11.07.2015 Views

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

Centrify DirectControl Best Practices - Cerberis

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CENTRIFY WHITE PAPERCENTRALIZED MANAGEMENT FOR UNIX, LINUX, MAC AND JAVA WITH ACTIVE DIRECTORY AND DIRECTCONTROL• ZoneGen requires the use of additional Active Directory Groups for filtering Usersand Groups into Zones; create a Zone_{Name}_Users Active Directory Group thatcontains both AD Users and Groups of Users for a given Zone.• Similarly, create a Zone_{Name}_Groups Active Directory Group that containsActive Directory Groups to be provisioned into a given Zone.• Schedule ZoneGen on a single Windows computer that manages all Zones or acrossmultiple Windows computers that each manages a distinct set of Zones.Additional documentation for ZoneGen is available in the <strong>Centrify</strong> <strong>DirectControl</strong> ZoneGenerator application note.5 Solution: Phase Three Solution ArchitecturePhase three projects with <strong>Centrify</strong> <strong>DirectControl</strong> typically focus on integration withexternal systems, such as monitoring and provisioning systems.5.1 Lights-out administrationTwo best practices apply to configuring <strong>Centrify</strong> <strong>DirectControl</strong> for lights-outadministration.1. Integration with external monitoring systems.Any monitoring system that can read the output of syslog on UNIX computers issuitable for monitoring <strong>Centrify</strong> <strong>DirectControl</strong>. This does not require changes to thestandard INFO log level used by <strong>DirectControl</strong>. For example, Illumi Clinics canconfigure a regular expression in their commercial monitoring solution:“adclient.* Running in disconnected mode”This simple regular expression will determine when <strong>DirectControl</strong> is no longerconnected to Active Directory. Illumi Clinics can configure their monitoring solutionto take remedial steps and/or alert the on-call UNIX operations personnel tomanually troubleshoot the condition.2. Integration with provisioning systems.It is a best practice to automate as much user and group UNIX profile provisioningas possible. Illumi Clinics will invest heavily in a commercial Identity Managementsolution as part of a future project. This is covered in another whitepaper,“Integrating <strong>Centrify</strong> <strong>DirectControl</strong> with Identity Management Systems”:This white paper provides detailed examples of how to integrate <strong>Centrify</strong><strong>DirectControl</strong> with commercial off-the-shelf Identity Management Systems. Itdemonstrates how to handle common Identity Management events and discusses© CENTRIFY CORPORATION 2004-2007. ALL RIGHTS RESERVED. PAGE 37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!