LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 01-29-2016, 04:48 AM   #1
mike1969
LQ Newbie
 
Registered: Jan 2016
Posts: 1

Rep: Reputation: Disabled
SSH-access and ActiveDirectory trust relationship with sub-domains


We use many linux servers with Oracle Enterprise 7.1/7.2 in ActiveDirectory domain/sub-domains.

Between that domain/sub-domains (domain A) exists a bidirectional trust relationship with another Active Directory domain (domain B).

Users from domain B must sign in on linux systems in domain/sub-domains A.

Global-security-groups from AD domain B are member in domain-local-groups from AD domain A.

/etc/samba/smb.conf is configured with id-map-ranges for domain A and domain B and winbind-separator +.
/etc/krb5.conf is configured with 'realms' and 'domain_realms' domain A and domain B.
An 'id domain-A-username' and 'id domain-B+username' is successful.
Group memberships are exactly displayed.

The AD-domain-local-groups domain A are insight /etc/ssh/sshd_config and /etc/sudoers for SSH-access and sudo-rights.
But although smb.conf, krb5.conf, id-search successful and AD-domain-B-groups are in AD-domain-A-groups nobody from domain B can sign in on linux systems.
The only successful way i found out was to put AD-global-groups domain B in sshd_config and sudoers.
But that is not wanted, because we have the domain-local-groups domain A in sshd_config and sudoers.
And in that groups are the domain B groups. Linux can't interpret that?

And SSH-access from users in domain B is only successful on systems in MAIN-domain A, not the SUB-domains A.
Although the sshd_config and sudoers files are the same in MAIN and SUB.

Is there a solution that linux can interpret the AD-domain-memberships?
And that access is possible on SUB-domain-systems?

Sorry for my bad english, i'm german.

And thanks a lot for answers :-)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
The trust relationship failed mccombs.eli Linux - Server 11 08-14-2013 05:59 PM
Trust relationship abhishek124 Linux - Networking 2 06-13-2005 02:18 AM
How to create trust relationship abhishek124 Linux - Networking 0 06-07-2005 06:56 AM
Trust relationship vineet_s280 Linux - Networking 2 07-23-2003 11:09 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 03:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration