[Freeipa-users] authenticate samba 3 or 4 with freeipa

Sandor Juhasz sjuhasz at chemaxon.com
Fri Mar 28 08:56:53 UTC 2014


Hello, 

i am ok to compile it myself, looking for source code. I hope that way i will be able to avoid messing 
around with the ldap tree. Any help/documentation is appreciated. 


Thanks. 

s 

----- Original Message -----

From: "Petr Spacek" <pspacek at redhat.com> 
To: freeipa-users at redhat.com 
Sent: Thursday, March 27, 2014 5:51:23 PM 
Subject: Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa 

On 27.3.2014 14:36, Sandor Juhasz wrote: 
> Hello, 
> 
> what is the best practice to authenticate samba file sharing with freeipa as auth service. 
> Either version 3 or 4 of samba is fine, as we are looking for this only for filesharing and not 
> domain service. 
> Our ipa service is hosted on CentOS 6.5. 
> The samba service is preferred to be hosted on Ubuntu Precise (12.04), later the new LTS. 
> 
> Found 3 methods, but all seem to have their issues. 
> 
> 
> 1. LDAP, ldapsam passdb backend. -> needs ldap schema modification to include fields (sambaSAMAccount, sambaGroupMapping, samabaSID) and have IPA populate those with dna plugin 
> 2. IPA, ipasam passdb backend -> did not find a working version from ipasam.so for ubuntu, mostly i did not find any 
The only how-to I'm aware of is: 
http://techslaves.org/2011/08/24/freeipa-and-samba-3-integration/ 

If you insist on Ubuntu you need to get ipasam somewhere, most likely to 
compile it yourself. 

Let us know if you are going to compile it, we can provide you some guidance. 

See the thread 'IPA - Samba / Redmine / Disable Kerberos?'. 

-- 
Petr^2 Spacek 

_______________________________________________ 
Freeipa-users mailing list 
Freeipa-users at redhat.com 
https://www.redhat.com/mailman/listinfo/freeipa-users 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140328/846c3ad9/attachment.htm>


More information about the Freeipa-users mailing list