?
Solved

Linux File Server in Windows AD environment.

Posted on 2009-02-18
3
Medium Priority
?
491 Views
Last Modified: 2013-12-15
am trying to see AD objects from permissions on Linux Suse Enterprise file server that is running Samba and is joined to AD domain.
Have installed SFU(Services for Unix)3.5 on Windows DC.

Can browse the domain from Linux server
Can create shares on folders or printers and see them from Windows clients but can't access them because I can't grant permissions to AD objects on the linux server because all I see is the linux users/groups.

tia
0
Comment
Question by:clownbird
2 Comments
 
LVL 2

Accepted Solution

by:
jannisj earned 1000 total points
ID: 23680111
You have to map the Windows AD groups to groups on the linux server:

It works like this:

net groupmap add ntgroup="Domain Admins" unixgroup=domadm rid=512 type=d

The unixgroup domadm must exist on the linux server.
(you could for instance use root as the Domain Admins group on linux).

Here is an example of a basic groupmapping:

net groupmap add ntgroup="Domain Admins" unixgroup=root
net groupmap add ntgroup="Domain Users" unixgroup=users
net groupmap add ntgroup="Domain Guests" unixgroup=nobody
0
 

Author Comment

by:clownbird
ID: 23681877
Would a dedicated LDAP directory simplify things, such as Tivoli DS or OpenLDAP to replicate against the AD and let the Linux server authenticate against it?  
OR, are you saying that ultimately there has to be name mappping for each object(user and/or group) on the Linux server for to control authorization on the shares?


thx
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the first part of this tutorial we will cover the prerequisites for installing SQL Server vNext on Linux.
Eseutil Hard Recovery is part of exchange tool and ensures Exchange mailbox data recovery when mailbox gets corrupt due to some problem on Exchange server.
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Suggested Courses
Course of the Month16 days, 8 hours left to enroll

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question