
Chapter 1 User Management Overview 29
Identity Validation
When authenticating a user, Mac OS X first locates the user’s account and then uses the
password strategy designated in the user’s account to validate the user’s password.
Open Directory gives you several options for validating a user’s password. For more
details about password validation options, read the Open Directory administration
guide.
Information Access Control
For any directory (folder) or file on a Mac OS X computer, you can specify permissions
for:
• the file’s owner
• the file’s group
• everyone else
Mac OS X uses a particular data item in a user’s account—the user ID—to keep track of
directory and file permissions.
User
account
Password can be validated
using value stored in user
account or Open Directory
authentication database.
Password can
also be validated
using another
authentication
authority.
Kerberos KDC
LDAP bind
Authenti-
cation
Open
Directory
Owner 127 can: Read & Write
Group 2017 can: Read only
Everyone else can: None
MyDoc
Komentáře k této Příručce