Deventer-2, M.S.J. van
2018-Apr-18 10:56 UTC
[Samba] Is anyone using Isilon OneFS in combination with Samba with AD authentication ?
Hi, We are in the process of testing a migration of our current setup which contains Samba 4 as Classic DC with LDAP backend, Isilon OneFS bulk storage serving NFS/SMB shares and Windows/Mac/Linux clients to a more modern Samba 4 AD. We need to migrate to Samba AD because of Windows 10 and macos 10.13.x (and for several other reasons). But we run into an issue with authenticating the clients in the Isilon OneFS system using Samba AD. Joining the Isilon OneFS to the domain is no problem, we can also see the users and groups from the domain (in the OneFS webinterface and on the cli but when connecting a client to and SMB share we always get an 'wrong password'. Before running into to much detail I would like to know if someone else is using the combination OneFS/Samba AD or tried it and failed like us :) For the record, yes I also opened a support case at our supplier. Thanks, Michel -- Michel van Deventer Integratie Specialist DBG-ICT UMC Utrecht The Netherlands ------------------------------------------------------------------------------ De informatie opgenomen in dit bericht kan vertrouwelijk zijn en is uitsluitend bestemd voor de geadresseerde. Indien u dit bericht onterecht ontvangt, wordt u verzocht de inhoud niet te gebruiken en de afzender direct te informeren door het bericht te retourneren. Het Universitair Medisch Centrum Utrecht is een publiekrechtelijke rechtspersoon in de zin van de W.H.W. (Wet Hoger Onderwijs en Wetenschappelijk Onderzoek) en staat geregistreerd bij de Kamer van Koophandel voor Midden-Nederland onder nr. 30244197. Denk s.v.p aan het milieu voor u deze e-mail afdrukt. ------------------------------------------------------------------------------ This message may contain confidential information and is intended exclusively for the addressee. If you receive this message unintentionally, please do not use the contents but notify the sender immediately by return e-mail. University Medical Center Utrecht is a legal person by public law and is registered at the Chamber of Commerce for Midden-Nederland under no. 30244197. Please consider the environment before printing this e-mail.
adam_xu at adagene.com.cn
2018-Apr-19 00:22 UTC
[Samba] Is anyone using Isilon OneFS in combination with Samba with AD authentication ?
We encountered the same situation last year. We tried EMC Isilon OneFS system last year. , but it seems that their products have compatibility issues with samba AD DC. After trying for a month to repair, they gave up. Finally we purchased HPE 3PAR SAN storage. yours Adam From: Deventer-2, M.S.J. van via samba Date: 2018-04-18 18:56 To: samba at lists.samba.org Subject: [Samba] Is anyone using Isilon OneFS in combination with Samba with AD authentication ? Hi, We are in the process of testing a migration of our current setup which contains Samba 4 as Classic DC with LDAP backend, Isilon OneFS bulk storage serving NFS/SMB shares and Windows/Mac/Linux clients to a more modern Samba 4 AD. We need to migrate to Samba AD because of Windows 10 and macos 10.13.x (and for several other reasons). But we run into an issue with authenticating the clients in the Isilon OneFS system using Samba AD. Joining the Isilon OneFS to the domain is no problem, we can also see the users and groups from the domain (in the OneFS webinterface and on the cli but when connecting a client to and SMB share we always get an 'wrong password'. Before running into to much detail I would like to know if someone else is using the combination OneFS/Samba AD or tried it and failed like us :) For the record, yes I also opened a support case at our supplier. Thanks, Michel -- Michel van Deventer Integratie Specialist DBG-ICT UMC Utrecht The Netherlands ------------------------------------------------------------------------------ De informatie opgenomen in dit bericht kan vertrouwelijk zijn en is uitsluitend bestemd voor de geadresseerde. Indien u dit bericht onterecht ontvangt, wordt u verzocht de inhoud niet te gebruiken en de afzender direct te informeren door het bericht te retourneren. Het Universitair Medisch Centrum Utrecht is een publiekrechtelijke rechtspersoon in de zin van de W.H.W. (Wet Hoger Onderwijs en Wetenschappelijk Onderzoek) en staat geregistreerd bij de Kamer van Koophandel voor Midden-Nederland onder nr. 30244197. Denk s.v.p aan het milieu voor u deze e-mail afdrukt. ------------------------------------------------------------------------------ This message may contain confidential information and is intended exclusively for the addressee. If you receive this message unintentionally, please do not use the contents but notify the sender immediately by return e-mail. University Medical Center Utrecht is a legal person by public law and is registered at the Chamber of Commerce for Midden-Nederland under no. 30244197. Please consider the environment before printing this e-mail. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
Jeremy Allison
2018-Apr-24 23:31 UTC
[Samba] Is anyone using Isilon OneFS in combination with Samba with AD authentication ?
On Wed, Apr 18, 2018 at 10:56:23AM +0000, Deventer-2, M.S.J. van via samba wrote:> Hi, > > We are in the process of testing a migration of our current setup which > contains Samba 4 as Classic DC with LDAP backend, Isilon OneFS bulk > storage serving NFS/SMB shares and Windows/Mac/Linux clients to a more > modern Samba 4 AD. > We need to migrate to Samba AD because of Windows 10 and macos 10.13.x > (and for several other reasons). > > But we run into an issue with authenticating the clients in the Isilon > OneFS system using Samba AD. Joining the Isilon OneFS to the domain is > no problem, we can also see the users and groups from the domain (in > the OneFS webinterface and on the cli but when connecting a client to > and SMB share we always get an 'wrong password'. > > Before running into to much detail I would like to know if someone > else is using the combination OneFS/Samba AD or tried it and failed > like us :) > > For the record, yes I also opened a support case at our supplier.We can maybe look into this if Isilon turn up at the SNIA SDC Conference. Do you have any packet traces of the failure ? I vaguely remember an old DCE-RPC alter-context issue, but that shouldn't affect krb5 auth.