Centrify releases new, free Mac and Linux integration toolkit for Active Directory

Centrify releases new, free Mac and Linux integration toolkit for Active Directory

Summary: Windows management vendor Centrify this week released Centrify Express, its new integration package for Windows Active Directory services. The software toolkit is a free, lite version of its Centrify Suite, which provides greater policy and identity management capabities, and features such as server isolation and encryption of data-in-motion.


Windows management vendor Centrify this week released Centrify Express, its new integration package for Windows Active Directory services. The software toolkit is a free, lite version of its Centrify Suite, which provides greater policy and identity management capabities, and features such as server isolation and encryption of data-in-motion.

In his blog, Centrify president Tom Kemp said the new software would bring Active Directory control authentication to SMBs and other small organizations. He said these companies would appreciate the growth path to the company's more-capable Centrify Suite.

Third, we were getting requests from many people who had tried other free Active Directory integration tools and found them very unreliable, difficult to deploy on a mass scale, and did not play with existing software such as Samba. We were getting tons of requests from Ubuntu and Red Hat and Mac users asking if we could do better. Our answer was Yes! ...

So instead of providing a one-off toolset for Active Directory authentication, we decided to give away a subset of the same enterprise-hardened technology that our 2,500+ customers have in production on hundreds of thousands of servers today. I think you will find our solution much more reliable and mature compared to other solutions, and be better optimized from a login experience perspective.

But even if you have AD authentication taken care of on your non-Microsoft systems, customers don't want to “manage the management system.” That’s why we are also providing DirectManage Express as part of our Express offering to centrally deploy and/or upgrade our agent on dozens or hundreds of systems.

But before DirectManage Express even does that, DirectManage Express also provide a means to do a centralized and automated pre-install check. The net net is this is a huge time saver over sneakernet and manually checking if a system can become an Active Directory client. DirectManage Express also provides the ability to quickly login to those remote systems via integration with SSH/SNC/VPC, and to view local system accounts, etc.

Topics: Security, Apple, Enterprise Software, Hardware, Linux, Open Source, Software

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.


Log in or register to join the discussion
  • RE: Centrify releases new, free Mac and Linux integration toolkit for Active Directory

    Perhaps I'm missing something here. Mac OS X already has Open Directory & Active Directory integration so how is Centrify Express of value?
  • RE: Centrify releases new, free Mac and Linux integration toolkit for Active Directory

    It's a very good question actually. A few points and I hope this helps.
    -Consistency across platforms (e.g. Linux) and across versions of Mac OS X
    -Deployability and upgradability via DirectManage Express
    -Integration w/ third party solutions such as PuTTY etc.
    -Support for multi-Domain, multi-Forest (one way and two way trusts)
    -Computer account password periodic updates just like windows to prevent the computer from looking like a stale account.
    -Upgradability to additional capabilities such as group policy and smart-card support on the Mac platform

    (disclosure: I work for Centrify)
  • Still not clear

    Ryan, I'm afraid that none of that is very clear, except the fact that, yes, it is a 'lite' version and you'd love us to get hooked so we want to upgrade to the full version.
    Do we install stuff on the Server? Is the Windows guy gonna be unhappy? Do we install stuff on the macs? I dont understand "account password periodic updates". The server has a policy... after the interval, the message pops up on the day telling the users they need to change their password and they all freak out. How does Centrify Express lighten this pain? Get your marketing people to make a table with the problems on one side and how C.E. fixes them on the other.
  • RE: Centrify releases new, free Mac and Linux integration toolkit for Active Directory


    Centrify Express does not require installing any software on the Windows Domain Controller or Windows Administrator's workstations. It also does not require storing any UNIX data in Active Directory since it will dynamically generate the user's UNIX profile from the existing Active Directory user object information. Windows administrators will be very happy that they can manage user accounts for the Mac exactly like they do for Windows systems today.

    When the Mac joins Active Directory a Computer Account will be created in Active Directory in the Computers container. This account has a corresponding password which Centrify Express will maintain for the life of the computer by periodically changing the password. This will ensure that the Mac computer accounts do not show up as "stale" accounts in AD, which is something that Administrators will search for when cleaning up Active Directory.

    In most environments, users are required to change their password every 90 days or so depending on your security policy. Centrify Express will warn users a week before the password expires so that the user has a chance to change it before it actually expires. When the user does change the password, it will be updated in both Active Directory as well as the Login Keychain so that the user is not challenged for multiple passwords at login (one for AD and one for the Keychain). You can fine tune the configuration of Centrify Express by modifying the configuration file (/etc/centrifydc/centrifydc.conf) adjusting the password expiration warning if desired.

