Specifications

Chapter 9 Maintaining Open Directory Services 193
4 Click Settings, then click General.
5 Click Change.
This opens the Open Directory Assistant.
6 Select Promote replication to an Open Directory Master, then click Continue.
7 Enter the following Master Domain Administrator information, then click Continue.
 Short Name, Password: You must create a user account for the primary administrator
of the LDAP directory. This account is not a copy of the administrator account in
the servers local directory domain. Make the short names of the LDAP directory
administrator dierent from names of user accounts in the local directory domain.
Note: If you plan to connect your Open Directory master to other directory domains,
pick a unique name and user ID for each domain. Don’t use the suggested diradmin
user ID. Use a name that helps you identify the directory domain that the directory
administrator controls.
8 Enter the following Master Domain information, then click Continue.
 Kerberos Realm: This eld is preset to be the same as the servers DNS name,
converted to capital letters. This is the convention for naming a Kerberos realm. You
can enter a dierent name if necessary.
 Search Base: This eld is preset to a search base sux for the new LDAP directory,
derived from the domain portion of the server’s DNS name. You can enter a dierent
search base sux or leave it blank. If you leave this eld blank, the LDAP directorys
default search base sux is used.
9 Conrm settings, then click Continue.
This saves your setting and restarts the service.
10 Click Done.
11 In Server Admin, connect to another replica of the old master.
12 Click the triangle at the left of the server.
The list of services appears.
13 From the expanded Servers list, select Open Directory.
14 Click Settings, then click General.
15 Click Change.
The Open Directory Assistant opens.
16 Choose Set up a Standalone Directory, then click Continue.
17 Conrm the Open Directory conguration setting, then click Continue.
18 If you are sure that users and services no longer need access to the directory data
stored in the shared directory domain that the server has been hosting or was
connected to, click Close.