Right now we are using a program called Centrify Direct Control, which installs on a domain controller, and then puts an app on each Linux machine. From what I can tell it functions similar to winbind ...
To me there's clearly a hole as 1) Anyone could add a system to the network and say it's an authorized machine, get people using it without knowing better, etc. and 2) They could setup the system to ...