<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Linux-AD Integration with Windows Server 2008</title>
	<atom:link href="http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:13:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Joe</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-52336</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Thu, 22 Dec 2011 22:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-52336</guid>
		<description>Thank you for this page Scott. I am so close to getting this working... kinit works, ldapsearch -x works, and if I create a local user with a username that corresponds to an AD user, I can login using the AD password. But no matter what iteration of config files I use, I cannot seem to get the machine to allow AD users to log in without having a corresponding local account.

I have asked this question on a number of forums, but no one has yet been able to assist me with this. I know that you aren&#039;t working on this stuff anymore Scott. My hope is that someone reading this page will have had the same issue and be able to respond.</description>
		<content:encoded><![CDATA[<p>Thank you for this page Scott. I am so close to getting this working&#8230; kinit works, ldapsearch -x works, and if I create a local user with a username that corresponds to an AD user, I can login using the AD password. But no matter what iteration of config files I use, I cannot seem to get the machine to allow AD users to log in without having a corresponding local account.</p>
<p>I have asked this question on a number of forums, but no one has yet been able to assist me with this. I know that you aren&#8217;t working on this stuff anymore Scott. My hope is that someone reading this page will have had the same issue and be able to respond.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-52010</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Sat, 12 Nov 2011 13:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-52010</guid>
		<description>Mc.SIM, I wish I could help but as I&#039;ve mentioned to numerous others I haven&#039;t touched this stuff in about three years or so. I leave the comments open here just in case other readers are able to respond and assist. Good luck!</description>
		<content:encoded><![CDATA[<p>Mc.SIM, I wish I could help but as I&#8217;ve mentioned to numerous others I haven&#8217;t touched this stuff in about three years or so. I leave the comments open here just in case other readers are able to respond and assist. Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mc.SIM</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-52005</link>
		<dc:creator>Mc.SIM</dc:creator>
		<pubDate>Fri, 11 Nov 2011 08:02:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-52005</guid>
		<description>after inserting in to file krb5.conf
[libdefaults]
...
        default_tkt_enctypes = rc4-hmac
        default_tgs_enctypes = rc4-hmac
        permitted_enctypes = rc4-hmac
....
krb-ticket obtained:
ARCHIV ~ # kinit -k -t /etc/krb5.keytab nfs/archiv.sag.local
ARCHIV ~ # klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: nfs/archiv.sag.local@SAG.LOCAL

Valid starting     Expires            Service principal
11/11/11 11:48:25  11/11/11 21:48:30  krbtgt/SAG.LOCAL@SAG.LOCAL
        renew until 11/12/11 11:48:25

team getting keytab as follows:

C:\Windows\system32&gt;ktpass.exe /princ nfs/archiv.sag.local@SAG.LOCAL /mapuser SAG\nfs /crypto ALL /ptype KRB5_NT_PRINCIPAL /pass 25121984 /out C:\tmp\archivkeytab
Targeting domain controller: DC.sag.local
Using legacy password setting method
Successfully mapped nfs/archiv.sag.local to nfs.
Key created.
Key created.
Key created.
Key created.
Key created.
Output keytab to C:\tmp\archivkeytab:
Keytab version: 0x502 keysize 57 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0x1 (DES-CBC-CRC) keylength 8 (0x153ea1290da8dc15)
keysize 57 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0x3 (DES-CBC-MD5) keylength 8 (0x153ea1290da8dc15)
keysize 65 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0x17 (RC4-HMAC) keylength 16 (0xff178150b60703459ae8cc430c5110cf)
keysize 81 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0x12 (AES256-SHA1) keylength 32 (0x7773839c803615d65375c23cf10b54dde94bcf2d8e1
70045e9b2ce30898f3650)
keysize 65 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0x11 (AES128-SHA1) keylength 16 (0xe1389b7c72ce329d388ad32468c46f43)</description>
		<content:encoded><![CDATA[<p>after inserting in to file krb5.conf<br />
[libdefaults]<br />
&#8230;<br />
        default_tkt_enctypes = rc4-hmac<br />
        default_tgs_enctypes = rc4-hmac<br />
        permitted_enctypes = rc4-hmac<br />
&#8230;.<br />
krb-ticket obtained:<br />
ARCHIV ~ # kinit -k -t /etc/krb5.keytab nfs/archiv.sag.local<br />
ARCHIV ~ # klist<br />
Ticket cache: FILE:/tmp/krb5cc_0<br />
Default principal: nfs/archiv.sag.local@SAG.LOCAL</p>
<p>Valid starting     Expires            Service principal<br />
11/11/11 11:48:25  11/11/11 21:48:30  krbtgt/SAG.LOCAL@SAG.LOCAL<br />
        renew until 11/12/11 11:48:25</p>
<p>team getting keytab as follows:</p>
<p>C:\Windows\system32&gt;ktpass.exe /princ nfs/archiv.sag.local@SAG.LOCAL /mapuser SAG\nfs /crypto ALL /ptype KRB5_NT_PRINCIPAL /pass 25121984 /out C:\tmp\archivkeytab<br />
Targeting domain controller: DC.sag.local<br />
Using legacy password setting method<br />
Successfully mapped nfs/archiv.sag.local to nfs.<br />
Key created.<br />
Key created.<br />
Key created.<br />
Key created.<br />
Key created.<br />
Output keytab to C:\tmp\archivkeytab:<br />
Keytab version: 0&#215;502 keysize 57 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;1 (DES-CBC-CRC) keylength 8 (0x153ea1290da8dc15)<br />
keysize 57 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;3 (DES-CBC-MD5) keylength 8 (0x153ea1290da8dc15)<br />
keysize 65 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;17 (RC4-HMAC) keylength 16 (0xff178150b60703459ae8cc430c5110cf)<br />
keysize 81 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;12 (AES256-SHA1) keylength 32 (0x7773839c803615d65375c23cf10b54dde94bcf2d8e1<br />
70045e9b2ce30898f3650)<br />
keysize 65 nfs/archiv.sag.local@SAG.LOCAL ptype 1 (KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;11 (AES128-SHA1) keylength 16 (0xe1389b7c72ce329d388ad32468c46f43)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mc.SIM</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-52000</link>
		<dc:creator>Mc.SIM</dc:creator>
		<pubDate>Thu, 10 Nov 2011 15:36:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-52000</guid>
		<description>Hello, Scott!
I&#039;m tired of fighting with Krebros)))
I can not connect the Deb and AD on Win 2k8 R2 SP1 and get correct the keytab for NFS service.
I would be very grateful for your help!
I keep getting an error:

