Active Directory and Bitlocker question

38 views
Skip to first unread message

John Lockwood

unread,
Nov 14, 2017, 7:12:55 AM11/14/17
to cauliflowervest-discuss

I can see that Cauliflowervest supports Windows clients via Bitlocker and syncing recovery keys from Active Directory to the Cauliflowervest server. I also managed to find the script that supposedly does this and it is a python script, however I could not find any documentation on the subject of Windows clients.

My question is that whilst the above is obviously going to be aimed at and work with a Windows Server environment with 'real' Active Directory I wanted to see if it was known to work with just SAMBA4 running as an Active Directory server and furthermore whether the sync script could run on the Linux i.e. SAMBA server. The fact it is written in python would seem to significantly increase the possibility this is going to be possible. Clearly if it had been a PowerShell script there would have been more difficulty.

Maxim Ermilov

unread,
Nov 20, 2017, 1:11:46 PM11/20/17
to cauliflower...@googlegroups.com
> to work with just SAMBA4 running as an Active Directory server

should work.

> furthermore whether the sync script could run on the Linux

it can.
libldap2-dev had to be installed before compiling cauliflowervest/client/win:bitlocker_ad_sync.

_____
Maxim

On Tue, Nov 14, 2017 at 7:12 AM, John Lockwood <jeloc...@gmail.com> wrote:

I can see that Cauliflowervest supports Windows clients via Bitlocker and syncing recovery keys from Active Directory to the Cauliflowervest server. I also managed to find the script that supposedly does this and it is a python script, however I could not find any documentation on the subject of Windows clients.

My question is that whilst the above is obviously going to be aimed at and work with a Windows Server environment with 'real' Active Directory I wanted to see if it was known to work with just SAMBA4 running as an Active Directory server and furthermore whether the sync script could run on the Linux i.e. SAMBA server. The fact it is written in python would seem to significantly increase the possibility this is going to be possible. Clearly if it had been a PowerShell script there would have been more difficulty.

--
You received this message because you are subscribed to the Google Groups "cauliflowervest-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cauliflowervest-discuss+unsub...@googlegroups.com.
To post to this group, send email to cauliflowervest-discuss@googlegroups.com.
Visit this group at https://groups.google.com/group/cauliflowervest-discuss.
For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages