Solved

User passwords domain/samba

Posted on 2012-03-15
6
403 Views
Last Modified: 2012-04-23
We have setup a domain in our network and we want the user passwords to expire every X days, however we do not want to have to manually change the samba share passwords for our linux file server.

Is there a way that when a users Windows (domain) password is changed that the new password can be sent to samba so they can still access the file server?
0
Comment
Question by:revo1059
  • 3
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37725331
I've worked at a few environment which had the same requirements for password changes, but never did we have to sync passwords to SAMBA.
I'm no *nix specialist but you should look into Windows and SAMBA integration.
That way your SAMBA will use AD for authentication and can query AD directly.

I think they discuss it in this post.
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0d5620db-8130-4b9b-90c2-2ee4ae367893/
0
 
LVL 5

Expert Comment

by:1ly4me
ID: 37725761
Samba with windows can be configured in two ways.
1. standalone server (Act as main DC)
2. As a domain member (Samba can authenticate users based on main DC in the domain)
However in your scenario the first option will not help, because I assume you have windows as main DC.
In the second option, you can join samba server to domain network, and samba can authenticate users based on windows DC. Whenever Samba try to authenticate, it will contact main DC for username/password match.
(I think you want to setup both windows and samba as domain controllers?)
0
 
LVL 1

Author Comment

by:revo1059
ID: 37725953
Option #2 sounds like a winner, I just need direction on how to implement it.
0
Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

 
LVL 5

Expert Comment

by:1ly4me
ID: 37728878
Are you using command based samba or GUI?
0
 
LVL 1

Author Comment

by:revo1059
ID: 37729482
I can use either.
0
 
LVL 5

Accepted Solution

by:
1ly4me earned 500 total points
ID: 37730160
Run,
#authconfig-tui and select winbind and  kerberos authentication.
In the next step enter appropriate details of your domain
The next step might to be enter details for winbind settings,
select domain as a security model, finally join the domain.
Make sure the samba global configuration is like below,
workgroup = EXAMPLE
   password server = dc.example.com
   realm = example.com
   security = domain
   idmap uid = 16777216-33554431
   idmap gid = 16777216-33554431
   template shell = /sbin/nologin
   winbind use default domain = false
   winbind offline logon = false

Open in new window

0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now