KB-1833: How to integrate 'Exceed on Demand' with DirectControl / PAM?

Centrify DirectAudit ,   Centrify DirectControl ,   Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:02 AM

Applies to: All versions of Centrify DirectControl on Linux/Solaris platforms

How to integrate 'Exceed on Demand' with DirectControl / PAM?

1. Logon as root on the Linux/Solaris host which installed Exceed onDemand Server

2. For Linux, run: cp /etc/pam.d/login /etc/pam.d/exceedondemand

3. For Solaris, edit /etc/pam.conf and add the following entries into the file:

exceedondemand      auth sufficient unix_cred
exceedondemand      auth requisite deny
exceedondemand      auth requisite
exceedondemand      auth required
exceedondemand      auth required
exceedondemand      auth required
exceedondemand      auth required

4. Edit the file /[EoDHomeDir]/conf/admin/cluster.cfg, where [EoDHomeDir] is the home directory of Exceed onDemand that you specified at installation. Then, change EoDCMAuth=native to EoDCMAuth=pam

5. Stop the EoD service by running: /[EoDHomeDir]/bin/eodstop

6. Start the EoD service by running: /[EoDHomeDir]/bin/eodstart

On the later version of Exceed on Demand (32 bit), you'd need to

cp /etc/pamd.d/login to /etc/pam.d/exceed-connection-server

and at the top of the file under the "auth include system-auth" entry add the following line:


Note:  It's critical that you update your connection Manager and clients with latest patches as below:

getversions - Exceed Connection Server 13.7
esessionmgr    Version, Revision 20262
ewebhost          Version, Revision 20240
authenticator    Version, Revision 20256
cli                        Version, Revision 17532
keymgr              Version, Revision 15473
elpr                    Version, Revision 19217

