{"id":765,"date":"2017-08-22T02:45:19","date_gmt":"2017-08-21T19:45:19","guid":{"rendered":"https:\/\/trichev.com\/blog\/?p=765"},"modified":"2017-08-22T02:47:51","modified_gmt":"2017-08-21T19:47:51","slug":"powerbroker-identity-services-open","status":"publish","type":"post","link":"https:\/\/trichev.com\/blog\/2017\/08\/22\/powerbroker-identity-services-open\/","title":{"rendered":"PowerBroker Identity Services Open"},"content":{"rendered":"<p>Download link: <a href=\"https:\/\/github.com\/BeyondTrust\/pbis-open\/releases\">https:\/\/github.com\/BeyondTrust\/pbis-open\/releases<\/a><\/p>\n<p><strong>PBIS AD membership, basic setup for Linux (RPM)<\/strong><\/p>\n<p>#UnattendedMode<br \/>\n<code>.\/pbis-open-8.5.4.334.linux.x86_64.rpm.sh install<\/code><\/p>\n<p><code>\/opt\/pbis\/bin\/domainjoin-cli join --assumeDefaultDomain yes your.domain.com yourname <\/code><\/p>\n<p><code># cat &lt; \/etc\/pbis.conf<br \/>\nrem AD domain: YOUR<br \/>\nAssumeDefaultDomain true<br \/>\nHomeDirTemplate \"%H\/%D\/%U\"<br \/>\nLoginShellTemplate \"\/bin\/bash\"<br \/>\nRemoteHomeDirTemplate \"\"<br \/>\nCacheEntryExpiry \"00000060\"<br \/>\nEOT<\/code><\/p>\n<p><code>\/opt\/pbis\/bin\/config --file \/etc\/pbis.conf<\/code><\/p>\n<p><code>\/opt\/pbis\/bin\/update-dns<\/code><\/p>\n<p><strong>Login\/Server Access Rights<\/strong><\/p>\n<p>In the \/etc\/pbis.conf file, before HomeDirTemplate, add or modify a new line beginning &#8216;RequireMembershipOf&#8217;. RequireMembershipOf specifies a comma separated list of AD groups &#8211; To login to the system the user must belong to one of the listed groups eg:<br \/>\n<code>RequireMembershipOf \"your\\\\group1\" \"your\\\\group2\"<\/code><\/p>\n<p>To apply a new configuration, you need to run \/opt\/pbis\/bin\/config &#8211;file \/etc\/pbis.conf manually.<\/p>\n<p><strong>SUDO Rights<\/strong><\/p>\n<p>Use the visudo command, and add the name of the AD group, prefixed with % using standard sudoers syntax: eg:<br \/>\n<code>%group1     ALL=(ALL)       ALL<\/code><\/p>\n<p><strong>PBIS Utilities<\/strong><\/p>\n<p>A number of useful scripts are available in the \/opt\/pbis\/bin directory. Most of these scripts are self documenting and support eg, the &#8211;help argument.<br \/>\n\/opt\/pbis\/bin\/get-status ; show ad connection\/status information<br \/>\n\/opt\/pbis\/bin\/find-user-by-name ; lookup an ad user by name.<br \/>\n\/opt\/pbis\/bin\/find-group-by-name ; lookup an ad group by name.<br \/>\n\/opt\/pbis\/bin\/list-groups-for-user [&#8211;level=2] ; show group membership for a user.<\/p>\n<p>There are lots of useful scripts in this directory, it&#8217;s worth exploring.<\/p>\n<p><strong>Delegate rights using Active Directory Users and Computers for PBIS computer join user<\/strong><\/p>\n<p>This process allows a specific user\/group to manage a group, or a section of the AD tree.<br \/>\n1.Open the Active Directory Users and Computers snap-in.<br \/>\n2.Right-click the container under which you want the computers added, and press Delegate Control.<br \/>\n3.Press Next.<br \/>\n4.Press Add.<br \/>\n5.After adding all the users and\/or groups, press Next.<br \/>\n6.Select Create custom task to delegate and press Next.<br \/>\n7.Select Only the following objects in the folder, check Computer objects, check the &#8220;Create selected objects in this folder&#8221;, &#8220;Create selected objects in this folder&#8221; boxes, and press Next.<br \/>\n8.Check the &#8220;Create all child object&#8221;, &#8220;Delete all child object&#8221; boxes and press Next.<br \/>\n9.Press Finish.<\/p>\n<p><strong>ISSUES<\/strong><\/p>\n<p>If pbis just stopped working and you get &#8220;Error: ERROR_FILE_NOT_FOUND code 0x00000002&#8221; after &#8220;service lwsmd restart&#8221;, remove it completely:<br \/>\n<code>\/opt\/pbis\/bin\/domainjoin-cli leave<br \/>\n\/opt\/pbis\/bin\/uninstall.sh uninstall<\/code><\/p>\n<p>and reinstall\/reconfigure<\/p>\n<p><code>pbis-open-8.5.4.334.linux.x86_64.rpm.sh install \/opt\/pbis\/bin\/domainjoin-cli join --assumeDefaultDomain yes your.domain.com yourname<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Download link: https:\/\/github.com\/BeyondTrust\/pbis-open\/releases PBIS AD membership, basic setup for Linux (RPM) #UnattendedMode .\/pbis-open-8.5.4.334.linux.x86_64.rpm.sh install \/opt\/pbis\/bin\/domainjoin-cli join &#8211;assumeDefaultDomain yes your.domain.com yourname # cat &lt; \/etc\/pbis.conf rem AD domain: YOUR AssumeDefaultDomain true HomeDirTemplate &#8220;%H\/%D\/%U&#8221; LoginShellTemplate &#8220;\/bin\/bash&#8221; RemoteHomeDirTemplate &#8220;&#8221; CacheEntryExpiry &#8220;00000060&#8221; EOT \/opt\/pbis\/bin\/config &#8211;file \/etc\/pbis.conf \/opt\/pbis\/bin\/update-dns Login\/Server Access Rights In the \/etc\/pbis.conf file, before HomeDirTemplate, add or modify [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[231],"tags":[32,240,241,14,11],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/posts\/765"}],"collection":[{"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/comments?post=765"}],"version-history":[{"count":4,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/posts\/765\/revisions"}],"predecessor-version":[{"id":769,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/posts\/765\/revisions\/769"}],"wp:attachment":[{"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/media?parent=765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/categories?post=765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trichev.com\/blog\/wp-json\/wp\/v2\/tags?post=765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}