PAM on LDAP on an enterprise environment

Hi,
my customer would like to implement PAM authentication using DS6. The DS is already in place and they want to be able to grant some users access to some servers.
While it is quite easy to find examples on how to configure one server to authenticate to DS it seems impossible to find a good guide explaining how to do that in an enterprise environment. In other words a guide explaining the non trivial configuration parameters. Questions I haven't been able to find the answer to are for example:
how to limit the users having access to a specific server?
how to modify the existing user profiles in an existing DS?
and many others.
Is anybody aware of such a book (either free or not)
Thanks in advance
Sergio

i'm not sure if it's the 'proper' way, but couldn't you achieve this sort of functionality through netgroups?

Similar Messages

  • How can we update or manage the Adobe Product for example Adobe Reader and Flash Player in a enterprise environment.  Enterprise lifecicle management

    We want to maintenance the adobe products in the enterprise environment. Specially Update for he reader and players.
    Thanks

    You will need to apply for both Reader and Flash Player Distribution agreements if you intend on enterprise deployments of these products.
    Adobe - Adobe Runtimes / Reader Distribution License Agreement
    If you are using SCCM and SCUP then use the available catalogs for both products.
    11   SCCM-SCUP — Enterprise Administration Guide
    Flash Player enterprise deployment | Adobe Developer Connection

  • How can I turn off IPv6 temporary addresses in a enterprise environment

    So in a default configuration Vista and Windows 7 clients will use IPv6 temporary address (per RFC 3041), but I would like to be able to disable this with a GPO.
    I know I can do this by using a startup script tied to a GPO using the netsh interface ipv6 set privacy state=disabled store=persistent but I really do not want to run a logon script especially when as you can see in the command it is a persistent
    setting.
    Any ideas on using a registry based GPO for this?

    Hi,
    OK, I understand what you want. But after I use the Process Monitor to capture the behavior, I found that a lot of registry keys would be changed. So you can not set it via registry unless the IPv6 is disabled.
    Thanks for understanding.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”
    Thank you again for the answer.
    As a follow up question... How does one suggest/request a change in default behavior in a MS product?
    While the RFC 3041 addresses might be nice to have for the average consumer they are not ideal in a enterprise environment. I have found that the temporary addresses will register in DNS, but this doesn't completely solve the issue of tracking and accountability,
    you would still need a application to query, correlate and store that information.
    So it would be nice if the business versions of Windows Vista/7/2K8 and the next client OS would not have this behavior by default.

  • Log in the Enterprise Environment

    Hi everyone, i'd like to know if logging in the enterprise environment i'll have a tool like the log viewer that we have in the studio.
    Thanks for help

    Hi,
    I couldn't find the link where to raise a new topic. I am posting it here.
    I have a custom view which I will identify from the URL parameter. When the user logs in to portal, I have to show the custom view according to the parameter I receive in URL.
    I see that in applicationsView.jsp, the currentView is obtained from (ApplicationsView)request.getAttribute(ApplicationConstants.REQUESTED_VIEW);
    I would like to know if I can set the value for REQUESTED_VIEW so that currentView will pick the customized one.
    Can you pls let me know how to and what object I need to set in request.setAttribute(ApplicationConstants.REQUESTED_VIEW, Object); for Object?

  • How to disable checking for updates on Mac Silverlight for enterprise environment

    Hi Guys,
    We are trying to create a package for our enterprise environment to push the install of Silverlight for the Mac and have it not automatically check for updates.
    What is the best way to do that?
    I found the setting in the com.microsoft.silverlight.plist file that was in the user profile/library/preferences folder.
    Is there a way to have this UpdateMode key set to the desired setting regardless of which user is logged onto the mac?
    Thanks.
    Aaron

    I have zero experience of macs.
    Can't you install Silverlight and the plugin for all users rather than a specific one?
    I would guess/hope/expect there'd then be one plist file for everyone? 
    Please don't forget to upvote posts which you like and mark those which answer your question.
    My latest Technet article - Dynamic XAML

  • Hi, in our Enterprise environment, we have a single mac with Mavericks version 10.9.2 and Office for Mac 14.4.1. When setting up outlook, we are trying to connect to a mailbox on exchange server 2007.

    Hi, in our Enterprise environment, we have a single mac with Mavericks version 10.9.2 and Office for Mac 14.4.1. When setting up outlook, we are trying to connect to a mailbox on exchange server 2007. We put in the EWS details in the server field since our autodiscover function is not functioning. But still it doesn't work. There are no errors, no popups. We turned on the logging and in the logs, it says a error of -3259. We are stuck and any help will be really appreciated.

    I have a customer experiencing exactly the same issue. Their computer is running Windows 7 Pro with Office 2007 SP3. After seemingly exhausting all troubleshooting options, I backed up their data, formatted the hard drive and performed a clean install of
    Windows and all their applications. It didn't solve the problem!
    What's strange is the customer also has a laptop computer, running the same version of Outlook, and that doesn't experience any problems connecting to Office 365 on the same network.
    My next step is to send the customer a new ADSL modem/router to try.
    I have another customer on Office 365, also running Outlook 2007, and they also experience issues with emails sitting in the outbox while Outlook displays the status message “Outlook is trying to retrieve data from the Microsoft exchange server outlook.office365.com.”
    In this case Outlook doesn't freeze/stop responding, like it does for the first customer I mentioned.

  • How to deploy ejb in an Enterprise Environment using the jbuilder plugin

    Hello:
    I use Oracle9iAS Plug-in Release 2 (9.0.2) for Borland JBuilder 7 to deploy my ejb. But now, i would like to deploy my ejb to oc4j in an Enterprise Environment (not as standalone).
    Does anybody know how can i do it? I noted that the plugin use admin.jar to deploy ejb, and I suppose it need to use dcmctl.
    Thank you
    Sergio

    Sergio,
    The current release of Borland JBuilder only allows you to deploy to standalone OC4J. If you want to deploy to Oracle9iAS (Enterprise OC4J), please try Oracle9i JDeveloper 9.0.3:
    http://otn.oracle.com/software/products/jdev/content.html
    JDeveloper 9.0.3 uses DCM to deploy to Oracle9iAS
    Regards,
    Chen.

  • Mac OS X Mavericks in an enterprise environment

    Has apple released any information on deploying mavericks in an enterprise environment?  I'm looking for information on best practices on how to access the installers for deploying the os over several computers without using the store on each upgrade?

    I found a section on OS X Server which might be useful:
    http://www.apple.com/osx/server/features/

  • Avoid activation in an enterprise environment

    we want to avoid activating each adobe product in an enterprise environment on every single PC as we want to do unattended deployments. Is there a way to avoid that or for a general activation ?
    Thanks

    Moving this discussion to the Creative Suite Enterprise Deployment forum.  Which type of license are you trying to activate?  Is it a subscription or perpetual license?

  • Can anyone tell me how they are handling software distribution for the iPad in an enterprise environment?

    Can anyone tell me how they are handling software distribution for the iPad in an enterprise environment?

    The new Business Volume Purchase Program is pretty interesting...it can be used to centrally purchase and distribute paid ( not free) items from the AppStore.  We are getting setup to use it.  You can keep an eye on licenses etc.  You can also use a single centralized form of payment. 
    http://www.apple.com/business/vpp/

  • Licensing of apps for multiple iPads in an enterprise environment

    I have 21 iPads in an enterprise environment, syncing to one iPad.  Am I violating licensing terms.? These are 21 iPads used by 21 board members on each Friday.  Do I need to purchase this app 21 times?  If so how?

    Yes, you may be. The applicable terms of sale are these:
    (ii) If you are a commercial enterprise or educational institution, you may download and sync an App Store Product for use by either (a) a single individual on one or more iOS Devices you own or control or (b) multiple individuals, on a single shared iOS Device you own or control. For example, a single employee may use the Product on both the employee's iPhone and iPad, or multiple students may serially use the Product on a single iPad located at a resource center or library.
    If these iPads are under your own control and you just loan them out for the board meetings, then that might fall under clause (a), though I'm no lawyer and I don't speak for Apple.
    If these iPads are kept by the board members for their use, then your company needs to purchase the app twenty-one times, and the only way at present to do that is through twenty-one different iTunes Store accounts. So each board member should probably buy through his or her own iTunes Store account, and get reimbursed by the company if appropriate. I know this is awkward; perhaps Apple will come up with a better mechanism in the future.
    Regards.
    Message was edited by: Dave Sawyer

  • Installing and managing firefox in an enterprise environment using a third party desktop managment system (Novell ZEN)

    We want to deploy Firefox in our enterprise environment and need to figure out a way to have the install run silently, no user interaction. We use Novell's ZEN to centrally manage our desktops and how we've done this with other installs is to create a response file, but I guess Firefox will not use response files. So, how would we accomplish this?
    Any help would be greatly appreciated.
    Ken

    Novell's ZEN and response files
    Fixed certs for Firefox 36 using Novell, not sure how they did this but was fixed for the next version. [https://bugzilla.mozilla.org/show_bug.cgi?id=1042889 1042889]
    [https://bugzilla.mozilla.org/show_bug.cgi?id=1042889#c8 comment 8 specifically]
    [https://bugzilla.mozilla.org/show_bug.cgi?id=1091778 1091778]
    Try it in beta.
    Otherwise an alternative to a silent install from the commandline is -ms and check out the recommendations for deploying in an enterprise environment in MDN: [https://developer.mozilla.org/en-US/Firefox/Enterprise_deployment]

  • How to configure C.C. in a proxy/firewall/enterprise environment?

