Specifications
Controlling Access to a Server’s Login Window
You can use Server Admin to control which users can log in to Mac OS X Server using the
login window. Users with server administrator privileges can always log in to the server.
To control who can use the login window on a server:
1 Open Server Admin and connect to the server.
2 Click Setting, then click Access.
3 Click Services.
4 Select “For selected services below” and select Login Window in the list on the left.
5 Select “Allow only users and groups below” and edit the list of users and groups that
you want to log in using the server’s login window:
Add users or groups that can use the login window by clicking the Add (+) button Â
and dragging users or groups from the User & Groups window to the list.
Remove users or groups from the list by selecting them and clicking the Â
Remove (–) button.
6 Click Save.
If “Allow all users and groups” is selected when you select “For selected services below”
in step 4, all services except login window will permit access to all users and groups.
If you want to restrict who can access a listed service in addition to login window,
select the service in the list, select “Allow only users and groups below,” and add users
and groups to the list.
If you want all users to log in using the server’s login window, select Login Window,
then select “Allow all users and groups.”
Controlling Access to SSH Service
You can use Server Admin to control which users can open a command-line
connection to Mac OS X Server using the ssh command in Terminal. Users with server
administrator privileges can always open a connection using ssh.
The ssh command uses the secure shell (SSH) service. For information about using the
ssh command, see Introduction to Command-Line Administration.
To control who can open an SSH connection to a remote server:
1 Open Server Admin and connect to the server.
2 Click Setting, then click Access.
3 Click Services.
4 Select “For selected services below” and select SSH in the list on the left.
17 8 Chapter 9 Maintaining Open Directory Services