LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-07-2015, 03:42 AM   #1
p3030128
LQ Newbie
 
Registered: Apr 2015
Posts: 2

Rep: Reputation: Disabled
Mcrosoft PKI+Samba AD


Hello to all,

Have you ever tried to build Samba as Active directory domain controller in order to install Active Directory Certificate Services???

The purpose is to have an enterprise ca with samba ad instead of common microsoft active directory.

The only thing i didn't manage to fix is a smart card logon certificate in order user to login with theirs smart cards.

Any help would be appreciated!

Thank you in advance,

IP
 
Old 04-07-2015, 09:50 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,666

Rep: Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970
Quote:
Originally Posted by p3030128 View Post
Hello to all,
Have you ever tried to build Samba as Active directory domain controller in order to install Active Directory Certificate Services??? The purpose is to have an enterprise ca with samba ad instead of common microsoft active directory. The only thing i didn't manage to fix is a smart card logon certificate in order user to login with theirs smart cards.
Smart card integration is covered in the Samba documentation. Did you look there?
https://wiki.samba.org/index.php/Sam...art_Card_Login

Also, certificate/kerberos integration is also documented:
https://access.redhat.com/documentat.../windbind.html
https://jimshaver.net/2014/07/13/set...-ubuntu-14-04/
 
Old 04-07-2015, 10:01 AM   #3
p3030128
LQ Newbie
 
Registered: Apr 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
Yes, i've already checked them!
Especially on the first url it says that i had to enable tls on smb.conf and replace the certificates with those i've published from my microsoft pki (domain+rootca certificates) on the krb5.conf.

When i enable tls there is no communication with the domain from my windows 7 clients(registry is already configured for tls 1.1 and tls 1.2).

Any thoughts?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
PKI: offline root CA PlatinumX Linux - Security 4 03-16-2010 04:50 AM
SSH with PKI prafulnama Linux - Security 6 03-19-2009 09:07 AM
How to run PKI Gins Linux - General 2 01-17-2007 12:45 PM
PKI implementation amsri Linux - Networking 0 01-24-2006 07:49 AM
Pki subban Linux - Enterprise 1 12-19-2004 04:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:05 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration