D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] ADS integration with winbindd

 

Na, the home directories don't replicate since it's just for filtering/authentication.
 
As for utilizing kerberos, you have more experience with it than me (I have only implemented it the once thus far).  I did this because the reading I did included it, and it is included as an integral part of MS domain/AD setups.  So, I read a bit more, and it seems that the only advantages I can find are that it's the "standard" for mixed domain setups as far as MS is concerned ( http://www.windowsecurity.com/articles/Kerberos-Authentication-Mixed-Windows-UNIX-Environment.html) and extending trusts outside your network (also with MS Federated Services in R2).
 
From these links below, it seems a registry edit is needed if using kerberos against 2k3.
 
http://www.microsoft.com/windowsserver2003/evaluation/overview/technologies/kerberos.mspx
 
http://lists.samba.org/archive/smb-clients/2003-May/000297.html
 
On 5/5/06, Simon Waters <simon@xxxxxxxxxxxxxx> wrote:
Kevin Tunison wrote:
>
> I 'sort of' have working what you want, BUT I have kerberos setup on the
> kit.  How come you don't want to set up kerberos?

Good question.

I think my original reasons may have been misguided, as I thought it
placed additional restrictions on the creating the user accounts
dynamically. Does you configuration generate home directories as needed
on the Linux box (I guess that isn't a requirement for Squid)?

However having now successfully worked it through with and without, I
think the Kerberos is an additional complication that probably doesn't
gain us anything. But does introduce case sensitivity on the domain name
in some parts (i.e. when it is a realm), and some time synchronisation
issues (everything runs NTP anyway), amongst other complications. But
I'm open to persuasion on the issue, if Kerberos does give me a clear
advantage somewhere.

> Have you renamed the machine and rejoined (and reset the machine account
> on the AD setup)?

Hehe - don't ask about that - I named the box the same as one of the
other test boxes originally. Microsoft make recovering from that so much
harder than it ought to be.

-
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html