Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-3084: What is the parameter to allow for blacklisting domains from trusts?

Authentication Service ,  

16 May,18 at 03:49 PM

Question:
What is the parameter to blacklist the domain(s) to be excluded from the trusts?

Answer:
Before Centrify DirectControl 5.1.2, 'adclient.ldap.trust.excluded.domains' is used to blacklist unwanted domains. 

  • Edit /etc/centrifydc/centrifydc.conf and add the following parameter to the bottom of the file
adclient.ldap.trust.excluded.domains: <domain> <domain>

Starting from Centrify DirectControl 5.1.2, new parameter 'adclient.excluded.domains' is introduced.

  • Edit /etc/centrifydc/centrifydc.conf and add the following parameter to the bottom of the file
adclient.excluded.domains<domain> <domain>


(https://www.centrify.com/downloads/products/documentation/suite2013/2013.3-release-notes/DirectControl-Release-Notes.html)

Please replace the <domain> with unwanted domain name and separate the names with white space. 

Please run the following commands as root to make the changes in configuration file effective:

# adreload
# adflush

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.