ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Large network of Windows machines without AD - GO!

    Scheduled Pinned Locked Moved IT Discussion
    68 Posts 10 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • notverypunnyN
      notverypunny @scottalanmiller
      last edited by

      @scottalanmiller said in Large network of Windows machines without AD - GO!:

      @notverypunny said in Large network of Windows machines without AD - GO!:

      Would something like Zentyal be appropriate?

      Just a package of Samba 4 which is just a third party AD. So this is just another way of saying to use Samba, which is another way of saying "keep AD." 🙂

      If the question is "how can I more affordably do AD", then Zentyal is a great AD distro. But if the question is "how do I ditch AD", Zentyal isn't ditching it at all.

      Fair enough, I read "without AD" and my mind went to "without M$"

      1 Reply Last reply Reply Quote 0
      • 1
        1337
        last edited by

        Would this be an option if you wanted central authentication in Windows without any AD or AD clone?

        https://www.freeipa.org/page/Windows_authentication_against_FreeIPA

        The way I understand it you could use this setup to authenticate your local account on Windows.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @1337
          last edited by

          @Pete-S said in Large network of Windows machines without AD - GO!:

          Would this be an option if you wanted central authentication in Windows without any AD or AD clone?

          https://www.freeipa.org/page/Windows_authentication_against_FreeIPA

          The way I understand it you could use this setup to authenticate your local account on Windows.

          Authenticate, yes. But FreeIPA isn't meant to do that, doesn't work well for it, and they themselves say that you should use Samba instead as it is meant for that.

          1 1 Reply Last reply Reply Quote 0
          • 1
            1337 @scottalanmiller
            last edited by

            @scottalanmiller said in Large network of Windows machines without AD - GO!:

            @Pete-S said in Large network of Windows machines without AD - GO!:

            Would this be an option if you wanted central authentication in Windows without any AD or AD clone?

            https://www.freeipa.org/page/Windows_authentication_against_FreeIPA

            The way I understand it you could use this setup to authenticate your local account on Windows.

            Authenticate, yes. But FreeIPA isn't meant to do that, doesn't work well for it, and they themselves say that you should use Samba instead as it is meant for that.

            But the point wasn't the product. The point was that it looks like you can authenticate local users on Windows against anything that supports Kerberos. So you can still use central authentication for your Windows clients (that can be be shared with linux, web apps and whatever) without using AD or anything in the entire windows ecosystem. I didn't know that was even possible but maybe it is old news for you guys working with this stuff everyday.

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @1337
              last edited by

              @Pete-S said in Large network of Windows machines without AD - GO!:

              @scottalanmiller said in Large network of Windows machines without AD - GO!:

              @Pete-S said in Large network of Windows machines without AD - GO!:

              Would this be an option if you wanted central authentication in Windows without any AD or AD clone?

              https://www.freeipa.org/page/Windows_authentication_against_FreeIPA

              The way I understand it you could use this setup to authenticate your local account on Windows.

              Authenticate, yes. But FreeIPA isn't meant to do that, doesn't work well for it, and they themselves say that you should use Samba instead as it is meant for that.

              But the point wasn't the product. The point was that it looks like you can authenticate local users on Windows against anything that supports Kerberos. So you can still use central authentication for your Windows clients (that can be be shared with linux, web apps and whatever) without using AD or anything in the entire windows ecosystem. I didn't know that was even possible but maybe it is old news for you guys working with this stuff everyday.

              You can do full AD without anything in the Windows ecosystem. You can do Linux AD server side, and Linux clients and never have Windows code at all and be all on AD. You don't, normally, as it is too heavy to bother with if you don't have Windows somewhere. But it works. AD is just a heavy version of LDAP that is classic to UNIX.

              FreeIPA is expected to be used either in an all Linux world, or in a hybrid world with AD handling the Windows side of things (but they recommend Linux based AD.)

              1 1 Reply Last reply Reply Quote 0
              • 1
                1337 @scottalanmiller
                last edited by

                @scottalanmiller said in Large network of Windows machines without AD - GO!:

                @Pete-S said in Large network of Windows machines without AD - GO!:

                @scottalanmiller said in Large network of Windows machines without AD - GO!:

                @Pete-S said in Large network of Windows machines without AD - GO!:

                Would this be an option if you wanted central authentication in Windows without any AD or AD clone?

                https://www.freeipa.org/page/Windows_authentication_against_FreeIPA

                The way I understand it you could use this setup to authenticate your local account on Windows.

                Authenticate, yes. But FreeIPA isn't meant to do that, doesn't work well for it, and they themselves say that you should use Samba instead as it is meant for that.

                But the point wasn't the product. The point was that it looks like you can authenticate local users on Windows against anything that supports Kerberos. So you can still use central authentication for your Windows clients (that can be be shared with linux, web apps and whatever) without using AD or anything in the entire windows ecosystem. I didn't know that was even possible but maybe it is old news for you guys working with this stuff everyday.

                You can do full AD without anything in the Windows ecosystem. You can do Linux AD server side, and Linux clients and never have Windows code at all and be all on AD. You don't, normally, as it is too heavy to bother with if you don't have Windows somewhere. But it works. AD is just a heavy version of LDAP that is classic to UNIX.

                FreeIPA is expected to be used either in an all Linux world, or in a hybrid world with AD handling the Windows side of things (but they recommend Linux based AD.)

                OK, thanks.

                K 1 Reply Last reply Reply Quote 0
                • K
                  krisleslie @1337
                  last edited by

                  😞

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @krisleslie
                    last edited by

                    @krisleslie said in Large network of Windows machines without AD - GO!:

                    😞

                    eh?

                    1 Reply Last reply Reply Quote 0
                    • 1
                    • 2
                    • 3
                    • 4
                    • 4 / 4
                    • First post
                      Last post