Setting Up for Linux Desktops

Table Of Contents
Setting Up Active Directory
Integration for Linux Desktops 3
View uses the existing Microsoft Active Directory (AD) infrastructure for user authentication and
management. You can integrate the Linux desktops with Active Directory so that users can log in to a Linux
desktop using their Active Directory user account.
This chapter includes the following topics:
n
“Integrating Linux with Active Directory,” on page 19
n
“Setting Up Single Sign-on and Smart Card Redirection,” on page 20
Integrating Linux with Active Directory
Multiple solutions exist to integrate Linux with Active Directory (AD).
The following solutions are known to work in a View environment:
n
OpenLDAP Pass-Through Authentication
n
Winbind
At a high level, the OpenLDAP pass-through authentication solution involves the following steps:
n
Configure the OpenLDAP server to delegate password verification to a separate process such as
saslauthd, which can perform password verification against Active Directory.
n
Configure the Linux desktops to authenticate users with OpenLDAP.
If you plan to bulk deploy Linux desktops, you can set up the template virtual machine (VM) to run the final
AD integration task. Be aware of the following considerations:
n
The OpenLDAP solution works for cloned VMs without any additional steps.
n
With the Winbind solution, the step to join the domain will fail because each cloned VM has a different
host name. Each cloned VM needs to run the following command to rejoin the domain:
sudo /usr/bin/net ads join -U <domain user>%<domain password>
VMware recommends the OpenLDAP or a similar solution because it does not require an additional step on
cloned VMs.
For more information about bulk deploying Linux desktops, see Chapter 7, “Bulk Deployment of Horizon 7
for Linux Desktops,” on page 51.
VMware, Inc.
19