Dell Wyse Enhanced Ubuntu Linux T50 Manual de usuario Pagina 111

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 220
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 110
Chapter 9. Authentication in ThinLinc
Further problems occur if the ThinLinc cluster is combined with Application Servers, for example
Windows Terminal Servers, to provide access to Windows Applications from ThinLinc. If "grace logins"
are enabled, each time the user starts an application on the Application server, one grace login attempt
will be consumed. One way of limiting this problem is to check if the password is about to expire in the
Netware login script. This can be done using the PASSWORD_EXPIRES or by using third-party software
such as passXchk available at http://www.novell.com/coolsolutions/tools/1911.html. If the password
change popup shouldn’t occur if the Windows Terminal Server session is used to execute a single
program, the program tl-is-appsession can be used to determine if the session is an application session
or not, in the login script.
9.3.6. Configuring Windows Terminal Servers with Netware Client for
Single Sign-On
In environments where ThinLinc users should be able to access software running on Windows Terminal
Servers, with ThinLinc Single Sign-On support, some extra configuration is needed if the Windows
Terminal Servers are configured to logon to a Novell network. The extra configuration is needed to make
sure the user can automatically login without having to manually enter the context where his/her user
object is located.
To solve this problem, the username is sent with context. For example, for a user with cn=user5 located
in the ou ou=school1,o=organization, the username will be sent as
cn=user5.ou=school1.o=organization over RDP.
For this to work, the Novell client installed on the Windows Terminal Server must be recent enough to
support receiving usernames with context over RDP. Version 4.91 SP4 is known to work.
Activate login to Windows Terminal Servers with context by adding the script tl-set-novelluser.sh to
/opt/thinlinc/etc/xstartup.d:
ln -s /opt/thinlinc/libexec/tl-set-novelluser.sh /opt/thinlinc/etc/xstartup.d/07-tl-set-novelluser.sh
This will set an environment variable at session startup. This environment variable is then detected by
tl-run-rdesktop when run.
Note: Please note that for login to work, users must exist not only in eDirectory, but also in the
Windows environment, for example via an AD domain or by using Zenworks dynamic local users
feature. Setup of this is however outside the scope of this document.
9.4. Using Public Key Authentication
9.4.1. Introduction
Public key authentication is a more secure alternative to passwords. It uses a challenge/response
101
Vista de pagina 110
1 2 ... 106 107 108 109 110 111 112 113 114 115 116 ... 219 220

Comentarios a estos manuales

Sin comentarios