root @ ubuntu: ~ # kinit-k-t /etc/krb5.keytab nfs/ubuntu.sag.local
kinit: Key table entry not found while getting initial credentials

keytab was created like this:
C:\Windows\system32&gt;ktpass.exe -princ nfs/ubuntu.sag.local@SAG.LOCAL -mapuser ubuntu -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL -pass *** -out C:\tmp\ubunutukeytab
Targeting domain controller: DC.sag.local
Using legacy password setting method
Successfully mapped nfs/ubuntu.sag.local to ubuntu.
Key created.
Output keytab to C:\tmp\ubunutukeytab:
Keytab version: 0x502
keysize 65 nfs/ubuntu.sag.local@SAG.LOCAL ptype 1 KRB5_NT_PRINCIPAL) vno 3 etype 0x17 (RC4-HMAC) keylength 16 (0xff178150b60703459ae8cc430c5110cf)

&quot;crypto&quot; tried to specify ALL, but the result is negative.
config krb5.conf: 

root@ubuntu:~# cat /etc/krb5.conf
[libdefaults]
        default_realm = SAG.LOCAL
        allow_weak_crypto=false

        v4_instance_resolve = false
        v4_name_convert = {
                host = {
                        rcmd = host
                        ftp = ftp
                }
                plain = {
                        something = something-else
                }
        }
        fcc-mit-ticketflags = true

[realms]
        SAG.LOCAL = {
                kdc = dc.sag.local
                admin_server = dc.sag.local
                default_domain = sag.local
        }

[domain_realm]
        .sag.local = SAG.LOCAL
        sag.local = SAG.LOCAL

[login]
        krb4_convert = true
        krb4_get_tickets = false

Very very thank you if you help me!

PS: sorry for my english</description>
		<content:encoded><![CDATA[<p>Hello, Scott!<br />
I&#8217;m tired of fighting with Krebros)))<br />
I can not connect the Deb and AD on Win 2k8 R2 SP1 and get correct the keytab for NFS service.<br />
I would be very grateful for your help!<br />
I keep getting an error:</p>
<p>root @ ubuntu: ~ # kinit-k-t /etc/krb5.keytab nfs/ubuntu.sag.local<br />
kinit: Key table entry not found while getting initial credentials</p>
<p>keytab was created like this:<br />
C:\Windows\system32&gt;ktpass.exe -princ nfs/ubuntu.sag.local@SAG.LOCAL -mapuser ubuntu -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL -pass *** -out C:\tmp\ubunutukeytab<br />
Targeting domain controller: DC.sag.local<br />
Using legacy password setting method<br />
Successfully mapped nfs/ubuntu.sag.local to ubuntu.<br />
Key created.<br />
Output keytab to C:\tmp\ubunutukeytab:<br />
Keytab version: 0&#215;502<br />
keysize 65 nfs/ubuntu.sag.local@SAG.LOCAL ptype 1 KRB5_NT_PRINCIPAL) vno 3 etype 0&#215;17 (RC4-HMAC) keylength 16 (0xff178150b60703459ae8cc430c5110cf)</p>
<p>&#8220;crypto&#8221; tried to specify ALL, but the result is negative.<br />
config krb5.conf: </p>
<p>root@ubuntu:~# cat /etc/krb5.conf<br />
[libdefaults]<br />
        default_realm = SAG.LOCAL<br />
        allow_weak_crypto=false</p>
<p>        v4_instance_resolve = false<br />
        v4_name_convert = {<br />
                host = {<br />
                        rcmd = host<br />
                        ftp = ftp<br />
                }<br />
                plain = {<br />
                        something = something-else<br />
                }<br />
        }<br />
        fcc-mit-ticketflags = true</p>
<p>[realms]<br />
        SAG.LOCAL = {<br />
                kdc = dc.sag.local<br />
                admin_server = dc.sag.local<br />
                default_domain = sag.local<br />
        }</p>
<p>[domain_realm]<br />
        .sag.local = SAG.LOCAL<br />
        sag.local = SAG.LOCAL</p>
<p>[login]<br />
        krb4_convert = true<br />
        krb4_get_tickets = false</p>
<p>Very very thank you if you help me!</p>
<p>PS: sorry for my english</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luigi</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-51865</link>
		<dc:creator>Luigi</dc:creator>
		<pubDate>Thu, 13 Oct 2011 12:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-51865</guid>
		<description>Hi, if i had only active directory user accounts, users logged in linux machines with their domain users... it is necessary to implement password synchronization?</description>
		<content:encoded><![CDATA[<p>Hi, if i had only active directory user accounts, users logged in linux machines with their domain users&#8230; it is necessary to implement password synchronization?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruuuuuubje</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-50839</link>
		<dc:creator>Ruuuuuubje</dc:creator>
		<pubDate>Mon, 16 May 2011 20:01:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-50839</guid>
		<description>for keytab information we used the microsoft page. 

http://technet.microsoft.com/en-us/library/cc753771(WS.10).aspx

can be that it&#039;s not much but helped us on afther 30 mins of searching</description>
		<content:encoded><![CDATA[<p>for keytab information we used the microsoft page. </p>
<p><a href="http://technet.microsoft.com/en-us/library/cc753771(WS.10).aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/cc753771(WS.10).aspx</a></p>
<p>can be that it&#8217;s not much but helped us on afther 30 mins of searching</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Franklin</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-50451</link>
		<dc:creator>Greg Franklin</dc:creator>
		<pubDate>Thu, 17 Mar 2011 03:51:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-50451</guid>
		<description>Paul Pham did you ever get your solution to the fail over capabilities.  I have been googling too, and havent figured it out yet.  I have a windows only AD environment, and am authenticating users agains it on the linux side.  I have it working great with only 1 DC, but have tried to get it to work with DC1 down and DC2 operating as primary DC.  Still no luck.

any input would be great.

thanks, 
Greg</description>
		<content:encoded><![CDATA[<p>Paul Pham did you ever get your solution to the fail over capabilities.  I have been googling too, and havent figured it out yet.  I have a windows only AD environment, and am authenticating users agains it on the linux side.  I have it working great with only 1 DC, but have tried to get it to work with DC1 down and DC2 operating as primary DC.  Still no luck.</p>
<p>any input would be great.</p>
<p>thanks,<br />
Greg</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzi</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-50426</link>
		<dc:creator>uzi</dc:creator>
		<pubDate>Mon, 07 Mar 2011 21:08:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-50426</guid>
		<description>Hi there,

its fairly simple to train your users to use kpasswd to change the domain user password. It&#039;s also possible to make a desktop-shortcut to a shell with kpasswd startet.
So you don&#039;t need ldap,pam ...what else.. only krb5, for password changes.

greetz from germany</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>its fairly simple to train your users to use kpasswd to change the domain user password. It&#8217;s also possible to make a desktop-shortcut to a shell with kpasswd startet.<br />
So you don&#8217;t need ldap,pam &#8230;what else.. only krb5, for password changes.</p>
<p>greetz from germany</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clement</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-50246</link>
		<dc:creator>clement</dc:creator>
		<pubDate>Thu, 10 Feb 2011 14:07:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-50246</guid>
		<description>here&#039;s the complete configuration of a Linux Server using Samba as a second Domain Controller. The first DC is a Windows Server 2008. The communication between the DC is bidirectionnal !
http://www.clementhallet.be/?p=195</description>
		<content:encoded><![CDATA[<p>here&#8217;s the complete configuration of a Linux Server using Samba as a second Domain Controller. The first DC is a Windows Server 2008. The communication between the DC is bidirectionnal !<br />
<a href="http://www.clementhallet.be/?p=195" rel="nofollow">http://www.clementhallet.be/?p=195</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Pham</title>
		<link>http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/comment-page-2/#comment-49081</link>
		<dc:creator>Paul Pham</dc:creator>
		<pubDate>Fri, 03 Sep 2010 22:26:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/2007/07/09/linux-ad-integration-with-windows-server-2008/#comment-49081</guid>
		<description>For anyone who might be curious, it is possible for DCs to be discovered in RHEL. Simply omit any references to your DC in your ldap configurations, but keep the domain configurations. Outside of that, just make sure you&#039;ve added the proper SRV records for all DCs (with appropriate priority configured). You can also add a SRV for kerberos admin interface to make your configuration completely dynamic (meaning no hardcoded hosts).</description>
		<content:encoded><![CDATA[<p>For anyone who might be curious, it is possible for DCs to be discovered in RHEL. Simply omit any references to your DC in your ldap configurations, but keep the domain configurations. Outside of that, just make sure you&#8217;ve added the proper SRV records for all DCs (with appropriate priority configured). You can also add a SRV for kerberos admin interface to make your configuration completely dynamic (meaning no hardcoded hosts).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

