Re: Active Directory Based Authentication?
Pandu Poluan <[email protected]> Sat, 12 May 2012 20:18:53 +0700
| Newsgroups | gmane.linux.gentoo.server |
|---|---|
| Message-ID | <CAA2qdGVN4MvMHkMnu3T8dw0V58oycg4YPfNfU56y0ZCZba22PA@mail.gmail.com> |
--bcaec54eefacc76af304bfd6b140 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On May 11, 2012 9:30 PM, "Brian Kroth" <[email protected]> wrote: > > Pandu Poluan <[email protected]> 2012-05-11 10:36: > >> Hello list, >> >> I just want to know, what is your recommendation(s) to implement Active >> Directory authentication on Gentoo? > > > Attribute data can be stored/retrieved in ldaps (as in AD usually only allows authenticated binds to retrieve data and it requires an ssl connection to do that, other than that it's really just ldap). > > Authentication can be done either via ldaps or kerberos, though I personally find the later to be extra complication that's usually unnecessary. > > As someone else mentioned, there's a wealth of data out there on how to do this in any number of schemes (eg: libnss-ldap, libpam-ldap, sssd, etc.)= . > > >> I want to use AD not only for logins, but also for running >> daemons/services. > > > I don't see the distinction. Either way it seems you're concerned with authenticating users and doing attribute lookups on them. > > >> *Ideally*, it would also allow me to manage my boxen using GPO, but I can >> live without that. > > > I'm not personally aware of anything that does that. If there is, it's probably something like redhat/suse specific. > > However, I believe it is possible to use a samba4 host as a domain controller to serve GPs to windows clients. > PowerBroker (n=C3=A9e Likewise) claims that it can manage Linux boxen via G= PO... ... but in my case I think I'll just force my subordinates to learn puppet *heh*heh* Rgds, --bcaec54eefacc76af304bfd6b140 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <p><br> On May 11, 2012 9:30 PM, "Brian Kroth" <<a href=3D"mailto:bpkr= [email protected]">[email protected]</a>> wrote:<br> ><br> > Pandu Poluan <<a href=3D"mailto:[email protected]">[email protected]= o</a>> 2012-05-11 10:36:<br> ><br> >> =C2=A0Hello list,<br> >><br> >> =C2=A0I just want to know, what is your recommendation(s) to imple= ment Active<br> >> =C2=A0Directory authentication on Gentoo?<br> ><br> ><br> > Attribute data can be stored/retrieved in ldaps (as in AD usually only= allows authenticated binds to retrieve data and it requires an ssl connect= ion to do that, other than that it's really just ldap).<br> ><br> > Authentication can be done either via ldaps or kerberos, though I pers= onally find the later to be extra complication that's usually unnecessa= ry.<br> ><br> > As someone else mentioned, there's a wealth of data out there on h= ow to do this in any number of schemes (eg: libnss-ldap, libpam-ldap, sssd,= etc.).<br> ><br> ><br> >> =C2=A0I want to use AD not only for logins, but also for running<b= r> >> =C2=A0daemons/services.<br> ><br> ><br> > I don't see the distinction. =C2=A0Either way it seems you're = concerned with authenticating users and doing attribute lookups on them.<br= > ><br> ><br> >> =C2=A0*Ideally*, it would also allow me to manage my boxen using G= PO, but I can<br> >> =C2=A0live without that.<br> ><br> ><br> > I'm not personally aware of anything that does that. =C2=A0If ther= e is, it's probably something like redhat/suse specific.<br> ><br> > However, I believe it is possible to use a samba4 host as a domain con= troller to serve GPs to windows clients.<br> ></p> <p>PowerBroker (n=C3=A9e Likewise) claims that it can manage Linux boxen vi= a GPO... </p> <p>... but in my case I think I'll just force my subordinates to learn = puppet *heh*heh*</p> <p>Rgds, <br> </p> --bcaec54eefacc76af304bfd6b140--