Re: Active Directory Based Authentication?
Pandu Poluan <[email protected]> Sat, 12 May 2012 20:22:28 +0700
| Newsgroups | gmane.linux.gentoo.server |
|---|---|
| Message-ID | <CAA2qdGWAh_1j9Mxe8i2GRDpXE-3OW5JvqUL3ygS56DUp5mG_yg@mail.gmail.com> |
--20cf302d4dd497ab1104bfd6be05 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On May 12, 2012 4:28 AM, "Matthew Thode" <[email protected]> wrote: > > On 05/11/2012 09:51 AM, Vin=C3=ADcius Ferr=C3=A3o wrote: > > Hello Pandu, > > > > I have done a implementation using a daemon named sssd. It's sponsored by the Fedora Project if I remember correctly. > > > > It supports 2008r2 AD without much hassle. I've setup everything relying on LDAP for information and Kerberos for authentication. So you don't need things like nss-ldap, nslcd, nscd and other old services. You can handle almost everything with SSSD. And even better: SSSD supports offline server authentication in the case of your AD is down or not reachable at the moment. > > > > I can send you some links in the night (Brazilian night) when I will be at home. > > > > Sent from my iPhone > > > > On 11/05/2012, at 00:36, Pandu Poluan <[email protected]> wrote: > > > >> Hello list, > >> > >> I just want to know, what is your recommendation(s) to implement Active Directory authentication on Gentoo? > >> > >> I want to use AD not only for logins, but also for running daemons/services. > >> > >> *Ideally*, it would also allow me to manage my boxen using GPO, but I can live without that. > >> > >> Rgds, > > > I can attest to how awesome sssd is. I use it for linux server to linux > client, but the concept is still the same. > Ahaha, this is what I've been looking for: a recommendation backed by experience ;-) Thanks for the heads up, guys! Honestly, this is the first time I ever heard of SSSD. Sounds very interesting... I'll certainly look into it. Rgds, --20cf302d4dd497ab1104bfd6be05 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <p><br> On May 12, 2012 4:28 AM, "Matthew Thode" <<a href=3D"mailto:pr= [email protected]">[email protected]</a>> wrote:<br> ><br> > On 05/11/2012 09:51 AM, Vin=C3=ADcius Ferr=C3=A3o wrote:<br> > > Hello Pandu,<br> > ><br> > > I have done a implementation using a daemon named sssd. It's = sponsored by the Fedora Project if I remember correctly.<br> > ><br> > > It supports 2008r2 AD without much hassle. I've setup everyth= ing relying on LDAP for information and Kerberos for authentication. So you= don't need things like nss-ldap, nslcd, nscd and other old services. Y= ou can handle almost everything with SSSD. And even better: SSSD supports o= ffline server authentication in the case of your AD is down or not reachabl= e at the moment.<br> > ><br> > > I can send you some links in the night (Brazilian night) when I w= ill be at home.<br> > ><br> > > Sent from my iPhone<br> > ><br> > > On 11/05/2012, at 00:36, Pandu Poluan <<a href=3D"mailto:pandu= @poluan.info">[email protected]</a>> wrote:<br> > ><br> > >> Hello list,<br> > >><br> > >> I just want to know, what is your recommendation(s) to implem= ent Active Directory authentication on Gentoo?<br> > >><br> > >> I want to use AD not only for logins, but also for running da= emons/services.<br> > >><br> > >> *Ideally*, it would also allow me to manage my boxen using GP= O, but I can live without that.<br> > >><br> > >> Rgds,<br> > ><br> > I can attest to how awesome sssd is. =C2=A0I use it for linux server t= o linux<br> > client, but the concept is still the same.<br> ></p> <p>Ahaha, this is what I've been looking for: a recommendation backed b= y experience ;-) </p> <p>Thanks for the heads up, guys! Honestly, this is the first time I ever h= eard of SSSD. Sounds very interesting... I'll certainly look into it. <= /p> <p>Rgds, <br> </p> --20cf302d4dd497ab1104bfd6be05--