Solved

Integrating with AD using NIS/NFS (MS SFU)-AutoFS Issue

Posted on 2009-04-11
2
2,034 Views
Last Modified: 2013-12-16
I am trying to use AD as our identity server (corporate thing, not my choice) and since it sux as an LDAP server I figured I'd try their "Services for Unix."  I'm using version 3 (the one that comes with Windows 2003 R2.)

I have their NIS service running and their NFS services exporting folders.  I also have my NetWare/eDirectory as an NIS subordinate server, as well as NIS services on my SLES10 SP2 server, and am exporting NetWare home directories using NFAP/NFS.  However, I can't use NIS, NFS and AutoFS as I should be able to, automatically mounting users' home directories, because Microsoft in their infinite wisdom chose to leave out the auto.master and auto.home NIS maps.  I can manually mount the NetWare home directories on my Linux server (mount -t nfs server:<user home dir nfs share> /home/<userid> -rw) but I can't figure out how to use autofs to do it at user login time.

I don't want to use Samba because that adds yet another set of credentials and permissions, and adds more smb/cifs port traffic that I don't want, and I am trying to reduce user identity A/C/D steps, not add more.  I don't want to use LDAP because then I also have to use Kerberos and try to make it all work together, because Microsoft in their infinite wisdom does not support secure LDAP authentication with PKIS.  

NIS/NFS/autofs have been around forever and should work - provided you can have the requisite NIS maps in play.

Has anyone done this?  If not, does anyone have an idea how I could either work around the shortcomings of Microsoft's NIS service or add the requisite autofs maps to their NIS service?  You can add maps, but they don't tell you what's needed for what map type - the directions are very sketchy and generally not helpful - as one might expect from Microsoft's "interoperability" tools...

Additionally, any help on how to set permissions on the mounted NFS shares would be of great help.  Perhaps some pointers on a shell script I can add to .profile?  If they're getting their home directory via NIS/NFS, the .profile script would have to be on the exported share, right?  How can that be forced to run after the autofs mount, or can it?
0
Comment
Question by:ShineOn
  • 2
2 Comments
 
LVL 35

Author Comment

by:ShineOn
ID: 24176916
OK, I have created the auto.master and auto.home NIS maps in MS SFU and successfully automount home directories at login time now, so never mind on the auto.master and auto.home thing.  There were instructions you have to really dig for, that also need tweaking to make them work (don't ask me how - I don't remember what all I tried, but I do know you have to use the AD editor.)

A .profile script in the NFS-mount home directory will run on login after the automount.

Now I'm having permissions difficulties. I don't want to make the home directories world-writable, but a process that gets launched by the .profile script needs to have write access to the home directory to create temp files.  I have read something about using netgroups for that but would like some insight into how the netgroup NIS map works, and how one might give permissions to a netgroup on the remote (nfs) server when that server is NetWare 6 SP5.  Will the netgroup populate an entry in an OU in eDirectory like group and passwd do, from the NIS map propagation, so there'd be an eDirectory group object for the netgroup that I can give filesystem rights to?
0
 
LVL 35

Accepted Solution

by:
ShineOn earned 0 total points
ID: 24186142
Oops, I guess I kicked off the wrong process here.

Please PAQ with the "what I did" stuff that I put in the "why delete it" dialog:

The original question was resolved primarily by use of MS KB ID 819233, "Server for NIS does not support automount maps."  It describes how to create te auto.master and auto.home using the nismap command.

The difference is, they want you to rename the map file from auto.master to auto_master, and that doesn't work in a Linux autofs environment.  Leave it auto.master.  Same with auto.home.

To make changes to either, you have to jump through additional hoops, including changing the c:\windows\idmu\nis\MapCache file associated with the map, and make the same change to an object in AD using adsiedit.msc, in the "defaultMigrationContainer30" OU..  Find the map object, display properties, and look for the nisMapEntry attribute.  That's what you have to change to match the MapCache file you changed.

Once those changes are made, you can select that map in the IDMU msc and propagate it as necessary.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Best way to virtualise a remote Linux server 2 69
Red Hat 7 Linux on Azure cannot run a command as root 22 44
bash file 10 38
how to configure linux OS using Ubuntu 7 47
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question