The DC is a Ubuntu 16.04, with samba 4.8 I want a local user in alls workstations with admin permissions, is for the support area, for install apps and if i make a freeipa and make the trust? i could have the users and GPOs for windows and users and tools for linux, is possible? El lun., 14 ene. 2019 a las 17:26, Rowland Penny via samba (< samba at lists.samba.org>) escribió:> On Mon, 14 Jan 2019 17:10:07 -0300 > Carlos Bordon via samba <samba at lists.samba.org> wrote: > > > Hi! i going to migrate all windows workstation to fedora and I need > > for example: make an administrator users in all workstation, is > > possible make a gpo for linux? > > > > All the workstation are in domain...obviosly is a SAMBA! > > > > King regards From Argentine > > What OS is the DC running on, Fedora ? > If so, are you using the Fedora Samba packages ? > If you are, then do not, a Samba AD DC using Fedora packages is > considered experimental and should not be used in production. > > If you do run AD, then all users are stored in AD, this includes > administrative users. > > There are (as far as I aware) no Linux GPO's > > Rowland > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba
On 1/14/19 4:57 PM, Carlos Bordon via samba wrote:> The DC is a Ubuntu 16.04, with samba 4.8 > > I want a local user in alls workstations with admin permissions, is for the > support area, for install apps > > and if i make a freeipa and make the trust? i could have the users and GPOs > for windows and users and tools for linux, is possible?If you are using FreeIPA, I think the answer is true, but you will define permissions on FreeIPA, not on the Windows GPOs. On the FreeIPA mailing lists you could get more information about the state of cross domain trusts with Samba.> > > El lun., 14 ene. 2019 a las 17:26, Rowland Penny via samba (< > samba at lists.samba.org>) escribió: > >> On Mon, 14 Jan 2019 17:10:07 -0300 >> Carlos Bordon via samba <samba at lists.samba.org> wrote: >> >>> Hi! i going to migrate all windows workstation to fedora and I need >>> for example: make an administrator users in all workstation, is >>> possible make a gpo for linux? >>> >>> All the workstation are in domain...obviosly is a SAMBA! >>> >>> King regards From Argentine >> >> What OS is the DC running on, Fedora ? >> If so, are you using the Fedora Samba packages ? >> If you are, then do not, a Samba AD DC using Fedora packages is >> considered experimental and should not be used in production. >> >> If you do run AD, then all users are stored in AD, this includes >> administrative users. >> >> There are (as far as I aware) no Linux GPO's >> >> Rowland >> >> -- >> To unsubscribe from this list go to the following URL and read the >> instructions: https://lists.samba.org/mailman/options/samba
On Mon, 14 Jan 2019 17:57:26 -0300 Carlos Bordon via samba <samba at lists.samba.org> wrote:> The DC is a Ubuntu 16.04, with samba 4.8 > > I want a local user in alls workstations with admin permissions, is > for the support area, for install appsIf you mean a local Unix admin user, as in one stored in /etc/passwd and using sudo, then this easy, just create one during the OS install or add one using the normal Unix tools.> > and if i make a freeipa and make the trust? i could have the users > and GPOs for windows and users and tools for linux, is possible?Why would you want to run freeipa and a Windows DC, they do nearly the same thing, Samba does some things that freeipa doesn't and visa versa. You asked about Linux GPO's, but now mention Windows GPO's, a Samba DC can hold and serve GPO's to Windows clients, just like a Windows AD DC. It might help if you could explain what you hope to achieve, bearing in mind you initially said you were migrating your Windows clients to Fedora (why Fedora, it has a very short shelf life) Rowland
This is beacuse all workstations are windows, but we are thinking migrate to fedora. i already have all the users in samba DC. We access to internet and others apps with user from DC. because of that, we need both systems for now El lun., 14 ene. 2019 a las 18:23, Rowland Penny via samba (< samba at lists.samba.org>) escribió:> On Mon, 14 Jan 2019 17:57:26 -0300 > Carlos Bordon via samba <samba at lists.samba.org> wrote: > > > The DC is a Ubuntu 16.04, with samba 4.8 > > > > I want a local user in alls workstations with admin permissions, is > > for the support area, for install apps > > If you mean a local Unix admin user, as in one stored in /etc/passwd > and using sudo, then this easy, just create one during the OS install > or add one using the normal Unix tools. > > > > > and if i make a freeipa and make the trust? i could have the users > > and GPOs for windows and users and tools for linux, is possible? > > Why would you want to run freeipa and a Windows DC, they do nearly the > same thing, Samba does some things that freeipa doesn't and visa versa. > > You asked about Linux GPO's, but now mention Windows GPO's, a Samba DC > can hold and serve GPO's to Windows clients, just like a Windows AD DC. > > It might help if you could explain what you hope to achieve, bearing > in mind you initially said you were migrating your Windows clients to > Fedora (why Fedora, it has a very short shelf life) > > Rowland > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba