11.07.2015 Views

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CENTRIFY WHITE PAPERCENTRALIZED MANAGEMENT FOR UNIX, LINUX, MAC AND JAVA WITH ACTIVE DIRECTORY AND DIRECTCONTROL• The separation of the Zone data into a separate tree is what allows the delegation ofadministration to the UNIX administrators for the UNIX data only; the UNIX datafor each Zone is separate from the other Zones and from the base Active Directoryobjects for the users and groups.• A user and a group can be associated with many Zones.3.4 Solution: Initial Patch AnalysisIllumi Clinics uses a commercial patch management system for software patchdeployment across Windows, UNIX and Linux. The minimum best practice is to reviewthe release notes included with the <strong>DirectControl</strong> agent for each platform, and then to atleast install those required patches before installing <strong>DirectControl</strong>. For example, therelease notes for Red Hat Linux 9.0 specify a minimum glibc patch level. Solaris versionsof <strong>DirectControl</strong> include the ‘pca’ script, which will help determine the required patches.Illumi Clinics is following their operating environment vendor’s best practices forsecurity and routinely updates their UNIX and Windows computers to the most recentrecommended security patches. As a result, their environment is up to date and requiresno changes in advance of deploying <strong>DirectControl</strong>.3.5 Solution: Software InstallationIllumi Clinics uses a commercial software package management system. This system willbe used to deploy <strong>DirectControl</strong> to all UNIX systems, using the native package installeron each platform (such as rpm on Red Hat and pkgadd on Solaris). The best practice fordeploying <strong>DirectControl</strong> is to install it on all machines that will be Zoned but notnecessarily to join those machines to Active Directory at the time of installation becausethe join process is what changes the configuration files which turn on authentication toAD.Illumi Clinics will also be deploying <strong>Centrify</strong>’s build of OpenSSH to all UNIX systems.The best practice for deploying OpenSSH is to remove the existing SSH packages, installthe <strong>Centrify</strong> build of OpenSSH, and then start the <strong>Centrify</strong> SSH server.If Illumi Clinics did not use a commercial software package management system then thedeployment of <strong>DirectControl</strong> and OpenSSH could be performed manually by UNIXoperators. Alternatively, Illumi Clinics could contact <strong>Centrify</strong>’s Professional Services tohelp develop a software distribution script for their environment. The best practice formanual installation is to write an installation and verification checklist to be used byUNIX operators who may be unfamiliar with the operation of <strong>DirectControl</strong> in order tominimize manual mistakes.Illumi Clinics purchased four console licenses for <strong>DirectControl</strong>. The best practice is toinstall the <strong>Centrify</strong> <strong>DirectControl</strong> Console on all UNIX operators and administrators’machines that need the ability to administer Zones, UNIX profiles for users and groups,© CENTRIFY CORPORATION 2004-2007. ALL RIGHTS RESERVED. PAGE 19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!