LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 12-29-2009, 08:03 AM   #1
your_shadow03
Senior Member
 
Registered: Jun 2008
Location: Germany
Distribution: Slackware
Posts: 1,466
Blog Entries: 6

Rep: Reputation: 51
ADS <==> FedoraDS <==> Linux/Unix Clients?


I have a certain query regarding the following structure:
Code:
    Active Directory Server
    ||
    ||
    Fedora Directory Server <=> Client(Linux | Fedora | Ubuntu | Solaris | HP)
Let me explain you what I want:

1.There is a company Active Directory Server under domain intinfra.com.As of now there are limited Windows Desktop Machine under that domain.I have few Linux / Unix Machines which I want to authenticate through ADS(which are presently not under ADS).Why? Becoz' everytime I need to delete the users whenver they leave the project.Thats Cumbersome.

So what I want is Setup Fedora DS(Wonder if We can do that without Fedora DS).Now I can ads join to Fedora DS(I have administrative privileges for ADS).What I really want to know is:

If I join Fedora DS to ADS then all employee can login to the Linux Machine through their login credentials. I dont want that to happen.We have 3000 employee in intinfra Domain but We are only 30 Admins. I only want those 30-40 admins to login restrictly.Is it possible to restrict at FedoraDS level.

2.Say, I joined ADS and fedora DS and say after 30 days one of System Admin left the company.So his name will be removed from ADS. Is it possible that ADS and Fedora DS are synchronized in such a way that a user whose name gets deleted in ADS, gets deleted too from fedora .Do fedora DS has the capability to synchronize to ADS everytime.

Pls Suggest.

Last edited by your_shadow03; 12-29-2009 at 08:09 AM.
 
Old 12-29-2009, 12:06 PM   #2
your_shadow03
Senior Member
 
Registered: Jun 2008
Location: Germany
Distribution: Slackware
Posts: 1,466

Original Poster
Blog Entries: 6

Rep: Reputation: 51
I Googled it around and found this link http://www.redhat.com/f/pdf/rhas/NetgroupWhitepaper.pdf
for answer to 1st Question.
The Answer is "yes" through Netgroup.
Do yu agree with this?

Also, I found http://www.redhat.com/docs/manuals/d...dows_Sync.html for second question.

Last edited by your_shadow03; 12-29-2009 at 12:08 PM.
 
Old 01-04-2010, 12:38 AM   #3
your_shadow03
Senior Member
 
Registered: Jun 2008
Location: Germany
Distribution: Slackware
Posts: 1,466

Original Poster
Blog Entries: 6

Rep: Reputation: 51
anyone who can suggest me with?
 
Old 01-06-2010, 01:34 PM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Why would you want to bother using FDS if AD works? You seem to have thought up some less than desirable solutions. Not horrible, but unneccessary. Just install the MSSFU schema extensions for AD and then use that as your (mostly) posix compliant LDAP server. As for the Admin only logins, again don't use netgroups, that *IS* pretty horrible, just use standard group memberships and only permit members of the admin group to log into a server within sshd_config or your /etc/security/access for system wide access.

Last edited by acid_kewpie; 01-06-2010 at 01:36 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Linux/Unix Want Ads - Humor That's Sad But True LXer Syndicated Linux News 0 10-18-2008 03:00 PM
LXer: IRC Clients for Linux Part 1: List of 6 GUI Clients LXer Syndicated Linux News 0 09-12-2008 04:40 PM
FedoraDS ??? ajeetraina Linux - Server 2 09-14-2007 07:14 AM
Searching/indexing software on a unix/linux server and windows-xp clients ArchNGEL Linux - Server 4 06-29-2007 02:45 PM
Unix Distro to act as server and backup clients over the network fyr3 Linux - General 2 06-23-2007 01:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 11:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration