Gentoo Archives: gentoo-server

From: Sean Cook <scook@×××××.net>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Samba PDC/BDC with OpenLDAP
Date: Mon, 25 Apr 2005 16:25:30
Message-Id: 1114446305.27250.0.camel@localhost.localdomain
In Reply to: Re: [gentoo-server] Samba PDC/BDC with OpenLDAP by Robert Larson
1 To add to this a bit. Under the roadmap for samba-4 is full ad
2 replacement. So we have a lot to look forward to until M$ decides to
3 break it ;)
4
5 On Mon, 2005-04-25 at 10:50 -0500, Robert Larson wrote:
6 > Hello Rene,
7 >
8 > I have actually set this up as an NT domain, as close to ADS as I could
9 > possibly get. The implementation was a little tricky, but it involves
10 > (heimdal)kerberos, sasl, openldap, pam, djbdns, dhcp, and samba. A web
11 > document I had found helped me significantly when I approached technical
12 > issues:
13 > http://www.opentechnet.com/auth-howto/
14 >
15 > Along the lines of replacing ADS, I think this is as close as you may get.
16 > The thing that sets Microsoft's ADS apart is that they use a form of Remote
17 > Procedure Calls that implements a lot of the leg work. This makes microsoft
18 > incompatible against samba.
19 >
20 > In AD mode, a Microsoft computer won't authenticate against a linux host
21 > (though it would as a PDC in NT mode) since it would be trying to communicate
22 > in misc forms of RPC talk. On the flip side, it should be possible to
23 > authenticate samba against ADS. Here is a tool that allows for flexibilty
24 > with authentication under windows:
25 > http://pgina.xpasystems.com/info/
26 >
27 > As far as drawbacks, that's it. I haven't seen anything wrong with doing it
28 > NT style, and with all of the added bells and whistles.
29 >
30 > I don't know the specifics, but the SMB-TNG is a lot more bleeding edge
31 > technology when it comes to samba in an enterprise environment. It may
32 > provide you with a solution closer to what you are looking for:
33 > http://www.samba-tng.org
34 >
35 > I had a lot of fun setting this up! ;)
36 >
37 > Regards,
38 >
39 > Robert
40 >
41 >
42 > On Monday 25 April 2005 04:25 am, Rene Zbinden wrote:
43 > > Has anyone experience using samba as PDC and BDC with OpenLDAP as backend?
44 > > Is it possible to totally go away from Windows Active Directories Servers
45 > > to the above solution? What are the Drawbacks?
46 > > --
47 > > cheers,
48 > > rene
49 >
50
51 --
52 gentoo-server@g.o mailing list