Welcome | Sign In
LinuxInsider.com
Network Security

New Utility Enforces Policies Across Linux, Unix and Windows Networks

Print Version
E-Mail Article
Reprints
New Utility Enforces Policies Across Linux, Unix and Windows Networks

Symark's new PowerAdvantage utility allows system administrators to centralize their authentication, authorization and access management across Windows, Unix and Linux networks. It provides cross-platform unified log-in -- users can have a single log-in and password for all Unix, Linux and Windows machines. This eliminates the need to establish separate access credentials for each system.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Symark International on Tuesday released PowerADvantage, an integrated authentication and configuration tool that extends features of Microsoft (Nasdaq: MSFT) Windows' Active Directory to networks also running Unix and Linux systems.

PowerAdvantage adds centralized authentication, authorization and account access functionality to Unix and Linux systems. It's also designed to bolster policy enforcement and infrastructure management functionality in the two non-Windows operating systems.

Among the chief benefits of PowerADvantage are the reduction in administration costs and security improvement, according to Symark. The new software also helps system administrators meet regulatory compliance efforts by centrally managing user identifications, authentication, security policies and automatic deployment of configuration settings across heterogeneous Unix and Linux environments.

"Why introduce this product now? The enterprise world is now ready to trim costs and make their networks more secure. Compliance laws now make it imperative to deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with situations such as five different user names for each worker needing access to Windows, Unix and Linux systems on the network," Ellen Libenson, vice president of product marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales of Symark International, told LinuxInsider.

How It Works

PowerADvantage places an agent on Unix and Linux machines that communicates with Active Directory's domain controllers. During the installation of the PowerADvantage agent, the Unix or Linux host is joined to the domain.

Then the host is configured to route authentication requests through the PowerADvantage agent. This allows the PowerADvantage agent to communicate with the Active Directory domain controllers to process authentication requests and access the Group Policy Objects used for configuration management.

After installation, the computer object for each Unix and Linux host can be moved to different organizational units in the Active Directory hierarchy, changing which set of Group Policy Objects apply to that host. The PowerADvantage Context of each host can also be changed, which will immediately change the log-in configuration for all Active Directory-based users logging in to that host.

Both of these changes can be performed without rebooting the host or restarting the PowerADvantage agent. Additionally, the PowerADvantage agent is configured by Group Policy. Thus, any changes in the configuration of the agents can be performed through Group Policy without the need to visit each individual host.

"The context feature in PowerADvantage can map to each user environment that has different user names for each system," Jeff Nielsen, senior product manager of Symark International, told LinuxInsider.

Key Features

PowerADvantage provides cross-platform unified log-in -- users can have a single log-in and password for all Unix, Linux and Windows machines. This eliminates the need to establish separate access credentials for each system and in turn increases efficiency and boosts productivity for end users while reducing calls to the help desk related to misplaced passwords, Symark said.

Easy installation allows system administrators to deploy the product quickly without making any irreversible changes to the Active Directory schema. The agent installation process eliminates complex, time-consuming configuration changes. Additionally, PowerADvantage's intelligent import wizard streamlines and simplifies the importing and mapping of current Unix and Linux user information directly into Active Directory.

PowerADvantage provides corporate officials with detailed compliance reports. These help ensure that all activities performed on Unix and Linux systems are written to the proper Active Directory logs. It produces audit reports required by Sarbanes-Oxley, the Payment Card Industry Data Security Standard, and the Health Insurance Portability and Accountability Act, providing a comprehensive trail for auditors. This simplifies the compliance process and reduces overall audit costs, said Symark, and it allows for the more rapid discovery of anomalies as part of a sound security posture.

"An essential advantage is the ability to disable access of former employees from one spot to each account. Administrators don't have to worry about orphaned access," Nielson explained.

Reduced Overhead

Comprehensive centralized storage keeps all user and group information within Active Directory. This reduces infrastructure costs by eliminating redundant identity stores, including legacy directories, unsecured network information system servers and locally managed files. Storing information within Active Directory, along with integrated use of existing Windows administration tools, enables IT managers to utilize applications with familiar interfaces.

This eliminates the need to license third-party synchronization products or to build and maintain in-house solutions. Operations, training and processes for provisioning, account maintenance and other administrative tasks are streamlined by standardizing on a single set of Active Directory-based tools.

Standalone or Integrated

"PowerADvantage is a standalone product, but it can be added onto PowerBroker," said Nielson.

PowerBroker provides Unix and Linux workstations and networks with increased security and accountability by delegating administrative privileges and granting selective access to corporate resources without disclosing the root password. This reduces the risk of accidental damage and the threat of malicious activities.

This integration with Symark's PowerBroker enhances security and compliance efforts by facilitating efficient management of both end-user and administrator account access from Active Directory while controlling access and tasks performed using the root account, he said.

Using either custom-created administrative templates or those provided by PowerADvantage, administrators create configuration settings that are automatically stored in Active Directory. This facilitates the rapid automatic deployment and maintenance of configuration settings across a large number of hosts, reducing administrative time and cost.

These policies are reapplied to each host based on a predetermined interval. The feature insures that any unapproved changes to the configuration items maintained by PowerADvantage will be reset back to the approved settings at the next policy refresh interval.

PowerADvantage is available for both server and work station pricing, according to Libenson.

For server installations the product costs US$290 per server. For workstation installations the product costs $45 per station.


Print Version E-Mail Article Reprints More by Jack M. Germain


More by Jack M. Germain

Microsoft FOSSifies .Net Micro Framework
November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma
November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS
November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network