    Looking for some answers: It seems that Adobe Application Manager does not currently work with proxies. Is this correct?
    It also seems that the Creative Cloud packager also does not work behind a proxy nor does any automatic updates. What are some options for those in an enterprise environment? From what I've read and have been told via tech support, not much at all.
    It seems that if we install Creative Cloud on our machines, we have to download and manually install the updates? That's not very "cloud" like.

    I am not sure if this can help but we opened these endpoints and now we have acces to everything:
    http://wwwimages.adobe.com/www.adobe.com/content/dam/Adobe/en/devnet/creativesuite/pdfs/Se rviceAndSiteURL_List.pdf
    https://creative.adobe.com/api/assets
    https://creative.adobe.com/api/collections
    hptts://creative.adobe.com/api/share
    https://api.typekit.com
    http://use.edgefonts.net
    https://www.adobeexchange.com/api
    https://lm.licenses.adobe.com
    https://ims-na1.adobelogin.com
    https://ims-na1-cc1.adobelogin.com
    https://adobeid-na1.services.adobe.com
    https://na1r.services.adobe.com
    https://ams.adobe.com
    https://ccmdls.adobe.com
    Greetings,
    Frederik

  • Integrate LDAP with ALBPM Enterprise

    hi,
    Did anyone tried to integrate LDAP with ALBPM Enterprise?
    If using LDAP for creating directory, will it create a new schema in LDAP?
    If need to make use of existing LDAP schema, how can we do it?
    Need HELP!!!
    Thanks

    Hi Jasmine,
    Here are the choices you have for your Directory Service in ALBPM 6.0 Enterprise Standalone (I pulled them off of http://portal.plumtree.com/portal/server.pt?open=512&objID=3422&&PageID=5325&mode=2&in_high_userid=573417&cached=true).
    Sorry - I don't see "Open LDAP" in the list.
    Single Source JNDI Plugins: Sun ONE Java System Directory Server 5.2 (JNDI), MS Active Directory 2003 (JNDI). (Deprecated - they cannot be created any more); Single Source JDBC Plugins: Oracle 9i and 10g, MS SQLServer 2005, IBM DB2 UDB 8.2 and 9.1 using DataDirect JDBC Drivers 3.6; Sybase ASE 15.0.2 will be supported in ALBPM 6.1; Hybrid Plugins: Sun ONE System Directory Server 5.2 and Oracle 9i, Sun ONE System Directory Server 5.2 and Oracle 10g, MS Active Directory 2003 and Oracle 9i, MS Active Directory 2003 and Oracle 10g, MS Active Directory 2003 and MS SQL Server 2005, Sun ONE System Directory Server 5.2 and IBM DB2 8.2 or 9.1
    hth,
    Dan

  • Problem with LDAP configuration in Enterprise Manager

    Hi all,
    I'm new at Java CAPS. After install some pieces of Java CAPS now I'm trying to install and configure a Sun Java System Directory Server 5.2 in our environment.
    I've already configured the Repository and the Logical Host to work with the ldap, but I have some troubles to do it with the Enterprise Manager.
    I followed the instructions of the Administrator guide about the changes to do in web.xml and ldap.properties of the sentinel app but when I do login the Enterprise Manager I can't see the options of the tree to manage servers or users.
    It seems that the app don't recover the user roles. I think so becouse I tried to create one user without roles (in normal authentication, without ldap configured) and when I did login in the result was the same.
    At the beginning of the process I created the roles 'all', 'administration' and 'management'. However I tried to copy de roles of the Tomcat authentication from 'tomcat-users.xml' to ldap roles, but it doesn't work.
    Anyone could help me?
    Thanks in advance, and sorry for my rudimentary English

    Check that you have the correct Preferred Credentials with Logon as batch job if this is windows. Also check the correct configuration with regards LDAP integration for you platform.

Maybe you are looking for

  • Nokia e6 OVI store and email problem

    I just bought a Nokia E6, but I have trouble connecting to the store and adding my email. Whenever I try to open the OVI store, it asks for an update. So select download, and it tries to download and install, but when it's almost done installing, it

  • Drag and drop in Applets

    Is it possible to use the drag and drop APIs in applets? thanks jim

  • Still can't buy a song

    Just updated to itunes 7.0.2, and I still get the -9807 error message when i try to sign into itunes to buy a song. i can play all the previews i want, but i can't buy anything. yet i can sign into the apple store and buy anything i want. Whats happe

  • Shelf life /Expiry

    Dear All, 1-if a material is expired then how can i restrict it to assign on an order, 2- MRP checks for shelf life and takes into account expired material or not.

  • Placing a png logo created in Fireworks cs5 into Illustrator cs5

    I am trying toplace a logo into illustrator. When I do it looks fine but any kind of scakeing makes it look all pixelated. I am trying to scale it down to fit onto a business card. When I do it looks just alright while the second logo (mostly test) l