[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [SAGE] RH directory server or IBM TDS and directory structure in a fairly complex environment



Nathan Hruby wrote:
On Jan 15, 2008 5:50 AM, Erling Ringen Elvsrud <erlingre@xxxxxxxxx> wrote:
Hello list,

I work for a fairly large organization and will probably  be involved
in planning, installing and maintaining
a LDAP based directory service this year. The directory will be
mainly used to authenticate developers and systems administrators that
need to access RH Linux servers  (and also maybe HP-UX in the future).
Microsoft AD is used elsewhere in the organization to authenticate
users of Windows based desktop computers. The best solution  would
be to use AD to authenticate users of Unix computers as well, but I'm
not sure if it is possible to make that solution work.

Depending on your AD forest and how willing your AD admins are to
working with you, this is a perfectly viable option.  Samba offers the
winbind daemon which can talk to AD, and in AD 2003-r2 they've fixed a
good number of the compatibility issues between windows and
non-windows hosts.  There are also several companies that offer
integration solutions for Unix+AD.

Yes, it can be made to work. But among all the things which AD does poorly (which is, most of them), LDAP authentication is one of the worst. I guess with only 200 active users you should be OK. (LDAP searching is pretty lame on AD too.)

http://connexitor.com/blog/pivot/entry.php?id=185

I'll warn against "having another directory" unless you plan to keep
the two in-sync.  Multiple identity stores in a large organization
never ends up helping.

Agrred, but sometimes it's a necessary evil, until a better solution can be deployed. (Though as we all know, temporary stopgap measures have a tendency to become permanent...)

Here are a few links that may (or may not) be helpful:
- http://www.quest.com/landing/?ID=1025&AdCode=GoogleAdTextADtoUnixLinuxJava06052007
- http://blog.scottlowe.org/2006/08/08/linux-active-directory-and-windows-server-2003-r2-revisited/
- http://gentoo-wiki.com/HOWTO_Active_Directory_with_Samba_and_Winbind

-n


--
  -- Howard Chu
  Chief Architect, Symas Corp.  http://www.symas.com
  Director, Highland Sun        http://highlandsun.com/hyc/
  Chief Architect, OpenLDAP     http://www.openldap.org/project/