Da, se poate, trebuie sa configurezi kerberos5, samba3, dns si
eventual ldap. Win xp si 2000 workstation lucreaza default cu
kerberos, ldap si dns. NT4 a murit.
Eu acum ma chinui sa fac niste servici de linux sa foloseasca KDC-ul
de pe DC-ul de windows. Adica cu o statia bagata in domeniu sa pot sa
authentific un user pentru un serviciu de linux (de ex squid) fara ca
individul sa bage vre-o parola in afara de aia care o baga dimineata
cand intra pe statia sa.



m-ai omorat cu postul asta al tau, lasa impresia ca un Samba 3.0 poate
sa inlocuiasca lejer un w2k3, dar as zice sa luati seama si la ce zice
Samba in documentatia oficiala:


<<<Samba-3 is not, and cannot act as, an Active Directory server. It
cannot truly function as an Active Directory PDC. The protocols for
some of the functionality of Active Directory domain controllers has
been partially implemented on an experimental only basis. Please do
not expect Samba-3 to support these protocols. Do not depend on any
such functionality either now or in the future. The Samba Team may
remove these experimental features or may change their behavior. This
is mentioned for the benefit of those who have discovered secret
capabilities in Samba-3 and who have asked when this functionality
will be completed. The answer is maybe someday or maybe never!

To be sure, Samba-3 is designed to provide most of the functionality
that Microsoft Windows NT4-style domain controllers have. Samba-3 does
not have all the capabilities of Windows NT4, but it does have a
number of features that Windows NT4 domain controllers do not have. In
short, Samba-3 is not NT4 and it is not Windows Server 200x: it is not
an Active Directory server. We hope this is plain and simple enough
for all to understand. >>>


da, daca vrei doar un login autentificat centralizat pe o baza de date
useri pe un server prin opozitie cu useri definiti pe statii, e ok,
dar n-o sa faca tot ce poate un AD server
on the other hand, politici de securitate si scripturi de login
propagate la statii/useri din cate stiu face, dar mai mult nu
adica sa nu te astepti sa poti ierarhiza servere samba 3 in
forest-uri/tree-uri ca alea w2k si w2k3

_______________________________________________
RLUG mailing list
[email protected]
http://lists.lug.ro/mailman/listinfo/rlug

Raspunde prin e-mail lui