Re: Active Directory Based Authentication?

Pandu Poluan <[email protected]> Sat, 12 May 2012 20:22:28 +0700
Newsgroups gmane.linux.gentoo.server
Message-ID <CAA2qdGWAh_1j9Mxe8i2GRDpXE-3OW5JvqUL3ygS56DUp5mG_yg@mail.gmail.com>
--20cf302d4dd497ab1104bfd6be05
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On May 12, 2012 4:28 AM, "Matthew Thode" <[email protected]> wrote:
>
> On 05/11/2012 09:51 AM, Vin=C3=ADcius Ferr=C3=A3o wrote:
> > Hello Pandu,
> >
> > I have done a implementation using a daemon named sssd. It's sponsored
by the Fedora Project if I remember correctly.
> >
> > It supports 2008r2 AD without much hassle. I've setup everything
relying on LDAP for information and Kerberos for authentication. So you
don't need things like nss-ldap, nslcd, nscd and other old services. You
can handle almost everything with SSSD. And even better: SSSD supports
offline server authentication in the case of your AD is down or not
reachable at the moment.
> >
> > I can send you some links in the night (Brazilian night) when I will be
at home.
> >
> > Sent from my iPhone
> >
> > On 11/05/2012, at 00:36, Pandu Poluan <[email protected]> wrote:
> >
> >> Hello list,
> >>
> >> I just want to know, what is your recommendation(s) to implement
Active Directory authentication on Gentoo?
> >>
> >> I want to use AD not only for logins, but also for running
daemons/services.
> >>
> >> *Ideally*, it would also allow me to manage my boxen using GPO, but I
can live without that.
> >>
> >> Rgds,
> >
> I can attest to how awesome sssd is.  I use it for linux server to linux
> client, but the concept is still the same.
>

Ahaha, this is what I've been looking for: a recommendation backed by
experience ;-)

Thanks for the heads up, guys! Honestly, this is the first time I ever
heard of SSSD. Sounds very interesting... I'll certainly look into it.

Rgds,

--20cf302d4dd497ab1104bfd6be05
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p><br>
On May 12, 2012 4:28 AM, &quot;Matthew Thode&quot; &lt;<a href=3D"mailto:pr=
[email protected]">[email protected]</a>&gt; wrote:<br>
&gt;<br>
&gt; On 05/11/2012 09:51 AM, Vin=C3=ADcius Ferr=C3=A3o wrote:<br>
&gt; &gt; Hello Pandu,<br>
&gt; &gt;<br>
&gt; &gt; I have done a implementation using a daemon named sssd. It&#39;s =
sponsored by the Fedora Project if I remember correctly.<br>
&gt; &gt;<br>
&gt; &gt; It supports 2008r2 AD without much hassle. I&#39;ve setup everyth=
ing relying on LDAP for information and Kerberos for authentication. So you=
 don&#39;t need things like nss-ldap, nslcd, nscd and other old services. Y=
ou can handle almost everything with SSSD. And even better: SSSD supports o=
ffline server authentication in the case of your AD is down or not reachabl=
e at the moment.<br>

&gt; &gt;<br>
&gt; &gt; I can send you some links in the night (Brazilian night) when I w=
ill be at home.<br>
&gt; &gt;<br>
&gt; &gt; Sent from my iPhone<br>
&gt; &gt;<br>
&gt; &gt; On 11/05/2012, at 00:36, Pandu Poluan &lt;<a href=3D"mailto:pandu=
@poluan.info">[email protected]</a>&gt; wrote:<br>
&gt; &gt;<br>
&gt; &gt;&gt; Hello list,<br>
&gt; &gt;&gt;<br>
&gt; &gt;&gt; I just want to know, what is your recommendation(s) to implem=
ent Active Directory authentication on Gentoo?<br>
&gt; &gt;&gt;<br>
&gt; &gt;&gt; I want to use AD not only for logins, but also for running da=
emons/services.<br>
&gt; &gt;&gt;<br>
&gt; &gt;&gt; *Ideally*, it would also allow me to manage my boxen using GP=
O, but I can live without that.<br>
&gt; &gt;&gt;<br>
&gt; &gt;&gt; Rgds,<br>
&gt; &gt;<br>
&gt; I can attest to how awesome sssd is. =C2=A0I use it for linux server t=
o linux<br>
&gt; client, but the concept is still the same.<br>
&gt;</p>
<p>Ahaha, this is what I&#39;ve been looking for: a recommendation backed b=
y experience ;-) </p>
<p>Thanks for the heads up, guys! Honestly, this is the first time I ever h=
eard of SSSD. Sounds very interesting... I&#39;ll certainly look into it. <=
/p>
<p>Rgds, <br>
</p>

--20cf302d4dd497ab1104bfd6be05--