Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
|
02-20-2006, 11:02 AM
|
#1
|
Member
Registered: Sep 2004
Distribution: Redhat / Fedora
Posts: 114
Rep:
|
Active Directory on Linux
All,
Im intersting on Running a Active Directory Server on Fedora Core 3/4.
Im sure that there is some software that does this but just cant recollect the name.
Any clue'es any one.
PS i dont want to authenticate a linux client using Windows AD server i want the AD server to be on the linux machine itself.
|
|
|
02-20-2006, 11:14 AM
|
#2
|
Senior Member
Registered: Mar 2003
Location: Seattle
Distribution: Slackware ?-14.1
Posts: 1,029
Rep:
|
You can't serve a true active directory on a linux server.
But you can come close using LDAP and SAMBA
|
|
|
02-20-2006, 10:50 PM
|
#3
|
Member
Registered: Sep 2004
Distribution: Redhat / Fedora
Posts: 114
Original Poster
Rep:
|
Im sure there is one which is really good.
One of the IBM guys had it running on a conference i had been to. He was running it on SUSE
|
|
|
02-21-2006, 03:48 AM
|
#4
|
LQ Newbie
Registered: Feb 2006
Posts: 3
Rep:
|
Active Directory is a propriertory microsoft technology which certainly wont run on Linux (unless your a highly skilled WINE guru with a huge amount of time on your hands & scant regard of copyright law).
Samba can function as a domain controller, providing native authentication services for a windows client but it's feature set is more akin to NT4 than AD - there's a lot missing compared to AD: group policy & the whole forest/domain thing, to name a couple off the top of my head, but there's a lot more.
If it wasn't Samba and the IBM guy was demonstrating some fancy management features, etc, then if may have been some novell software he was showing you: I know v. little about it, but my understanding is that it can authenticate windows clients and has some pretty nifty management functions to boot: probably more akin to AD than Samba. It aint free though and migrating your network to novell would be no trivial undertaking.
-ross
|
|
|
02-21-2006, 10:24 AM
|
#5
|
Senior Member
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873
|
quiffhanger is right. Here is some more information. The current release version of Samba is 3. The Samba project is trying to get (some) AD support into Samba 4. The Samba documentation is located here.
http://samba.org/samba/docs/man/Samba-HOWTO-Collection/
Samba can act as a LanManager (NT4) domain controller if all of the other domain controllers are also Samba. Samba cannot act as a domain controller if any genuine Microsoft domain controllers exist.
In all other respects Samba emulates LanManager (NT4) networking. It provides the System Message Block (SMB) file sharing protocol. This protocol was invented by IBM; it is not a Microsoft product. SMB is much more robust than NFS. IMO you would do well to use Samba SMB protocol for file shares even in a pure Unix/Linux environment.
The last thing about Samba is that it not only allows you to set permissions on shares, like in LanManager, but you can also add Unix file permissions on the files in the shares. That is also true of Windows, but some people are impressed when you mention it. 
|
|
|
02-21-2006, 07:53 PM
|
#6
|
Senior Member
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552
Rep:
|
Quote:
Originally Posted by abhijeetudas
Im intersting on Running a Active Directory Server on Fedora Core 3/4.
Im sure that there is some software that does this but just cant recollect the name.
|
Have you looked at OpenLDAP?
|
|
|
03-02-2006, 04:03 PM
|
#7
|
LQ Newbie
Registered: Dec 2005
Location: Blacksburg, VA
Distribution: Fedora Core 4
Posts: 12
Rep:
|
This was a very helpful thread, so thanks to all who have posted so far. I am looking to replace a Windows 2000 Active Directory server with a Linux solution. The clients that will need authentication include Windows XP and Mac OSX (nothing older than that). I also running a few servers based on Fedora Core 4.
From what I gather Samba 3 sounds like a way to go, maybe the way. Is Samba all I need or do I also need LDAP? I read somewhere that OpenLDAP does not authenticate Windows XP users. I don't know if this is true or not.
I also have found an LDAP server called Fedora Directory Server which caught my eye because my servers are using Fedora. I basically am looking for some confirmation on my logic (or correction) and a few links on where I should go from here.
I am down to just two Microsoft servers at this point, one for VPN and this one for user authentication. I'm getting close!
Thanks in advance.
|
|
|
03-04-2006, 12:15 PM
|
#8
|
Senior Member
Registered: Feb 2003
Location: CT
Distribution: Debian 6+, CentOS 5+
Posts: 1,323
Rep: 
|
There is no one stop solution to replacing AD with Linux, however, I have read many articles which use DHCP, DNS, LDAP, and Samba which emulates most of the AD features. Don't quote me on this, but I believe the policies, etc can be done with LDAP, the filesharing is with Samba, and the DHCP and DNS work like the forests.
|
|
|
03-06-2006, 12:30 PM
|
#9
|
LQ Newbie
Registered: Dec 2005
Location: Blacksburg, VA
Distribution: Fedora Core 4
Posts: 12
Rep:
|
Thanks scheidel21, My further research has indicated that going Samba 3-only is not what I am looking for. I need to include LDAP in the mix. I am not too interested in setting up the forests at the moment but running DNS and DHCP on the same machine seems logical for other reasons.
You mentioned that you have read some articles on setting this up. Would you please recommend one?
Thanks again!
|
|
|
03-06-2006, 01:54 PM
|
#10
|
Member
Registered: Feb 2005
Location: Metro Detroit, US
Distribution: Suse/Slackware/Mepis
Posts: 174
Rep:
|
Quote:
Originally Posted by scheidel21
There is no one stop solution to replacing AD with Linux, however, I have read many articles which use DHCP, DNS, LDAP, and Samba which emulates most of the AD features. Don't quote me on this, but I believe the policies, etc can be done with LDAP, the filesharing is with Samba, and the DHCP and DNS work like the forests.
|
For those who don't mind paying.... there IS Novell's eDirectory and Zenworks which is a VERY nice (IE. far superior) replacement for AD. And it all can run on SuSE (and to some extent Redhat).
Group policies, fileshares, DHCP/DNS, remote workstation control, single sign-on plus ALOT more..... there's also Groupwise for mail, clients and server for linux.
FYI
|
|
|
03-07-2006, 07:38 PM
|
#11
|
Member
Registered: Aug 2005
Location: Chicago
Distribution: RHEL5,CENTOS
Posts: 62
Rep:
|
I have been playing with eDirectory on my home network. It is Very Nice. You can Down load a trial version of the Novell OES on novells website it includes eDirectory. Give it a try if you like Purchase the full version, Ithink it will be well worth the money
|
|
|
03-08-2006, 06:27 AM
|
#12
|
Member
Registered: Feb 2005
Location: Metro Detroit, US
Distribution: Suse/Slackware/Mepis
Posts: 174
Rep:
|
While the advantages of eDirectory over AD are vast, one point to mention is that you can run eDirectory on Linux,Netware,AIX,Solaris, and even Windows. AND you are NOT required to use a PC running Windows to take advantage of eDirectory (although you can).
|
|
|
03-08-2006, 05:18 PM
|
#13
|
LQ Newbie
Registered: Dec 2005
Location: Blacksburg, VA
Distribution: Fedora Core 4
Posts: 12
Rep:
|
I appreciate the alternative suggestion. My setup is required to scale from 20 users up to about 40. So I think I'm going to stick with an OSS solution for now.
Does anyone have any suggestions on where I can go to read a comprehensive tutorial for setting up a LDAP/Samba server?
|
|
|
05-01-2006, 08:56 PM
|
#14
|
Member
Registered: Apr 2004
Distribution: RedHat, Fedora, Suse, Debian, Gentoo, Mandrake
Posts: 132
Rep:
|
|
|
|
05-02-2006, 09:14 AM
|
#15
|
LQ Newbie
Registered: Dec 2005
Location: Blacksburg, VA
Distribution: Fedora Core 4
Posts: 12
Rep:
|
Thanks ziox, I'll check that out. I haven't spent much time looking into this since my last post, but its something that I can only put off for so long.
|
|
|
All times are GMT -5. The time now is 12:12 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|