Installing and publishing the Web Interface extensions adds a number of pages and commands to theActive Roles Web Interface, enabling the management of Unix-specific information in Active Directory.
These pages and commands include:
To publish Web Interface extensions
-
Start the ActiveRoles Server Web Interface.
-
Start Google Chrome or Mozilla Firefox.
-
Navigate to the following URL:
http://<IP Address>/ARWebAdmin
-
At the login screen, enter your user name and password.
-
From the Customization menu on the main page of the ActiveRoles Server Web Interface, choose the Reload option.
NOTE: If you do not see the Customization link on the ActiveRoles Server Web Interface on Windows 2008 R2, run the browser with elevated privileges.
You can manage the Unix-specific information for a Windows user account in the Active Roles Web Interface.
To Unix-enable a user
-
On the home page of the ActiveRoles Server, click the Directory Management link.
-
In the Active Roles directory tree, navigate to Active Directory and select the Users folder under your managed domain.
-
In the details pane, click a user name link.
-
From the drop-down, select Unix Properties.
-
On the Unix Account tab, select the Unix Enabled option.
-
Modify any of the Unix-related properties.
The UID Number is the unique identifier for a Unix user. Ideally, each Windows user is assigned a unique UID number. By default the Integration Pack generates a unique ID automatically. If you change the User ID, the Integration Pack checks to ensure the specified value is unique among Unix-enabled users.
NOTE: The Primary Group box displays the Domain Name of the group corresponding to the Primary Group ID. You can click Change to browse Unix-enabled groups to find the Primary Group by name.
-
To commit your changes, click Save.
You can use ActiveRoles Server to Unix-disable users.
To Unix-disable a user
-
On the home page of ActiveRoles Server, click the Directory Management link.
-
In the Active Roles directory tree, navigate to Active Directory and select the Users folder under your managed domain.
-
In the details pane, click a user name link.
-
From the drop-down, select Unix Properties.
-
On the Unix Account tab, clear the Unix Enabled option.
-
To commit your changes, click Save.
Unix-disabling a user changes their login shell to bin/false.
After you Unix-disable a user, you may want to clear that user's Unix attributes.
To clear Unix attributes
-
Click the Directory Management link on the home page of ActiveRoles Server.
-
From the ActiveRoles Server directory tree, navigate to Active Directory and select the Users folder under your managed domain.
-
In the details pane, click a user name link.
-
From the drop-down menu, select Unix Properties.
-
Clear the text of each Unix-related property and click Save.
NOTE: When you click Save, if there is a Unix property in any of the fields, the Integration Pack makes no changes to the user's Unix properties.