    The primary benefit of Centrify Express on Mac OS X is that it provides a more natural upgrade path for IT Administrators who need to get the Macs joined into Active Directory for user authentication and password management where they want to eventually lock down the configuration of the system, centrally managing security settings using Group Policy in the future upon upgrade to Centrify DirectControl (this is accomplished by simply installing administrator tools and licenses in Active Directory, no software changes on the Mac).

    -Great suggestion on the table.
    • Question about licensing

      @ryan.vong Thanks for the great explanation. I have one question regarding the licensing of the paid license. Is price per user a one-time fee or is there a monthly or annual renewal fee?
  • RE: Centrify releases new, free Mac and Linux integration toolkit for Active Directory

    expover microsoft internet working at sites with the
    - and <a href="http://www.balimsohbet.com" title="sohbet odalari" target="_blank">sohbet odalari</a> - and <a href="http://www.manolyam.net" title="Mynet" target="_blank">mynet</a> - <a href="http://www.manolyam.net" title="Mynet sohbet" target="_blank">mynet sohbet</a> -
    turkey the microsoft is a good format is also <a href="http://www.facesohbet.net" title="face" target="_blank">face</a> -
    - <a href="http://www.metin2pvpserver.net" title="metin2 pvp" target="_blank">metin2 pvp</a> -
    operiation <a href="http://www.faceboksohbet.com/">facebok</a> - <a href="http://www.twittersohbet.com/">twitter</a>
    Behaviour of desdek bigger role in these sites <a href="http://www.sohbetix.net/">sohbet</a> Microsoft A network connection to the game s dada gubve unwanted surprises
    <a href="http://www.metin2pvpserverlar.com" title="metin2 pvp serverlar" target="_blank">metin2 pvp serverlar</a> -
    <a href="http://www.facesohbet.net" title="facesohbet" target="_blank">facesohbet</a> -
    and <a href="http://www.twittersohbet.com/yonja-sohbet" title="yonja" target="_blank">yonja</a> - and <a href="http://www.faceboksohbet.com" title="facebok" target="_blank">facebok</a> -<a href="http://www.sexsohbeti.org" title="sex sohbet" target="_blank">sex sohbet</a> - <a href="http://www.sexmuhabbet.net" title="sex hikayeleri" target="_blank">sex hikayeleri</a> - and- and <a href="http://www.facesohbet.net" title="facebook" target="_blank">facebook</a> - and <a href="http://www.facesohbet.net" title="fesbuk" target="_blank">fesbuk</a> - and <a href="http://www.balimsohbet.com" title="sohbet" target="_blank">sohbet</a> - and <a href="http://www.manolyam.net" title="cet" target="_blank">cet</a> - - and <a href="http://www.metin2oyunu.org/indir" title="metin2 indir" target="_blank">metin2 indir</a> - and <a href="http://www.metin2oyunu.org/resimleri" title="metin2 resimleri" target="_blank">metin2 resimleri</a> - and <a href="http://www.metin2oyunu.org/metin2-kaydol" title="metin2 kaydol" target="_blank">metin2 kaydol</a> - ang <a href="http://www.metin2oyunu.org/" title="metin2" target="_blank">metin2</a> -

    <a href="http://www.faceboksohbet.com/tag/fesbok-giris" title="fesbok giris" target="_blank">fesbok giris</a>
    room turkey
    twitter sohbet portallari <a href="http://www.twittersohbet.com/netlog/" title="netlog" target="_blank">netlog</a> and <a href="http://www.twittersohbet.com/twitter-turkce/" title="twitter turkce" target="_blank">twitter t?rkce</a> and <a href="http://www.twittersohbet.com/twitter-giris/" title="twitter giris" target="_blank">twitter giris</a> and <a href="http://www.twittersohbet.com/" title="twitter kaydol" target="_blank">twitter kaydol</a>
    <a href="http://facesohbet.net/modules/news/index.php?storytopic=41-fesbuk-videolar" title="fesbuk" target="_blank">fesbuk</a>

    turkiye mt2, metin2 online games serverlar
    and and and <a href="http://www.metin2pvpserver.net" title="mt2 pvp server" target="_blank">mt2 pvp server</a> and <a href="http://www.metin2pvpserver.net" title="metin2 pvp server" target="_blank">metin2 pvp server</a> and <a href="http://www.metin2pvpserver.net" title="metin2" target="_blank">metin2</a> and <a href="http://www.metin2pvpserver.net" title="pvp server" target="_blank">pvp server</a> and <a href="http://www.metin2pvpserverlar.com" title="metin2 pvp serverlar" target="_blank">metin2 pvp serverlar</a> and <a href="http://www.metin2pvpserverlar.com" title="metin2 pvp serverler" target="_blank">metin2 pvp serverler</a> and
    <a href="http://www.metin2pvpserverlar.com" title="pvp serverler" target="_blank">pvp serverler</a> and <a href="http://www.metin2pvpserverlar.com" title="pvp serverlar" target="_blank">pvp serverlar</a>

    <a href="http://www.istanbulsohbetodasi.net" title="istanbul sohbet" target="_blank">istanbul sohbet</a><a href="http://www.istanbulsohbetodasi.net" title="istanbul sohbet sitesi" target="_blank">istanbul sohbet sitesi</a><a href="http://www.istanbulsohbetodasi.net" title="istanbul sohbet odasi" target="_blank">istanbul sohbet odasi</a><a href="http://www.istanbulsohbetodasi.net" title="istanbul sohbet odalar?" target="_blank">istanbul sohbet odalar?</a>

    <a href="http://www.ankarasohbetodalari.org" title="ankara sohbet" target="_blank">ankara sohbet</a><a href="http://www.ankarasohbetodalari.org" title="ankara sohbet odalar?" target="_blank">ankara sohbet odalar?</a><a href="http://www.ankarasohbetodalari.org" title="ankara sohbet sitesi" target="_blank">ankara sohbet sitesi</a><a href="http://www.ankarasohbetodalari.org" title="ankara sohbet odas?" target="_blank">ankara sohbet odas?</a><a href="http://www.izmirsohbetodalari.org" title="izmir sohbet" target="_blank">izmir sohbet</a><a href="http://www.izmirsohbetodalari.org" title="izmir sohbet odalar?" target="_blank">izmir sohbet odalar?</a><a href="http://www.izmirsohbetodalari.org" title="izmir sohbet sitesi" target="_blank">izmir sohbet sitesi</a><a href="http://www.izmirsohbetodalari.org" title="izmir sohbet chat" target="_blank">izmir sohbet chat</a><a href="http://www.bursasohbetodalari.com" title="bursa sohbet" target="_blank">bursa sohbet</a><a href="http://www.bursasohbetodalari.com" title="bursa sohbet odalar?" target="_blank">bursa sohbet odalar?</a><a href="http://www.bursasohbetodalari.com" title="bursa sohbet siteleri" target="_blank">bursa sohbet siteleri</a><a href="http://www.bursasohbetodalari.com" title="bursa sohbet odasi" target="_blank">bursa sohbet odasi</a><a href="http://www.seviyelisohbetodalari.com" title="seviyeli sohbet" target="_blank">seviyeli sohbet</a><a href="http://www.seviyelisohbetodalari.com" title="seviyeli sohbet odalari" target="_blank">seviyeli sohbet odalar?</a><a href="http://www.seviyelisohbetodalari.com" title="seviyeli sohbet siteleri" target="_blank">seviyeli sohbet siteleri</a><a href="http://www.seviyelisohbetodalari.com" title="seviyeli sohbet kanallar?" target="_blank">seviyeli sohbet kanalalr?</a><a href="http://www.twittersohbet.com/yonja-sohbet" title="yonja" target="_blank">yonja</a><a href="http://www.twittersohbet.com/netlog/" title="netlog" target="_blank">netlog</a><a href="http://www.twittersohbet.com/" title="twitter" target="_blank">twitter</a><a href="http://www.faceara.com" title="face" target="_blank">face</a><a href="http://www.faceara.com" title="facebook" target="_blank">facebook</a><a href="http://www.metin2pvpserver.net" title="metin2 pvp, metin2 pvp server, mt2 server," target="_blank">pvp</a>

    Bunu mu demek istediniz? Cok guzel bir oyun be?eni ile oynuyorum ama bunun metin2
    Metin veya web sitesi adresi yaz?n ya da bir dok?man? ?evirin.
    Fonetik olarak okuyun
    T?rk?e dilinden ?ngilizce diline ?eviri
    I play a game with very nice, but it <a href="http://www.metin2oyunu.org" title="metin2" target="_blank">metin2</a>
    <a href="http://www.metin2pvpserver.net" title="metin2 pvp" target="_blank">metin2 pvp</a>
    <a href="http://www.metin2pvpserverlar.com" title="metin2 pvp serverler" target="_blank">metin2 pvp serverler</a>

    and install servers by lara s depending on the tour game bilrisiniz
  • More Centrify Updates?

    Centrify just delivered some cloud-based <a href="http://www.talkincloud.com/centrify-links-mobile-device-management-mdm-to-active-directory/">updates</a> that link mobile device management (MDM) to Active Directory. Curious to know if any readers have given the new offerings a look, how they work, etc.

    Joe Panettieri
    Editorial Director
    Talkin' Cloud