LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 09-15-2016, 10:55 AM   #1
who10
LQ Newbie
 
Registered: Sep 2016
Location: Midwest USA
Posts: 9

Rep: Reputation: Disabled
Options for Connecting to Windows Active Directory Groups from Linux


I'm very new to Linux and I'm wanting to know if it's technically possible to obtain Windows Active directory group information from Linux bash?

We have a vbscript that we would like to convert to bash and that is one of the functions of the script.
 
Old 09-16-2016, 05:54 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,627

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
Virtually any AD information that can be requested from any Windows workstation on the AD domain can be requested from any Linux workstations on the AD domain using SAMBA and the proper tools. My scripts test group membership in a couple of ways. Memberships of a user can be viewed using the 'id' command on the linux side, as one example.
 
Old 09-16-2016, 08:13 AM   #3
who10
LQ Newbie
 
Registered: Sep 2016
Location: Midwest USA
Posts: 9

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wpeckham View Post
Virtually any AD information that can be requested from any Windows workstation on the AD domain can be requested from any Linux workstations on the AD domain using SAMBA and the proper tools. My scripts test group membership in a couple of ways. Memberships of a user can be viewed using the 'id' command on the linux side, as one example.
I'll have to look into this. We do use SAMBA, but I wouldn't know if the "proper tools" are in place. I can use groups ID to see what groups an ID is a member of, but it only returns Linux groups when I know this particular user is a member of a Windows AD group. I've also tried to use getent group groupname and it only works on the Linux groups, not AD. I suspect we may not have all the tools in place, or maybe they're not properly configured.
 
Old 09-16-2016, 09:08 PM   #4
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,627

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
It does depend upon your version of SAMBA and the level of your AD servers. On my network we are using Windows server 2012 and SAMBA 4. Any AD user can log into any joined Linux box using the Windows credentials, and if their home folder does not exist it will be created and populated properly. I can run ID on the Linux box for a user that has never logged into that box, and see the AD users PID, AD groups and GIDs, etc. I can also run Finger or getent passwd on them and see that the home folder matches what I would expect. It can be a b1tc4 to set up, but should work that naturally once you get it right.

The docs for SAMBA 4+ are very good, and that group is insanely helpful. (Comes from fighting with Microsoft 'standards' all day. Mere mortal problems like ours start to look so EASY!) ;-)
 
Old 09-21-2016, 12:21 PM   #5
who10
LQ Newbie
 
Registered: Sep 2016
Location: Midwest USA
Posts: 9

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wpeckham View Post
It does depend upon your version of SAMBA and the level of your AD servers. On my network we are using Windows server 2012 and SAMBA 4. Any AD user can log into any joined Linux box using the Windows credentials, and if their home folder does not exist it will be created and populated properly. I can run ID on the Linux box for a user that has never logged into that box, and see the AD users PID, AD groups and GIDs, etc. I can also run Finger or getent passwd on them and see that the home folder matches what I would expect. It can be a b1tc4 to set up, but should work that naturally once you get it right.

The docs for SAMBA 4+ are very good, and that group is insanely helpful. (Comes from fighting with Microsoft 'standards' all day. Mere mortal problems like ours start to look so EASY!) ;-)
Thanks for the info. Once set up, it sounds like a nice environment to work in.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Connecting Linux VM to Windows 2008 Active Directory user9999 Linux - Newbie 1 01-18-2011 02:46 AM
Active directory Groups daveginorge Linux - Server 2 04-08-2010 01:46 AM
Windows Active Directory Groups with Linux Kerberos cjosephson Linux - Software 0 03-22-2009 03:04 PM
connecting samba to a windows 2003 active directory domain Jcrofton Linux - Networking 8 09-17-2006 06:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 02:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration