Manage Linux Endpoints Using Remote Inspection
You can inspect Linux endpoints using Remote Inspection with Active Directory (AD) domain accounts through AD password, Kerberos, or SSH key authentication.
Use Active Directory (AD) for Remote Inspection
Connect a Linux endpoint to an Active Directory (AD) domain to log in and use AD features. Linux endpoints connect using built-in system tools. AD users can log in after connection.
To connect an endpoint to an Active Directory domain:
- Connect the domain
Run:
sudo realm joinEnter AD administrator credentials when prompted.
- Verify the connection
Run:
realm list -
Turn on automatic home directories
Run:
sudo pam-auth-update --enable mkhomedir
Configure the password source for Active Directory domain credentials
When you add or edit an Active Directory domain credential for Remote Inspection, Password source determines where the domain password is stored.
Configure the password source
- In the Linux plugin configuration, select the Remote Inspection tab.
- Under Active Directory Domain Credentials, do one of the following:
- Select Add to create a new credential.
- Select an existing credential, and then select Edit.
- In Password source, select one of the following options:
- Local: Enter the password in Domain Password and Retype Domain Password.
- CyberArk: Retrieve the password from a CyberArk vault. The Domain Password fields are unavailable. Select ... to configure a CyberArk query.
- Select OK.
Configure the password source for the 'run as root' password
When you configure Password to 'run as root' on the Advanced tab, Password source determines where the password is stored.
Configure the password source
- In the Linux plugin configuration, select the Advanced tab.
- Under Password to 'run as root', in Password source, select one of the following options:
- Local: Enter the password in Password for sudo access and Retype Password for sudo access.
- CyberArk: Retrieve the password from a CyberArk vault. The password fields are unavailable. Select ... to configure a CyberArk query.
- Select Apply.
Configure a CyberArk query
When Password source is set to CyberArk, select ... to open the CyberArk Query dialog.
Choose a query method
Select one of the following methods:
Query fields
Specify one or more fields to identify the credential:
- Safe
- Username
- Address
- Platform (Policy ID)
- Folder
- Object name
Custom query
Enter a custom query string to retrieve the credential.
Verify the query
- Select Test to verify that the query retrieves the credential successfully.
- Select OK.
Use SSH Key Authentication with Remote Inspection
SSH remote access requires distribution of the Appliance public key to managed endpoints when you use SSH key authentication.
For information about setting up SSH key authentication, see Distribute the Public Key.
When Not Using Remote Inspection
If you do not use Remote Inspection to manage Linux endpoints, clear the Remote Inspection option when you configure the plugin. This avoids unnecessary network overhead from establishing unused SSH connections.
When Remote Inspection is not used, you can use SecureConnector to manage devices. See Manage Endpoints Using SecureConnector for information about SecureConnector setup.
Define an admin-level user on each endpoint that you want to manage. This user should have the name you entered in the
minute read