LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-10-2015, 06:54 AM   #1
Blue_Ice
Member
 
Registered: Jul 2006
Location: Belgium
Distribution: Debian, Fedora, CentOS, Windows
Posts: 361

Rep: Reputation: Disabled
Question Using Samba4 to authenticate users on OpenVPN


Does anyone have any experience on authenticating users on OpenVPN by using Samba4? Samba4 is configured as an Active Directory Domain Controller.
I have used a configuration file that I know is working as I used it before. The only difference is that in that config file I am using the linux accounts to authenticate instead of Samba4.

So far I have tried to setup OpenVPN using openvpn-plugin-auth-pam.so/pam_winbind.so and openvpn-auth-ldap.so. But neither one of them I got to work.

Code:
# OpenVPN.config
mode server
tls-server
route-gateway dhcp
local xxx.xxx.xxx.xxx
port 1194
proto tcp
dev tap0
ca /etc/openvpn/easy-rsa/keys/ca.crt
cert /etc/openvpn/easy-rsa/keys/server.crt
key /etc/openvpn/easy-rsa/keys/server.key
dh /etc/openvpn/easy-rsa/keys/dh2048.pem
server-bridge
client-to-client
keepalive 10 120
tls-auth /etc/openvpn/easy-rsa/keys/ta.key 0
cipher AES-128-CBC
comp-lzo
max-clients 200
persist-key
persist-tun
status /var/log/openvpn-status.log
log-append  /var/log/openvpn.log
verb 3
duplicate-cn
push "redirect-gateway def1"
management localhost 7505
passtos
plugin /usr/lib/openvpn/openvpn-plugin-auth-pam.so /etc/pam.d/openvpn
#plugin /usr/lib/openvpn/openvpn-auth-ldap.so "ldap-auth.config"
 
Old 07-10-2015, 08:11 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
I'm not familiar with using Samba in such a role. Ordinarily, I see LDAP being used. Can Samba be used for this purpose? Can you cite some web-page sources?
 
Old 07-10-2015, 10:28 AM   #3
Blue_Ice
Member
 
Registered: Jul 2006
Location: Belgium
Distribution: Debian, Fedora, CentOS, Windows
Posts: 361

Original Poster
Rep: Reputation: Disabled
Sorry to all... It was not the authentication that went wrong. The daemon is not starting all the time. Since I fixed this, I can authenticate through ldap.
 
Old 07-14-2015, 09:06 AM   #4
fshah
Member
 
Registered: Apr 2013
Posts: 45

Rep: Reputation: 0
@sundialsvcs yes samba4 can be used as AD DC. Please view below link

http://ubuntuforums.org/showthread.php?t=2146198

Thanks
 
  


Reply

Tags
authentication, configuration, openvpn, samba4



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Samba4 - users cannot modify files in samba mount mfoley Linux - Server 7 06-12-2015 09:03 AM
how to authenticate openvpn 2.0 with Ldap server anis123 Linux - Server 4 12-10-2013 04:18 AM
LXer: How To Set Up OpenVPN To Authenticate With LinOTP LXer Syndicated Linux News 0 10-24-2012 02:50 PM
nm-openvpn: Authenticate/Decrypt packet error: cipher final failed jonaskellens Linux - Newbie 0 08-27-2009 02:52 PM
how to authenticate external users but bypass prompt on local LAN users? taiwf Linux - Security 5 07-13-2005 09:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration