ErrorsWhen a server encounters a setup problem, Server Assistant shows a description of the set

Strany 27

Setting Up ServicesAfter installation and initial startup, the rst time you open Server Admin, you see any services that were congured during server

Strany 28 - Migrating from Windows

Chapter 6 Initial Server Setup 12 3Setting Up Open DirectoryUnless your server must be integrated with another vendor’s directory system or the

Strany 29

12 4This chapter shows you how to complete ongoing management for your systems, including setting up administrator computers, designating administra

Strany 30

Chapter 7 Ongoing System Management 12 5In the following illustration, the arrows originate from administrator computers and point to servers th

Strany 31

Using the Administration ToolsInformation about administration tools can be found on the pages indicated in the following table.Use this application o

Strany 32

Chapter 7 Ongoing System Management 12 7You can use Workgroup Manager on a v10.6 server to manage Mac OS X clients running the latest Mac OS X v

Strany 33 - Understanding Backup Types

Server Admin BasicsYou use Server Admin to administer services on Mac OS X Server computers. Server Admin also lets you specify settings that support

Strany 34 - Understanding Restores

Chapter 7 Ongoing System Management 12 9If a server in the Servers list appears gray, double-click the server or click the Connect button in the

Strany 35

Preface About This Guide 13Document Road MapMac OS X v10.6 has a suite of guides which can cover management of individual services. Each service

Strany 36

IP address ÂOS version ÂTo create a server smart group: 1 Under the Server list at the bottom of the Server Admin window, click the Add (+) button. 2

Strany 37

Chapter 7 Ongoing System Management 131The following table contains a summary of what you nd for each button:Toolbar button ShowsOverview Info

Strany 38 - Administration Tools

Server-side le tracking for mobile home-sync is a feature of mobile home folders. For information about when to enable this feature, see the online h

Strany 39 - Server Admin Interface

Chapter 7 Ongoing System Management 133The following sections give guidance regarding the types of changes will be necessary for a name or IP ad

Strany 40

Your network conguration might have other domains, computers, and record types that are impacted by a server’s IP address change (SRV records, for in

Strany 41 - Server Assistant

Chapter 7 Ongoing System Management 13 5Changing the DNS name of the directory server requires that all bound machines be rebound to the new dir

Strany 42 - Workgroup Manager

VPNVPN servers allocate IP address ranges to VPN clients and mediate DNS queries of VPN clients. Any of these can be aected by a change to the VPN se

Strany 43 - Workgroup Manager Interface

Chapter 7 Ongoing System Management 137MySQLIn general, MySQL is not aected by changing an IP address or DNS name. However, none of the data in

Strany 44 - Server Monitor

For the most part, changing the network address or DNS name of a le server has no internal aect on le services. The le service processes monitor n

Strany 45

Chapter 7 Ongoing System Management 13 9IMAP and POPDovecot, the IMAP and POP service, loads the fully-qualied domain name at startup and cong

Strany 46

14 Preface About This GuideViewing PDF Guides OnscreenWhile reading the PDF version of a guide onscreen:Show bookmarks to see the guide’s outl

Strany 47 - Media Streaming Management

Address Book ServiceChanging the IP address of an Address Book server does not aect new connections to the server; however, it can disconnect existin

Strany 48 - RAID Admin

Chapter 7 Ongoing System Management 141Certicates for Collaboration ServicesAddressBook, iCal, and iChat servers that use SSL will need new cer

Strany 49 - Xgrid Admin

To change the IP address of the Podcast Producer computer: 1 Stop the Xgrid job queue when empty (or stop and empty it). 2 Recongure DNS, Open Dire

Strany 50 - Apple Remote Desktop

Chapter 7 Ongoing System Management 143Software Update Service ÂXgrid ÂAfter Software Update changes the DNS name or IP address, a number of cha

Strany 51 - Enhancing Security

Changing the IP Address of a ServerYou can change the IP address of a server using the Network pane of System Preferences or the networksetup tool.Do

Strany 52 - About Network Security

Chapter 7 Ongoing System Management 145You can use the scutil command-line tool to set the local hostname and local hostname. For more informati

Strany 53 - MAC Filtering

Adding and Removing Services in Server AdminServer Admin can only show you the services you are administering, hiding all other service conguration p

Strany 54 - Payload Encryption

Chapter 7 Ongoing System Management 147Controlling Access to ServicesYou can use Server Admin to congure which users and groups can use service

Strany 55 - About File Security

Using SSL for Remote Server AdministrationYou can control the level of security of communications between Server Admin and remote servers by choosing

Strany 56 - Secure Delete

Chapter 7 Ongoing System Management 149The following is the File Sharing conguration pane in Server Admin.Tiered Administration PermissionsIn p

Strany 57

Preface About This Guide 15Getting Documentation UpdatesPeriodically, Apple posts revised help pages and new editions of guides. Some revised he

Strany 58 - Single Sign-On

Server Admin updates to reect what operations are possible for a user’s permissions. For example, some services are hidden or the Settings pane is di

Strany 59 - Public and Private Keys

Chapter 7 Ongoing System Management 151The following topics describe general Workgroup Manager usage. Instructions for conducting specic admini

Strany 60 - Certicates

The following is a sample user record conguration pane in Workgroup Manager: Initially, accounts listed are those stored in the last directory node o

Strany 61 - About Intermediate Trust

Chapter 7 Ongoing System Management 153Dening Managed PreferencesTo work with managed preferences for user accounts, group accounts, or compute

Strany 62

Working with Directory DataTo work with raw directory data, use Workgroup Manager’s Inspector.The following is the record Inspector pane in Workgroup

Strany 63

Chapter 7 Ongoing System Management 155Service Conguration AssistantsServer Admin has conguration assistants to guide you through setting up s

Strany 64 - Readying Certicates

Address Book ServiceFile type LocationConguration les /etc/cardavd/cardavd.plistData /Library/AddressBookServer/Documents/iCal ServiceFile type Loca

Strany 65

Chapter 7 Ongoing System Management 157Mail—AmavisdFile type LocationConguration les /etc/amavisd.confData: (default locations) /var/amavis/M

Strany 66

NoticationsFile type LocationConguration les /etc/emond.d//etc/emond.d/rules//Library/Keychains/System.keychainOpenDirectory ServiceThe entire Open

Strany 67

Chapter 7 Ongoing System Management 159Web ServiceFile type LocationConguration les /etc/apache2/* (for Apache 2.2)/etc/httpd/* (for Apache 1.

Strany 68

16Mac OS X Server gives you everything you need to provide standards-based workgroup and Internet services — delivering a world-class UNIX server so

Strany 69 - Managing Certicates

Some single points of failure include:Computer system ÂHard disk ÂPower supply ÂAlthough it is almost impossible to eliminate all single points of fai

Strany 70 - Deleting a Certicate

Chapter 7 Ongoing System Management 161Using Backup PowerIn the architecture of a server solution, power is a single point of failure. If power

Strany 71 - Using Certicates

The automatic restart options are: Â Restart automatically after a power failure. The power management unit automatically starts up the server after a

Strany 72 - SSH and SSH Keys

Chapter 7 Ongoing System Management 163Link AggregationAlthough not common, the failure of a switch, cable, or network interface card can cause

Strany 73

About the Link Aggregation Control Protocol (LACP)IEEE 802.3ad Link Aggregation denes a protocol called Link Aggregation Control Protocol (LACP) that

Strany 74 - Administration Level Security

Chapter 7 Ongoing System Management 165Computer to SwitchIn this scenario shown in the following illustration, you connect your server to a swit

Strany 75 - Service Level Security

For example, you can connect two links to the master switch and the remaining links to the backup switch. As long as the master switch is active, the

Strany 76 - Security Best Practices

Chapter 7 Ongoing System Management 167The interface name bond<num> assigned by the system is dierent from the name you give to the link

Strany 77 - Password Guidelines

Load BalancingOne factor that can cause services to become unavailable is server overload. A server has limited resources and can service a limited nu

Strany 78 - Creating Complex Passwords

Chapter 7 Ongoing System Management 169Daemon OverviewBy the time a user logs in to a Mac OS X system, a number of processes are running. Many o

Strany 79 - Installation and Deployment

Chapter 1 System Overview and Supported Standards 17What’s New in Mac OS X Server v10.6Mac OS X Server v10.6 oers major enhancements in several

Strany 80

The launchctl utility is the command-line tool used to control launchd. It can:Load and unload daemons ÂStart and stop launchd controlled jobs ÂGet sy

Strany 81

171Eective monitoring allows you to detect potential problems before they occur and gives you early warning when they occur.Detecting potential p

Strany 82 - About the Server Install Disc

Several factors can be considered for a monitoring response:What are relevant response methods? In other words, how will the response take Âplace?Wha

Strany 83

Chapter 8 Monitoring Your System 173A green status indicator shows the component is OK, a yellow status indicator notes a warning, and a red sta

Strany 84 - Before Starting Up

df -HlFilesystem Size Used Avail Capacity Mounted on/dev/disk0s9 40G 38G 2.1G 95% /In this example, the hard disk is almost full with only 2.1 GB left

Strany 85

Chapter 8 Monitoring Your System 175If you detect an unusual number of requests coming from the same source, use Firewall service to block trac

Strany 86

The following shows a sample Overview pane for a single server.This overview shows basic hardware, operating system versions, active services, and gr

Strany 87

Chapter 8 Monitoring Your System 177When a server kernel panics it abruptly halts all normal system operations. Usually, a kernel process named

Strany 88

Setting Up a Core Dump ServerYou can use any Mac OS X v10.5 or later computer to be a core dump server that ts the following criteria. The core dump

Strany 89

Chapter 8 Monitoring Your System 179Setting Up a Core Dump ClientA core dump client sends its kernel panic debug information to the core dump se

Strany 90

OpenCL support ÂMac OS X Server v10.6 supports OpenCL and makes it possible for developers to use the GPU for general computational tasks.What’s New i

Strany 91 - Destination

Conguring Common Core Dump OptionsBy default, core dumps happen using UDP port 1069 over the built-in Ethernet (en0) interface, and the resulting le

Strany 92

Chapter 8 Monitoring Your System 181SNMPv2 is the default access protocol and the default read-only community string is “public.”Enabling SNMP r

Strany 93 - Choosing a File System

To enable and congure SNMP:Use the /usr/bin/snmpconf command, which takes you through a basic text-based msetup assistant for conguring the communi

Strany 94

Chapter 8 Monitoring Your System 183Step 3: Collect SNMP information from the hostTo get the SNMP-available information you added, execute this

Strany 95

There are two main notication daemons: syslogd and emond. Â syslogd: The syslogd daemon is a standard UNIX method of monitoring systems. It logs mes

Strany 96 - JournaledHFS+ DataStore 50%

Chapter 8 Monitoring Your System 185LoggingMac OS X Server maintains standard UNIX log les and Apple-specic process logs. Logs for the OS can

Strany 97

Syslog Conguration FileThe Syslog conguration le can be found at /etc/syslog.conf. Each line has the following format:<facility>.<loglevel

Strany 98

Chapter 8 Monitoring Your System 187To run slapd in debugging mode: 1 Stop and remove slapd from launchd’s watch list:launchctl unload /System/

Strany 99

188Provide increased server responsiveness to clients and reduce server load with Push Notication Server.Mac OS X Server v10.6 uses an XMPP Pubsub

Strany 100 - Terminal application

Chapter 9 Push Notication Server 189Starting and Stopping Push NoticationWhen you start push notication on a server, the service broadcasts i

Strany 101 - Subnet 2

Chapter 1 System Overview and Supported Standards 19The following table highlights the capabilities of each conguration tool.Service Set in ini

Strany 102

Changing a Service’s Push Notication ServerIf push notication is congured on the server, it is listed in the location on the service’s settings pan

Strany 103 - --setBoot

AaccessACLs 55, 75IMAP 13 9IP address restrictions 52Keychain Access Utility 66LDAP 21, 58Mac address 53, 90remote installation 84, 88, 90, 101

Strany 104 - Software

192 Indexpreparing 64private keys 59public keys 59renewing 71requesting 63, 64, 65root 66self-signed 61, 65Server Admin 62, 148services us

Strany 105

Index 193Eemail. See mail serviceemond daemon 184encryption 54, 55, 59, 11 8See also SSLEthereal packet sning tool 175Ethernet 53, 109, 166exp

Strany 106 - Installing Multiple Servers

19 4 Indexserver 14 4static 82See also identityIPv6 addressing 22Jjournaling, le system 93junk mail screening 13 9KKerberos 21, 57, 58, 13 4

Strany 107 - How to Keep Current

Index 195See also Open DirectoryOpenCL 18OpenLDAP 21OpenSSL 54operating environment requirements 162PPackageMaker 47packets, data, ltering of

Strany 108 - Initial Server Setup

19 6 IndexServer Adminaccess control 147as administration tool 12 8authentication 38certicates 62, 148conguration methods 18customizing 40n

Strany 109

Index 197UUDP (User Datagram Protocol) 52, 180UNIX 23updating software 107upgradingfrom previous server versions 25, 28saved setup data 11 7vs

Strany 110

Apple Inc. K© 2009 Apple Inc. All rights reserved.The owner or authorized user of a valid copy of Mac OS X Server software may reproduce this publicat

Strany 111 - Â Congure Manually

Service Set in initial server setupServer Preferences Server AdminOpen Directory master (user accounts and other data)Optional Optional Yes Podcast P

Strany 112

Chapter 1 System Overview and Supported Standards 21A standards-based directory services architecture oers centralized management of network re

Strany 113

 Web Technologies: Mac OS X Server is a complete AMP stack (a bundle of integrated Apache-MySQL-PHP/Perl/Python software). Mac OS X Server web tech

Strany 114

Chapter 1 System Overview and Supported Standards 23 Â XMPP: Extensible Messaging and Presence Protocol (XMPP) is an open XML-based messaging p

Strany 115 - Using Automatic Server Setup

24Before installing and setting up Mac OS X Server do a little planning and become familiar with your options.The major goals of the planning phase

Strany 116

Chapter 2 Planning Server Usage 25During the planning stage, you’ll also decide which installation and server setup options best suit your needs

Strany 117

If you’ve been planning to replace a Windows NT computer, consider using Mac OS X Server with its extensive built-in support for Windows clients. Make

Strany 118

Chapter 2 Planning Server Usage 27Home folders for network users can be consolidated onto one server or distributed Âamong various servers. Alt

Strany 119

Dening a Migration StrategyIf you’re using Mac OS X Server v10.4–10.5 or a Windows-based server, examine the opportunities for moving data and settin

Strany 120

Chapter 2 Planning Server Usage 29The rst aspect primarily involves directory services integration. Identify which Mac OS X Server computers wi

Strany 121 - Handling Setup Errors

11 Preface: About This Guide11 What’s in This Guide12 Using Onscreen Help13 Document Road Map14 Viewing PDF Guides Onscreen14 Printing PDF Gui

Strany 122 - Setting Up Services

For example, if you use Mac OS X Server to provide DHCP, network time, or BootP services to other servers, you should set up the servers that provide

Strany 123 - Setting Up All Other Services

Chapter 2 Planning Server Usage 31Making Sure Required Server Hardware Is AvailableYou might want to postpone setting up a server until all its

