Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

User passwords domain/samba

Posted on 2012-03-15
6
Medium Priority
?
412 Views
Last Modified: 2012-04-23
We have setup a domain in our network and we want the user passwords to expire every X days, however we do not want to have to manually change the samba share passwords for our linux file server.

Is there a way that when a users Windows (domain) password is changed that the new password can be sent to samba so they can still access the file server?
0
Comment
Question by:revo1059
  • 3
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37725331
I've worked at a few environment which had the same requirements for password changes, but never did we have to sync passwords to SAMBA.
I'm no *nix specialist but you should look into Windows and SAMBA integration.
That way your SAMBA will use AD for authentication and can query AD directly.

I think they discuss it in this post.
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0d5620db-8130-4b9b-90c2-2ee4ae367893/
0
 
LVL 5

Expert Comment

by:1ly4me
ID: 37725761
Samba with windows can be configured in two ways.
1. standalone server (Act as main DC)
2. As a domain member (Samba can authenticate users based on main DC in the domain)
However in your scenario the first option will not help, because I assume you have windows as main DC.
In the second option, you can join samba server to domain network, and samba can authenticate users based on windows DC. Whenever Samba try to authenticate, it will contact main DC for username/password match.
(I think you want to setup both windows and samba as domain controllers?)
0
 
LVL 1

Author Comment

by:revo1059
ID: 37725953
Option #2 sounds like a winner, I just need direction on how to implement it.
0
Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

 
LVL 5

Expert Comment

by:1ly4me
ID: 37728878
Are you using command based samba or GUI?
0
 
LVL 1

Author Comment

by:revo1059
ID: 37729482
I can use either.
0
 
LVL 5

Accepted Solution

by:
1ly4me earned 1000 total points
ID: 37730160
Run,
#authconfig-tui and select winbind and  kerberos authentication.
In the next step enter appropriate details of your domain
The next step might to be enter details for winbind settings,
select domain as a security model, finally join the domain.
Make sure the samba global configuration is like below,
workgroup = EXAMPLE
   password server = dc.example.com
   realm = example.com
   security = domain
   idmap uid = 16777216-33554431
   idmap gid = 16777216-33554431
   template shell = /sbin/nologin
   winbind use default domain = false
   winbind offline logon = false

Open in new window

0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question