In EditShare software version 2021.1 and later, it is possible to restrict which DNS/Active Directory servers the EditShare system communicates with.
By default, EditShare will generally avoid DNS servers that are unavailable or have a round-trip latency of approximately 300 ms or greater. However, in environments with geographically distributed Active Directory servers, this may not be sufficient.
For example, an EditShare server may be able to communicate successfully with an AD server located in another country or region. Although the latency may still be below 300 ms, authentication and directory operations can be unnecessarily slow.
The adsso_dns_servers setting can be used to restrict the EditShare system to specific, preferred local Domain Controllers, such as those located on the same local network or site.
Configure the Preferred DNS Servers
Open a terminal on the EFS Master server and edit:
/etc/editshare/prefs.conf
For example:
nano /etc/editshare/prefs.conf
Locate the [AD SSO Options] section. It may look similar to the following:
[Mail Options] external_mail = False [Trash Options] time = 2 [AD Options] ad_enabled = False [AD SSO Options] adsso_enabled = True adsso_sync_group_query = |(CN=EditShare*) adsso_sync_group_path = DC=example,DC=com adsso_sync_interval = 3600 dns_proxy_enable = True
Under the [AD SSO Options] section, add:
adsso_dns_servers=dc1.example.com,dc2.example.com
Replace dc1.example.com and dc2.example.com with the Fully Qualified Domain Names (FQDNs) of the local Domain Controllers that should be used.
Multiple servers should be separated by commas.
Important: Use the servers' FQDNs. Do not specify their IP addresses.
Save the file
Restart the AD SSO Server Scanner
Save the configuration file and restart the service:
sudo systemctl restart editshare-adsso-server-scanner
The EditShare system should now restrict Domain Controllers communication to the servers specified in adsso_dns_servers.
Comments
0 comments
Article is closed for comments.