D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] ADS integration with winbindd

 

Kevin Tunison wrote:
> 
> I 'sort of' have working what you want, BUT I have kerberos setup on the
> kit.  How come you don't want to set up kerberos?

Good question.

I think my original reasons may have been misguided, as I thought it
placed additional restrictions on the creating the user accounts
dynamically. Does you configuration generate home directories as needed
on the Linux box (I guess that isn't a requirement for Squid)?

However having now successfully worked it through with and without, I
think the Kerberos is an additional complication that probably doesn't
gain us anything. But does introduce case sensitivity on the domain name
in some parts (i.e. when it is a realm), and some time synchronisation
issues (everything runs NTP anyway), amongst other complications. But
I'm open to persuasion on the issue, if Kerberos does give me a clear
advantage somewhere.

> Have you renamed the machine and rejoined (and reset the machine account
> on the AD setup)?

Hehe - don't ask about that - I named the box the same as one of the
other test boxes originally. Microsoft make recovering from that so much
harder than it ought to be.

-
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html