Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-7431: How to prove that a UNIX user was authenticated by AD

Authentication Service ,  

30 September,16 at 08:44 PM

Applies to:
All versions of Centrify DirectControl on all platforms

How to prove that a UNIX user was authenticated by AD?

If we want to see adclient authenticate user with Active Directory's DC in action, then addebug is the only way. Turn '/usr/share/centrifydc/bin/addebug on', have AD login, then the log will show adclient authenticate with AD(Please refer this KB-0062 for more details on capturing debug logs).

To prove that that the users are coming from AD,we could get a cache dump then the section uid.idx/uname.idx will show user's AD dn. Cache dump can be obtained by root runs
/usr/share/centrifydc/bin/adcache -L -o /tmp/adcache.txt.