Improve company productivity with a Business Account.Sign Up

x
?
Solved

User passwords domain/samba

Posted on 2012-03-15
6
Medium Priority
?
417 Views
Last Modified: 2012-04-23
We have setup a domain in our network and we want the user passwords to expire every X days, however we do not want to have to manually change the samba share passwords for our linux file server.

Is there a way that when a users Windows (domain) password is changed that the new password can be sent to samba so they can still access the file server?
0
Comment
Question by:revo1059
  • 3
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37725331
I've worked at a few environment which had the same requirements for password changes, but never did we have to sync passwords to SAMBA.
I'm no *nix specialist but you should look into Windows and SAMBA integration.
That way your SAMBA will use AD for authentication and can query AD directly.

I think they discuss it in this post.
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0d5620db-8130-4b9b-90c2-2ee4ae367893/
0
 
LVL 5

Expert Comment

by:1ly4me
ID: 37725761
Samba with windows can be configured in two ways.
1. standalone server (Act as main DC)
2. As a domain member (Samba can authenticate users based on main DC in the domain)
However in your scenario the first option will not help, because I assume you have windows as main DC.
In the second option, you can join samba server to domain network, and samba can authenticate users based on windows DC. Whenever Samba try to authenticate, it will contact main DC for username/password match.
(I think you want to setup both windows and samba as domain controllers?)
0
 
LVL 1

Author Comment

by:revo1059
ID: 37725953
Option #2 sounds like a winner, I just need direction on how to implement it.
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
LVL 5

Expert Comment

by:1ly4me
ID: 37728878
Are you using command based samba or GUI?
0
 
LVL 1

Author Comment

by:revo1059
ID: 37729482
I can use either.
0
 
LVL 5

Accepted Solution

by:
1ly4me earned 1000 total points
ID: 37730160
Run,
#authconfig-tui and select winbind and  kerberos authentication.
In the next step enter appropriate details of your domain
The next step might to be enter details for winbind settings,
select domain as a security model, finally join the domain.
Make sure the samba global configuration is like below,
workgroup = EXAMPLE
   password server = dc.example.com
   realm = example.com
   security = domain
   idmap uid = 16777216-33554431
   idmap gid = 16777216-33554431
   template shell = /sbin/nologin
   winbind use default domain = false
   winbind offline logon = false

Open in new window

0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

The article explains the process to deploy a Self-Service password reset portal I developed a few years ago. Hopefully, it will prove useful to someone.  Any comments, bug reports etc. are welcome...
If you need to implement application level security in an Access database application or other VBA code, I strongly encourage you to take advantage of Active Directory groups.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question