• Linux can directly integrate with AD (Active Directory) via PAM
  • We buy Dell/Qwest VAS
  • all AD stuff must be queried thru VAS
  • /opt/quest/bin/vastool -u host/ attrs USERNAME [thing]
  • better way is to use the keytab, but i'm lazy, so i don't
  • only works from AD-joined boxes
  • check VAS status: /opt/quest/bin/vastool -u host/ info domain
  • if not joined, you're in trouble: you'll need to get a ticket filed to someone.
  • NEXT
    PREVIOUS
    Master Index