<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Solaris 10-AD Integration, Version 3</title>
	<atom:link href="http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:13:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Bill</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-4/#comment-52174</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Tue, 06 Dec 2011 14:05:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-52174</guid>
		<description>Scott,
Thanks ! Your document saved me lots of time. 

Do you or anyone out there have any new info on getting 

&quot;...password management (the ability to change an AD 
password from Solaris) ..&quot; 

working ? I haven&#039;t been able to find any.
Bill</description>
		<content:encoded><![CDATA[<p>Scott,<br />
Thanks ! Your document saved me lots of time. </p>
<p>Do you or anyone out there have any new info on getting </p>
<p>&#8220;&#8230;password management (the ability to change an AD<br />
password from Solaris) ..&#8221; </p>
<p>working ? I haven&#8217;t been able to find any.<br />
Bill</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-4/#comment-51372</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 16 Aug 2011 02:33:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-51372</guid>
		<description>Thanks for your blog.

I&#039;ve  managed to get LDAPS+KRB5 working on Sol10U9, RHEL5.6, and RHEL6.0 to Win2k8R2. I&#039;m using keytabs to prove the authenticity of the KDC, and stubbornly using LDAPS rather than LDAP. 

Secondary Groups aren&#039;t working for me in Solaris nor RHEL6.

Of particular annoyance was that Window 2008 R2 doesn&#039;t like using AES256/128 for keytabs. I&#039;m using RC4-HMAC.

Doco&#039;ed here:

https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-1-set-up-windows/

https://osdude.wordpress.com/2011/08/11/authenticating-unixlinux-to-windows-2008r2-part-2-solaris-10/

https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-3-rhel-5-6/

https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-4-rhel-6-0/


etc..

cheers- chris</description>
		<content:encoded><![CDATA[<p>Thanks for your blog.</p>
<p>I&#8217;ve  managed to get LDAPS+KRB5 working on Sol10U9, RHEL5.6, and RHEL6.0 to Win2k8R2. I&#8217;m using keytabs to prove the authenticity of the KDC, and stubbornly using LDAPS rather than LDAP. </p>
<p>Secondary Groups aren&#8217;t working for me in Solaris nor RHEL6.</p>
<p>Of particular annoyance was that Window 2008 R2 doesn&#8217;t like using AES256/128 for keytabs. I&#8217;m using RC4-HMAC.</p>
<p>Doco&#8217;ed here:</p>
<p><a href="https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-1-set-up-windows/" rel="nofollow">https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-1-set-up-windows/</a></p>
<p><a href="https://osdude.wordpress.com/2011/08/11/authenticating-unixlinux-to-windows-2008r2-part-2-solaris-10/" rel="nofollow">https://osdude.wordpress.com/2011/08/11/authenticating-unixlinux-to-windows-2008r2-part-2-solaris-10/</a></p>
<p><a href="https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-3-rhel-5-6/" rel="nofollow">https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-3-rhel-5-6/</a></p>
<p><a href="https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-4-rhel-6-0/" rel="nofollow">https://osdude.wordpress.com/2011/08/12/authenticating-unixlinux-to-windows-2008r2-part-4-rhel-6-0/</a></p>
<p>etc..</p>
<p>cheers- chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil Kirsch</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-4/#comment-45914</link>
		<dc:creator>Phil Kirsch</dc:creator>
		<pubDate>Sat, 19 Sep 2009 21:05:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-45914</guid>
		<description>Hi Scott,

After many hours of looking around the internet, I was excited to find your Solaris-oriented description of how to integrate Solaris and AD. But one thing still isn&#039;t clear. What value should be entered for the &quot;proxyPassword in the ldapclient command? The administrative user password for the AD server, the root password for the Solaris system or some other value? 

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi Scott,</p>
<p>After many hours of looking around the internet, I was excited to find your Solaris-oriented description of how to integrate Solaris and AD. But one thing still isn&#8217;t clear. What value should be entered for the &#8220;proxyPassword in the ldapclient command? The administrative user password for the AD server, the root password for the Solaris system or some other value? </p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ravi Channavajhala</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-4/#comment-44365</link>
		<dc:creator>Ravi Channavajhala</dc:creator>
		<pubDate>Sat, 02 May 2009 19:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-44365</guid>
		<description>OK I forgot to mention one detail in my previous post, the net ads info command does work,  so would it still be necessary to run the net ads join just for the sake of samba?</description>
		<content:encoded><![CDATA[<p>OK I forgot to mention one detail in my previous post, the net ads info command does work,  so would it still be necessary to run the net ads join just for the sake of samba?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ravi Channavajhala</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-4/#comment-44364</link>
		<dc:creator>Ravi Channavajhala</dc:creator>
		<pubDate>Sat, 02 May 2009 19:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-44364</guid>
		<description>I got the LDAP/AD/Kerberos/NSS/PAM setup properly on Solaris 10 and I can authenticate the solaris logins via AD server.  So far so good.  Now, my problem is if I run net ads join, to get the samba going, it will try to re-create the /etc/krb5/krb5.keytab, add the computer object again in AD.  I want to avoid all this.  Because, I got a working configuration, which I dont want to upset.

I tried to run samba server without actually running net ads join, with all the proper config in smb.conf such as security = ads, encrypt passwords = yes, use kerberos keytab = true and whole shebang, but I&#039;m getting errors.  Also, I don&#039;t want to specify an explicit password server directive in the smb.conf.  Someone tell me why samba is insistent on running net ads join command and essentially duplicating what I setup already anyway?  The other problem is &quot;net ads&quot; requires windows Admin password, which I dont have.  My questions

1.  How to avoid running the net ads join altogether?
2.  If I&#039;m forced to run net ads anyway, how can I make it run as an non-admin user?  (I studied Eric Roseme&#039;s paper which is a bit dated)
3.  Even if I run net ads I don&#039;t want it to mess with krb5.keytab, Why does it have to anyway?  I already got valid tickets (generated with ktpass.exe) for the authentication supported by Samba arcfour, DES etc.

The real issue, I&#039;m trying to avoid is having to run to Windows admins every time there is an issue as the unix/windows teams are run independently.  There must be a way out of not running net ads join and still have samba work...Thanks.</description>
		<content:encoded><![CDATA[<p>I got the LDAP/AD/Kerberos/NSS/PAM setup properly on Solaris 10 and I can authenticate the solaris logins via AD server.  So far so good.  Now, my problem is if I run net ads join, to get the samba going, it will try to re-create the /etc/krb5/krb5.keytab, add the computer object again in AD.  I want to avoid all this.  Because, I got a working configuration, which I dont want to upset.</p>
<p>I tried to run samba server without actually running net ads join, with all the proper config in smb.conf such as security = ads, encrypt passwords = yes, use kerberos keytab = true and whole shebang, but I&#8217;m getting errors.  Also, I don&#8217;t want to specify an explicit password server directive in the smb.conf.  Someone tell me why samba is insistent on running net ads join command and essentially duplicating what I setup already anyway?  The other problem is &#8220;net ads&#8221; requires windows Admin password, which I dont have.  My questions</p>
<p>1.  How to avoid running the net ads join altogether?<br />
2.  If I&#8217;m forced to run net ads anyway, how can I make it run as an non-admin user?  (I studied Eric Roseme&#8217;s paper which is a bit dated)<br />
3.  Even if I run net ads I don&#8217;t want it to mess with krb5.keytab, Why does it have to anyway?  I already got valid tickets (generated with ktpass.exe) for the authentication supported by Samba arcfour, DES etc.</p>
<p>The real issue, I&#8217;m trying to avoid is having to run to Windows admins every time there is an issue as the unix/windows teams are run independently.  There must be a way out of not running net ads join and still have samba work&#8230;Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: heiner</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-3/#comment-44255</link>
		<dc:creator>heiner</dc:creator>
		<pubDate>Fri, 17 Apr 2009 09:55:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-44255</guid>
		<description>Hi Scott,

Thank you for your very helpful articles.

I&#039;m coming back with a question about supplementary groups.

I&#039;m using schema extensions provided by Windows Server 2003 R2.
All group memberships work fine when I configure ldapclient with the following mappings:
NS_LDAP_ATTRIBUTEMAP= group:memberuid=memberUid
NS_LDAP_ATTRIBUTEMAP= group:uniquemember=member
This makes it necessary to administer two attributes in AD.
In my Linux environment this is not necessary. The Linux LDAP client supports RF2307bis and follows the DN in member attribute to get the uid from the user entry.
I tried to invalidate the memberuid Attribute in Solaris by
NS_LDAP_ATTRIBUTEMAP= group:memberuid=noSuchAttribute
But this didn&#039;t help.

Is it possible to activate this RF2307bis support also in Solaris-LDAP?

Thanks
Heiner</description>
		<content:encoded><![CDATA[<p>Hi Scott,</p>
<p>Thank you for your very helpful articles.</p>
<p>I&#8217;m coming back with a question about supplementary groups.</p>
<p>I&#8217;m using schema extensions provided by Windows Server 2003 R2.<br />
All group memberships work fine when I configure ldapclient with the following mappings:<br />
NS_LDAP_ATTRIBUTEMAP= group:memberuid=memberUid<br />
NS_LDAP_ATTRIBUTEMAP= group:uniquemember=member<br />
This makes it necessary to administer two attributes in AD.<br />
In my Linux environment this is not necessary. The Linux LDAP client supports RF2307bis and follows the DN in member attribute to get the uid from the user entry.<br />
I tried to invalidate the memberuid Attribute in Solaris by<br />
NS_LDAP_ATTRIBUTEMAP= group:memberuid=noSuchAttribute<br />
But this didn&#8217;t help.</p>
<p>Is it possible to activate this RF2307bis support also in Solaris-LDAP?</p>
<p>Thanks<br />
Heiner</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BM</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-3/#comment-44254</link>
		<dc:creator>BM</dc:creator>
		<pubDate>Fri, 17 Apr 2009 05:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-44254</guid>
		<description>Can somebody explain how to get secondary groups issue solved, please share the ldapclient file, thanks in advance</description>
		<content:encoded><![CDATA[<p>Can somebody explain how to get secondary groups issue solved, please share the ldapclient file, thanks in advance</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cage</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-3/#comment-43588</link>
		<dc:creator>Cage</dc:creator>
		<pubDate>Tue, 10 Feb 2009 10:19:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-43588</guid>
		<description>Hi, Josh

“The kerberos part seems to work since since when I use kinit “ADuser” and type in the correct password nothing comes back.

However, on the ldap client side I’m having a problem where running getent “ADuser” returns nothing&quot;

Now, I have the same problem.
Can you share  which attribute mappings errors?Thanks.</description>
		<content:encoded><![CDATA[<p>Hi, Josh</p>
<p>“The kerberos part seems to work since since when I use kinit “ADuser” and type in the correct password nothing comes back.</p>
<p>However, on the ldap client side I’m having a problem where running getent “ADuser” returns nothing&#8221;</p>
<p>Now, I have the same problem.<br />
Can you share  which attribute mappings errors?Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dstan</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-3/#comment-43543</link>
		<dc:creator>dstan</dc:creator>
		<pubDate>Thu, 05 Feb 2009 13:59:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-43543</guid>
		<description>For multiple domains to work we use the UPN for login - so that everyone has to login using username@DOMAIN - it&#039;s not the best solution but it works.</description>
		<content:encoded><![CDATA[<p>For multiple domains to work we use the UPN for login &#8211; so that everyone has to login using username@DOMAIN &#8211; it&#8217;s not the best solution but it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen P. Schaefer</title>
		<link>http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/comment-page-3/#comment-43381</link>
		<dc:creator>Stephen P. Schaefer</dc:creator>
		<pubDate>Thu, 15 Jan 2009 22:52:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/04/25/solaris-10-ad-integration-version-3/#comment-43381</guid>
		<description>Note for Solaris 10: if the loginShell attribute does not have a value, the graphical login program dtgreet dumps core.</description>
		<content:encoded><![CDATA[<p>Note for Solaris 10: if the loginShell attribute does not have a value, the graphical login program dtgreet dumps core.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

