TOM KEMP'S CENTRIFY BLOG

What's New in DirectControl 4, Part 3: Further Extending Active Directory to non-Microsoft Platforms

Monday, November 26, 2007

This is the third and final installment of a set blog posts on some of the major new features of DirectControl 4, which shipped in early November. In prior postings I discussed new functionality such as our new web console as well as enhancements to our Group Policy support and compliance reporting. In this post I am going to highlight some of the enhancements we have made in the areas of extending Active Directory to additional non-Microsoft systems and applications, as well as discuss our new LDAP Proxy feature in DirectControl and improvements we have made to DirectControl's NIS support. As a reminder, you can view a webinar on all the new features added to DirectControl 4 — just click here to register and watch.

New Platform Support in DirectControl 4

Centrify DirectControl offers the industry's broadest set of Active Directory integration solutions for non-Microsoft systems, web applications, databases and storage systems. With DirectControl 4, Centrify enables organizations to further extend their Active Directory infrastructure with expanded operating system support, bringing the total to over 110 (well more than any other solution in the market), including:

  • Citrix XenServer 4.0.1 Express, Standard and Enterprise editions
  • Red Hat Enterprise Linux 4 on PPC & Itanium 64
  • HP-UX 11.31 PA-RISC 32- and 64-bit, including Trusted Mode (aka 11i v3)
  • HP-UX 11.31 Itanium 32- and 64-bit, including Trusted Mode (aka 11i v3)
  • Oracle Enterprise Linux 5, 32- and 64-bit
  • VMware ESX Server 3.0.2

I am particularly pleased with our support for XenServer - much like the case of Centrify being the first vendor to deliver a solution that can integrate VMware's ESX Server into Active Directory, Centrify is now the first (and only) vendor to integrate Citrix's XenServer platform into Active Directory. What is the significance of this to customers deploying XenServer?

  • Using DirectControl, XenServer administrators can now seamlessly leverage Microsoft Active Directory to centrally control access to their XenServer deployment and use DirectControl's cross-platform extensions to Microsoft Group Policy to globally manage key security and configuration settings on those servers. In other words, by consolidating user authentication, access control and policy configuration management for Citrix XenServer in Active Directory, Centrify DirectControl lets organizations easily add Citrix XenServers into their Microsoft infrastructure without increasing administrative overhead or introducing additional identity repositories.
  • DirectControl customers can implement a common security model across the XenServer virtualization platform as well as Windows and Linux guests running on top of the underlying virtualization platform.

In other words, with DirectControl, no matter what the underlying virtualization platform is (VMware or XenServer) and what guest OSes (Windows, Linux, Solaris x86, etc.) are running on top of those virtual platforms, this "grid" can all work against the same identity and policy directory. This is true even if you run VMware's Fusion for the Mac given DirectControl's robust Mac support. Powerful stuff.

I should also point out that DirectControl 4 now also fully supports Linux distributions running SE Linux, including Red Hat Enterprise Linux 4 onward, Fedora 3 onward, CentOS 4 onward, Scientific Linux 4 onward, and Oracle Linux 4 onward. It also supports AppArmor for SUSE Linux Enterprise 10 and openSuSE 10.1 onward. This is important because, unlike other identity management solutions, DirectControl 4 does not require these Security Enhanced capabilities of the Linux system to be disabled.

New LDAP Proxy and NIS Server Enhancements in DirectControl 4

With the release of DirectControl 4, the DirectControl NIS Server now supports existing NIS clients without any client modification, enabling full replacement of existing NIS servers with a secure, centralized Active Directory-integrated solution. The NIS Server can be used to support Active Directory user authentication to the NIS client systems in order to support legacy systems for which there is no DirectControl Agent or as part of a phased migration plan.

Finally, in order to support the secure integration of a large number of LDAP-aware applications into Active Directory, DirectControl 4 delivers a new LDAP Proxy. Those applications can now communicate to the LDAP Proxy in order to access Active Directory data over an encrypted and mutually authenticated connection without having to change either the application or the Active Directory security policies.

Bottom Line: Industry's Most Comprehensive Solution for Extending Active Directory

As you can see, DirectControl 4 extends Centrify's industry-leading support for UNIX, Linux, VMware and Mac OS X by adding over 10 new platform versions - including unique support for the Citrix XenServer product family and Security-Enhanced Linux variants such as SELinux from Red Hat and AppArmor from Novell - to bring the total number of UNIX platforms secured under the Active Directory umbrella by DirectControl to over 110. DirectControl 4 also offers a new LDAP Proxy that enables LDAP-aware applications to securely communicate with Active Directory. In addition, the DirectControl NIS Server now supports existing NIS clients without any client modification, enabling full replacement of existing NIS servers with a secure, centralized Active Directory-integrated solution. Check out the DirectControl 4 webinar today for more details or request an evaluation to give it a test drive.

Bookmarks: del.icio.usDiggFurlNetscapeYahoo! My WebStumbleUponGoogle BookmarksTechnoratiBlinkListNewsvinema.gnoliaRedditWindows LiveTailrank

< Previous Article: What's New in DirectControl 4, Part 2: Enhanced Cross-Platform Group Policy and Compliance Reporting
> Next Article: Performing a NIS Migration the Centrify and Active Directory Way