In my previous post I reviewed the trends related to the integration of Linux systems into environments managed by Active Directory (AD). In this post I will review two integration options, namely: direct integration and indirect integration.
The direct option is, not surprisingly, when your systems are integrated into AD directly (i.e. your Linux systems communicate directly with AD), while the indirect option leverages an intermediary server (see figure below).
Before we dive into an overview and detailed comparison of these two integration options we need to define “the aspects of the integration”. The aspects of integration are:
- Authentication - A user logs into a Linux system, how is he or she authenticated?
- Identity Lookup - How does a given system know about the right accounts? How are Active Directory accounts are mapped to accounts used on Linux?
- Name Resolution and Service Discovery - How does a system know where to find its authentication and identity server?
- Policy Management - How are other identity related policies are managed on the system?
Having outlined this set of criteria, my next post will use it towards reviewing both the direct and indirect integration options in greater detail.
关于作者
产品
工具
试用购买与出售
沟通
关于红帽
我们是世界领先的企业开源解决方案供应商,提供包括 Linux、云、容器和 Kubernetes。我们致力于提供经过安全强化的解决方案,从核心数据中心到网络边缘,让企业能够更轻松地跨平台和环境运营。