Link to home
Start Free TrialLog in
Avatar of marchopkins
marchopkinsFlag for United States of America

asked on

Can see my Domain in AD, but I still need to tweak.

Adding the Internal Windows DNS server to the TCP properties did the trick.  My Acitve Directory Forrest and my Active Directory Domain are the same (xyz.com).  I still have a small issue.  I still need to enable SMB/CIFS to be able to see the shared files on our Domain.  I was able to see these files without joining the domain in the first place.  Do I need to have this SMB/CIFS enabled?  I would like to use my MacBook Pro (Tiger OSX 10.4.10) to login to the domain just as I would (or in similar fashion to) a Windows box.  When SMB is enabled, I still need to enter my username and password every time to view folders on our company file server.  I want to be able to use the Domain Controller user attributes assigned to me to allow access instead.

Thoughts?

Thanks
Avatar of aces4all
aces4all

Bad news

The use of access tokens allows the single sign-on like feature you're looking for.  A domain controller will only issue acess tokens to authenticated computers.  Only computers with domain accounts that are using the "Client for Microsoft Networks" and the "Netlogon" service can authenticate to the domain (Windows NT 4, Windows 2000, Windows XP Professional, Windows Server 2003, Windows Vista Business/Enterprise/Ultimate).  While there are a few Samba/Cifs clients out there that will allow you save your user authentication credentials and present them on your behalf there are no easy out of the box solutions for what you are looking for.   There are a few Identity Management products out there that can help with this like Microsoft Identity Integration Server and Vintela Authentication Services.
Avatar of marchopkins

ASKER

Hmm, this makes a lot of sense to me.  So, just another quick question:  Why do i even need to join the xyz.com domain?  Are there benefits other than just using the SMB/CIFS in the directory access plugin.  I was able to view the files without joining the domain.

Thanks
ASKER CERTIFIED SOLUTION
Avatar of aces4all
aces4all

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks for the help.  I'll run with it.