TweetFollow Us on Twitter

Changing Spots

Volume Number: 23 (2007)
Issue Number: 11
Column Tag: MacEnterprise

Changing Spots

New ways of manipulating Directory Services in Leopard

By Philip Rinehart, Yale University

User Account Changes

Occasionally, questions about user accounts and how to maintain them appear on the Macenterprise list. Leopard changes the landscape, as NetInfo no longer exists. What does this mean practically? All user account information is now stored as flat text files. No more messing around with command line utilities like nicl, nidump, etc. All access is now accomplished using the command line directory service utility, dscl. Let's take a look at how it works.

DSCL

Dscl, Directory Service Command Line, utility was originally introduced in Tiger. With the death of NetInfo, it is the new way of manipulating user accounts. Also, astute users may note that NetInfo Manager is now completely gone, so any manipulation of NetInfo attributes must be accomplished by using dscl. Directory Service attributes can be changed, appended or deleted. Let's take a very basic example.

   dscl . -read /Users/myuser

This example operates on the local node by using the period, and returns all of the attributes for myuser. The command returns a list of all of the values that would have been seen in NetInfo Manager. They are printed out as a single line for each value. While interesting, it only begins to tap dscl for its true power. Here's a second example, listing all the users on the local system, as well as their UniqueID values (UID).

   dscl /Local/Default -list /Users UniqueID

This command is a really quick way to list any attribute of any user that is stored in the local Directory Services store. Notice a slight difference in this command? Instead of using a period, the full node is specified, in this case, the local database, /Local/Default. Let's step back just a second. Since NetInfo is gone, where is all the information? Here is the complete path:

   
   /var/db/dslocal/nodes/Default/Users

Explore the contents of the directory, notice how everything is a plist? One of the decisions made when moving away from NetInfo is that all of the information is now stored in xml plist format in the above directory. As an interesting side effect, any properly formatted plist that is added to the user will now appear on the system as a valid user. Returning to our UID example, now that the UID is known for any user, it is a pretty simple operation to change a UID on the fly. Back to dscl:

   
   dscl /Local/Default -create /Users/myuser UniqueID 503

This command takes the current UniqueID value for myuser and overwrites or it with the new value. Instead of the user's previous value for UniqueID, a new one has now been put in place. Note that use of the create option will completely overwrite any current value. If the value does not exist, it creates it in the plist.

PUMP IT UP

All of our example dscl commands will work in Tiger. Dscl in Leopard has been beefed up considerably. It now has the ability to read subkeys through the use of additional command line options. If you ever looked at a NetInfo record that contained mcx information, you know that mcx settings are typically sent to the client as a plist. Now that this information is stored in a flat plist with nested values, dscl needs a way to manipulate the data. New options have been added, readpl, readpli, and createpl, createpli. Unfortunately the syntax is difficult to master, as it requires a very specific format. Here's a somewhat simplified example for managed preferences.

   dscl . -readpl /Users/myuser MCXSettings mcx_application_data:com.apple.finder

Note the syntax of the key, colons separate nested values. In this particular case, the managed preference key for the Finder is read. This example should give you a taste of how the command works, but getting the path exactly right can be a bit tricky. Fortunately, there is a way out of the weeds, with a new mcx options for dscl..

MCX!

One of the major complaints in previous versions of OS X was the inability to easily understand and manipulate managed preferences. Leopard is the first version of OS X that has options to help manage via script, or the command line. It has also been quite difficult to troubleshoot managed client preferences, and to truly understand what is going on when managed preferences are applied. Let's look at our friend dscl again, this time with an eye toward the options that were added to dscl. Here's a very simple example:

   dscl . -readmcx /User/myuser

Note how the information is returned. Each managed preference is returned as a set of values with a consistent format. So for example, if a Finder preference was managed, the value might look like this:

App domain: com.apple.finder
Key: ComputerViewOptions_Arrangement
State: always
Value: None

Cool! The mcxread option is useful, but even more useful is the ability to set, import and export keys with dscl and its associated mcx commands. Imagine being able to set preferences from the command line from a client! A sample process could be:

   dscl . -mcxexport /Users/myuser -o /tmp/export.plist com.apple.finder

This command exports the managed client settings for myuser. The settings can then be altered in the exported file, export.plist with any text editor. Once finished editing, use this command to import the changed values:

   dscl . -mcximport /Users/myuser -d /tmp/export.plist

One note about this command, the -d option deletes any keys that existed previously. It is equivalent to calling mcxdelete for every key found in the import file. There are many options available for command line managed preference manipulation of preferences, which are not documented in the manual page. So how can you find the proper options? Use the flag -mcxhelp.

   dscl . -mcxhelp

This short command returns all of the options available, and is quite thorough in its description of how to use the command line options.

What if you only want to see what managed preferences are being applied? A new command for Leopard, mcxquery has been added. It can be called directly to present all of the options for any known user, group or machine. Here's how:

   mcxquery -user myuser -group mygroup -computer mycomputer

This command returns a list of all managed preferences for all three options. Additionally, it specifies exactly which domain the management is being applied from. If it is a user management preference, it indicates the managed preference. Very useful! Now that Leopard is finally out, a whole new world of discovery awaits us. As always, see you on the lists!


Philip Rinehart is co-chair of the steering committee leading the Mac OS X Enterprise Project (macenterprise.org) and is the Lead Mac Analyst at Yale University. He has been using Macintosh Computers since the days of the Macintosh SE, and Mac OS X since its Developer Preview Release. Before coming to Yale, he worked as a Unix system administrator for a dot-com company. He can be reached at: philip.rinehart@yale.edu. The MacEnterprise project is a community of IT professionals sharing information and solutions to support Macs in an enterprise. We collaborate on the deployment, management, and integration of Mac OS X client and server computers into multi-platform computing environments.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All

Top Hat Studios unveils a new gameplay t...
There are a lot of big games coming that you might be excited about, but one of those I am most interested in is Athenian Rhapsody because it looks delightfully silly. The developers behind this project, the rather fancy-sounding Top Hat Studios,... | Read more »
Bound through time on the hunt for sneak...
Have you ever sat down and wondered what would happen if Dr Who and Sherlock Holmes went on an adventure? Well, besides probably being the best mash-up of English fiction, you'd get the Hidden Through Time series, and now Rogueside has announced... | Read more »
The secrets of Penacony might soon come...
Version 2.2 of Honkai: Star Rail is on the horizon and brings the culmination of the Penacony adventure after quite the escalation in the latest story quests. To help you through this new expansion is the introduction of two powerful new... | Read more »
The Legend of Heroes: Trails of Cold Ste...
I adore game series that have connecting lore and stories, which of course means the Legend of Heroes is very dear to me, Trails lore has been building for two decades. Excitedly, the next stage is upon us as Userjoy has announced the upcoming... | Read more »
Go from lowly lizard to wicked Wyvern in...
Do you like questing, and do you like dragons? If not then boy is this not the announcement for you, as Loongcheer Game has unveiled Quest Dragon: Idle Mobile Game. Yes, it is amazing Square Enix hasn’t sued them for copyright infringement, but... | Read more »
Aether Gazer unveils Chapter 16 of its m...
After a bit of maintenance, Aether Gazer has released Chapter 16 of its main storyline, titled Night Parade of the Beasts. This big update brings a new character, a special outfit, some special limited-time events, and, of course, an engaging... | Read more »
Challenge those pesky wyverns to a dance...
After recently having you do battle against your foes by wildly flailing Hello Kitty and friends at them, GungHo Online has whipped out another surprising collaboration for Puzzle & Dragons. It is now time to beat your opponents by cha-cha... | Read more »
Pack a magnifying glass and practice you...
Somehow it has already been a year since Torchlight: Infinite launched, and XD Games is celebrating by blending in what sounds like a truly fantastic new update. Fans of Cthulhu rejoice, as Whispering Mist brings some horror elements, and tests... | Read more »
Summon your guild and prepare for war in...
Netmarble is making some pretty big moves with their latest update for Seven Knights Idle Adventure, with a bunch of interesting additions. Two new heroes enter the battle, there are events and bosses abound, and perhaps most interesting, a huge... | Read more »
Make the passage of time your plaything...
While some of us are still waiting for a chance to get our hands on Ash Prime - yes, don’t remind me I could currently buy him this month I’m barely hanging on - Digital Extremes has announced its next anticipated Prime Form for Warframe. Starting... | Read more »

Price Scanner via MacPrices.net

Save $300 at Apple on 14-inch M3 MacBook Pros...
Apple has 14″ M3 MacBook Pros with 16GB of RAM, Certified Refurbished, available for $270-$300 off MSRP. Each model features a new outer case, shipping is free, and an Apple 1-year warranty is... Read more
Apple continues to offer 14-inch M3 MacBook P...
Apple has 14″ M3 MacBook Pros, Certified Refurbished, available starting at only $1359 and ranging up to $270 off MSRP. Each model features a new outer case, shipping is free, and an Apple 1-year... Read more
Apple AirPods Pro with USB-C return to all-ti...
Amazon has Apple’s AirPods Pro with USB-C in stock and on sale for $179.99 including free shipping. Their price is $70 (28%) off MSRP, and it’s currently the lowest price available for new AirPods... Read more
Apple Magic Keyboards for iPads are on sale f...
Amazon has Apple Magic Keyboards for iPads on sale today for up to $70 off MSRP, shipping included: – Magic Keyboard for 10th-generation Apple iPad: $199, save $50 – Magic Keyboard for 11″ iPad Pro/... Read more
Apple’s 13-inch M2 MacBook Airs return to rec...
Apple retailers have 13″ MacBook Airs with M2 CPUs in stock and on sale this weekend starting at only $849 in Space Gray, Silver, Starlight, and Midnight colors. These are the lowest prices currently... Read more
Best Buy is clearing out iPad Airs for up to...
In advance of next week’s probably release of new and updated iPad Airs, Best Buy has 10.9″ M1 WiFi iPad Airs on record-low sale prices for up to $200 off Apple’s MSRP, starting at $399. Sale prices... Read more
Every version of Apple Pencil is on sale toda...
Best Buy has all Apple Pencils on sale today for $79, ranging up to 39% off MSRP for some models. Sale prices for online orders only, in-store prices may vary. Order online and choose free shipping... Read more
Sunday Sale: Apple Studio Display with Standa...
Amazon has the standard-glass Apple Studio Display on sale for $300 off MSRP for a limited time. Shipping is free: – Studio Display (Standard glass): $1299.97 $300 off MSRP For the latest prices and... Read more
Apple is offering significant discounts on 16...
Apple has a full line of 16″ M3 Pro and M3 Max MacBook Pros available, Certified Refurbished, starting at $2119 and ranging up to $600 off MSRP. Each model features a new outer case, shipping is free... Read more
Apple HomePods on sale for $30-$50 off MSRP t...
Best Buy is offering a $30-$50 discount on Apple HomePods this weekend on their online store. The HomePod mini is on sale for $69.99, $30 off MSRP, while Best Buy has the full-size HomePod on sale... Read more

Jobs Board

*Apple* App Developer - Datrose (United Stat...
…year experiencein programming and have computer knowledge with SWIFT. Job Responsibilites: Apple App Developer is expected to support essential tasks for the RxASL Read more
Omnichannel Associate - *Apple* Blossom Mal...
Omnichannel Associate - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Read more
Operations Associate - *Apple* Blossom Mall...
Operations Associate - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Read more
Cashier - *Apple* Blossom Mall - JCPenney (...
Cashier - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Blossom Mall Read more
*Apple* Software Engineer - HP Inc. (United...
…Mobile, Windows and Mac applications. We are seeking a high energy Senior Apple mobile engineer who can lead and drive application development while also enabling Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.