Quantcast
Channel: All Centrify Express posts
Viewing all articles
Browse latest Browse all 1833

Re: find-generic-password /Active Directory/DOMAINAME Equivelent for Centrify

$
0
0

- sure I can provide a big picture of what I am trying to accomplish.

 

End goal is to pull down a machine domain certificate from the certificate server to use for wireless and VPN authentication. See sample script at the URL below.

REFERENCES: nkalister - https://jamfnation.jamfsoftware.com/discussion.html?id=3387

 

With the help of I was able to get the AD_COMPUTER_NAME and AD_TRUST_ACCOUNT and pull down the certificate for the machines that have the /CentrifyDC item stored in the keychain.

 

I just have a few machines in my Test Lab that don't have the /CentrifyDC item in keychain (even though they show domain joined and connected) and I'm not sure yet how many other end users have macs in the same situation.

 

We have been using Group Policy to pull down a machine certificate currently but there hasn't been a way to specify the ACL permissions on that certificate. So the cert it pulls down doesn't allow it to be used by Airport or our VPN Application. If I can pull down a cert manually with the Web Enrollment menthod using an adapted script as referenced above I can make that certificate pull down and then adjust the ACL to "allow all applications" to use it.


Viewing all articles
Browse latest Browse all 1833

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>