LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-13-2008, 10:19 AM   #1
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Rep: Reputation: 32
Authenticate to a Windows domain


Hello and thanks in advance for any help you might be.

We currently have about 40 Linux servers authenticating to a NIS domain and about 15 Windows systems authenticating to a Windows 2003 domain. For Security reasons we would like to have the Linux systems authenticate to the Windows domain. This would also facilitate sharing files between the the Windows and Linux boxes and allow us to have a single login to all systems.

I know that we can do this, the question I have is how do we make the Windows username and Linux username be the same?

Example. I have a username of thllgo on the Windows domain and share mount from Windows to a Linux box. Windows says the files belong to thllgo but the Linux side doesn't know the UID. My GID under Linux is 27142 my UID under Windows is 11113.

It would also be nice if we could coordinate the GIDs.

Has anyone dealt with this?
 
Old 11-13-2008, 11:25 AM   #2
irishbitte
Senior Member
 
Registered: Oct 2007
Location: Brighton, UK
Distribution: Ubuntu Hardy, Ubuntu Jaunty, Eeebuntu, Debian, SME-Server
Posts: 1,213
Blog Entries: 1

Rep: Reputation: 88
Take a look at this link: http://ubuntuforums.org/showthread.php?t=91510.

This talks about a successful setup of authenticating linux servers in a w2k3 domain. I daresay, the only way of organising the UID issue is by manually making them the same, bit of a painful time consuming job. Maybe a script?
 
Old 11-13-2008, 06:28 PM   #3
latinmusic74
Member
 
Registered: Jun 2007
Posts: 118

Rep: Reputation: 16
Hey thllgo,

let us know your resolution of the problem.
 
Old 11-17-2008, 10:08 AM   #4
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Original Poster
Rep: Reputation: 32
I seem to have gotten things working. Most of what I had to do was get the DC working correctly. All I had to do on Linux was run the authconfig utility and specify
use winbind
use md5 passwords
use shadow passwords
use kerberos
local authorization is sufficient
the realm which is the full domain name
KDC, seems to have filled out itself
admin server FQDN
use DNS to resolv hosts to realm

Done.

The ugly part is the new UIDs and GIDs are not the same as the old ones so I have to go around and change a lot of ownership issues and group issues. Yuk in a big way. Not hard just time consuming.

Thanks
 
Old 11-17-2008, 02:30 PM   #5
irishbitte
Senior Member
 
Registered: Oct 2007
Location: Brighton, UK
Distribution: Ubuntu Hardy, Ubuntu Jaunty, Eeebuntu, Debian, SME-Server
Posts: 1,213
Blog Entries: 1

Rep: Reputation: 88
thllgo,

I had similar issues with ownership when we went to a full LDAP authentication setup. painful enough. However, for thefuture, i have found that if i setup the user in LDAP, and have the /home directory already mapped, the first time the user logs in the machine will create the home directory for them. Now, i know your situation is slightly different, using AD, but for adding users, create them in AD, then see if they can login and whether or not their /home is created automatically? Saves a lot of work, and is alot safer than what i think you are talking about!
 
Old 11-17-2008, 03:46 PM   #6
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Original Poster
Rep: Reputation: 32
That works for new users. I'm just bummed about the 30+ machines already setup in a NIS environment, with gobs of user files. I should be able to simply create a script that does a find on files with specific UIDs and do a chown on them. Same with GID. Survivable just annoying.
 
Old 11-17-2008, 03:56 PM   #7
irishbitte
Senior Member
 
Registered: Oct 2007
Location: Brighton, UK
Distribution: Ubuntu Hardy, Ubuntu Jaunty, Eeebuntu, Debian, SME-Server
Posts: 1,213
Blog Entries: 1

Rep: Reputation: 88
How many users? All on one NFS /home mount?
 
Old 11-17-2008, 04:27 PM   #8
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Original Poster
Rep: Reputation: 32
about 30 users mainly developers.
 
Old 11-17-2008, 04:46 PM   #9
irishbitte
Senior Member
 
Registered: Oct 2007
Location: Brighton, UK
Distribution: Ubuntu Hardy, Ubuntu Jaunty, Eeebuntu, Debian, SME-Server
Posts: 1,213
Blog Entries: 1

Rep: Reputation: 88
To be honest, if all the files are stored more or less on one machine, I'd give it a go manually, simply to make sure I got them all. But then, users have a way of playing about, eh!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RHEL 4 authenticate to NT domain? pgrimes Linux - Networking 5 04-11-2006 11:48 AM
Winbind will not authenticate new 2003 domain users kaiser.jd Linux - Networking 2 04-09-2006 08:48 PM
Cant authenticate to LDAP domain with Redhat9 shaughto Red Hat 3 07-22-2004 11:29 PM
Cant authenticate to LDAP domain with Redhat9 shaughto Linux - Networking 1 07-01-2004 02:49 PM
Samba: Authenticate Linux-Clients in Samba Domain & Mount mule Linux - Software 0 12-10-2003 01:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 09:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration