<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Dirk Frehse - IT Professional Blog : Identity &amp;amp; Acess Management</title><link>http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx</link><description>Tags: Identity &amp;amp; Acess Management</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Microsoft e Trusted Computing Group promovem interoperabilidade de controle de acesso de rede (NAC)</title><link>http://blogs.technet.com/dirk_frehse/archive/2007/05/22/microsoft-e-trusted-computing-group-promovem-interoperabilidade-de-controle-de-acesso-de-rede-nac.aspx</link><pubDate>Tue, 22 May 2007 19:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1021298</guid><dc:creator>dirkfr</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/dirk_frehse/comments/1021298.aspx</comments><wfw:commentRss>http://blogs.technet.com/dirk_frehse/commentrss.aspx?PostID=1021298</wfw:commentRss><description>&lt;P&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;O Trusted Computing Group (TCG) anunciou durante a feria de Interop em Las Vegas que estará&amp;nbsp;anunciando uma nova especificação do&amp;nbsp;seu padrão de software de autenticação&amp;nbsp;para que soluções concebidas usando essa especificação possam ser&amp;nbsp;integradas diretamente com&amp;nbsp;a plataforma de proteção de acesso de rede (NAP) da Microsoft. Esse movimento é visto por&amp;nbsp;líderes do segmento de controle de acesso de rede (NAC)&amp;nbsp;como um importante&amp;nbsp;passo na direção de ter produtos de diferentes fornecedores trabalhando juntos.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;Os produtos de NAC, incluindo o Network Access Protection (NAP)&amp;nbsp;da Microsoft, são usados para identificar e autenticar dispositivos que tentam conectar-se à redes e garantir que&amp;nbsp;os mesmos tenham permissão de acesso somente depois de passar por uma série de verificações de saúde de segurança.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;Para maiores informações veja o artigo: &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://www.infoworld.com/article/07/05/21/Microsoft-TCG-closer-on-NAC_1.html"&gt;&lt;SPAN lang=PT-BR style="mso-ansi-language: PT-BR"&gt;http://www.infoworld.com/article/07/05/21/Microsoft-TCG-closer-on-NAC_1.html&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1021298" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx">Identity &amp;amp; Acess Management</category><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Interoperabilidade/default.aspx">Interoperabilidade</category></item><item><title>Oprotunidade de Treinamento em Interoperabilidade Online</title><link>http://blogs.technet.com/dirk_frehse/archive/2007/05/14/oprotunidade-de-treinamento-em-interoperabilidade-online.aspx</link><pubDate>Mon, 14 May 2007 17:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:961422</guid><dc:creator>dirkfr</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/dirk_frehse/comments/961422.aspx</comments><wfw:commentRss>http://blogs.technet.com/dirk_frehse/commentrss.aspx?PostID=961422</wfw:commentRss><description>&lt;P&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;A TechX World Online está oferecendo gratuitamente uma oportunidade de treinamento online sobre as melhores formas de&amp;nbsp;interoperar ambientes Windows e Linux. Para maiores informações visite o site: &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://events.unisfair.com/index.jsp?eid=162&amp;amp;seid=230"&gt;&lt;SPAN lang=PT-BR style="mso-ansi-language: PT-BR"&gt;http://events.unisfair.com/index.jsp?eid=162&amp;amp;seid=230&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR"&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Bom treinamento.&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=961422" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx">Identity &amp;amp; Acess Management</category><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Interoperabilidade/default.aspx">Interoperabilidade</category></item><item><title>Frutos do Acordo Tecnologico entre Microsoft e Novell</title><link>http://blogs.technet.com/dirk_frehse/archive/2007/03/26/frutos-do-acordo-tecnologico-entre-microsoft-e-novell.aspx</link><pubDate>Mon, 26 Mar 2007 17:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:708424</guid><dc:creator>dirkfr</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/dirk_frehse/comments/708424.aspx</comments><wfw:commentRss>http://blogs.technet.com/dirk_frehse/commentrss.aspx?PostID=708424</wfw:commentRss><description>&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;Após o anúncio do acordo, os frutos desta parceria&amp;nbsp;começam a ser mostrados.&amp;nbsp;Recentemente, durante a conferencia BrainShare da Novell,&amp;nbsp;foram demonstrados:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;Máquinas virtuais de Windows executando em sistemas operacionais SUSE e Microsoft Windows Server codinome Longhorn executando máquinas virtuais de SUSE Linux.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;Interoperabilidade do Active Directory e transferência de arquivos entre SUSE e&amp;nbsp;Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;Conversor de OpenXML que permite&amp;nbsp;salvar&amp;nbsp;documentos do OpenOffice no formato OpenXML&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: PT-BR; mso-fareast-font-family: 'Times New Roman'"&gt;Para maiores informações acesso site &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;SPAN lang=PT-BR style="COLOR: blue; mso-ansi-language: PT-BR; mso-bidi-font-size: 11.0pt"&gt;&lt;SPAN lang=PT-BR style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: PT-BR; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;&lt;FONT color=#000000&gt;&lt;A class="" href="http://www.linuxworld.com/news/2007/031907-brainshare-novell-microsoft.html?page=1" mce_href="http://www.linuxworld.com/news/2007/031907-brainshare-novell-microsoft.html?page=1"&gt;http://www.linuxworld.com/news/2007/031907-brainshare-novell-microsoft.html?page=1&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=708424" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx">Identity &amp;amp; Acess Management</category><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Interoperabilidade/default.aspx">Interoperabilidade</category></item><item><title>Soluções de Terceiros para Integração Unix/Linux com Active Directory</title><link>http://blogs.technet.com/dirk_frehse/archive/2006/04/18/solu-es-de-terceiros-para-integra-o-unix-linux-com-active-directory.aspx</link><pubDate>Wed, 19 Apr 2006 02:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:425593</guid><dc:creator>dirkfr</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/dirk_frehse/comments/425593.aspx</comments><wfw:commentRss>http://blogs.technet.com/dirk_frehse/commentrss.aspx?PostID=425593</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;No último artigo foi mostrado como é possível fornecer o &lt;I style="mso-bidi-font-style: normal"&gt;logon&lt;/I&gt; único usando o serviço de diretórios Active Directory em ambiente baseados em servidores e estações UNIX/Linux e Windows. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Embora relativamente simples, o processo descrito é 100% manual. Isto exige alguns cuidados, especialmente na hora da seleção dos componentes Kerberos e LDAP para o ambiente UNIX/Linux, pois suas respectivas implementações variam e podem resultar em falta de desempenho no processo de &lt;I style="mso-bidi-font-style: normal"&gt;logon &lt;/I&gt;ou simplesmente não oferecer o &lt;I style="mso-bidi-font-style: normal"&gt;logon&lt;/I&gt; quando a máquina não estiver conectada à rede (Ex.: Notebook). &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Numa recente conversa com profissionais de TI sobre este assunto, fui questionado sobre alternativas ao processo manual e que diminuíssem o tempo de implantação de tal integração.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Atualmente existem duas empresas no mercado que fornecem este tipo de solução. As soluções são:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Vintela Autentication Services (VAS) da Quest Software. Para maiores informações visite o endereço &lt;A href="http://www.vintela.com/" mce_href="http://www.vintela.com/"&gt;&lt;FONT color=#ffa500&gt;http://www.vintela.com&lt;/FONT&gt;&lt;/A&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;DirectControl da Centrify. Para maiores informações visite o endereço &lt;A href="http://www.centrify.com/" mce_href="http://www.centrify.com/"&gt;&lt;FONT color=#ffa500&gt;http://www.centrify.com&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=425593" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx">Identity &amp;amp; Acess Management</category><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Interoperabilidade/default.aspx">Interoperabilidade</category></item><item><title>Integrando Autenticação e Autorização entre UNIX/Linux e Windows Server</title><link>http://blogs.technet.com/dirk_frehse/archive/2006/04/07/integrando-autentica-o-e-autoriza-o-entre-unix-linux-e-windows-server.aspx</link><pubDate>Sat, 08 Apr 2006 01:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:424687</guid><dc:creator>dirkfr</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/dirk_frehse/comments/424687.aspx</comments><wfw:commentRss>http://blogs.technet.com/dirk_frehse/commentrss.aspx?PostID=424687</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;É comum empresas utilizarem várias plataformas operacionais para suportar seus sistemas de informação. Esse fato decorre da natural evolução dos sistemas informação que, para atender as crescentes necessidade de negócio ou incorporar novas tecnologias, acabam gerando essa heterogeneidade.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Essa heterogeneidade possui um impacto direto sobre a segurança dos sistemas, pois os processos de autenticação&lt;SUP&gt;&lt;FONT color=#ff0000&gt;2&lt;/FONT&gt;&lt;/SUP&gt; e autorização&lt;SUP&gt;&lt;FONT color=#ff0000&gt;3&lt;/FONT&gt;&lt;/SUP&gt; variam entre as diversas plataformas.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Um dos vários desafios contemporâneos dos profissionais de TI é de buscar uma centralização do gerenciamento de identidades e uniformizar os protocolos de autenticação e autorização, promovendo assim o &lt;I style="mso-bidi-font-style: normal"&gt;logon&lt;/I&gt; único dos agentes&lt;SUP&gt;&lt;FONT color=#ff0000&gt;1&lt;/FONT&gt;&lt;/SUP&gt;. As motivações para isso são:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l3 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Uma única credencial para autenticação e autorização de usuários do sistema de informação.&lt;/SPAN&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l3 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Simplicidade no monitoramento e auditoria do acesso a dados sensíveis.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l3 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Conformidade com legislações que visam privacidade e confidencialidade das informações.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l3 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Uma complexa infra-estrutura para gerenciamento de identidade é difícil de expandir para novos processos de negócio e resulta em custos operacionais elevados.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Antes de descrevermos como integrar a autenticação e autorização entre UNIX/Linux e Windows, vamos apresentar alguns conceitos importantes:&lt;/SPAN&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level1 lfo4; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ffa500&gt;Agente&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ff0000&gt;1&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt; é um participante individualmente identificado numa interação. Nos sistemas de informação os agentes mais comuns são: usuário, máquina ou serviço.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level1 lfo4; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ffa500&gt;Autenticação&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ff0000&gt;2&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt; é o processo de provar que um agente é realmente a entidade que alega ser. Os mecanismos típicos são:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;UL&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level2 lfo4; tab-stops: list 1.0in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Usuário e senha&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level2 lfo4; tab-stops: list 1.0in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Dispositivos físicos (Smartcards, Tokens)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level2 lfo4; tab-stops: list 1.0in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Biométricos&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level2 lfo4; tab-stops: list 1.0in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Fator n - combinação de 2 ou mais mecanismos descritos acima&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level1 lfo4; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ffa500&gt;Autorização&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;FONT color=#ff0000&gt;3&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SUP&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt; é o processo pelo qual se verifica quais as possíveis ações que podem ser realizadas por um agente num determinado contexto.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l1 level1 lfo4; tab-stops: list .5in"&gt;&lt;SPAN&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#ffa500&gt;Repositório de Autorização&lt;/FONT&gt; é o componente necessário para armazenar os dados requeridos para autorização de agentes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;As autenticações nativas disponíveis no Windows Server 2000/2003 são:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l5 level1 lfo5; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Kerberos v5 (veja o artigo Technet &lt;A href="http://technet2.microsoft.com/WindowsServer/en/Library/4a1daa3e-b45c-44ea-a0b6-fe8910f92f281033.mspx" mce_href="http://technet2.microsoft.com/WindowsServer/en/Library/4a1daa3e-b45c-44ea-a0b6-fe8910f92f281033.mspx"&gt;http://technet2.microsoft.com/WindowsServer/en/Library/4a1daa3e-b45c-44ea-a0b6-fe8910f92f281033.mspx&lt;/A&gt; e o Webcast &lt;A href="http://download.microsoft.com/download/6/1/f/61f2010f-b259-4930-8aff-2e3b6cc3513b/MSDN/WebcastArq-Kerberos-20060322.zip" mce_href="http://download.microsoft.com/download/6/1/f/61f2010f-b259-4930-8aff-2e3b6cc3513b/MSDN/WebcastArq-Kerberos-20060322.zip"&gt;http://download.microsoft.com/download/6/1/f/61f2010f-b259-4930-8aff-2e3b6cc3513b/MSDN/WebcastArq-Kerberos-20060322.zip&lt;/A&gt;). &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l5 level1 lfo5; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Infra-estrutura de chaves Publica-Privada (PKI) &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l5 level1 lfo5; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Smartcards&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l5 level1 lfo5; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;NTLMv2 – Somente para compatibilidade com sistemas legados com Windows 9.x e Windows NT&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Já o repositório de autorização e as informações de autorização no Windows Server 2000/2003 são:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Repositório de autorização: Active Directory, que oferece suporte a protocolo Lightweight Directory Access Protocol v3 e suas APIs, além das APIs ADSI.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Informações de autorização:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l4 level1 lfo6; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Baseados em Security Identifiers (SIDs), que são números grandes (~192 bits) e considerados únicos globalmente.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l4 level1 lfo6; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Os SIDs do usuário (ou máquina), dos grupos de segurança ao qual pertence representam os dados necessários para calcular as ações permitidas pelo Security Reference Module (SRM). O SRM está disponível em cada copia do Windows.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l4 level1 lfo6; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Os dados de autorização são transmitidos através do Windows Privilege Attribute Certificate (PAC) que são inseridos em &lt;I style="mso-bidi-font-style: normal"&gt;tickets &lt;/I&gt;Kerberos (TGT) pelo Kerberos Key Distribution Center (KDC). Cada controlador do domínio de serviços de diretórios baseado em Active Directory é um KDC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;A exemplo do que aconteceu com o protocolo de rede TCP/IP, os processos de autenticação e autorização estão convergindo para o uso de protocolos padrões que favorecem uma melhor interoperabilidade entre sistemas.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Neste sentido, os protocolos para autenticação e autorização recomendados para integração UNIX/Linux e Windows são respectivamente Kerberos e Lightweight Directory Access Protocol (LDAP).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Nota: Embora o LDAP ofereça um processo de autenticação, o mesmo manterá um&amp;nbsp;agente autenticado somente se a conexão ao diretório for mantida. A desvantagem deste modelo em ambientes distribuídos é o fato de que a “prova” de autenticação é a conexão e não um ticket como no caso do Kerberos.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Para fornecer o &lt;I style="mso-bidi-font-style: normal"&gt;logon&lt;/I&gt; único usando o serviço de diretórios Active Directory em ambiente baseados em UNIX/Linux e Windows, recomendamos as seguintes práticas:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Interoperabilidade do Kerberos:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;No Windows -&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="MARGIN-TOP: 0in" type=1&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Crie contas de usuários UNIX/Linux no Active Directory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Crie contas de máquinas UNIX/Linux no Active Directory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Crie arquivo Keytab para máquinas UNIX/Linux&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;No UNIX/Linux -&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="MARGIN-TOP: 0in" type=1 start=4&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Transfira e instale o arquivo keytable nas máquinas UNIX/Linux&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Instale componente Kerberos&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Configure o arquivo pam.conf&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l2 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Verdana; mso-ansi-language: EN-US"&gt;Configure o arquivo krb5.conf&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Interoperabilidade do LDAP:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;No Windows -&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="MARGIN-TOP: 0in" type=1&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo3; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Faça a expansão do schema do Active Directory para incroporar as informações de autorização do UNIX/Linux (RFC 2307)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo3; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Faça o provimento (UID, GID e etc) de usuários e grupos UNIX/Linux no Active Directory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;No UNIX/Linux -&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="MARGIN-TOP: 0in" type=1 start=3&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo3; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Instale o componente LDAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo3; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Configure um cliente LDAP nas máquinas com UNIX/Linux para conectar-se ao Active Directory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l0 level1 lfo3; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Configure nss_ldap de forma que ele use os atributos apropriados no Active Directory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Neste modelo de integração descrito acima, o resultado obtido é:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l6 level1 lfo7; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Único repositório (Active Directory) para armazenamento das informações de autorização tanto do Windows como do UNIX/Linux.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l6 level1 lfo7; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Gerenciamento centralizado de identidades. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l6 level1 lfo7; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;Políticas unificadas e rígidas de senhas (ex.: histórico, freqüência, tamanho máximo/mínimo, n° de tentativas e complexidade de senhas).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-ALIGN: justify; mso-list: l6 level1 lfo7; tab-stops: list .5in"&gt;&lt;SPAN lang=PT-BR style="FONT-FAMILY: Verdana"&gt;O uso do Kerberos permite uma autenticação mútua (ex.: do usuário e com quem ele está se conectando) aumentando assim a segurança.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=424687" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Identity+_2600_amp_3B00_+Acess+Management/default.aspx">Identity &amp;amp; Acess Management</category><category domain="http://blogs.technet.com/dirk_frehse/archive/tags/Interoperabilidade/default.aspx">Interoperabilidade</category></item></channel></rss>