SlideShare ist ein Scribd-Unternehmen logo
1 von 10
Open Source in companies
Integration of an Active Directory
into check_mk
Purpose of the project
• Integrating IT employees into the
mentoring solution
• Integration based on existing
directory service (AD)
• Reduce the number of passwords
and logins that need to be
remembered
• The information must also be
available in case the directory
service fails
Quelle: CC by David el Nomo – http://www.fotopedia.com/items/flickr-3191470593
The environment
• For all users the attribute field mail has to have a value
• An Active Directory Domain with the name foo.bar
• All users objects are located at ou=Users,dc=foo,dc=bar
• All IT employees are member of the group cn=edv-
it,ou=Groups,dc=foo,dc=bar an
• An existing monitoring server based on check_mk (version 1.2.2 or newer)
• WATO is used to configure the Nagios or Icinga service
• The Contact group IT Abteilung contains all contacts to notify
Configuration for AD connection
• Enter in WATO the Global configuration section
• Open the sub-section User Management and choose
LDAP (Active Directory, OpenLDAP) connector
• Adjust the LDAP Connection Settings as follows:
LDAP Server directoryserver1.foo.bar
Directory Type Active Directory
Bind dn cn=ldapsearch_user,ou=Users,dc=f
oo,dc=bar
Bind Passwort $YOUR_SECRET_PASSWORD$
Configuration for AD connection
• The LDAP User Settings contain the following values
• The LDAP Group Settings contain these values
User Base DN ou=Users,dc=foo,dc=bar
Search Filter (&(objectclass=user)(objectcatego
ry=person)(memberOf=cn=edv-
it,ou=Groups,dc=foo,dc=bar))
Group Base DN ou=Groups,dc=foo,dc=bar
Search Filter (objectclass=group)
Implementation
• Through the Default User Profile the default values
for AD users are specified for example
• If all information are entered correctly, the AD users
can be seen in WATO in the section Users & Contacts.
For these users the connector type LDAP is set.
• Any changes to attributes or groups and roles are
saved separately by check_mk
User Roles Normal monitoring user
Contact groups IT Abteilung
Summary of configuration items
Overview of the configured items in check_mk
Exemplary imported users into check_mk
Be aware….!
• Users are imported into
check_mk.
• User attributes are checked for up-
to-dateness.
• To add a new user, the section
Users & Contacts in WATO need to
be called
• If employees leave the companies,
they must be manually removed
Quelle: CC by thethreesisters – http://www.flickr.com/photos/tripletsisters/7643953482/
Conclusion
• The integration into an existing
Active Directory simplifies the
administration significantly
• It avoids the double maintenance
of contacts, passwords and users
• Even if the AD fails, the
information of the users like mail
address are stored. Thus a well-
running of the system can be
ensured
Quelle: CC-BY-SA Bundesarchiv – http://commons.wikimedia.org/wiki/File:Bundesarchiv_Bild_183-48084-0031,_Leipzig,_Turn-
_und_Sporttreffen,_800m-Lauf,_Ziel.jpg

Weitere ähnliche Inhalte

Ähnlich wie Open source in companies - Active Directory integration into check mk

VRE Cancer Imaging BL RIC Workshop 22032011
VRE Cancer Imaging BL RIC Workshop 22032011VRE Cancer Imaging BL RIC Workshop 22032011
VRE Cancer Imaging BL RIC Workshop 22032011
djmichael156
 

Ähnlich wie Open source in companies - Active Directory integration into check mk (20)

Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
 
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
 
SetFocus Portfolio
SetFocus PortfolioSetFocus Portfolio
SetFocus Portfolio
 
Unit 4 The Design and Layout of LMS Management Plan
Unit 4 The Design and Layout of LMS Management Plan Unit 4 The Design and Layout of LMS Management Plan
Unit 4 The Design and Layout of LMS Management Plan
 
VRE Cancer Imaging BL RIC Workshop 22032011
VRE Cancer Imaging BL RIC Workshop 22032011VRE Cancer Imaging BL RIC Workshop 22032011
VRE Cancer Imaging BL RIC Workshop 22032011
 
Necto 16 training 17 - administration
Necto 16 training 17 -  administrationNecto 16 training 17 -  administration
Necto 16 training 17 - administration
 
ECS19 - Benjamin Niaulin - MOVED TO OFFICE 365, NOW WHAT?
ECS19 - Benjamin Niaulin - MOVED TO OFFICE 365, NOW WHAT?ECS19 - Benjamin Niaulin - MOVED TO OFFICE 365, NOW WHAT?
ECS19 - Benjamin Niaulin - MOVED TO OFFICE 365, NOW WHAT?
 
Architecting your Frontend
Architecting your FrontendArchitecting your Frontend
Architecting your Frontend
 
ADManager Plus Active Directory Management & Reporting
ADManager Plus Active Directory Management & ReportingADManager Plus Active Directory Management & Reporting
ADManager Plus Active Directory Management & Reporting
 
Southeast Michigan AUG - April 25 2018
Southeast Michigan AUG - April 25 2018Southeast Michigan AUG - April 25 2018
Southeast Michigan AUG - April 25 2018
 
Webinar: Deploy Microsoft Teams and stay in control
Webinar: Deploy Microsoft Teams and stay in controlWebinar: Deploy Microsoft Teams and stay in control
Webinar: Deploy Microsoft Teams and stay in control
 
Centralizing users’ authentication at Active Directory level 
Centralizing users’ authentication at Active Directory level Centralizing users’ authentication at Active Directory level 
Centralizing users’ authentication at Active Directory level 
 
Office365 groups from the ground up - SPTechCon Boston
Office365 groups from the ground up - SPTechCon BostonOffice365 groups from the ground up - SPTechCon Boston
Office365 groups from the ground up - SPTechCon Boston
 
Windows Server 2012 Managing Active Directory Domain
Windows Server 2012 Managing  Active Directory DomainWindows Server 2012 Managing  Active Directory Domain
Windows Server 2012 Managing Active Directory Domain
 
Library Management System
Library Management SystemLibrary Management System
Library Management System
 
24 - Panorama Necto 14 administration - visualization & data discovery solution
24  - Panorama Necto 14 administration - visualization & data discovery solution24  - Panorama Necto 14 administration - visualization & data discovery solution
24 - Panorama Necto 14 administration - visualization & data discovery solution
 
Software Design Document
Software Design DocumentSoftware Design Document
Software Design Document
 
Partitioning IBM Connections Cloud Administration
Partitioning IBM Connections Cloud AdministrationPartitioning IBM Connections Cloud Administration
Partitioning IBM Connections Cloud Administration
 
Corporate-informatica-training-in-mumbai
Corporate-informatica-training-in-mumbaiCorporate-informatica-training-in-mumbai
Corporate-informatica-training-in-mumbai
 
Corporate-informatica-training-in-mumbai
Corporate-informatica-training-in-mumbaiCorporate-informatica-training-in-mumbai
Corporate-informatica-training-in-mumbai
 

Kürzlich hochgeladen

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Kürzlich hochgeladen (20)

Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 

Open source in companies - Active Directory integration into check mk

  • 1. Open Source in companies Integration of an Active Directory into check_mk
  • 2. Purpose of the project • Integrating IT employees into the mentoring solution • Integration based on existing directory service (AD) • Reduce the number of passwords and logins that need to be remembered • The information must also be available in case the directory service fails Quelle: CC by David el Nomo – http://www.fotopedia.com/items/flickr-3191470593
  • 3. The environment • For all users the attribute field mail has to have a value • An Active Directory Domain with the name foo.bar • All users objects are located at ou=Users,dc=foo,dc=bar • All IT employees are member of the group cn=edv- it,ou=Groups,dc=foo,dc=bar an • An existing monitoring server based on check_mk (version 1.2.2 or newer) • WATO is used to configure the Nagios or Icinga service • The Contact group IT Abteilung contains all contacts to notify
  • 4. Configuration for AD connection • Enter in WATO the Global configuration section • Open the sub-section User Management and choose LDAP (Active Directory, OpenLDAP) connector • Adjust the LDAP Connection Settings as follows: LDAP Server directoryserver1.foo.bar Directory Type Active Directory Bind dn cn=ldapsearch_user,ou=Users,dc=f oo,dc=bar Bind Passwort $YOUR_SECRET_PASSWORD$
  • 5. Configuration for AD connection • The LDAP User Settings contain the following values • The LDAP Group Settings contain these values User Base DN ou=Users,dc=foo,dc=bar Search Filter (&(objectclass=user)(objectcatego ry=person)(memberOf=cn=edv- it,ou=Groups,dc=foo,dc=bar)) Group Base DN ou=Groups,dc=foo,dc=bar Search Filter (objectclass=group)
  • 6. Implementation • Through the Default User Profile the default values for AD users are specified for example • If all information are entered correctly, the AD users can be seen in WATO in the section Users & Contacts. For these users the connector type LDAP is set. • Any changes to attributes or groups and roles are saved separately by check_mk User Roles Normal monitoring user Contact groups IT Abteilung
  • 7. Summary of configuration items Overview of the configured items in check_mk
  • 8. Exemplary imported users into check_mk
  • 9. Be aware….! • Users are imported into check_mk. • User attributes are checked for up- to-dateness. • To add a new user, the section Users & Contacts in WATO need to be called • If employees leave the companies, they must be manually removed Quelle: CC by thethreesisters – http://www.flickr.com/photos/tripletsisters/7643953482/
  • 10. Conclusion • The integration into an existing Active Directory simplifies the administration significantly • It avoids the double maintenance of contacts, passwords and users • Even if the AD fails, the information of the users like mail address are stored. Thus a well- running of the system can be ensured Quelle: CC-BY-SA Bundesarchiv – http://commons.wikimedia.org/wiki/File:Bundesarchiv_Bild_183-48084-0031,_Leipzig,_Turn- _und_Sporttreffen,_800m-Lauf,_Ziel.jpg