Skip to content
/ gmsad Public

gmsad manages Active Directory group Managed Service Account (gMSA) on Linux

License

Notifications You must be signed in to change notification settings

cea-sec/gmsad

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

gmsad

gmsad manages Active Directory group Managed Service Account (gMSA) on Linux.

Given the keytab of an account which has the ability to retrieve the secret of a gMSA, gmsad creates a keytab for the service account and renew it when necessary. It can execute an arbitrary command just after renewing the keytab.

Requirements

Your Active Directory domain must be able to use group Managed Service Account which implies :

In addition, gmsad requires a working LDAPS interface on domain controllers with a valid TLS certificate.

Documentation

Contributing

Any contribution is welcome, be it code, bug report, packaging, documentation or translation.

License

gmsad is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

gmsad is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with gmsad. If not, see the gnu.org web site.