LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 09-14-2004, 10:53 AM   #1
integr8er
LQ Newbie
 
Registered: Mar 2004
Location: Milwaukee, Wi. USA
Distribution: Redhat 9
Posts: 12

Rep: Reputation: 0
seeking clarification- Samba CAL License usage with W2K AD Domain network environment


I'm being told by our sysadmin that a Linux box on the network that is a member of a Windows 2000 AD Domain requires that a cal be expended for a user to connect to a Samba server. Thus, you are not escaping the MS Licensing and CAL requirements for the operation of the business, even by using a Samba file server. Becasue you need to authenticate to a PDC to gain access to the samba server, you're still needing MS License CALS to connect and therefore - What's the use of going Linux?

I'm having a hard time with this and would like all the good input and clarifications I can get.

Thanks in advance,
 
Old 09-17-2004, 04:30 AM   #2
cyberliche
Member
 
Registered: Aug 2004
Location: Atlanta
Distribution: Slackware 10
Posts: 85

Rep: Reputation: 15
This has been discussed on the Samba mailing list, albeit 3 years ago:

http://lists.samba.org/archive/samba...il/018995.html

You can also check the following link for an over view of the Win2000 CAL:

http://www.microsoft.com/windows2000...cing/model.asp

If your looking to avoid the CAL, remove your Win2000 PDC. Samba is perfectly capable of functioning as a PDC, and in many ways out preforms a windows based PDC.

See
here
and
here
 
Old 09-17-2004, 04:44 PM   #3
homey
Senior Member
 
Registered: Oct 2003
Posts: 3,057

Rep: Reputation: 61
Quote:
Becasue you need to authenticate to a PDC to gain access to the samba server,
Why not set up the Samba server as a PDC and stop paying the big bucks to MS?
 
Old 09-17-2004, 09:39 PM   #4
cyberliche
Member
 
Registered: Aug 2004
Location: Atlanta
Distribution: Slackware 10
Posts: 85

Rep: Reputation: 15
Heh, yea that was my question .
 
Old 09-21-2004, 11:54 PM   #5
integr8er
LQ Newbie
 
Registered: Mar 2004
Location: Milwaukee, Wi. USA
Distribution: Redhat 9
Posts: 12

Original Poster
Rep: Reputation: 0
Thanks to those who have replied. Your answers were really useful and enlightening. I find myself burning up over the idea that I put up a non windows machine using software that was not authored by MS and is not controlled by MS and itself has no connecttion licenses involved with it and yet the MS fee is still needed. It makes you come to the very stark realization that this MS notion that an MS Domain control - single sign in - is like buying a jail and then locking yourself up in it and then everyttime you try to escape, you sort of happily pay the jaoiler some more money to not let you escape. I've concluded that businesses are bilked of tons of money for this and they do not see that a kind of freedom to access and use their own bought and paid for resources is available to them using other software solutions.

However, as I look at moving foreward with technology, I find that customers that I have now are buying into the MS world and are also moving more and more into the W2K3 platform and would seriously ask - Why would you want to setup an NT4 Style Domain at this point in time. They would all consider that the Active Directory is the route to go. I'm not sure how to fight that. Seems to me that I'd really like to see the Samba team catch up to doing a Win2000 AD level PDC implementation. Some reading indicates that they cannot do this due to some issues with the MS closed Kerberos extensions??? Not sure on this area.

Thanks Again

Last edited by integr8er; 09-21-2004 at 11:56 PM.
 
Old 10-01-2004, 09:23 AM   #6
LanRx
Member
 
Registered: Jul 2004
Posts: 85

Rep: Reputation: 15
If your licensing is USER based, then you would require CALS for your users, but you would not require a server license for the device. And if you are using node based licensing, you would have the same thing...you need to have a CAL for any device that authenticates against the DC. AD/Linux integration is not going to be a mechanism to avoid microsoft licensing, but rather a way to manage your linux resources with AD tools, I suppose.
 
Old 10-01-2004, 09:25 AM   #7
LanRx
Member
 
Registered: Jul 2004
Posts: 85

Rep: Reputation: 15
Also, it's my understanding (second hand), that there is an LDAP GINA now for NT based devices (NT/2k/2k3/XP) that will allow authentication against an OpenLDAP environment. I am unsure of yet if that will require a Kerberos environment as well. Might be an interesting thing to look into, once I get back into the lab.
 
Old 10-06-2004, 05:50 PM   #8
jjohnston62
Member
 
Registered: Aug 2003
Location: Minnesota, USA
Distribution: RedHat, Suse
Posts: 106

Rep: Reputation: 15
- If your customers are content with AD, don't mind paying licensing, and don't mind the constant patching, then just bill them for all of it and go on with your life. There's nothing wrong with that. It's not a sin, although some would have you believe so.

- If you truly want to rid them of AD -there's a simple question to ask. What is AD doing for them that NT Domain structure doesn't handle? Are they implementing group policies? Is it the redundancy you want? What's really being used in AD that's helping the business?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Clarification on GNU GPL license sureshkellemane Linux - Newbie 10 10-25-2005 06:04 AM
Move w2k Member of Samba Domain to DMZ ollitronix Linux - Networking 2 07-19-2004 02:16 AM
Samba and w2k domain users ymichy Linux - Networking 0 09-15-2003 07:32 AM
Samba authentication in W2k Domain ixion Linux - Networking 7 02-18-2003 08:55 AM
Samba: W2k clients cannot login after joining domain Ajentsmith Linux - Networking 2 09-04-2002 12:29 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 10:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration