Quest has been named as an ASP "Ten Best Web Support Sites" award winner. Learn more.

Authentication Services 4.1 - Upgrade Guide

One Identity Privileged Access Suite for Unix Introducing One Identity Authentication Services What's New in Authentication Services 4.1 Upgrade from 3.5 to 4.1 Considerations Upgrade the Web Console Upgrade Authentication Services Windows Components Configure Active Directory for Authentication Services Configure Unix Agent Components Upgrade Authentication Services Client Components Manually Getting Started with Authentication Services Troubleshooting

One Identity Privileged Access Suite for Unix

One Identity Privileged Access Suite for Unix
Unix Security Simplified

Privileged Access Suite for Unix solves the inherent security and administration issues of Unix-based systems (including Linux® and Mac OS X®) while making satisfying compliance requirements a breeze. It unifies and consolidates identities, assigns individual accountability and enables centralized reporting for user and administrator access to Unix. The Privileged Access Suite for Unix is a one-stop shop for Unix security that combines an Active Directory bridge and root delegation solutions under a unified console that grants organizations centralized visibility and streamlined administration of identities and access rights across their entire Unix environment.

Active Directory Bridge

Achieve unified access control, authentication, authorization and identity administration for Unix, Linux®, and Mac OS X® systems by extending them into Active Directory (AD) and taking advantage of AD’s inherent benefits. Patented technology allows non-Windows® resources to become part of the AD trusted realm, and extends AD’s security, compliance and Kerberos-based authentication capabilities to Unix, Linux®, and Mac OS X®. (See https://www.quest.com/products/authentication-services/ for more information about the Active Directory Bridge product.)

Root Delegation

The Privileged Access Suite for Unix offers two different approaches to delegating the Unix root account. The suite either enhances or replaces sudo, depending on your needs.

  • By choosing to enhance sudo, you will keep everything you know and love about sudo while enhancing it with features like a central sudo policy server, centralized keystroke logs, a sudo event log, and compliance reports for who can do what with Sudo.

    (See https://www.quest.com/products/privilege-manager-for-sudo/ for more information about enhancing sudo.)

  • By choosing to replace sudo, you will still be able to delegate the Unix root privilege based on centralized policy reporting on access rights, but with a more granular permission and the ability to log keystrokes on all activities from the time a user logs in, not just the commands that are prefixed with "sudo". In addition, this option implements several additional security features like restricted shells, remote host command execution, and hardened binaries that remove the ability to escape out of commands and gain undetected elevated access.

    (See https://www.quest.com/products/privilege-manager-for-unix/ for more information about replacing sudo.)

Privileged Access Suite for Unix

Privileged Access Suite for Unix offers two editions - Standard edition and Advanced edition. Both editions include: Management Console for Unix®, a common mangement console that provides a consolidated view and centralized point of management for local Unix users and groups; and, Authentication Services, patented technology that enables organizations to extend the security and compliance of Active Directory to Unix, Linux®, and Mac OS X® platforms and enterprise applications. In addition

  • The Standard edition licenses you for Privilege Manager for Sudo.
  • The Advanced edition licenses you for Privilege Manager for Unix®.

Quest recommends that you follow these steps:

  1. Install Authentication Services on one machine, so you can set up your Active Directory Forest.
  2. Install Management Console for Unix®, so you can perform all the other installation steps from the mangement console.
  3. Add and profile host(s) using the mangement console.
  4. Configure the console to use Active Directory.
  5. Deploy client software to remote hosts.

    Depending on which Privileged Access Suite for Unix edition you have purchased, deploy either:

    • Privilege Manager for Unix® software (that is, Privilege Manager Agent packages)

      -OR-

    • Privilege Manager for Sudo software (that is, Sudo Plugin packages)

Was this topic helpful?

[Select Rating]



About This Guide

The Authentication Services Upgrade Guide is intended for Windows®, Unix*, Linux®, and Macintosh system administrators, network administrators, consultants, analysts, and any other IT professionals who will be upgrading Authentication Services to version 4.1 from any previous release. This guide walks you through one simple approach to upgrading Authentication Services, highlighting the changes and enhancements associated with installing and configuring Authentication Services using Management Console for Unix®.

Of course, you can upgrade and install Authentication Services without using Management Console for Unix®. You can find those instructions in the Authentication Services Installation Guide.

Note: Authentication Services versions 3.x and 4.x can both run in the same domain (on different machines).

These are the basic Authentication Services upgrade steps:

  1. Upgrade from 3.5 to 4.1 Considerations
  2. Installing and Configuring the Management Console
  3. Upgrade Authentication Services Windows Components
  4. Configure Active Directory for Authentication Services
  5. Configure Unix Agent Components

Note: The term "Unix" is used informally throughout the Authentication Services documentation to denote any operating system that closely resembles the trademarked system, UNIX®.


Was this topic helpful?

[Select Rating]



Introducing One Identity Authentication Services

Introducing Authentication Services

One Identity Authentication Services is patented technology that enables organizations to extend the security and compliance of Active Directory to Unix, Linux®, and Mac OS X® platforms and enterprise applications. It addresses the compliance need for cross-platform access control, the operational need for centralized authentication and single sign-on, and enables the unification of identities and directories for simplified identity and access management.


Was this topic helpful?

[Select Rating]



Upgrade Requirements

You can upgrade Authentication Services from any existing supported version of the product by installing Authentication Services on the computer where the old version was installed.

To upgrade Authentication Services, you must have local administrator rights to:

  • create a container and a child container in Active Directory
  • join a Unix host to the Active Directory domain

Note: Have your license available for the Setup wizard.


Was this topic helpful?

[Select Rating]



Self Service Tools
Knowledge Base
Product Support
Software Downloads
Technical Documentation
User Forums
Video Tutorials
Related Documents