Samba authentication to AD server

View: New views
4 Messages — Rating Filter:   Alert me  

Samba authentication to AD server

by George-45 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Greetings all;

I currently have a task to put together a SAMBA (3.2) server that can
authenticate users to our local AD server. I was told recently that in
order for that to happen, the authentication needs to be in "mixed"
mode vice "native" (whatever that means), or it won't work. Can
someone a bit more knowledgable than I confirm or deny this statement,
or point me at documents that explain the difference? Thanks in
advance.

George
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Re: Samba authentication to AD server

by Jeremy Allison :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Wed, Jul 16, 2008 at 12:59:36PM -0400, Gman wrote:
> Greetings all;
>
> I currently have a task to put together a SAMBA (3.2) server that can
> authenticate users to our local AD server. I was told recently that in
> order for that to happen, the authentication needs to be in "mixed"
> mode vice "native" (whatever that means), or it won't work. Can
> someone a bit more knowledgable than I confirm or deny this statement,
> or point me at documents that explain the difference? Thanks in
> advance.

If the Samba server is merely a member of the AD domain,
then no, you don't need to have the AD domain in mixed
mode. It will work just fine with native mode.

If the Samba server is a PDC and you need it to have
trusts with the AD domain, then yes, the AD domain must
be in mixed mode.

Hope that helps,

Jeremy.
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Re: Samba authentication to AD server

by Volker Lendecke :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Wed, Jul 16, 2008 at 01:19:17PM -0700, Jeremy Allison wrote:

> On Wed, Jul 16, 2008 at 12:59:36PM -0400, Gman wrote:
> > Greetings all;
> >
> > I currently have a task to put together a SAMBA (3.2) server that can
> > authenticate users to our local AD server. I was told recently that in
> > order for that to happen, the authentication needs to be in "mixed"
> > mode vice "native" (whatever that means), or it won't work. Can
> > someone a bit more knowledgable than I confirm or deny this statement,
> > or point me at documents that explain the difference? Thanks in
> > advance.
>
> If the Samba server is merely a member of the AD domain,
> then no, you don't need to have the AD domain in mixed
> mode. It will work just fine with native mode.
>
> If the Samba server is a PDC and you need it to have
> trusts with the AD domain, then yes, the AD domain must
> be in mixed mode.
Sorry, that's wrong. The only thing that native mode
prevents is a NT4 BDC, so old-style "net rpc vampire" won't
work anymore. Trusts should work. If they don't, please file
a bug.

Volker


--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

attachment0 (196 bytes) Download Attachment

Re: Samba authentication to AD server

by Jeremy Allison :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Wed, Jul 16, 2008 at 10:28:49PM +0200, Volker Lendecke wrote:
>
> Sorry, that's wrong. The only thing that native mode
> prevents is a NT4 BDC, so old-style "net rpc vampire" won't
> work anymore. Trusts should work. If they don't, please file
> a bug.

Ah, thanks Volker. Thanks for the correction ! It's been
a while since I had to set this up in production :-).

Jeremy.
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba
LightInTheBox - Buy quality products at wholesale price