Gentoo Archives: gentoo-server

From: Pandu Poluan <pandu@××××××.info>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Active Directory Based Authentication?
Date: Sat, 12 May 2012 13:23:06
Message-Id: CAA2qdGWAh_1j9Mxe8i2GRDpXE-3OW5JvqUL3ygS56DUp5mG_yg@mail.gmail.com
In Reply to: Re: [gentoo-server] Active Directory Based Authentication? by Matthew Thode
1 On May 12, 2012 4:28 AM, "Matthew Thode" <prometheanfire@g.o> wrote:
2 >
3 > On 05/11/2012 09:51 AM, Vinícius Ferrão wrote:
4 > > Hello Pandu,
5 > >
6 > > I have done a implementation using a daemon named sssd. It's sponsored
7 by the Fedora Project if I remember correctly.
8 > >
9 > > It supports 2008r2 AD without much hassle. I've setup everything
10 relying on LDAP for information and Kerberos for authentication. So you
11 don't need things like nss-ldap, nslcd, nscd and other old services. You
12 can handle almost everything with SSSD. And even better: SSSD supports
13 offline server authentication in the case of your AD is down or not
14 reachable at the moment.
15 > >
16 > > I can send you some links in the night (Brazilian night) when I will be
17 at home.
18 > >
19 > > Sent from my iPhone
20 > >
21 > > On 11/05/2012, at 00:36, Pandu Poluan <pandu@××××××.info> wrote:
22 > >
23 > >> Hello list,
24 > >>
25 > >> I just want to know, what is your recommendation(s) to implement
26 Active Directory authentication on Gentoo?
27 > >>
28 > >> I want to use AD not only for logins, but also for running
29 daemons/services.
30 > >>
31 > >> *Ideally*, it would also allow me to manage my boxen using GPO, but I
32 can live without that.
33 > >>
34 > >> Rgds,
35 > >
36 > I can attest to how awesome sssd is. I use it for linux server to linux
37 > client, but the concept is still the same.
38 >
39
40 Ahaha, this is what I've been looking for: a recommendation backed by
41 experience ;-)
42
43 Thanks for the heads up, guys! Honestly, this is the first time I ever
44 heard of SSSD. Sounds very interesting... I'll certainly look into it.
45
46 Rgds,