114

6Review the new settings of the group by entering the following command, replacing officegroup with the group account’s short name:

> read officegroup

dscl displays the settings for the group account, similar to the following output:

apple-generateduid:4B3A5678-E9C1-2EC3-4567-891D234E5678 cn: officegroup

gidNumber: 600

MemberUid: mchen ajohnson bmiller

objectClass: posixGroup apple-group extensibleObject top

AppleMetaNodeLocation: /LDAPv3/ipaddress

GeneratedUID:4B3A5678-E9C1-2EC3-4567-891D234E5678

GroupMembers:2B3A4567-E8C9-9EC2-3456-789D123E4567 1B2A3456-E7C8-9EC1-2345-

678D912E3456 8B9A1234-E5C6-7EC8-9123-456D78E9123 GroupMembership: mchen ajohnson bmiller

Member: mchen ajohnson bmiller

PasswordPlus:********

PrimaryGroupID: 600

RecordName: officegroup

RecordType: dsRecTypeStandard:Groups

7Quit dscl by entering:

> quit

To find the guid of the administrator user:

>cd /Users/

>read adminusername GeneratedUID

Removing a User from a Group

You can remove users from a group by using the dscl tool.

To remove a user from a group:

1Start the dscl tool in interactive mode, specifying the computer you are using as the source of directory service data:

$ dscl localhost

>

2Change the current folder to /LDAPv3/ipaddress/Groups by entering the path at the prompt:

> cd /LDAPv3/ipaddress/Groups

Replace ipaddress with the IP address of your directory server. If using a NetInfo directory domain, enter cd /NetInfo/root/Groups at the prompt.

3Authenticate as an administrator by entering the following command, replacing adminusername with your administrator user name, and entering your administrator password when prompted:

> auth adminusername

Chapter 8 Working with Users and Groups

Page 114
Image 114
Apple Mac OS X Server manual Removing a User from a Group, You can remove users from a group by using the dscl tool