Re: [Fed-Talk] Centrify Mac OS 10.9 -> 10.12
Re: [Fed-Talk] Centrify Mac OS 10.9 -> 10.12
- Subject: Re: [Fed-Talk] Centrify Mac OS 10.9 -> 10.12
- From: Peter Thoenen - NOAA Federal <email@hidden>
- Date: Wed, 02 Nov 2016 09:10:11 -1000
> I know that everyone has opinions about Centrify. What I am looking to
> understand are what gotcha’s may be out there. I know that I have to
> join the
> Mac’s to AD, modified the AD structure slightly while not my first choice…
First off let me state that folk don't just use Centrify simply to join AD
and for smartcard/CAC support, I say this because everybody jumps to that.
Many folk also buy it for the GPO(like) support as well, etc. There really
are no gotcha's, it doesn't require schema updates, etc like it's primary
competitor. We have used for quite a while now and the gotcha's really are
trivial, i.e. they don't have standardize toolsets across their various
platforms, e.g. dzdo is the Centrify integrated Kerberos sudo replacement on
Linux but doesn’t work on Mac (so often to simply things like centralized
scanning, scripts, etc you have to create a symlink for sudo called dzdo on
OSX).
That being said it's has a direct competitor with Quest (now Dell)
[https://software.dell.com/products/authentication-services/] and I vastly
preferred that though the downside was it required schema changes plus TBH
their support was vastly worse that Centrify .. still from a GPO like
perspective it was much better. We have to move off it as our agency
standardized on Centrify a couple years ago but can't I approved of it but
is what it is. Centrify does the job.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden