• United States

Apple’s newest cat

Mar 29, 20044 mins
AppleEnterprise ApplicationsServers

OS/X Panther 10.3 purrs with more management savvy.

For a $129 upgrade fee, Apple’s latest OS/X code provides a boost in functionality, VPN support, Microsoft network compatibility and ease of administration, but not a noticeable performance increase.

The most significant difference that we found in our testing between OS/X 10.2 (Jaguar) and 10.3 (Panther) is that Apple’s previously disjointed management applications have been replaced by one Server Admin application that offers greater control over most of the system. However, Xserve RAID subsystem management still requires an extra application. Server Admin feels similar to Microsoft’s Management System (MMS) but lacks plug-ins and multi-server administrative appeal.

How we did it

Archive of Network World reviews

Subscribe to the Product Review newsletter

Several open source applications have been ported and polished for Panther. Sendmail is out, and Postfix is in. Apple also added open source client interfaces from the Cyrus product that include support for both Post Office Protocol and Internet Message Access Protocol mail. There is also an open source mail list manager called Mailman. Managing all of these elements collectively was quick and simple using Server Admin.

Apple also has added integrated Point-to-Point Tunneling Protocol and Layer 2 Tunneling Protocol (L2TP) support to facilitate IPSec-based VPNs. Lacking an X.509 server to generate the VPN key exchanges needed for dynamic keys, Apple’s IPSec implementation accepts only pre-shared keys that Kame generates and therefore lacks the appeal of variable-key infrastructure in the Protected Extensible Authentication Protocol (PEAP) vein. Kame is an open source IPSec/IPv6 initiative.

Because the bundled L2TP VPN software doesn’t support the pre-draft IPSec network address translation-traversal function that lets VPNs transverse firewalls, an Apple server running Panther needs to be on the Internet boundary perimeter to support L2TP.

Panther includes Apple’s first distribution of Samba 3.0, an open source directory service application that emulates a Windows NT primary domain controller. This lets Windows and Macs use Apple’s Open Directory service to perform many of the tasks that typically are completed by a Windows Active Directory server.

There have been numerous initial bug/security fixes associated with Samba 3.0, and despite several automatic updates to the code, we found a few issues when attempting to authenticate between Panther/Samba 3.02 and Active Directory.

For example, when schema changes are made to the Active Directory database, Samba began to have authentication (and therefore additional Kerberos security problems) with Active Directory-based resources. Until this bug is sorted out, we suggest that such changes to the Active Directory schema be performed before adding the updated Panther/Samba 3.02 combination to a network.

Apple has added some fleet rollout capabilities to this revision. The first is the ability to build images for Mac clients that can be delivered from a Panther distribution server, called NetBoot. Building the images was comparatively simple using NetBoot and the new Network Image Utility. However, we couldn’t build unique software IDs for distributed client applications, a problem that has myriad work-arounds in the Windows world. Fortunately many Mac applications usually don’t need software IDs or serialization to work properly and legally.

Another new feature called Network Install uses NetBoot methods to roll out applications and updates. It bundles applications and/or folders into packages that can be distributed in a number of different ways. Fleet server update/rollout for Panther is managed on Xserve systems via another new element called Server Assistant. While not as handy as other server fleet distributors we’ve tested, the Server Assistant is a step in the right direction in terms of having a means of rolling out this operating system across a large network.

Apple OS/X 10.3.02

(Panther Server)

Company: Apple, (408) 996-1010 Price: $995 new, $129 upgrade fee Pros: More astute management features; more support for open source applications. Cons: Some integration issues with SAMBA and Active Directory; some rough edges still exist.
The breakdown   
Performance 25%  4
Management/ease of use 25%  4.25
Scalability and redundancy 25%  3.5
Installation and documention 25%  4.25
Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Consistently subpar

In terms of security, Apple has made it easier to manage how files get encrypted with the FileVault file encryption software that comes bundled with its operating system. Specifically, Apple has simplified how administrators control encryption authorization, key storage (so that keys can be recovered), and key generation. Panther also limits the encryption capabilities to home directories rather than to application, system or library root areas.

While we found only nominal performance increase – our performance tests yielded nearly identical Web-based and disk I/O numbers as that seen with OS/X 10.2 tests (see here) – Panther shows a determination on Apple’s part to be taken seriously in the server operating system market.