I have a windows domain that I want to use as the centralized logon authenticator for both my windows AD domain and our unix users.
Currently our unix users have their own ldap, but I need to get them on my AD.
I installed NIS on my windows 2003 domain controllers, created the SG (Global Security Group) group for my Linux users and created a test user account.
I added that test user to the correct NIS domain, used their correct UID, and made sure their primary group was that SG group.
They can authenticate with my AD just fine; HOWEVER, when they try and change their password from the UNIX side they get an error that the authentication token failed. I can reset it from the AD side, but need them to be able to reset their own passwords.
What am I missing here?