11.07.2015 Views

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CENTRIFY WHITE PAPERCENTRALIZED MANAGEMENT FOR UNIX, LINUX, MAC AND JAVA WITH ACTIVE DIRECTORY AND DIRECTCONTROLHere is a sample excerpt from the checklist prepared for use by Illumi Clinics UNIXoperations team.Task InstructionExpected ResultLog on or switch (su) to the root user on thecomputer. If possible, use the console headserver or the local console.The root prompt “#” will bedisplayed.Disable user logins:# touch /etc/nologinDisable the NTP service.For Solaris 10 Systems Only:# svcadm disable network/ntpFor Solaris 2.6 – 9 Systems Only:# /etc/rc2.d/S74xntpd stop# mv /etc/rc2.d/S74xntpd/etc/rc2.d/K74xntpdFor Red Hat Systems Only:# /sbin/chkconfig ntpd off# /sbin/service ntpd stopType the following command to join thedomain:# adjoin –u username -c“container or OU DN” –z zoneillumiclinics.comThe correct values for username, container,and zone can be found in section 3.1 of thisdocument.Note: Only use the partial DN for the OUpath. Do not include the domain name.Example:“cn=zone34,ou=computers,ou=unix”.Sample output:<strong>Centrify</strong> <strong>DirectControl</strong>started.You have successfullyjoined the ActiveDirectory domain:illumiclinics.comIn the <strong>Centrify</strong><strong>DirectControl</strong> zone:CN=ZONENAME,CN=Zones,OU=UNIX,DC=Illumiclinics,DC=COMYou may need to restartother services that relyupon PAM and NSS or simplyreboot the computer forproper operation. Failureto do so may result inlogin problems for ADusers.Enable user logins:# touch /etc/nologin© CENTRIFY CORPORATION 2004-2007. ALL RIGHTS RESERVED. PAGE 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!