Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
11.07.2015 Views

Chapter 29 Kerio Active Directory ExtensionsFigure 29.4Mailbox Limitsministration. This option is used by default. We recommend creating a local accountfor the Kerio MailServer administration (see chapter 13.2). In case the Active Directoryserver is not accessible, administration of KMS will still be possible if the account ismanaged internally to KMS.• Read only access to administration — user is allowed to access the administration onlyto read it. User can connect to the server with Kerio Administration Console and viewthe settings, however, he/she is not allowed to edit the administration.• Read/write access to administration — full access to the administration. User is allowedto read and write in the administration. As few users as possible should begranted these rights for security reasons.29.4 Group DefinitionWithin Kerio Active Directory Extensions, group definition is almost identical to user accountdefinition; however, the wizard for creating new groups is extended by one step. This stepenables the administrator to define a primary email address that will be used by the group.The Kerio MailServer Account bookmark allows the administrator to define email addresses ofthe group (the E-Mail Addresses button) as well as access rights to Kerio MailServer administration(the Administration Rights button).For detailed information, see chapter 29.3.310

Chapter 30Kerio Open Directory ExtensionsKerio Open Directory Extensions is an extension to Apple Open Directory service that allowsmapping of the accounts to Kerio MailServer (Kerio MailServer items are added to the LDAPdatabase scheme). When user accounts are created, edited or deleted in Apple Open Directorydatabase, the changes are also made in Kerio MailServer.Warning:• If an account is created in Kerio Administration Console, it will be created only locally, itwill not be copied into Open Directory database.• Warning 2: If Open Directory server is unavailable, logging in to Kerio MailServer will beimpossible. It is therefore recommended to create at least one local account with read/writepermissions.• When creating a user account in Apple Open Directory, ASCII must be used to specify username.If the username includes special characters or symbols, it might happen that theuser cannot log in.30.1 Kerio Open Directory Extensions installationThe installation package with Kerio Open Directory Extensions can be downloaded from productweb pages of Kerio Technologies.A standard wizard is used for installation of Kerio Open Directory Extensions.When using configurations of Mac OS X servers of Master/Replica type, Kerio Open DirectoryExtensions must be installed to the master server, as well as to all replica servers, otherwisethe account mapping will not work.System requirementsKerio Open Directory Extensions since version 6.1 can be installed to Mac OS X 10.3 (Panther)and later versions.30.2 Apple Open DirectoryApple Open Directory is a directory service shipped with Mac OS X Server systems. This directoryservice is an equivalent to Active Directory created by Microsoft. As in Active Directory,it allows to store object information in a network (about users, groups, workstations, etc.),authenticate users, etc.The information about users and groups in Apple Open Directory are stored in Open LDAPdatabase. When mapping accounts to Kerio MailServer, all user accounts are stored in one311

Chapter 29 <strong>Kerio</strong> Active Directory ExtensionsFigure 29.4Mailbox Limitsministration. This option is used by default. We recommend creating a local accountfor the <strong>Kerio</strong> MailServer administration (see chapter 13.2). In case the Active Directoryserver is not accessible, administration of KMS will still be possible if the account ismanaged internally to KMS.• Read only access to administration — user is allowed to access the administration onlyto read it. User can connect to the server with <strong>Kerio</strong> Administration Console and viewthe settings, however, he/she is not allowed to edit the administration.• Read/write access to administration — full access to the administration. User is allowedto read and write in the administration. As few users as possible should begranted these rights for security reasons.29.4 Group DefinitionWithin <strong>Kerio</strong> Active Directory Extensions, group definition is almost identical to user accountdefinition; however, the wizard for creating new groups is extended by one step. This stepenables the administrator to define a primary email address that will be used by the group.The <strong>Kerio</strong> MailServer Account bookmark allows the administrator to define email addresses ofthe group (the E-Mail Addresses button) as well as access rights to <strong>Kerio</strong> MailServer administration(the Administration Rights button).For detailed information, see chapter 29.3.310

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!