ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SSSD AD authentication and ubuntu 18.04

    Scheduled Pinned Locked Moved IT Discussion
    8 Posts 3 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Jame_sJ
      Jame_s
      last edited by

      has anybody got this working?
      from a clean install i followed this link
      https://help.ubuntu.com/lts/serverguide/sssd-ad.html
      and i have getent passwd working but when i try to su to the user it just stops. if i restart the sssd service it will cause su to return
      su: Authentication service cannot retrieve authentication info.
      any ideas anybody?

      1 Reply Last reply Reply Quote 1
      • ObsolesceO
        Obsolesce
        last edited by

        It works great in Fedora as of today. Just not with Samba.

        Something with something broke recently... with Samba not starting when joined to an MS AD Domain with SSSD, causing me to switch from SSSD to Winbind.

        1 Reply Last reply Reply Quote 0
        • Jame_sJ
          Jame_s
          last edited by

          what a waste of time. i canned it and went with centrify express, worked 1st time.

          ObsolesceO 1 Reply Last reply Reply Quote 0
          • ObsolesceO
            Obsolesce @Jame_s
            last edited by Obsolesce

            @jame_s said in SSSD AD authentication and ubuntu 18.04:

            what a waste of time. i canned it and went with centrify express, worked 1st time.

            Yeah third party software works. I used to use PowerBrokers Identity Services from BeyondTrust... that worked great...

            But, it's third party non-open source software.

            Now I simply use realmd and winbind:
            https://www.timothygruber.com/linux/samba-file-server-with-microsoft-ad/#Install_Packages

            Very easy to do and I know winbind is reliable. The issues I had before was with SSSD, which there's really no benefit over Winbind.

            pmonchoP 1 Reply Last reply Reply Quote 1
            • pmonchoP
              pmoncho @Obsolesce
              last edited by

              @obsolesce said in SSSD AD authentication and ubuntu 18.04:

              @jame_s said in SSSD AD authentication and ubuntu 18.04:

              what a waste of time. i canned it and went with centrify express, worked 1st time.

              Yeah third party software works. I used to use PowerBrokers Identity Services from BeyondTrust... that worked great...

              But, it's third party non-open source software.

              Now I simply use realmd and winbind:
              https://www.timothygruber.com/linux/samba-file-server-with-microsoft-ad/#Install_Packages

              Were you able to get nested groups from AD to work properly on the Samba shares without PowerBroker's software?

              Side-note - I never did get a chance to play with that. To much upgrading over the last few months.

              ObsolesceO 1 Reply Last reply Reply Quote 0
              • ObsolesceO
                Obsolesce @pmoncho
                last edited by

                @pmoncho said in SSSD AD authentication and ubuntu 18.04:

                @obsolesce said in SSSD AD authentication and ubuntu 18.04:

                @jame_s said in SSSD AD authentication and ubuntu 18.04:

                what a waste of time. i canned it and went with centrify express, worked 1st time.

                Yeah third party software works. I used to use PowerBrokers Identity Services from BeyondTrust... that worked great...

                But, it's third party non-open source software.

                Now I simply use realmd and winbind:
                https://www.timothygruber.com/linux/samba-file-server-with-microsoft-ad/#Install_Packages

                Were you able to get nested groups from AD to work properly on the Samba shares without PowerBroker's software?

                Side-note - I never did get a chance to play with that. To much upgrading over the last few months.

                Yes nested groups work in Samba.

                What does it show if you enter the command: id [email protected]?

                pmonchoP 2 Replies Last reply Reply Quote 0
                • pmonchoP
                  pmoncho @Obsolesce
                  last edited by

                  @obsolesce said in SSSD AD authentication and ubuntu 18.04:

                  @pmoncho said in SSSD AD authentication and ubuntu 18.04:

                  @obsolesce said in SSSD AD authentication and ubuntu 18.04:

                  @jame_s said in SSSD AD authentication and ubuntu 18.04:

                  what a waste of time. i canned it and went with centrify express, worked 1st time.

                  Yeah third party software works. I used to use PowerBrokers Identity Services from BeyondTrust... that worked great...

                  But, it's third party non-open source software.

                  Now I simply use realmd and winbind:
                  https://www.timothygruber.com/linux/samba-file-server-with-microsoft-ad/#Install_Packages

                  Were you able to get nested groups from AD to work properly on the Samba shares without PowerBroker's software?

                  Side-note - I never did get a chance to play with that. To much upgrading over the last few months.

                  Yes nested groups work in Samba.

                  What does it show if you enter the command: id [email protected]?

                  I don't have that server running at the moment but will check as soon as I can.

                  1 Reply Last reply Reply Quote 0
                  • pmonchoP
                    pmoncho @Obsolesce
                    last edited by

                    @obsolesce said in SSSD AD authentication and ubuntu 18.04:

                    @pmoncho said in SSSD AD authentication and ubuntu 18.04:

                    @obsolesce said in SSSD AD authentication and ubuntu 18.04:

                    @jame_s said in SSSD AD authentication and ubuntu 18.04:

                    what a waste of time. i canned it and went with centrify express, worked 1st time.

                    Yeah third party software works. I used to use PowerBrokers Identity Services from BeyondTrust... that worked great...

                    But, it's third party non-open source software.

                    Now I simply use realmd and winbind:
                    https://www.timothygruber.com/linux/samba-file-server-with-microsoft-ad/#Install_Packages

                    Were you able to get nested groups from AD to work properly on the Samba shares without PowerBroker's software?

                    Side-note - I never did get a chance to play with that. To much upgrading over the last few months.

                    Yes nested groups work in Samba.

                    What does it show if you enter the command: id [email protected]?

                    Booted up the server yesterday and it only has ubuntu 16.04.
                    id [email protected] - no such user

                    I am going to use your notes and build a new server with Fedora and see if I have any sticking points.

                    Ultimate goal - We use a linux fax server that puts pdf's into each users folder on the share based on the phone number. I am trying to figure out how lock down each users folder using RBAC with nested groups from AD. If that's possible at all.

                    Trying to move away from Windows in the future. Don't know how successful I will be.

                    1 Reply Last reply Reply Quote 1
                    • 1 / 1
                    • First post
                      Last post