Enable Calendar service access for users of Active Directory and third-party LDAP servers

Learn how to enable Calendar service access for use with users of Active Directory or third-party LDAP servers.

The Calendar service in OS X Server uses the MD5 Digest authentication method by default. This doesn't allow users to log into the Calendar server using Active Directory credentials. Apple recommends configuring Kerberos for Active Directory users.

If you require a non-Kerberos solution to support Active Directory users, cleartext authentication can be enabled for the Calendar service using the steps below. If you choose to use cleartext authentication, Apple strongly recommends you use SSL to provide a more secure environment.

To enable cleartext authentication in the Calendar server, use the following Terminal commands. Changes you make to the authentication methods in the Calendar or iCal service are also applied to the Contacts or Address Book service.

  1. To enable cleartext authentication, use this command:
    sudo serveradmin settings calendar:Authentication:Basic:Enabled = yes
  2. To disable digest authentication, use this command:
    sudo serveradmin settings calendar:Authentication:Digest:Enabled = no
  3. Restart the Calendar server:
    sudo serveradmin stop calendar
    sudo serveradmin start calendar
  4. Restart the Address Book server:   
    sudo serveradmin stop addressbook
    sudo serveradmin start addressbook

After restarting both services, support for cleartext and Kerberos authentication methods take effect.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Risks are inherent in the use of the Internet. Contact the vendor for additional information. Other company and product names may be trademarks of their respective owners.

Last Modified: