Cynthia Marie Calvin
2002-Jul-09 15:15 UTC
[Samba] Samba authenication to Window Active Directory
Has any version of Samba been tested for compatibility with the new Windows Active Directory? We will be upgrading our NT domain to 2000 and creating Active Directory. Currently our solaris samba 2.0.7 server is configured to authenicate users from our NT domain controllers. Will we encounter problems with the 2000 upgrade? Thanks in advance, Cynthia --------------------------------- Do You Yahoo!? New! SBC Yahoo! Dial - 1st Month Free & unlimited access -------------- next part -------------- HTML attachment scrubbed and removed
Andrew Bartlett
2002-Jul-09 16:39 UTC
[Samba] Samba authenication to Window Active Directory
Cynthia Marie Calvin wrote:> > Has any version of Samba been tested for compatibility with the new > Windows Active Directory? > > We will be upgrading our NT domain to 2000 and creating Active > Directory. > > Currently our solaris samba 2.0.7 server is configured to authenicate > users from our NT domain controllers. Will we encounter problems withOnly if you move to native mode. However, due to other bugs (in win2k as much as in Samba) and upgrade to 2.2.5 wold be a good idea. Native AD support is available in Samba HEAD. Andrew Bartlett -- Andrew Bartlett abartlet@pcug.org.au Manager, Authentication Subsystems, Samba Team abartlet@samba.org Student Network Administrator, Hawker College abartlet@hawkerc.net http://samba.org http://build.samba.org http://hawkerc.net
Javid Abdul-AJAVID1
2002-Jul-10 07:26 UTC
[Samba] Samba authenication to Window Active Directory
Just wondering if native AD support would be there in samba-3.0 version Am not sure how to use HEAD thanks again -----Original Message----- From: Andrew Bartlett [mailto:abartlet@samba.org] Sent: Tuesday, July 09, 2002 6:38 PM To: Cynthia Marie Calvin Cc: samba@samba.org Subject: Re: [Samba] Samba authenication to Window Active Directory Cynthia Marie Calvin wrote:> > Has any version of Samba been tested for compatibility with the new > Windows Active Directory? > > We will be upgrading our NT domain to 2000 and creating Active > Directory. > > Currently our solaris samba 2.0.7 server is configured to authenicate > users from our NT domain controllers. Will we encounter problems withOnly if you move to native mode. However, due to other bugs (in win2k as much as in Samba) and upgrade to 2.2.5 wold be a good idea. Native AD support is available in Samba HEAD. Andrew Bartlett -- Andrew Bartlett abartlet@pcug.org.au Manager, Authentication Subsystems, Samba Team abartlet@samba.org Student Network Administrator, Hawker College abartlet@hawkerc.net http://samba.org http://build.samba.org http://hawkerc.net -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Javid Abdul-AJAVID1
2002-Jul-10 07:51 UTC
[Samba] Samba authenication to Window Active Directory
we are moving our member servers ( windows ) to win2000 from NT4.0 right now samba is memeber server in NT4.0 resource domain, but accounts domain is AD. so we have samba directing authentication to PDC in NT domain which again gets info from AD accounts DC. Just wondering if i need to upgrade from 2.0.7 to 2.2.5 if PDC in NT resource domain is being upgraded to Win2K DC. so far 2.0.7 is pretty solid without any issues. thanks -----Original Message----- From: Gerald Carter [mailto:jerry@samba.org] Sent: Wednesday, July 10, 2002 8:56 AM To: Andrew Bartlett Cc: Cynthia Marie Calvin; samba@samba.org Subject: Re: [Samba] Samba authenication to Window Active Directory On Wed, 10 Jul 2002, Andrew Bartlett wrote:> Cynthia Marie Calvin wrote: > > > > Has any version of Samba been tested for compatibility with the new > > Windows Active Directory? > > > > We will be upgrading our NT domain to 2000 and creating Active > > Directory. > > > > Currently our solaris samba 2.0.7 server is configured to authenicate > > users from our NT domain controllers. Will we encounter problems with > > Only if you move to native mode. However, due to other bugs (in win2k > as much as in Samba) and upgrade to 2.2.5 wold be a good idea. > > Native AD support is available in Samba HEAD.Now andrew, you know that 2.2.x can operate in a native Win2k domain using NTLM. :-) Just not kerberos, which is what I know you were referring to. cheers, jerry --------------------------------------------------------------------- Hewlett-Packard http://www.hp.com SAMBA Team http://www.samba.org -- http://www.plainjoe.org "Sam's Teach Yourself Samba in 24 Hours" 2ed. ISBN 0-672-32269-2 --"I never saved anything for the swim back." Ethan Hawk in Gattaca-- -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
-----Original Message----- From: Gerald Carter [mailto:jerry@samba.org] Sent: Wednesday, July 10, 2002 08:56 To: Andrew Bartlett Cc: Cynthia Marie Calvin; samba@samba.org Subject: Re: [Samba] Samba authenication to Window Active Directory On Wed, 10 Jul 2002, Andrew Bartlett wrote:> Cynthia Marie Calvin wrote: > > > > Has any version of Samba been tested for compatibility with the new > > Windows Active Directory? > > > > We will be upgrading our NT domain to 2000 and creating Active > > Directory. > > > > Currently our solaris samba 2.0.7 server is configured toauthenicate> > users from our NT domain controllers. Will we encounter problemswith> > Only if you move to native mode. However, due to other bugs (in win2k > as much as in Samba) and upgrade to 2.2.5 wold be a good idea. > > Native AD support is available in Samba HEAD.Now andrew, you know that 2.2.x can operate in a native Win2k domain using NTLM. :-) Just not kerberos, which is what I know you were referring to. I had difficulties getting 2.2.5 to do encrypted authentication on a Win2K Domain in native mode. HEAD was much easier to get up and running correctly. I must say that I would recommend using it. cheers, jerry --------------------------------------------------------------------- Hewlett-Packard http://www.hp.com SAMBA Team http://www.samba.org -- http://www.plainjoe.org "Sam's Teach Yourself Samba in 24 Hours" 2ed. ISBN 0-672-32269-2 --"I never saved anything for the swim back." Ethan Hawk in Gattaca-- -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
On Wed, 10 Jul 2002, Andrew Bartlett wrote:> Cynthia Marie Calvin wrote: > > > > Has any version of Samba been tested for compatibility with the new > > Windows Active Directory? > > > > We will be upgrading our NT domain to 2000 and creating Active > > Directory. > > > > Currently our solaris samba 2.0.7 server is configured toauthenicate> > users from our NT domain controllers. Will we encounter problemswith> > Only if you move to native mode. However, due to other bugs (in win2k > as much as in Samba) and upgrade to 2.2.5 wold be a good idea. > > Native AD support is available in Samba HEAD.Now andrew, you know that 2.2.x can operate in a native Win2k domain using NTLM. :-) Just not kerberos, which is what I know you were referring to. I had difficulties getting 2.2.5 to do encrypted authentication on a Win2K Domain in native mode. HEAD was much easier to get up and running correctly. I must say that I would recommend using it.
Javid Abdul-AJAVID1
2002-Jul-10 08:07 UTC
[Samba] Samba authenication to Window Active Directory
THough its pretty old, some of our clearcase custmers ( not all , a minority ) still needs this 2.0.7 as clearcae officially supports this version on solaris8 :-)) does anybody know that 2.2.5 has issues with clearcase interoperability -----Original Message----- From: Gerald Carter [mailto:jerry@samba.org] Sent: Wednesday, July 10, 2002 9:54 AM To: Javid Abdul-AJAVID1 Cc: Andrew Bartlett; Cynthia Marie Calvin; samba@samba.org Subject: RE: [Samba] Samba authenication to Window Active Directory On Wed, 10 Jul 2002, Javid Abdul-AJAVID1 wrote:> we are moving our member servers ( windows ) to win2000 from NT4.0 > > right now samba is memeber server in NT4.0 resource domain, but accounts > domain is AD. > so we have samba directing authentication to PDC in NT domain which again > gets info from AD accounts DC. > > Just wondering if i need to upgrade from 2.0.7 to 2.2.5 if PDC in NT > resource domain is being upgraded to Win2K DC. > > > so far 2.0.7 is pretty solid without any issues. >And also pretty old right now. Try it and see. My guess is that you will end up required 2.2.5 due to some Win2k SP issue or feature. Although I can' give a specific example. Sid History maybe? Don't remember if this was supported in 2.0.7 or not. cheers, jerry --------------------------------------------------------------------- Hewlett-Packard http://www.hp.com SAMBA Team http://www.samba.org -- http://www.plainjoe.org "Sam's Teach Yourself Samba in 24 Hours" 2ed. ISBN 0-672-32269-2 --"I never saved anything for the swim back." Ethan Hawk in Gattaca--
-----Original Message----- From: Gerald Carter [mailto:jerry@samba.org] Sent: Wednesday, July 10, 2002 09:54 To: Javid Abdul-AJAVID1 Cc: Andrew Bartlett; Cynthia Marie Calvin; samba@samba.org Subject: RE: [Samba] Samba authenication to Window Active Directory On Wed, 10 Jul 2002, Javid Abdul-AJAVID1 wrote:> we are moving our member servers ( windows ) to win2000 from NT4.0 > > right now samba is memeber server in NT4.0 resource domain, butaccounts> domain is AD. > so we have samba directing authentication to PDC in NT domain whichagain> gets info from AD accounts DC. > > Just wondering if i need to upgrade from 2.0.7 to 2.2.5 if PDC in NT > resource domain is being upgraded to Win2K DC. > > > so far 2.0.7 is pretty solid without any issues. >And also pretty old right now. Try it and see. My guess is that you will end up required 2.2.5 due to some Win2k SP issue or feature. Although I can' give a specific example. Sid History maybe? Don't remember if this was supported in 2.0.7 or not. As long a Windows 2000 is in 'Mixed Mode' and not 'Native Mode' you should not have any problems as Win2K will continue legacy compatibility. However, if your intent is to shift into full Windows 2000 Native mode as I have done here, I expect you will find yourself needing to upgrade your SAMBA servers as well. cheers, jerry --------------------------------------------------------------------- Hewlett-Packard http://www.hp.com SAMBA Team http://www.samba.org -- http://www.plainjoe.org "Sam's Teach Yourself Samba in 24 Hours" 2ed. ISBN 0-672-32269-2 --"I never saved anything for the swim back." Ethan Hawk in Gattaca-- -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Gerald Carter
2002-Jul-10 08:38 UTC
[Samba] Samba authenication to Window Active Directory
On Wed, 10 Jul 2002, Javid Abdul-AJAVID1 wrote:> Just wondering if native AD support would be there in samba-3.0 version > Am not sure how to use HEAD > thanks againThe HEAD development branch will become 3.0. cheers, jerry
Drew.Zeller@statcan.ca
2002-Jul-31 07:08 UTC
[Samba] Samba authenication to Window Active Directory
Cynthia, I know it has been a little bit since you post this, however I thought I would mention that I currently have all the SAMBA servers in my area at our company authenticating against the Active Directory we have here. We are still running in a mixed mode, however we did some testing in a test lab and switched to native mode and we did not experience any problems. Out testing with the native mode was based upon a White Paper written for the HP product CIFS (which is based upon SAMBA 2.2.3a). The white paper is called "HP's CIFS/9000 And Windows 2000 Interoperability". My servers are running Samba 2.2.4 on HP-UX 11.00 (although in the test lab we tested on both Solaris and HP-UX). I would recommend that you move your SAMBA version up to at least 2.2.4 to be able authenticate (although I know 2.2.5 is out there and you may want move that into place since it is the latest version). Hope this helps. --__--__-- Date: Tue, 9 Jul 2002 15:14:39 -0700 (PDT) From: Cynthia Marie Calvin <cyncalvin@yahoo.com> To: samba@samba.org Subject: [Samba] Samba authenication to Window Active Directory --0-311941400-1026252879=:51652 Content-Type: text/plain; charset=us-ascii Has any version of Samba been tested for compatibility with the new Windows Active Directory? We will be upgrading our NT domain to 2000 and creating Active Directory. Currently our solaris samba 2.0.7 server is configured to authenicate users from our NT domain controllers. Will we encounter problems with the 2000 upgrade? Thanks in advance, Cynthia