Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7431: How to prove that a UNIX user was authenticated by AD

Centrify DirectControl ,  

30 September,16 at 08:44 PM

Applies to:
All versions of Centrify DirectControl on all platforms

Question:
How to prove that a UNIX user was authenticated by AD?

Answer:
If we want to see adclient authenticate user with Active Directory's DC in action, then addebug is the only way. Turn '/usr/share/centrifydc/bin/addebug on', have AD login, then the log will show adclient authenticate with AD(Please refer this KB-0062  https://centrify.force.com/support/Article?id=ka080000000PiIE for more details on capturing debug logs).

To prove that that the users are coming from AD,we could get a cache dump then the section uid.idx/uname.idx will show user's AD dn. Cache dump can be obtained by root runs
/usr/share/centrifydc/bin/adcache -L -o /tmp/adcache.txt.



 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.