LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-30-2008, 02:22 PM   #1
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Rep: Reputation: 41
Active Directory Replacement OpenLdap and/or freeipa?


Hello all,

Just finished a release cycle and now I have time to do the network upgrades I'd like to do. The upgrade on my mind is centralizing all of the user accounts to one server much like MS's AD.. however Linux

The linux boxes connecting to a ldap server for logon information would be easier I imagine and I'd like to start off with trying it as a client first.

The Windows boxes - Server 2003 mostly, I'd simply like the accounts and their associated passwords be read off the ldap server.

I do have a fairly large share, but apache and samba can directly use ldap for authentication if I remember reading correctly. I looked a bit at freeipa, but what other wholesome systems are out there for this kind of migration and centralization?

Ideas? howtos would be greatly appreciated.

Ronnie
 
Old 09-30-2008, 03:05 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by Lantzvillian View Post
Hello all,

Just finished a release cycle and now I have time to do the network upgrades I'd like to do. The upgrade on my mind is centralizing all of the user accounts to one server much like MS's AD.. however Linux

The linux boxes connecting to a ldap server for logon information would be easier I imagine and I'd like to start off with trying it as a client first.

The Windows boxes - Server 2003 mostly, I'd simply like the accounts and their associated passwords be read off the ldap server.

I do have a fairly large share, but apache and samba can directly use ldap for authentication if I remember reading correctly. I looked a bit at freeipa, but what other wholesome systems are out there for this kind of migration and centralization?

Ideas? howtos would be greatly appreciated.

Ronnie
If you're looking for something that's easy to scale, and is supported very well, I'd certainly go with LDAP. Apache, Squid, and Samba can all authenticate via LDAP.
 
Old 09-30-2008, 03:16 PM   #3
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
Tb0ne,

Indeed you are right, but I would like to have 15+ linux servers be all centrally authenticated against the ldap server like a domain. They are 3 different OS's and then I have 10+ Windoze 2003 servers that need to auth against it. Root passwords the same on each for example for the Linux boxes.

Nothing fancy, all of the Windows boxes can be local profiles and have local policies... I just want centralized accounts and passwords.
 
Old 10-02-2008, 06:44 PM   #4
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
Using Fedora 8 and Fedora Directory I have the Linux clients talking to it for authentication.

I now want Windows authentication to the FDS, I read using pGina or Samba.. anyone else have ideas?
 
Old 10-07-2008, 03:09 PM   #5
rzafar
LQ Newbie
 
Registered: Sep 2008
Distribution: ubuntu hardy heron
Posts: 5

Rep: Reputation: 0
You might want to try zivios (http://www.zivios.org). Its a consolidated web panel and an n-tiered PHP-5 application. It uses MySQL and OpenLDAP as it's data store, with OpenLdap being the primary back end for identity management and application integration and MySQL being used for panel specific data. Check it out!
 
Old 10-13-2008, 07:46 PM   #6
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
Back again,

I have a server 2003 box on my domain. From Swat I can login and change that machines Administrator account's password. However, on the server 2003 box I want to login with an account on the domain(samba) and not get a username or password is incorrect error.

Thanks,

Ron

My conf looks like this:

[global]
workgroup = AWESOMO
server string = Samba Server Version %v
passdb backend = tdbsam
time server = Yes
add user script = /usr/sbin/useradd "%u" -n -g users
add group script = /usr/sbin/groupadd "%g"
add machine script = /usr/sbin/useradd -d /dev/null -g samba-clients -s /bin/false -M %u
domain logons = Yes
os level = 65
preferred master = Yes
domain master = Yes
wins support = Yes
cups options = raw

[homes]
comment = Home Directories
read only = No
browseable = No

[printers]
comment = All Printers
path = /var/spool/samba
printable = Yes
browseable = No
 
Old 09-13-2012, 03:24 AM   #7
Roke
LQ Newbie
 
Registered: Nov 2007
Posts: 5

Rep: Reputation: 0
Wink linux active directory - update 2012

http://www.heise.de/ix/meldung/Activ...n-1468714.html
http://www.univention.de/produkte/ucs/

sounds good - klingt aber gut. go samba go.
 
Old 09-13-2012, 06:20 AM   #8
Roke
LQ Newbie
 
Registered: Nov 2007
Posts: 5

Rep: Reputation: 0
also nice

http://www.zentyal.org/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenLDAP query Active Directory noir911 Linux - Server 0 04-30-2008 06:18 AM
OpenLDAP vs Active directory compatibility unforkable Linux - Enterprise 2 02-23-2008 06:43 AM
OpenLDAP and Active Directory custangro Linux - Enterprise 1 01-05-2008 01:55 AM
Active Directory vs. OpenLDAP msteiner Linux - Software 1 10-30-2007 12:09 PM
openldap and active directory akismax Linux - Enterprise 1 07-21-2006 05:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration