ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Comparison of Salt vs AD

    Scheduled Pinned Locked Moved IT Discussion
    38 Posts 11 Posters 7.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RomoR
      Romo @dafyre
      last edited by

      @dafyre said in Comparison of Salt vs AD:

      @scottalanmiller said in Comparison of Salt vs AD:

      @msff-amman-Itofficer said in Comparison of Salt vs AD:

      @dafyre

      The windows installer of salt minion asks you for :

      Salt Master Hostname or IP address
      Minion Name

      And you can install it silently with:

      Salt-Minion-2016.11.5-AMD64-Setup.exe /S /master=yoursaltmaster /minion-name=yourminionname

      Sadly I cant trust my users to run the installer and do the steps, I ASKED THEM TO PLACE THE 3 letter number sticker on their machine, and I emailed them an example photo, and the idiots entered alot of crap for minion name

      Now I have to do them all manually
      90 MACHINES

      User PowerShell or GPO.

      Or PDQ Deploy, lol. I probably should have mentioned I was thinking only of pushing out the Salt agent to the mentions.

      @dafyre That is exactly how I deployed my salt-minions. Added the salt entry on my dns and deployed the minion with PDQ Deploy.

      scottalanmillerS Emad RE 2 Replies Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @Romo
        last edited by

        @Romo said in Comparison of Salt vs AD:

        @dafyre said in Comparison of Salt vs AD:

        @scottalanmiller said in Comparison of Salt vs AD:

        @msff-amman-Itofficer said in Comparison of Salt vs AD:

        @dafyre

        The windows installer of salt minion asks you for :

        Salt Master Hostname or IP address
        Minion Name

        And you can install it silently with:

        Salt-Minion-2016.11.5-AMD64-Setup.exe /S /master=yoursaltmaster /minion-name=yourminionname

        Sadly I cant trust my users to run the installer and do the steps, I ASKED THEM TO PLACE THE 3 letter number sticker on their machine, and I emailed them an example photo, and the idiots entered alot of crap for minion name

        Now I have to do them all manually
        90 MACHINES

        User PowerShell or GPO.

        Or PDQ Deploy, lol. I probably should have mentioned I was thinking only of pushing out the Salt agent to the mentions.

        @dafyre That is exactly how I deployed my salt-minions. Added the salt entry on my dns and deployed the minion with PDQ Deploy.

        I use Chocolatey.

        RomoR 1 Reply Last reply Reply Quote 1
        • matteo nunziatiM
          matteo nunziati @NerdyDad
          last edited by

          @NerdyDad said in Comparison of Salt vs AD:

          I'm trying to clarify this statement from this post

          By @scottalanmiller "I'll add a note for clarity given the title... SaltStack does not do authentication like AD does. AD does not do patching of any sort like Salt does. Salt is an alternative to common myths about AD functionality, but not to actual AD functionality. But you can use Salt to do distributed local authentication management, which does replace the need for AD, but is very different than what is being discussed here. In this case Salt is replacing GPO, not AD."

          https://mangolassi.it/topic/13786/how-to-patch-wannacry-using-saltstack-ad-alternative/3

          Please correct me if I am wrong, but I want to clarify if I am understanding this correctly.

          We all know that AD is a collective, server/client, authentication system. Client computers connected to an AD system has to communicate with an AD server in order to authenticate users for resources.

          Salt syncs local users to each other in a mesh-network so that all users are still capable of accessing all of the computers with the same credentials without having to authenticate to a central server.

          Is this correct or am I reading too much into this?

          a more strict analogous of AD authentication in linux is kerberos (on which AD is based). Using Salt is most of an hack, which, considering the apparent possibility to fire events in Salt, seems anyway a feasible one.

          1 Reply Last reply Reply Quote 0
          • RomoR
            Romo @scottalanmiller
            last edited by

            @scottalanmiller said in Comparison of Salt vs AD:

            @Romo said in Comparison of Salt vs AD:

            @dafyre said in Comparison of Salt vs AD:

            @scottalanmiller said in Comparison of Salt vs AD:

            @msff-amman-Itofficer said in Comparison of Salt vs AD:

            @dafyre

            The windows installer of salt minion asks you for :

            Salt Master Hostname or IP address
            Minion Name

            And you can install it silently with:

            Salt-Minion-2016.11.5-AMD64-Setup.exe /S /master=yoursaltmaster /minion-name=yourminionname

            Sadly I cant trust my users to run the installer and do the steps, I ASKED THEM TO PLACE THE 3 letter number sticker on their machine, and I emailed them an example photo, and the idiots entered alot of crap for minion name

            Now I have to do them all manually
            90 MACHINES

            User PowerShell or GPO.

            Or PDQ Deploy, lol. I probably should have mentioned I was thinking only of pushing out the Salt agent to the mentions.

            @dafyre That is exactly how I deployed my salt-minions. Added the salt entry on my dns and deployed the minion with PDQ Deploy.

            I use Chocolatey.

            I actually deployed the salt-minions to upgrade powershell and deploy chocolatey =).

            1 Reply Last reply Reply Quote 1
            • Emad RE
              Emad R @Romo
              last edited by

              @Romo @aaronstuder @dafyre

              This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
              or it just relies on Active Directory to work.

              NerdyDadN 1 Reply Last reply Reply Quote 0
              • NerdyDadN
                NerdyDad @Emad R
                last edited by

                @msff-amman-Itofficer said in Comparison of Salt vs AD:

                @Romo @aaronstuder @dafyre

                This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                or it just relies on Active Directory to work.

                No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                scottalanmillerS Emad RE 2 Replies Last reply Reply Quote 3
                • scottalanmillerS
                  scottalanmiller @NerdyDad
                  last edited by

                  @NerdyDad said in Comparison of Salt vs AD:

                  @msff-amman-Itofficer said in Comparison of Salt vs AD:

                  @Romo @aaronstuder @dafyre

                  This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                  or it just relies on Active Directory to work.

                  No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                  Same as with PowerShell.

                  DashrenderD 1 Reply Last reply Reply Quote 1
                  • Emad RE
                    Emad R @NerdyDad
                    last edited by

                    @NerdyDad

                    Interesting, thanks.

                    1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @scottalanmiller
                      last edited by

                      @scottalanmiller said in Comparison of Salt vs AD:

                      @NerdyDad said in Comparison of Salt vs AD:

                      @msff-amman-Itofficer said in Comparison of Salt vs AD:

                      @Romo @aaronstuder @dafyre

                      This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                      or it just relies on Active Directory to work.

                      No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                      Same as with PowerShell.

                      Does PowerShell require some sort of remote access to be enabled?

                      Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                      wirestyle22W scottalanmillerS 2 Replies Last reply Reply Quote 0
                      • wirestyle22W
                        wirestyle22 @Dashrender
                        last edited by

                        @Dashrender said in Comparison of Salt vs AD:

                        Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                        • UDP 137
                        • UDP 138
                        • UDP 445
                        • TCP 139
                        • TCP 445
                        • TCP 6336
                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @wirestyle22
                          last edited by

                          @wirestyle22 said in Comparison of Salt vs AD:

                          @Dashrender said in Comparison of Salt vs AD:

                          Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                          • UDP 137
                          • UDP 138
                          • UDP 445
                          • TCP 139
                          • TCP 445
                          • TCP 6336

                          Man that's a lot.

                          dafyreD 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @Dashrender said in Comparison of Salt vs AD:

                            @scottalanmiller said in Comparison of Salt vs AD:

                            @NerdyDad said in Comparison of Salt vs AD:

                            @msff-amman-Itofficer said in Comparison of Salt vs AD:

                            @Romo @aaronstuder @dafyre

                            This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                            or it just relies on Active Directory to work.

                            No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                            Same as with PowerShell.

                            Does PowerShell require some sort of remote access to be enabled?

                            Yes, but it is enabled by default. Just don't turn it off.

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • dafyreD
                              dafyre @scottalanmiller
                              last edited by

                              @scottalanmiller said in Comparison of Salt vs AD:

                              @wirestyle22 said in Comparison of Salt vs AD:

                              @Dashrender said in Comparison of Salt vs AD:

                              Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                              • UDP 137
                              • UDP 138
                              • UDP 445
                              • TCP 139
                              • TCP 445
                              • TCP 6336

                              Man that's a lot.

                              Could be easily done as part of an image, logon batch.

                              DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @dafyre
                                last edited by

                                @dafyre said in Comparison of Salt vs AD:

                                @scottalanmiller said in Comparison of Salt vs AD:

                                @wirestyle22 said in Comparison of Salt vs AD:

                                @Dashrender said in Comparison of Salt vs AD:

                                Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                                • UDP 137
                                • UDP 138
                                • UDP 445
                                • TCP 139
                                • TCP 445
                                • TCP 6336

                                Man that's a lot.

                                Could be easily done as part of an image, logon batch.

                                That is an insane amount of open ports! And oh yeah.. it's wannacry enabled!

                                1 Reply Last reply Reply Quote 1
                                • DashrenderD
                                  Dashrender @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Comparison of Salt vs AD:

                                  @Dashrender said in Comparison of Salt vs AD:

                                  @scottalanmiller said in Comparison of Salt vs AD:

                                  @NerdyDad said in Comparison of Salt vs AD:

                                  @msff-amman-Itofficer said in Comparison of Salt vs AD:

                                  @Romo @aaronstuder @dafyre

                                  This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                                  or it just relies on Active Directory to work.

                                  No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                                  Same as with PowerShell.

                                  Does PowerShell require some sort of remote access to be enabled?

                                  Yes, but it is enabled by default. Just don't turn it off.

                                  And is the firewall ports open by default too? I'm guessing not.. but I'm willing to open those for this purpose..

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @dafyre
                                    last edited by

                                    @dafyre said in Comparison of Salt vs AD:

                                    @scottalanmiller said in Comparison of Salt vs AD:

                                    @wirestyle22 said in Comparison of Salt vs AD:

                                    @Dashrender said in Comparison of Salt vs AD:

                                    Are the needed ports open by default to allow the use of PDQ Deploy in a non AD environment?

                                    • UDP 137
                                    • UDP 138
                                    • UDP 445
                                    • TCP 139
                                    • TCP 445
                                    • TCP 6336

                                    Man that's a lot.

                                    Could be easily done as part of an image, logon batch.

                                    But why would you want so many?

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @Dashrender
                                      last edited by

                                      @Dashrender said in Comparison of Salt vs AD:

                                      @scottalanmiller said in Comparison of Salt vs AD:

                                      @Dashrender said in Comparison of Salt vs AD:

                                      @scottalanmiller said in Comparison of Salt vs AD:

                                      @NerdyDad said in Comparison of Salt vs AD:

                                      @msff-amman-Itofficer said in Comparison of Salt vs AD:

                                      @Romo @aaronstuder @dafyre

                                      This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                                      or it just relies on Active Directory to work.

                                      No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                                      Same as with PowerShell.

                                      Does PowerShell require some sort of remote access to be enabled?

                                      Yes, but it is enabled by default. Just don't turn it off.

                                      And is the firewall ports open by default too? I'm guessing not.. but I'm willing to open those for this purpose..

                                      Why would they enable it and not have the firewall ready to work?

                                      wirestyle22W 1 Reply Last reply Reply Quote 0
                                      • wirestyle22W
                                        wirestyle22 @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in Comparison of Salt vs AD:

                                        @Dashrender said in Comparison of Salt vs AD:

                                        @scottalanmiller said in Comparison of Salt vs AD:

                                        @Dashrender said in Comparison of Salt vs AD:

                                        @scottalanmiller said in Comparison of Salt vs AD:

                                        @NerdyDad said in Comparison of Salt vs AD:

                                        @msff-amman-Itofficer said in Comparison of Salt vs AD:

                                        @Romo @aaronstuder @dafyre

                                        This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                                        or it just relies on Active Directory to work.

                                        No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                                        Same as with PowerShell.

                                        Does PowerShell require some sort of remote access to be enabled?

                                        Yes, but it is enabled by default. Just don't turn it off.

                                        And is the firewall ports open by default too? I'm guessing not.. but I'm willing to open those for this purpose..

                                        Why would they enable it and not have the firewall ready to work?

                                        Why have a firewall if you're opening a thousand ports anyway 😄

                                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @wirestyle22
                                          last edited by

                                          @wirestyle22 said in Comparison of Salt vs AD:

                                          @scottalanmiller said in Comparison of Salt vs AD:

                                          @Dashrender said in Comparison of Salt vs AD:

                                          @scottalanmiller said in Comparison of Salt vs AD:

                                          @Dashrender said in Comparison of Salt vs AD:

                                          @scottalanmiller said in Comparison of Salt vs AD:

                                          @NerdyDad said in Comparison of Salt vs AD:

                                          @msff-amman-Itofficer said in Comparison of Salt vs AD:

                                          @Romo @aaronstuder @dafyre

                                          This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                                          or it just relies on Active Directory to work.

                                          No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                                          Same as with PowerShell.

                                          Does PowerShell require some sort of remote access to be enabled?

                                          Yes, but it is enabled by default. Just don't turn it off.

                                          And is the firewall ports open by default too? I'm guessing not.. but I'm willing to open those for this purpose..

                                          Why would they enable it and not have the firewall ready to work?

                                          Why have a firewall if you're opening a thousand ports anyway 😄

                                          PS doesn't need them. That's for other tools, like PDQDeploy.

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in Comparison of Salt vs AD:

                                            @wirestyle22 said in Comparison of Salt vs AD:

                                            @scottalanmiller said in Comparison of Salt vs AD:

                                            @Dashrender said in Comparison of Salt vs AD:

                                            @scottalanmiller said in Comparison of Salt vs AD:

                                            @Dashrender said in Comparison of Salt vs AD:

                                            @scottalanmiller said in Comparison of Salt vs AD:

                                            @NerdyDad said in Comparison of Salt vs AD:

                                            @msff-amman-Itofficer said in Comparison of Salt vs AD:

                                            @Romo @aaronstuder @dafyre

                                            This PDQ Deploy you guys have been mentioning, does it require an agent on the other Windows clients ?
                                            or it just relies on Active Directory to work.

                                            No agent required. You can deploy based on AD, computer name, or IP address. AD is not required as long as you have local admin credentials.

                                            Same as with PowerShell.

                                            Does PowerShell require some sort of remote access to be enabled?

                                            Yes, but it is enabled by default. Just don't turn it off.

                                            And is the firewall ports open by default too? I'm guessing not.. but I'm willing to open those for this purpose..

                                            Why would they enable it and not have the firewall ready to work?

                                            Why have a firewall if you're opening a thousand ports anyway 😄

                                            PS doesn't need them. That's for other tools, like PDQDeploy.

                                            PS needs at least one.

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post