Strany 124 - Ongoing System Management

Understanding Backup and Restore PoliciesThere are many reasons to have a backup and restore policy. Your data is subject to failure because of failed

Strany 125 - Mac OS X

Chapter 2 Planning Server Usage 33Your organization must determine the following:What must be backed up? ÂWhat should not be backed up (as per o

Strany 126

Understanding Backup SchedulingBacking up les requires time and resources. Before deciding on a backup plan, consider the following questions:How muc

Strany 127 - Ports Open By Default

Chapter 2 Planning Server Usage 35Consider the following questions:How long will it take to restore data at each level of granularity? ÂFor exam

Strany 128 - Server Admin Basics

 Capacity. If you back up only a small amount of data, low-capacity storage media can do the job. But if you need to back up large amounts of data,

Strany 129 - Grouping Servers Manually

Chapter 2 Planning Server Usage 37For example, Time Machine doesn’t back up user and group directory records, email, DNS records, Address Book s

Strany 130

38Manage Mac OS X Server using graphical applications or command-line tools.Mac OS X Server v10.6 administration applications must be run from eithe

Strany 131

Chapter 3 Administration Tools 39Server Admin InterfaceThe Server Admin interface is shown here, with each element explained in the following ta

Strany 132 - Identity

4 Contents33 Understanding Backup Types34 Understanding Backup Scheduling34 Understanding Restores35 Other Backup Policy Considerations36 Co

Strany 133 - Infrastructure Services

DMain Work Area: Shows status and conguration options. This looks dierent for each service and for each context button selected.EAvailable servers:

Strany 134

Chapter 3 Administration Tools 41Server AssistantServer Assistant is used for:Remote server installations ÂInitial setup of a local server ÂInit

Strany 135

Server PreferencesServer Preferences is the simplied administration application you need for managing Mac OS X Server v10.6. You can use Server Prefe

Strany 136 - Wiki Services

Chapter 3 Administration Tools 43Workgroup Manager InterfaceThe Workgroup Manager interface is shown here, with each element explained in the fo

Strany 137 - Services

Customizing the Workgroup Manager EnvironmentThere are several ways to tailor the Workgroup Manager environment:To open Workgroup Manager Preferences,

Strany 138

Chapter 3 Administration Tools 45To identify the Xserve computer to monitor, click Add Server, identify the server, and enter user name and pass

Strany 139 - Collaboration Services

iCal Service UtilityiCal Service Utility gives users access to shared information about locations and resources. Users can use iCal Service Utility to

Strany 140

Chapter 3 Administration Tools 47System Image ManagementYou can use the following Mac OS X Server applications to set up and manage NetBoot and

Strany 141 - Producer

Command-Line ToolsIf you’re an administrator who prefers to work in a command-line environment, you can do so with Mac OS X Server.From the Terminal

Strany 142

Chapter 3 Administration Tools 49Podcast Capture, Composer, and ProducerPodcast Capture takes audio and video from a local or remote camera, cap

Strany 143

Contents 558 Single Sign-On59 About Certicates, SSL, and Public Key Infrastructure59 Public and Private Keys60 Certicates60 About Certicate

Strany 144

Apple Remote DesktopApple Remote Desktop (ARD), which you can optionally purchase, is an easy-to-use network-computer management application. It simpl

Strany 145 - Administering Services

51By vigilantly adhering to security policies and practices, you can minimize the threat to system integrity and data privacy.Mac OS X Server is b

Strany 146

About Network SecurityNetwork security is as important to data integrity as physical security. Although someone might immediately see the need to lock

Strany 147

Chapter 4 Enhancing Security 53This allows an organization to provide services to the external network while protecting the internal network fro

Strany 148 - Managing Sharing

In theory, MAC ltering allows a network administrator to permit or deny network access to hosts and devices associated with the MAC address, although

Strany 149

Chapter 4 Enhancing Security 55Most transport encryption requires the participation of both parties in the transaction. Some services (such as S

Strany 150 - Workgroup Manager Basics

 Secure VM: Secure VM encrypts system virtual memory (memory data temporarily written to the hard disk), not user les. It improves system security

Strany 151 - Administering Accounts

Chapter 4 Enhancing Security 57In Mac OS X Server, users trying to access services (like logging in to a directory-aware workstation, or trying

Strany 152

Web Service (Apache via the SPNEGO Simple and Protected GSS-API Negotiation ÂMechanism protocol)Xgrid  ÂStoring passwords in user accounts. This app

Strany 153 - Dening Managed Preferences

Chapter 4 Enhancing Security 59Kerberos also provides a single sign-on environment where users must authenticate only once a day, week, or other

Strany 154 - Working with Directory Data

6 Contents84 About Starting Up for Installation84 Before Starting Up85 Starting Up from the Install DVD85 Starting Up from an Alternate Parti

Strany 155

Web, mail, and directory services use the public key with SSL to negotiate a shared key for the duration of the connection.For example, a mail server

Strany 156

Chapter 4 Enhancing Security 61About IdentitiesIdentities are a certicate and a private key, together. The certicate identies the user, and t

Strany 157

Several keychains can hold certicates: Â SystemRootCerticates: This keychain holds root certicates that ship with Mac OS X. The certicates alread

Strany 158

Chapter 4 Enhancing Security 63The Server Admin interface is shown below, with Certicates selected.Certicate Manager provides integrated manag

Strany 159

When certicates and keys are imported via Certicate Manager, they are put in the /etc/certicates/ directory. The directory contains four PEM format

Strany 160

Chapter 4 Enhancing Security 65Creating a Self-Signed CerticateA self-signed certicate is generated at server setup. Although it is available

Strany 161 - Using Backup Power

4 Click the Action button below the certicates list and choose “Generate Certicate Signing Request (CSR).”Certicate manager creates the signing r

Strany 162

Chapter 4 Enhancing Security 67 5 If you override the defaults, provide the following information in the next few screens:A unique serial numbe

Strany 163 - Link Aggregation

Using a CA to Create a Certicate for Someone ElseYou can use your CA certicate to issue a certicate to someone else. By doing so you are stating yo

Strany 164 - Link Aggregation Scenarios

Chapter 4 Enhancing Security 69 7 Click the Import button.If prompted, enter the private key passphrase.Managing CerticatesAfter you create an

Strany 165

Contents 7124 Chapter 7: Ongoing System Management124 Computers You Can Use to Administer a Server124 Setting Up an Administrator Computer125 U

Strany 166

For instructions on how to do this, see “Replacing an Existing Certicate” on page 71.Distributing a CA Public Certicate to ClientsIf you’re using se

Strany 167

Chapter 4 Enhancing Security 71 5 Click Save.Renewing an Expiring CerticateCerticates have an expiration date and must be renewed periodicall

Strany 168 - Load Balancing

SSH and SSH KeysSSH is a network protocol that establishes a secure channel between your computer and a remote computer. It uses public-key cryptograp

Strany 169 - Daemon Overview

Chapter 4 Enhancing Security 73The -b ag sets the length of the keys to 1,024-bits, -t indicates to use the RSA hashing algorithm, -f sets the

Strany 170 - Set environment settings Â

$count = @{[$_ =~ /$match/g]};if($count > 0) {$flag = 1;}}close SBUFF;if($flag == 1) {"ssh $server -x -o batchmode=yes shutdown -r now"}}

Strany 171 - Monitoring Your System

Chapter 4 Enhancing Security 75You can determine which services other admin group users can modify. To do this, the administrator making the de

Strany 172 - Using Server Monitor

Security Best PracticesServer administrators must make sure that adequate security measures are implemented to protect a server from attacks. A compro

Strany 173 - Using Disk Monitoring Tools

Chapter 4 Enhancing Security 77Do not use administrator (UNIX “admin” group) accounts for daily use. ÂRestrict the use of administration privile

Strany 174

Creating Complex PasswordsUse the following tips to create complex passwords:Use a mix of alphabetic (upper and lower case), numeric, and special char

Strany 175

79Whether you install Mac OS X Server on a single server or a cluster of servers, there are tools and processes to help the installation and deplo

Strany 176

8 Contents159 Eliminating Single Points of Failure160 Using Xserve for High Availability161 Using Backup Power161 Setting Up Your Server for

Strany 177

Step 3: Set up the environmentIf you are not in complete control of the network environment (DNS servers, DHCP server, rewall, and so forth) coordina

Strany 178 - Setting Up a Core Dump Server

Chapter 5 Installation and Deployment 81“ Â Installing Remotely with Server Assistant” on page 101“ Â Installing Remotely with Screen Sharing an

Strany 179 - Setting Up a Core Dump Client

Setting Up Network ServicesBefore you can install, you must set up the following for your network service: Â DNS: You must have a fully qualied doma

Strany 180

Chapter 5 Installation and Deployment 83Mac OS X Server Install DiscThe Install Disc has a Documentation folder with Getting Started, Installati

Strany 181 - Conguring snmpd

When you install and set up Mac OS X Server on a computer that has a display and keyboard, it’s already an administrator computer. To make a computer

Strany 182 - /usr/sbin/snmpd

Chapter 5 Installation and Deployment 85Starting Up from the Install DVDThis is the simplest method of starting the computer, if you have physic

Strany 183 - Tools to Use with SNMP

However, if you are reinstalling regularly, or if you are creating an external Firewire drive-based installation to take to various computers, or if y

Strany 184

Chapter 5 Installation and Deployment 87 4 Select File > New > Disk Image from <device>. 5 Give the image a name; select Read-only

Strany 185

Tip: ∏ You can use asr to restore a disk over a network, multicasting the blocks to client computers. Using the multicast server feature of asr, you

Strany 186 - Open Directory Logging

Chapter 5 Installation and Deployment 89This is usually the rst eight characters of the server’s built-in hardware serial number.For more infor

Strany 187 - Additional Monitoring Aids

Contents 9188 Chapter 9: Push Notication Server188 About Push Notication Server189 Starting and Stopping Push Notication190 Changing a Servi

Strany 188 - Push Notication Server

2 Identify the target server.If you don’t know the IP address and the remote server is on the local subnet, you can nd servers using the comannd l

Strany 189 - # on the notification server

Chapter 5 Installation and Deployment 91You can use the dns-sd tool to identify computers on the local subnetwhere you can install server softwa

Strany 190

Step 1: Create a NetInstall image from the Install DVDThis step doesn’t need to be done on the target computer. It can be done on an administrator com

Strany 191

Chapter 5 Installation and Deployment 93If you’re using an installation disc for Mac OS X Server v10.6, you can perform these tasks from another

Strany 192 - 192 Index

A case-sensitive volume is supported as a start volume format. An HFSX le system for Mac OS X Server must be specically selected when erasing a volu

Strany 193 - Index 193

Chapter 5 Installation and Deployment 95Partitioning a DiskYou can use the Installer to open Disk Utility and then use Disk Utility to partition

Strany 194 - 19 4 Index

Additional information about diskutil and other uses can be found in Introduction to Command-Line Administration. For complete command syntax for disk

Strany 195 - Index 195

Chapter 5 Installation and Deployment 97You can combine RAID sets to combine their benets. For example, you can create a RAID set that combines

Strany 196 - 19 6 Index

5 Drag the disks to the window. 6 Follow the instructions in the window to set parameters. 7 Click Create.You can nd instructions for partitionin

Strany 197 - Index 197

Chapter 5 Installation and Deployment 99Erasing a Disk or PartitionYou have several options for erasing a disk, depending on your preferred tool

Komentáře k této Příručce

Žádné komentáře