Navigation

    ML
    • Register
    • Login
    • Search
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups

    Authenticating Linux against AD

    IT Discussion
    active directory ldap linux sssd winbind
    10
    31
    4518
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • brianlittlejohn
      brianlittlejohn last edited by brianlittlejohn

      I used centrify express I believe...

      edit: it was express, I didnt pay anything.

      1 Reply Last reply Reply Quote 0
      • stacksofplates
        stacksofplates last edited by stacksofplates

        this only works with red hat systems, but is one thing we will be doing in the future. Their Identity Management system will integrate with AD. IdM is set up as its own forest and you can have a trust between the two (pardon my windows jargon if it's incorrect). You can then set up host and user based sudo permissions.

        Kelly 1 Reply Last reply Reply Quote 0
        • Kelly
          Kelly @stacksofplates last edited by

          @johnhooks said:

          this only works with red hat systems, but is one thing we will be doing in the future. Their Identity Management system will integrate with AD. IdM is set up as its own forest and you can have a trust between the two (pardon my windows jargon if it's incorrect). You can then set up host and user based sudo permissions.

          Is that for RHEL only, or the derived distros too?

          stacksofplates 1 Reply Last reply Reply Quote 0
          • stacksofplates
            stacksofplates @Kelly last edited by stacksofplates

            @Kelly said:

            @johnhooks said:

            this only works with red hat systems, but is one thing we will be doing in the future. Their Identity Management system will integrate with AD. IdM is set up as its own forest and you can have a trust between the two (pardon my windows jargon if it's incorrect). You can then set up host and user based sudo permissions.

            Is that for RHEL only, or the derived distros too?

            All RHEL based as far as I know. I've only tried RHEL, CentOS and Fedora though.

            Kelly 1 Reply Last reply Reply Quote 1
            • Kelly
              Kelly @stacksofplates last edited by

              @johnhooks said:

              @Kelly said:

              @johnhooks said:

              this only works with red hat systems, but is one thing we will be doing in the future. Their Identity Management system will integrate with AD. IdM is set up as its own forest and you can have a trust between the two (pardon my windows jargon if it's incorrect). You can then set up host and user based sudo permissions.

              Is that for RHEL only, or the derived distros too?

              All RHEL based as far as I know. I've only tried RHEL, CentOS and Fedora though.

              Now I have an interesting quandary. Do I go with something more universally supported so the scientists that love Ubuntu can stay on it, or push for unification on CentOS...

              Probably the former given internal culture.

              stacksofplates 1 Reply Last reply Reply Quote 1
              • stacksofplates
                stacksofplates @Kelly last edited by stacksofplates

                @Kelly said:

                @johnhooks said:

                @Kelly said:

                @johnhooks said:

                this only works with red hat systems, but is one thing we will be doing in the future. Their Identity Management system will integrate with AD. IdM is set up as its own forest and you can have a trust between the two (pardon my windows jargon if it's incorrect). You can then set up host and user based sudo permissions.

                Is that for RHEL only, or the derived distros too?

                All RHEL based as far as I know. I've only tried RHEL, CentOS and Fedora though.

                Now I have an interesting quandary. Do I go with something more universally supported so the scientists that love Ubuntu can stay on it, or push for unification on CentOS...

                Probably the former given internal culture.

                Ya we are an all Red Hat shop so it's easy for us.

                I don't remember but Landscape might give you this ability for Ubuntu also.

                1 Reply Last reply Reply Quote 1
                • scottalanmiller
                  scottalanmiller @Kelly last edited by

                  @Kelly said:

                  Centrify Express or the paid option?

                  Paid. It was a large installation.

                  1 Reply Last reply Reply Quote 0
                  • stacksofplates
                    stacksofplates last edited by

                    FWIW on RHEL systems with Cockpit installed, there is a button named Join Domain. What it does I don't know, but I'm guessing it's for this function. I never looked it up.

                    scottalanmiller 1 Reply Last reply Reply Quote 1
                    • scottalanmiller
                      scottalanmiller @stacksofplates last edited by

                      @johnhooks said:

                      FWIW on RHEL systems with Cockpit installed, there is a button named Join Domain. What it does I don't know, but I'm guessing it's for this function. I never looked it up.

                      Interesting, never noticed that it had a button like that. have only demo'd it once so have not used Cockpit much, that would be a neat feature.

                      stacksofplates 1 Reply Last reply Reply Quote 1
                      • stacksofplates
                        stacksofplates @scottalanmiller last edited by

                        @scottalanmiller said:

                        @johnhooks said:

                        FWIW on RHEL systems with Cockpit installed, there is a button named Join Domain. What it does I don't know, but I'm guessing it's for this function. I never looked it up.

                        Interesting, never noticed that it had a button like that. have only demo'd it once so have not used Cockpit much, that would be a neat feature.

                        Just got in. Here's what comes up when you click it:

                        0_1460549287675_cockpit.png

                        DustinB3403 1 Reply Last reply Reply Quote 2
                        • DustinB3403
                          DustinB3403 @stacksofplates last edited by

                          @johnhooks So it works as expected (or at least it appears to).

                          Did you join this system to your domain?

                          stacksofplates 1 Reply Last reply Reply Quote 0
                          • stacksofplates
                            stacksofplates @DustinB3403 last edited by stacksofplates

                            @DustinB3403 said:

                            @johnhooks So it works as expected (or at least it appears to).

                            Did you join this system to your domain?

                            No I dont have anything to do with the domain stuff. This pc is also on a different network so I can't join it to our normal domain anyway.

                            If I feel ambitious I'll try it at home.

                            1 Reply Last reply Reply Quote 0
                            • Kelly
                              Kelly last edited by

                              I've also been looking at PowerBroker Identity Services from BeyondTrust. It is where Likewise ended up after a series of acquisitions. It looks like I'm going to have to be building a virtual network and trying some of this.

                              Have any of you ever tried Zentyal (for the authentication portion, not the email)?

                              stacksofplates Romo 2 Replies Last reply Reply Quote 1
                              • scottalanmiller
                                scottalanmiller last edited by

                                No, keep meaning to look at Zentyal but never get around to it.

                                1 Reply Last reply Reply Quote 0
                                • stacksofplates
                                  stacksofplates @Kelly last edited by

                                  @Kelly said:

                                  I've also been looking at PowerBroker Identity Services from BeyondTrust. It is where Likewise ended up after a series of acquisitions. It looks like I'm going to have to be building a virtual network and trying some of this.

                                  Have any of you ever tried Zentyal (for the authentication portion, not the email)?

                                  I did it one time with a Zentyal VM and an old windows 7 laptop. All I did was join the domain, so other than saying yes it will join I have no idea what management and everything else is like.

                                  1 Reply Last reply Reply Quote 0
                                  • Romo
                                    Romo @Kelly last edited by

                                    @Kelly Zentyal uses samba 4, so you basically end up with a compatible Active Directory domain controller. You would still need to use pbis or sssd to authenticate your linux machines to the domain controller. Centrify does not work with a samba 4 domain controller, but as I mentioned before either pbis or setting up sssd works ok.

                                    As for the managment aspect of Zentyal, you can use the web interface to set most of the things your are used to when managing an ad dc except group policy settings, in order to also have groups policy settings you can use RSAT and manage it exactly the same as a windows ad dc.

                                    1 Reply Last reply Reply Quote 0
                                    • PSX_Defector
                                      PSX_Defector last edited by

                                      @Kelly said:

                                      I've also been looking at PowerBroker Identity Services from BeyondTrust. It is where Likewise ended up after a series of acquisitions. It looks like I'm going to have to be building a virtual network and trying some of this.

                                      I've used this in multiple companies, from an airline in America to an oil exploration company.

                                      Works like a champ, it's built on Winbind, but now has actual support versus calling RedHat and hoping for the best.

                                      Kelly 1 Reply Last reply Reply Quote 0
                                      • Kelly
                                        Kelly @PSX_Defector last edited by

                                        @PSX_Defector said:

                                        @Kelly said:

                                        I've also been looking at PowerBroker Identity Services from BeyondTrust. It is where Likewise ended up after a series of acquisitions. It looks like I'm going to have to be building a virtual network and trying some of this.

                                        I've used this in multiple companies, from an airline in America to an oil exploration company.

                                        Works like a champ, it's built on Winbind, but now has actual support versus calling RedHat and hoping for the best.

                                        Did you use PBIS Open or the paid version? The paid version is significantly more than I can afford at about $1,600 per server instance.

                                        PSX_Defector 1 Reply Last reply Reply Quote 0
                                        • dafyre
                                          dafyre last edited by

                                          Any particular reason winbind won't work? That is what we use here.

                                          Kelly 1 Reply Last reply Reply Quote 0
                                          • Kelly
                                            Kelly @dafyre last edited by

                                            @dafyre said:

                                            Any particular reason winbind won't work? That is what we use here.

                                            Nope, I'm just trying to do due diligence and evaluate all the options and what we gain/lose from them. At this point Winbind is looking like a strong contender due to its ability to work with sudo, but I'd like to compare all the possibilities that are in my price range.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post