LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-02-2010, 07:08 AM   #1
zokken
Member
 
Registered: Oct 2008
Posts: 44

Rep: Reputation: 16
ssh + Samba + AD = ?


We have a large website that we're migrating to a new machine. The current server uses Samba with the 'Server' security mode (deprecated), and it's also an NIS client for for ssh/sftp logins.

The new server is Redhat EL 5.4 with Samba 3.0.33. We're planning to get rid of the NIS server and authenticate ssh/sftp logins against AD. From what I've read, this can be done with Samba, using the 'ADS' security mode, and Kerberos. Since Samba's 'Server' security mode is deprecated, it makes sense to switch to ADS anyway.

Here's the challenge. We have a very large number of files/directories uploaded by users that are owned by local accounts/groups. When we switch to Samba with ADS and join the new server to our AD domain, we'll need to get rid of all local accounts. This means that all of the current user/group ownerships will no longer be valid.

One possible solution is to write a script to grab the current user/group ownerships and then modify them on the new server. There are a lot of potential 'gotchas' though, and we have very little time to do this (this sprang up suddenly). Is there a way to have local accounts, setup ssh/sftp to authenticate logins against AD, yet use local account/group permissions?

If not, any other suggestions?
 
Old 03-03-2010, 03:33 AM   #2
leslieviljoen
LQ Newbie
 
Registered: Sep 2008
Posts: 10

Rep: Reputation: 1
I would write scripts and try and get another machine with which to do trial runs. ie. duplicate the relevant portion of the hard drive on that other machine and runs the scripts on there.

Then I could iron out the gotchas before doing the final run.

In any event if you do this kind of thing too quickly you end up taking more time in the long run as you rebuild huge disasters by hand.
 
Old 03-03-2010, 06:50 AM   #3
beadyallen
Member
 
Registered: Mar 2008
Location: UK
Distribution: Fedora, Gentoo
Posts: 209

Rep: Reputation: 36
I agree that you'd be better off thoroughly testing some scripts to do the migration. However, there's no reason why you can't (AFAIK) just have ssh/sftp authenticating against the AD. Just set up PAM to use kerberos, and point it to the AD server. You may well have to do a bit of messing around with usernames, but it should work (famous last words ). Of course, since you'd be using two different sets of passwords (samba and AD), they could get out of sync, but as a temporary measure it might be good enough until you properly convert to AD throughout.

Good luck.

Out of interest, why the rush? This sort of thing really does require thorough testing before 'going live'.
 
Old 03-04-2010, 10:46 AM   #4
zokken
Member
 
Registered: Oct 2008
Posts: 44

Original Poster
Rep: Reputation: 16
Thanks for the replies.

Quote:
Originally Posted by beadyallen View Post
Out of interest, why the rush? This sort of thing really does require thorough testing before 'going live'.
I know! Unfortunately, planning and testing don't seem to interest 'higher ups'.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba over SSH ohswrestler2009 Linux - Newbie 16 11-05-2007 11:43 PM
Samba through SSH tunnel. Aka_yaiba Linux - Networking 4 10-30-2007 07:55 AM
Samba over ssh stfusonxxxx Linux - Newbie 4 10-26-2007 01:34 PM
SSH and Samba over internet FNC Linux - Networking 5 10-25-2007 08:49 AM
Samba over ssh stfusonxxxx Linux - Newbie 1 10-23-2007 08:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration