<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Complete Linux-AD Authentication Details</title>
	<atom:link href="http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<pubDate>Fri, 12 Mar 2010 13:44:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nisso Moyal</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-43834</link>
		<dc:creator>Nisso Moyal</dc:creator>
		<pubDate>Wed, 11 Mar 2009 16:53:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-43834</guid>
		<description>Slowe,
forgot to mention that I have 2008 AD installed, I'm going to test your method with ubuntu clients. I saw your article about the 2008 server so I'll use that and will let you know if i have any issues.</description>
		<content:encoded><![CDATA[<p>Slowe,<br />
forgot to mention that I have 2008 AD installed, I&#8217;m going to test your method with ubuntu clients. I saw your article about the 2008 server so I&#8217;ll use that and will let you know if i have any issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-43817</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Mon, 09 Mar 2009 18:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-43817</guid>
		<description>Nisso,

I don't think that the overhead of using LDAP is going to be all that much different from the overhead of using Winbind, but I don't have any objective data one way or another.

And yes, it does work the way I describe above.</description>
		<content:encoded><![CDATA[<p>Nisso,</p>
<p>I don&#8217;t think that the overhead of using LDAP is going to be all that much different from the overhead of using Winbind, but I don&#8217;t have any objective data one way or another.</p>
<p>And yes, it does work the way I describe above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nisso Moyal</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-43815</link>
		<dc:creator>Nisso Moyal</dc:creator>
		<pubDate>Mon, 09 Mar 2009 17:06:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-43815</guid>
		<description>I'm about to add 200 linux users to my domain and thought about the option you offer but I was worried about the overhead of ldap server.
I ran into this article and thought using it through winbind
http://technet.microsoft.com/en-us/magazine/2008.12.linux.aspx

Does single sign on really work for you with the method that you described?</description>
		<content:encoded><![CDATA[<p>I&#8217;m about to add 200 linux users to my domain and thought about the option you offer but I was worried about the overhead of ldap server.<br />
I ran into this article and thought using it through winbind<br />
<a href="http://technet.microsoft.com/en-us/magazine/2008.12.linux.aspx" rel="nofollow">http://technet.microsoft.com/en-us/magazine/2008.12.linux.aspx</a></p>
<p>Does single sign on really work for you with the method that you described?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linux-AD Integration, Version 4 &#171; Junji&#8217;s Blog Site</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-40778</link>
		<dc:creator>Linux-AD Integration, Version 4 &#171; Junji&#8217;s Blog Site</dc:creator>
		<pubDate>Wed, 20 Aug 2008 08:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-40778</guid>
		<description>[...] are looking for information on using Linux with a previous version of Windows, please refer back to this article.  The only significant changes in the process involve the mapping of the LDAP attributes; [...]</description>
		<content:encoded><![CDATA[<p>[...] are looking for information on using Linux with a previous version of Windows, please refer back to this article.  The only significant changes in the process involve the mapping of the LDAP attributes; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deependra Singh Shekhawat</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-40171</link>
		<dc:creator>Deependra Singh Shekhawat</dc:creator>
		<pubDate>Sat, 26 Jul 2008 04:33:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-40171</guid>
		<description>Hi,

Very excellent tutorial. I was able to authenticate Linux machines from Active Directory on windows server 2003.

Kerberos part really helped me alot. 

Will be reading your article regarding NFS mounts next.

Again thanks alot.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Very excellent tutorial. I was able to authenticate Linux machines from Active Directory on windows server 2003.</p>
<p>Kerberos part really helped me alot. </p>
<p>Will be reading your article regarding NFS mounts next.</p>
<p>Again thanks alot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: User</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-40065</link>
		<dc:creator>User</dc:creator>
		<pubDate>Tue, 15 Jul 2008 18:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-40065</guid>
		<description>I have followed the instructions as above but without using SFU as post 3. However getent passwd username returns nothing. /etc/ldap.conf looks correct.

Can you help?</description>
		<content:encoded><![CDATA[<p>I have followed the instructions as above but without using SFU as post 3. However getent passwd username returns nothing. /etc/ldap.conf looks correct.</p>
<p>Can you help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-39666</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Tue, 01 Jul 2008 21:48:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-39666</guid>
		<description>Greg,

Great point--adding a local user is a great way to help isolate some of the different components involved in this kind of integration project. This at least lets you determine if the problem is Kerberos, LDAP, PAM, or something else entirely.

Thanks for reading!</description>
		<content:encoded><![CDATA[<p>Greg,</p>
<p>Great point&#8211;adding a local user is a great way to help isolate some of the different components involved in this kind of integration project. This at least lets you determine if the problem is Kerberos, LDAP, PAM, or something else entirely.</p>
<p>Thanks for reading!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Kenoyer</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-39660</link>
		<dc:creator>Greg Kenoyer</dc:creator>
		<pubDate>Tue, 01 Jul 2008 16:34:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-39660</guid>
		<description>Ryan,  While you may never come back to this page I thought I should just answer for future readers.  I am also on this path and am trying to tie my AD to RHEL v5.1/2 workstations.  
I encountered the same issue (able to generate tickets but cannot logon).  I was able to finally log on when I created (via adduser script) a local account that matched the AD account.  I am still trying to get the username map and the winbind methods to work...but at least I know that the other 'stuff' is working.</description>
		<content:encoded><![CDATA[<p>Ryan,  While you may never come back to this page I thought I should just answer for future readers.  I am also on this path and am trying to tie my AD to RHEL v5.1/2 workstations.<br />
I encountered the same issue (able to generate tickets but cannot logon).  I was able to finally log on when I created (via adduser script) a local account that matched the AD account.  I am still trying to get the username map and the winbind methods to work&#8230;but at least I know that the other &#8217;stuff&#8217; is working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-36215</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Thu, 13 Mar 2008 21:53:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-36215</guid>
		<description>Hi,

Just a shot in the dark to hopefully get a response.  I realize this article is a bit old.

Anyways, I've been working on Red Hat/AD authentication for a little while now and I managed to get my Red Hat version AS4 authenticating to the AD server just fine.  However, when I follow the exact same steps on a Red Hat ES3 server, it doesn't work.
Kerberos configures properly (I can generate tickets for AD users no problem) but cannot logon or anything else.
I tried making my ldap.conf file the same as yours (adding a few attributes) but still nothing.  I also read you mention there are differences between Red hat versions regarding system-auth.  Both my files are word for word identical.  
Is there something I should be doing differently for ES3 and AS4?

Thanks,
Ryan</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Just a shot in the dark to hopefully get a response.  I realize this article is a bit old.</p>
<p>Anyways, I&#8217;ve been working on Red Hat/AD authentication for a little while now and I managed to get my Red Hat version AS4 authenticating to the AD server just fine.  However, when I follow the exact same steps on a Red Hat ES3 server, it doesn&#8217;t work.<br />
Kerberos configures properly (I can generate tickets for AD users no problem) but cannot logon or anything else.<br />
I tried making my ldap.conf file the same as yours (adding a few attributes) but still nothing.  I also read you mention there are differences between Red hat versions regarding system-auth.  Both my files are word for word identical.<br />
Is there something I should be doing differently for ES3 and AS4?</p>
<p>Thanks,<br />
Ryan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://blog.scottlowe.org/2005/12/22/complete-linux-ad-authentication-details/comment-page-1/#comment-34156</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 14 Nov 2007 22:22:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=143#comment-34156</guid>
		<description>Trying to follow this, but having a hell of a time with Kerberos.  I follow the directions here and get the following Warning/Error

WARNING: Account DEVSERVER$ is not a user account (uacflags=0x1021).
WARNING: Resetting DEVSERVER$'s password may cause authentication problems if DEVSERVER$ is being used as a server.

Reset DEVSERVER$'s password [y/n]?  y
WARNING: pType and account type do not match. This might cause  problems.

I then copy the resulting keytab file to the server and try:
kinit -V -k -t ./devserver.keytab host/devserver.dsgi.us

and get the following message:
kinit(v5): Key table entry not found while getting initial credentials


Any idea what I am doing wrong?</description>
		<content:encoded><![CDATA[<p>Trying to follow this, but having a hell of a time with Kerberos.  I follow the directions here and get the following Warning/Error</p>
<p>WARNING: Account DEVSERVER$ is not a user account (uacflags=0&#215;1021).<br />
WARNING: Resetting DEVSERVER$&#8217;s password may cause authentication problems if DEVSERVER$ is being used as a server.</p>
<p>Reset DEVSERVER$&#8217;s password [y/n]?  y<br />
WARNING: pType and account type do not match. This might cause  problems.</p>
<p>I then copy the resulting keytab file to the server and try:<br />
kinit -V -k -t ./devserver.keytab host/devserver.dsgi.us</p>
<p>and get the following message:<br />
kinit(v5): Key table entry not found while getting initial credentials</p>
<p>Any idea what I am doing wrong?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
