LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 06-19-2012, 02:23 AM   #1
virusakos
LQ Newbie
 
Registered: Apr 2012
Posts: 7

Rep: Reputation: Disabled
Windows smart card logon with Linux based server


Hello all,

I already know that it is possible to replace Windows Active Directory with Samba Primary Domain Controller and have Windows clients join Samba PDC (at least I have tested it successfully with Windows XP and Samba 3 on Lutuntu) and login using username and password.

But now I am trying to move a step forward into smart card logon.

Is it possible to have a Linux based server that can be used to provide Windows smart card logon?
Is there any guide that can help me implement such a solution? My search on Google hasn't been successful.
(I prefer a solution based on CentOS if it is possible)

I appreciate any help you can provide me.
Thank you.
 
Old 06-19-2012, 06:00 AM   #2
truboy
Member
 
Registered: Oct 2010
Location: Switzerland
Posts: 84

Rep: Reputation: 9
Hi,

I'm currently working on smartcard logon as well. I've been able to setup one with Windows Server 2008 and Windows 7 for the client. I must say I'm a little pessimistic concerning a Linux alternative on the server side. This doc shows how a smartcard logon is performed within a Windows environment. As you can see, not only an Active Directory is needed, but a lot of other services.

Since you asked, I assume you really need an online (Active Directory) logon ? Because if you're interested in an offline (local) smartcard logon, you might want to take a look at EIDAuthenticate.

Don't hesitate to ask for more information and tell us if you find your answer !

Cheers
 
Old 06-20-2012, 08:21 AM   #3
virusakos
LQ Newbie
 
Registered: Apr 2012
Posts: 7

Original Poster
Rep: Reputation: Disabled
Yes I need online logon.

I've read that Samba 4 supports smart card logon but I can't find a guide for it.
 
Old 06-21-2012, 02:38 AM   #4
truboy
Member
 
Registered: Oct 2010
Location: Switzerland
Posts: 84

Rep: Reputation: 9
Yeah, it seems that it doesn't exist yet. But you still have plenty of information to read when googling.

Tell us if you find a solution !

Cheers
 
Old 07-04-2012, 05:13 AM   #5
virusakos
LQ Newbie
 
Registered: Apr 2012
Posts: 7

Original Poster
Rep: Reputation: Disabled
Current status:
I have already installed Samba 4 and joined a Windows XP PC and Windows 7 PC in the domain successfully.
I am trying to make Heimdal to work with certificates, i.e. I'm in "Configure Heimdal to accept PKINIT" step of the not existing yet guide on Samba wiki.

I have asked for help in the Samba list http://www.spinics.net/lists/samba/msg102522.html

I will keep updating this thread whenever I have something new to add.
 
Old 07-12-2012, 03:56 AM   #6
virusakos
LQ Newbie
 
Registered: Apr 2012
Posts: 7

Original Poster
Rep: Reputation: Disabled
Status update:

Documentation to configure Heimdal to accept PKINIT can be found in http://www.h5l.org/manual/HEAD/info/..._002dINIT.html

I couldn't find hxtool in Samba 4, so I had to download and built (no need to install though) Heimdal first.

Next step, is to configure Samba 4 to know about the certificate.
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Ubuntu TV vs. Google TV: Battle of the Linux-based Smart TVs LXer Syndicated Linux News 0 01-27-2012 12:10 AM
Linux-based Smart Home nicodoggie Linux - General 2 07-14-2008 01:19 AM
Can i put Windows based PCs on a Linux run server network? bigalexe Linux - Server 8 04-24-2008 09:18 AM
Linux Logon: Network based authentications? bignerd Linux - Networking 3 03-13-2005 04:21 PM
Linux as a Windows domain logon server, possible? Tsuroerusu Linux - Networking 3 03-08-2005 04:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 10:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration