Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Sifting Through Billions and Billions of Bytes

Miro 2.0 - Watch TV Podcasts and Videos in HD

Hands off the Gimp

Course: Using LDAP

Bazaar for Subversion users, part 1 - the basics

Firefox 3.5 - A Really Impressive Release

Linux Migration Guide: Finding Linux Equivalents to Your Favorite Windows Programs

Tiny Core Linux 2.1 Review

5 Top of the Line Twitter Desktop Clients for Linux

SECURITY: How Microsoft benefits from Conficker




Senior Windows Engineer (NC)
Next Step Systems
US-NC-Charlotte

Justtechjobs.com Post A Job | Post A Resume
:Authenticate Linux Clients with Active Directory (Technet)
Authenticate Linux Clients with Active Directory (Technet)
Nov 20, 2008, 04 :03 UTC (0 Talkback[s]) (2845 reads)

The discussion on LWN contains a lot of useful information--ed.
"I personally find several advantages for using samba winbind over straight Kerberos + LDAP.

"1. Samba joins AD as a regular host. If you want to use plain Kerberos with pam authentication, you'll have to make host/server@REALM users by hand in AD instead of machine accounts and export a /etc/krb5.keytab file using Microsoft's ktpass tool from the windows support tools. ktpass has a lot of weird limitations and an uncertain future. I have done this, and it works, but the samba way is easier.

"2. Winbind can use regular microsoft groups. Most Unix -> LDAP solutions, regardless of what your LDAP server is (Microsoft? Sun? Novell? IBM? OpenLDAP), use rfc2307 attributes for uid, gid, home directory, shell, etc. There is a subtle but important difference between rfc2307 and rfc2307bis: group members in rfc2307 were LDAP IA5string types (lists of usernames, compare /etc/group). rfc2307bis also allows group members to be LDAP "distinguished names". Microsoft groups in AD use DN's in the "member" attribute. winbind lets you tap into the regular groups, including nested group memberships. If you don't use winbind you may be spending a lot of time mucking around in tools like adsiedit and using different procedures to edit your unix groups than your windows groups. Microsoft has extensions to their "active directory user and computer" tool for "unix attributes" tabs, but those don't include any decent editing support for group memberships. A plain LDAP implementation is going to have more trouble in /etc/nsswitch.conf with mapping groups."

Complete Story

Related Stories:
Zeroshell Delivers Big Network Services in a Small Package(Nov 19, 2008)
Let PAM Take Care of GNU/Linux Security for You(Oct 15, 2008)
Tip of the Trade: Setting Password Policy With PAM(Sep 15, 2008)
Local User Management in FreeNAS(Aug 28, 2008)
Integrating Linux into Active Directory keeps getting easier(Jul 30, 2008)
Symark's Security Access Tool Bridges Linux, Active Directory(Apr 09, 2008)
OpenLDAP + Samba Domain Controller On Ubuntu 7.10(Jan 08, 2008)
Linux Authentication Troubles? Try Active Directory(Jul 31, 2007)
HowtoForge: Install and Configure Auth Shadow on Debian/Ubuntu(Feb 26, 2007)



No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP