Setting Up for Linux Desktops

Table Of Contents
Setting Up Active Directory
Integration for Linux Desktops 3
View uses the existing Microsoft Active Directory (AD) infrastructure for user authentication and
management. You can integrate the Linux desktops with Active Directory so that users can log in to a Linux
desktop using their Active Directory user account.
This chapter includes the following topics:
n
“Integrating Linux with Active Directory,” on page 25
n
“Seing Up Single Sign-on and Smart Card Redirection,” on page 26
Integrating Linux with Active Directory
Multiple solutions exist to integrate Linux with Active Directory (AD) and Horizon 7 for Linux Desktop has
no dependency on which solution is used.
The following solutions are known to work in a Horizon 7 for Linux Desktop environment:
n
OpenLDAP Server Pass-through Authentication
n
System Security Services Daemon (SSSD) LDAP Authentication against the Microsoft Active Directory
n
Winbind Domain Join
At a high level, the OpenLDAP Pass-through authentication solution involves the following steps:
1 Install Certicate Services on the Active Directory to enable LDAPS (Lightweight Directory Access
Protocol over SSL).
2 Setup an OpenLDAP server.
3 Synchronize user information (except password) from the Active Directory to the OpenLDAP server.
4 Congure the OpenLDAP server to delegate password verication to a separate process such as
saslauthd, which can perform password verication against the Active Directory.
5 Congure the Linux desktops to use a LDAP client to authenticate users with the OpenLDAP server.
The SSSD LDAP authentication against the Microsoft Active Directory solution involves the following steps:
1 Install the Certicate Services on the Active Directory to enable LDAPS.
2 Congure the SSSD in the Linux desktop to directly use LDAP authentication against the Microsoft
Active Directory.
The Winbind Domain Join solution involves the following steps:
1 Install the Winbind, Samba, and Kerberos packages on the Linux desktop.
2 Join the Linux desktop to the Microsoft Active Directory.
VMware, Inc.
25