Re: [Samba] nslcd / pam_ldap HowTo

2013-08-29 Thread steve
On Thu, 2013-08-29 at 01:41 +0200, Marc Muehlfeld wrote: https://wiki.samba.org/index.php/Local_user_management_and_authentication/nslcd @All: Please give some feedback. Thanks. Hi The first 4 bullets of 'Method 2' are unnecessary. Why don't we use what we already have? How about this

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-29 Thread Marc Muehlfeld
Am 29.08.2013 12:31, schrieb steve: The first 4 bullets of 'Method 2' are unnecessary. Why don't we use what we already have? How about this instead? 1. For a client joined to the domain, please skip to (3) below. 2. On the DC: Extract the machine key: samba-tool domain exportkeytab

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-29 Thread steve
On Thu, 2013-08-29 at 13:08 +0200, Marc Muehlfeld wrote: I think most companies running Samba in production don't use the latest versions of everything, because they run enterprise distributions like RHEL, SLES, Debian, etc. At work we only run self compiled software, when there's a

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-28 Thread Marc Muehlfeld
Am 27.08.2013 10:52, schrieb Marc Muehlfeld: I had a short search for 0.8 and it seems that since that, some comfortable changes where done for AD. If I have time tonight, I'll compile the latest version and try to find out the differences and comment my examples accordingly. Then the users can

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-27 Thread steve
On Tue, 2013-08-27 at 01:39 +0200, Marc Muehlfeld wrote: Hello Steve, thanks for your suggestions. Am 27.08.2013 00:40, schrieb steve: 1. Nested groups work fine with nslcd. Please use the latest version: man nslcd.conf(5) I use the version Redhat ships. I haven't used that

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-27 Thread Marc Muehlfeld
Am 27.08.2013 10:11, schrieb steve: Your distro must be still using the 0.7 series. Yes. RHEL ships 0.7.5. I had a short search for 0.8 and it seems that since that, some comfortable changes where done for AD. If I have time tonight, I'll compile the latest version and try to find out

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-26 Thread Marc Muehlfeld
Am 25.08.2013 09:27, schrieb Bruno Vane: I have some Ubuntu LTS servers running openssh server authenticating to external openldap. I installed a new Ubuntu LTS server with Samba4 to create a domain and is working very well. I managed to make a pfsense firewall authenticate users in this Samba4

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-26 Thread steve
On Tue, 2013-08-27 at 00:12 +0200, Marc Muehlfeld wrote: Am 25.08.2013 09:27, schrieb Bruno Vane: I have some Ubuntu LTS servers running openssh server authenticating to external openldap. I installed a new Ubuntu LTS server with Samba4 to create a domain and is working very well. I managed

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-26 Thread Marc Muehlfeld
Hello Steve, thanks for your suggestions. Am 27.08.2013 00:40, schrieb steve: 1. Nested groups work fine with nslcd. Please use the latest version: man nslcd.conf(5) I use the version Redhat ships. I haven't used that latest version and I think most will use the one shipped with their