N
N
Nikolai Savelyev2016-08-01 06:51:07
linux
Nikolai Savelyev, 2016-08-01 06:51:07

How is user identification configured in heterogeneous networks?

Previously, everything was simple - all data is stored in openldap, clients on linux drag it directly, on windows - through samba3. Currently samba3 is not supported and samba4 is not friendly with openldap. How to be?
It is clear when you have 100 machines under Windows and 10 under linux. He brought everyone to the domain and everything. But what if the proportion is reversed? Somehow I do not want to fence a screw domain for 10 computers.
I watched freeIPA - everything is there for linux. samba4 is tailored for windows. Where to twitch?
You also need to take into account that a bunch of third-party services for AD and openldap are sharpened - mail servers, openfire, and more.
Maybe someone has experience in implementing and maintaining something universal?
About how ... It turns out I already asked a similar question a year ago and did not receive an answer. Well, apparently the topic of corporate use of linux has finally died out, only the web and mail remain. It's a pity, a pity...

Answer the question

In order to leave comments, you need to log in

4 answer(s)
X
xmoonlight, 2016-08-01
@xmoonlight

help.ubuntu.ru/wiki/samba4_as_dc_12.04
wiki.val.bmstu.ru/doku.php?id=linux_freebsd_%D0%B2...

V
Vladimir Grabko, 2016-08-02
@VGrabko

Don't choke. You have a gag in the fact that you use two operating systems

D
Dima Kim, 2016-08-02
@jalpy

How to properly manage a fleet of Unix servers?
you might find something useful.

M
Maxim Vasiliev, 2016-08-12
@qmax

The built-in ldap in samba4 is quite capable of storing the attributes required for linux-auth (posixGroup, posixAccount). And, theoretically, additional arbitrary schemes.
When creating accounts through samba-tool, they are filled in automatically.
When creating through the windows admin panel, you need to additionally click on the "unix account" tab.
In general, there was a page on the samba wiki about setting up a backend in openldap and dns in bind9.
A couple of years ago everything was bad there, but maybe something has already been washed down.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question