Setting Up for Linux Desktops

Table Of Contents
Setting Up Active Directory
Integration for Linux Desktops 3
View uses the existing Microsoft Active Directory (AD) infrastructure for user authentication and
management. You can integrate the Linux desktops with Active Directory so that users can log in to a
Linux desktop using their Active Directory user account.
This section includes the following topics:
n
Integrating Linux with Active Directory
n
Setting Up Single Sign-on and Smart Card Redirection
Integrating Linux with Active Directory
Multiple solutions exist to integrate Linux with Active Directory (AD) and Horizon 7 for Linux Desktop has
no dependency on which solution is used.
The following solutions are known to work in a Horizon 7 for Linux Desktop environment:
n
OpenLDAP Server Pass-through Authentication
n
System Security Services Daemon (SSSD) LDAP Authentication against the Microsoft Active
Directory
n
Winbind Domain Join
At a high level, the OpenLDAP Pass-through authentication solution involves the following steps:
1 Install Certificate Services on the Active Directory to enable LDAPS (Lightweight Directory Access
Protocol over SSL).
2 Setup an OpenLDAP server.
3 Synchronize user information (except password) from the Active Directory to the OpenLDAP server.
4 Configure the OpenLDAP server to delegate password verification to a separate process such as
saslauthd, which can perform password verification against the Active Directory.
5 Configure the Linux desktops to use a LDAP client to authenticate users with the OpenLDAP server.
The SSSD LDAP authentication against the Microsoft Active Directory solution involves the following
steps:
1 Install the Certificate Services on the Active Directory to enable LDAPS.
VMware, Inc.
30