Manage Linux Endpoints Using Remote Inspection

You can inspect Linux endpoints using Remote Inspection with Active Directory (AD) domain accounts through AD password, Kerberos, or SSH key authentication.

Use Active Directory (AD) for Remote Inspection

Connect a Linux endpoint to an Active Directory (AD) domain to log in and use AD features. Linux endpoints connect using built-in system tools. AD users can log in after connection.

Note: Each AD user must have a local home directory.

To connect an endpoint to an Active Directory domain:

  1. Connect the domain

    Run: sudo realm join

    Enter AD administrator credentials when prompted.

  2. Verify the connection

    Run:realm list

    id [email protected]

  3. Turn on automatic home directories

    Run: sudo pam-auth-update --enable mkhomedir

Configure the password source for Active Directory domain credentials

When you add or edit an Active Directory domain credential for Remote Inspection, Password source determines where the domain password is stored.

Configure the password source

  1. In the Linux plugin configuration, select the Remote Inspection tab.
  2. Under Active Directory Domain Credentials, do one of the following:
    • Select Add to create a new credential.
    • Select an existing credential, and then select Edit.
  3. In Password source, select one of the following options:
    • Local: Enter the password in Domain Password and Retype Domain Password.
    • CyberArk: Retrieve the password from a CyberArk vault. The Domain Password fields are unavailable. Select ... to configure a CyberArk query.
  4. Select OK.

Configure the password source for the 'run as root' password

When you configure Password to 'run as root' on the Advanced tab, Password source determines where the password is stored.

Configure the password source

  1. In the Linux plugin configuration, select the Advanced tab.
  2. Under Password to 'run as root', in Password source, select one of the following options:
    • Local: Enter the password in Password for sudo access and Retype Password for sudo access.
    • CyberArk: Retrieve the password from a CyberArk vault. The password fields are unavailable. Select ... to configure a CyberArk query.
  3. Select Apply.

Configure a CyberArk query

When Password source is set to CyberArk, select ... to open the CyberArk Query dialog.

Choose a query method

Select one of the following methods:

Query fields

Specify one or more fields to identify the credential:

  • Safe
  • Username
  • Address
  • Platform (Policy ID)
  • Folder
  • Object name

Custom query

Enter a custom query string to retrieve the credential.

Verify the query

  1. Select Test to verify that the query retrieves the credential successfully.
  2. Select OK.

Use SSH Key Authentication with Remote Inspection

SSH remote access requires distribution of the Appliance public key to managed endpoints when you use SSH key authentication.

For information about setting up SSH key authentication, see Distribute the Public Key.

When Not Using Remote Inspection

If you do not use Remote Inspection to manage Linux endpoints, clear the Remote Inspection option when you configure the plugin. This avoids unnecessary network overhead from establishing unused SSH connections.

When Remote Inspection is not used, you can use SecureConnector to manage devices. See Manage Endpoints Using SecureConnector for information about SecureConnector setup.

Note: Remote inspection detects when a system is ready for commands by matching the command prompt. If commands fail after connection, verify that the configured prompt pattern matches the endpoint prompt. See Prompt Patternfor configuration details.
Define a Remote Inspection User on Linux Endpoints

Define an admin-level user on each endpoint that you want to manage. This user should have the name you entered in the User field of the Remote Inspection tab during plugin configuration.