Quantcast
Channel: All Centrify Express posts
Viewing all articles
Browse latest Browse all 1833

Re: Centrify Express and DeepFreeze

$
0
0

Hello,

 

I am not entirely sure of what does DeepFreeze as I am not familiar with this product but, I understand it allow you to suspend a system in a state and wake it up by restoring it's state when you need it (some sort of hot snapshot solution).

 

Bare in mind that to comuunicate with Active Directory, a joined Computer with Kerberos credentials that need to be synced: a password Hash on AD side, a shared secret store in the system keytab file on the system side.

 

If you keep the system off comunication with AD for too long you end up desynchronising the password, preventing this system to be able to talk to AD (bet that adclient shows in disconect mode then).

 

I guess one of the option here is to rejoin the system to AD at wake up from eternal sleep, so it cans update the keytab with a new Computer account password. Reseting the password is also a valid approach, I simply suspect that the updated keytab is not commited into the forzen state and so rebooting the system will loose the new keytab information and restore the system with an expired one.

 

Hope that helps,

Fab

 


Viewing all articles
Browse latest Browse all 1833

Trending Articles