Daniel Lindgren
2007-Oct-01 17:32 UTC
[CentOS-docs] HowTo: Samba with ADS security in CentOS 5
Hello! I have recently gone through the hassle of trying to get a CentOS 5 server (no gui) with Samba to use ADS for security. After several days of googling and trying different howtos I finally got it working, I now want to write a howto for CentOS 5, Samba 3.0 and Windows Server 2003 SP2. Basically it's a combination of http://www.howtoforge.com/samba_ads_security_mode and http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/winbind.html, with additions that actually make things work. Regards, Daniel Lindgren -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.centos.org/pipermail/centos-docs/attachments/20071001/1a6449bf/attachment-0001.html>
On Mon, 1 Oct 2007, Daniel Lindgren wrote:> I have recently gone through the hassle of trying to get a CentOS 5 server > (no gui) with Samba to use ADS for security. After several days of googling > and trying different howtos I finally got it working, I now want to write a > howto for CentOS 5, Samba 3.0 and Windows Server 2003 SP2. > > Basically it's a combination of > http://www.howtoforge.com/samba_ads_security_mode and > http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/winbind.html, > with additions that actually make things work.Consider me a reviewer. I am very interested in your contribution ! -- -- dag wieers, dag at centos.org, http://dag.wieers.com/ -- [Any errors in spelling, tact or fact are transmission errors]
Christoph Maser
2007-Oct-02 06:33 UTC
[CentOS-docs] HowTo: Samba with ADS security in CentOS 5
Daniel, for me adding a samba/winbindd server to the domain is 2 calls to system-config-securitylevel_: authconfig --enableshadow --enablemd5 --enablekrb5 --krb5realm$KRB_REALM --k rb5kdc=$AD_SERVER --kickstart authconfig-tui --kickstart --enablewinbind --enablewinbindauth --smbsecurity=ads --smbrealm=$KRB_REALM --smbservers=$AD_SERVER --winbindjoin="Administrator" --winbindtemplatehomedir=/home/%U --winbindtemplateshell=/bin/bash --enablewinbindusedefaultdomain --smbworkgroup=FINANCIAL --enablelocauthorize So what is the big deal here? Oh yea you need a patched authconfig until CentOS 5.1 is released, see http://bugs.centos.org/view.php?id=2213. Maybe you could modify your contribution a bit... Chris Am Montag, den 01.10.2007, 19:32 +0200 schrieb Daniel Lindgren:> Hello! > > I have recently gone through the hassle of trying to get a CentOS 5 > server (no gui) with Samba to use ADS for security. After several days > of googling and trying different howtos I finally got it working, I > now want to write a howto for CentOS 5, Samba 3.0 and Windows Server > 2003 SP2. > > Basically it's a combination of > http://www.howtoforge.com/samba_ads_security_mode and > http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/winbind.html, with additions that actually make things work. > > Regards, > Daniel Lindgrenfinancial.com AG Munich head office/Hauptsitz M?nchen: Maria-Probst-Str. 19 | 80939 M?nchen | Germany Frankfurt branch office/Niederlassung Frankfurt: Messeturm | Friedrich-Ebert-Anlage 49 | 60327 Frankfurt | Germany Management board/Vorstand: Dr. Steffen Boehnert (CEO/Vorsitzender) | Dr. Alexis Eisenhofer | Dr. Yann Samson | Matthias Wiederwach Supervisory board/Aufsichtsrat: Dr. Dr. Ernst zur Linden (chairman/Vorsitzender) Register court/Handelsregister: Munich ? HRB 128 972 | Sales tax ID number/St.Nr.: DE205 370 553