LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-21-2011, 08:31 AM   #1
csaunders
LQ Newbie
 
Registered: Jan 2007
Posts: 26

Rep: Reputation: 15
configuring kerb for samba


We need to implement ntlm for apache

http://adldap.sourceforge.net/wiki/doku.php?id=samba

Apparently this requires joining our linux host to our domain. however we have two active directory servers in seperate domains, one ads is for users only, the other is for computers only. Testing kerb and joining your linux host to the domain requires you enter in a user that has permissions to join the domain on ADS. But how do I join a computer to a domain where my account does not exist, the ADS that only contains computers is the one I need to join. Any ideas?
 
Old 01-23-2011, 05:21 AM   #2
New2Linux2
Member
 
Registered: Jan 2004
Location: Arizona
Distribution: Debian
Posts: 153

Rep: Reputation: 43
Quote:
Originally Posted by csaunders View Post
Apparently this requires joining our linux host to our domain.
That is correct. Active Directory controls who has what access to what resources on the network (or in the domain, if you will.)
Quote:
however we have two active directory servers in seperate domains, one ads is for users only, the other is for computers only.
Odd, because every implementation of AD already separates user and computer accounts. Having this handled by two different servers seems like a kludge IMHO.
Quote:
Testing kerb and joining your linux host to the domain requires you enter in a user that has permissions to join the domain on ADS.
Correct again. In order for a server to offer anything in the domain, that server must have a domain account of its own, created by a domain user with permission to create computer/server accounts or by a domain admin.
Quote:
But how do I join a computer to a domain where my account does not exist?
You don't. In order for you to join a server to a domain, you must have the appropriate permissions to do so. If your user account does not have permission to add computers to the domain you will not be able to. You will need to get permission to do this, or have a domain admin add the server to the domain for you.
 
Old 01-25-2011, 10:29 AM   #3
csaunders
LQ Newbie
 
Registered: Jan 2007
Posts: 26

Original Poster
Rep: Reputation: 15
it is a different environment and it is done for security and political reasons. I am trying to do a net ads join, and i want to do it in a specific OU ,the command im using is throwing errors

net ads join -S DOMAIN.LOCAL -U myaccountname createcomputer="DOMAIN.LOCAL/DC1/DevTest BMC BladeLogic/Servers"

Failed to join domain: failed to precreate account in ou ou=Servers,ou=DevTest BMC BladeLogic,ou=DC1,ou=DOMAIN.LOCAL,dc=DOMAIN,dc=LOCAL: No such object

i replaced the real name with DOMAIN.LOCAL, i got the slashed from the ad server on the properties of the OU
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help Configuring Samba hewittrj Linux - Server 5 10-30-2009 07:44 PM
LDAP bind trouble via Kerb/SASL/GSSAPI- principal name mangled riemann_noodles Linux - Server 0 07-09-2008 01:08 PM
multiple nis -> ldap kerb transistion gigscomputer Linux - Server 0 02-10-2008 03:39 PM
Active Directory Auth via Kerb, How to mount a network home? greslore Linux - General 0 01-31-2007 02:44 PM
Configuring Samba alexr186 SUSE / openSUSE 1 10-18-2005 09:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 12:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration