LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-24-2005, 04:08 AM   #1
Pravat
LQ Newbie
 
Registered: Apr 2005
Location: India-Bangalore
Distribution: RHEL, Xandros, Fedora etc.
Posts: 12

Rep: Reputation: 0
Linux & Active Directory Services ?


Can i add my linux box to be one of the Windows 2003 server domian members, in other words can the authentication process of the linux client done by the windows 2003 ent. server.

i use RHEL 3.0 WS as my distro.

and another question the right opposite....

can i make all the windows client to be authenticated by my redhat linux server.

So, pls help me out...

Bye for now...
 
Old 04-24-2005, 10:46 AM   #2
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
I know that you can have windows client to authenticate to your linux system, running a samba server on your RH box. All the process will be transparent to the client. This is slightly different from ADS but it will works the same.

About the opposite... I really dont know, but I would believe that you can't. I really doubt Micro$oft made a way for any system other than M$ systems to authenticate to ADS. But i'm not quite sure, maybe some hackers already reverse engineered the authentication process. My best guess would be to first take a look at Samba website... In worst case I _think_ you can setup LDAP on a Windoze box, you could use that to authenticate Unix client (this is just a guess).
 
Old 04-24-2005, 03:22 PM   #3
scowles
Member
 
Registered: Sep 2004
Location: Texas, USA
Distribution: Fedora
Posts: 620

Rep: Reputation: 31
Using Samba's "winbind" and kerberos, a linux client can be configured to join and authenticate against a Microsoft AD controller. I do it here. See: Samba ADS Domain Membership

Last edited by scowles; 04-24-2005 at 08:15 PM.
 
Old 04-24-2005, 06:06 PM   #4
guitarman85281
Member
 
Registered: Aug 2004
Location: Tempe, Arizona
Distribution: RedHat 9, SuSE 9.1, Fedora Core 4, Gentoo
Posts: 52

Rep: Reputation: 15
Greetings
I am also trying to get a RH9 Samba server to authenticate to a Win 2003 AD. Any help would be much appreciated...perhaps if scowles reposts his link with an actual link?
 
Old 04-24-2005, 08:17 PM   #5
scowles
Member
 
Registered: Sep 2004
Location: Texas, USA
Distribution: Fedora
Posts: 620

Rep: Reputation: 31
Oops! Sorry about that. I have updated the link
 
Old 04-25-2005, 08:01 AM   #6
Brian Knoblauch
Member
 
Registered: Jan 2005
Distribution: OpenSuse Tumbleweed
Posts: 288

Rep: Reputation: 39
Quote:
Originally posted by scowles
Using Samba's "winbind" and kerberos, a linux client can be configured to join and authenticate against a Microsoft AD controller. I do it here. See: Samba ADS Domain Membership
Note, does not work in 2003 AD native mode (at least not for me...).
 
Old 04-25-2005, 08:19 PM   #7
scowles
Member
 
Registered: Sep 2004
Location: Texas, USA
Distribution: Fedora
Posts: 620

Rep: Reputation: 31
Quote:
Originally posted by Brian Knoblauch
Note, does not work in 2003 AD native mode (at least not for me...).
Interesting! Thanks for pointing this out. When I checked the properties of my 2003 AD controller, it says its set to 2000 native mode. Which works fine with linux winbind/kerberos (at least at this end).

I might have to find some time to setup an AD controller in the lab and try raising the functional level to 2003 and see if I can't get linux winbind/kerberos and AD to play together.
 
Old 04-26-2005, 07:17 AM   #8
Brian Knoblauch
Member
 
Registered: Jan 2005
Distribution: OpenSuse Tumbleweed
Posts: 288

Rep: Reputation: 39
Quote:
Originally posted by scowles
Interesting! Thanks for pointing this out. When I checked the properties of my 2003 AD controller, it says its set to 2000 native mode. Which works fine with linux winbind/kerberos (at least at this end).

I might have to find some time to setup an AD controller in the lab and try raising the functional level to 2003 and see if I can't get linux winbind/kerberos and AD to play together.
If you do, I'd be very interested in the results. I have Linux and Mac boxen that won't play nice with all my Windows equipment. Sure would be nice to get them to talk to Active Directory.

I don't know if the protocols themselves changed much in 2003 native mode, but I do seem to remember that the ports changed (old NetBIOS ports have been abandoned). I would expect that a lot of the gaping security holes in the "NetBIOS" support have been patched and not just moved to a new port? :-)
 
Old 05-11-2005, 12:56 PM   #9
lumpyhed
LQ Newbie
 
Registered: Feb 2003
Posts: 8

Rep: Reputation: 0
Just thought i'd pip in to say Kerby auth works fine on my SuSE 9.2 test box with our 2003 native mode setup. With pur current fileserver running out of space i am contemplating running a Samba 3 Winbind/Kerb setup on an additional box - perhaps even taking the current 2003 based server down and putting it on there also (Does no AD stuff anyways) as the virtual filing system would make future drive expansion easier.

Does anyone know of any perils with running Winbind? I seem to hear one fellow having his SIDs go out of sync between samba and windows, which sounds rather serious!

How about Quotas, is that easy enough to setup? Because i've read of some place that is basically selling these linux boxes with a terabyte of storage rather cheaply, but they lack quota control & don't intend to bring anything out to address that so far.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix Aliases & Active Directory paul_mat Linux - Networking 0 11-16-2005 11:09 PM
SUSE DNS & Active Directory suseguy Linux - General 0 11-15-2005 02:46 AM
Active Directory & OpenLDAP to synchronize paul_mat Linux - Networking 1 08-13-2005 06:32 AM
Postfix, Active Directory Services and Authentication weazy Linux - Software 1 04-28-2003 03:38 PM
Samba & Active Directory in Win2k robinhood1995 Linux - General 3 04-13-2002 09:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration