OpenLDAP with Linux and Windows
Realizing the promise of Apache® Hadoop® requires the effective deployment of compute, memory, storage and networking to achieve optimal results. With its flexibility and multitude of options, it is easy to over or under provision the server infrastructure, resulting in poor performance and high TCO. Join us for an in depth, technical discussion with industry experts from leading Hadoop and server companies who will provide insights into the key considerations for designing and deploying an optimal Hadoop cluster.
Sponsored by AMD
Built-in forensics, incident response, and security with Red Hat Enterprise Linux 6
Every security policy provides guidance and requirements for ensuring adequate protection of information and data, as well as high-level technical and administrative security requirements for a system in a given environment. Traditionally, providing security for a system focuses on the confidentiality of the information on it. However, protecting the data integrity and system and data availability is just as important. For example, when processing United States intelligence information, there are three attributes that require protection: confidentiality, integrity, and availability.
Learn more about catching the bad guy in this free white paper.
Sponsored by DLT Solutions
| Designing Electronics with Linux | May 22, 2013 |
| Dynamic DNS—an Object Lesson in Problem Solving | May 21, 2013 |
| Using Salt Stack and Vagrant for Drupal Development | May 20, 2013 |
| Making Linux and Android Get Along (It's Not as Hard as It Sounds) | May 16, 2013 |
| Drupal Is a Framework: Why Everyone Needs to Understand This | May 15, 2013 |
| Home, My Backup Data Center | May 13, 2013 |
- New Products
- Linux Systems Administrator
- Senior Perl Developer
- Technical Support Rep
- UX Designer
- Web & UI Developer (JavaScript & j Query)
- Designing Electronics with Linux
- Dynamic DNS—an Object Lesson in Problem Solving
- Making Linux and Android Get Along (It's Not as Hard as It Sounds)
- Using Salt Stack and Vagrant for Drupal Development
- Reply to comment | Linux Journal
4 hours 18 min ago - Nice article, thanks for the
14 hours 59 min ago - I once had a better way I
20 hours 45 min ago - Not only you I too assumed
21 hours 2 min ago - another very interesting
22 hours 55 min ago - Reply to comment | Linux Journal
1 day 49 min ago - Reply to comment | Linux Journal
1 day 7 hours ago - Reply to comment | Linux Journal
1 day 7 hours ago - Favorite (and easily brute-forced) pw's
1 day 9 hours ago - Have you tried Boxen? It's a
1 day 15 hours ago
Enter to Win an Adafruit Pi Cobbler Breakout Kit for Raspberry Pi

It's Raspberry Pi month at Linux Journal. Each week in May, Adafruit will be giving away a Pi-related prize to a lucky, randomly drawn LJ reader. Winners will be announced weekly.
Fill out the fields below to enter to win this week's prize-- a Pi Cobbler Breakout Kit for Raspberry Pi.
Congratulations to our winners so far:
- 5-8-13, Pi Starter Pack: Jack Davis
- 5-15-13, Pi Model B 512MB RAM: Patrick Dunn
- 5-21-13, Prototyping Pi Plate Kit: Philip Kirby
- Next winner announced on 5-27-13!
Featured Jobs
| Linux Systems Administrator | Houston and Austin, Texas | Host Gator |
| Senior Perl Developer | Austin, Texas | Host Gator |
| Technical Support Rep | Houston and Austin, Texas | Host Gator |
| UX Designer | Austin, Texas | Host Gator |
| Web & UI Developer (JavaScript & j Query) | Austin, Texas | Host Gator |
Free Webinar: Hadoop
How to Build an Optimal Hadoop Cluster to Store and Maintain Unlimited Amounts of Data Using Microservers
Realizing the promise of Apache® Hadoop® requires the effective deployment of compute, memory, storage and networking to achieve optimal results. With its flexibility and multitude of options, it is easy to over or under provision the server infrastructure, resulting in poor performance and high TCO. Join us for an in depth, technical discussion with industry experts from leading Hadoop and server companies who will provide insights into the key considerations for designing and deploying an optimal Hadoop cluster.
Some of key questions to be discussed are:
- What is the “typical” Hadoop cluster and what should be installed on the different machine types?
- Why should you consider the typical workload patterns when making your hardware decisions?
- Are all microservers created equal for Hadoop deployments?
- How do I plan for expansion if I require more compute, memory, storage or networking?



Comments
Re: OpenLDAP with Linux and Windows
What about synchronizing OpenLDAP and Windows2000
schema? The differents of their schemes prevent to copy
ActiveDirectory tree in LDBM database and vice versa.
Re: OpenLDAP with Linux and Windows
Very nice. But, for use a windows2000 server with ldap server and my linux stations for conect them?
How to make it?
Thanks
Re: OpenLDAP with Linux and Windows
VERY easy.
Active Directory uses DNS and LDAP v2 and v3. Just run ldap clients on the Linux machines. Bam, you got yourself Linux workstations authenticating to a Windows 2000 domain controller. How's that for surreal?
Easier installation
The RH Server Development Project has a package that will do alot of the "hardwork" for you and set up a samba PDC with LDAP + the webmin frontend
http://rhems.sourceforge.net/
its allmost too easy
Or just use Mandrake ...
Mandrake RPMs of 2.2.5 for Mandrake 8.x built with LDAP support are available on ftp.samba.org.
The RPMs in cooker have everything but the webmin frontend running (but by default are not compiled with ldap support, just do 'rpm --rebuild --with ldap' to get it).
RPMs for 8.x will be updated soon ...
Of course, for anything later than 8.1 that also means you get ACLs, nss_wins and winbind out the box ...
Still have some work to do tracking down the webmin module.
Re: Easier installation
Anonymous, you deserve a kiss. ;-) Thank you so much.
/P
the need for TNG ?
As others have said samba supports LDAP quite well.
however, from my similar setup, It looks like TNG is needed to handle domain groups.
groups of users on the domain seems to have very limited support in the main samba (so far).
for example allowing a group of users to access a share on a server in the domain.
I think this is only possible in TNG with ACL's
If im wrong please email me
dmiller at judcom.nsw.gov.au
No ACLs in TNG
AFAIK, there aren't ACLs in TNG, and for what you want to accomplish (use domain groups on the server), you don't need domain groups, since LDAP does that for you.
The only place domain groups are useful, are on the windows boxen, and this can be accomplished (though I am not sure with LDAP) using some tools from samba-3alpha on a samba-2.2.x domain controller (it was smbgroupedit, it might have changed).
samba-2.2.x of course supports posix acls with xfs or ext2/3+betbits patch.
Re: OpenLDAP with Linux and Windows
Is there anyone who has normal Samba 2.2.x working in simmilar scenario ?
Re: OpenLDAP with Linux and Windows
Yes we have it working. At the Brigham Young University, both the CS Department and the Chemistry Department are using LDAP to drive Samba HEAD 2.2.2 Domain controllers to server windows domains. Works great. No probs at all, except for the caveat that machines joined to the domain have to exist in the local password file of the domain controller, and not in ldap because for some reason pam cannot find any unames like 'machine1$' in ldap. Other than that users are all there in LDAP. We use kerberos for authentication on our unix machines and LDAP integration with kerberos will soon be pretty tight. We're still working on some good password synchronization tools.
In the chem department, we actually have three different domains (3 samba 2.2.2 pdcs) serving from one LDAP database source. We use LDAP filters in the smb.conf file to limit domain access to particular gidNumbers. Very nice indeed.
You can contact me with questions at torriem at byu dot edu.
cheers,
Michael Torrie
Re: OpenLDAP with Linux and Windows
idealx.org has got a project like this going on...
http://samba.idealx.org
btw. what i would really like if being able to combine one of these approaches with "that dreaded exchange server"
Re: OpenLDAP with Linux and Windows
That would be interesting ....
How could we do that ..............
samba 2.2.x works fine
Samba 2.2.x has supported LDAP for quite some time, plus, you get a lot of features that are not available in samba-tng, such as ACLs, downloadable print drivers etc.
Plus, I don't think the schema for samba-tng is compatilbe with samba HEAD cvs (which will become 3.0).
Also, you might want to have samba use SSL or TLS for it's LDAP connections, otherwise you are sending windows password hashes across the network in clear text. These are easily cracked, and are password-equivalents. Of course, this mostly applies to the rest of the setup also if you don't use sasl.
But, my question now is, how would you handle linux laptops in this scenario. Windows laptops would work fine, having cached credentials from the DC, and probably having cached profiles also.
Re: OpenLDAP with Linux and Windows
It's nice to see more people using the LDAP backend in Samba, however that only TNG and the 3.0 alpha branch support it is wholly incorrect. The "stable" branch of 2.2.x has supported it for quite a while (I don't remember when it first started appearing in the official tree, but I had patches working for it before 2.2.2). As it stands, the current stable version of Samba supports LDAP very well. There are some difference between what is described here and the 3.0 and 2.x versions, the most obvious (at least on my cursory glance) being how the ldap password is specified.
Suffice it to say, for those that don't want to use unstable, development, software but want the benefits of unified logins and passwords, can (and I recommend they) use the latest and greatest Samba 2.x for windows account management.
--Shahms
OpenLDAP and LDAP integration documentation
I've made an extensive LDAP presentation and posted it at -
ftp://kalamazoolinux.org/pub/pdf/ldapv3.pdf
Greate Work, thx
Thanks alot, great work. Let me see how fast I get into ;-)
Re: OpenLDAP and LDAP integration documentation
This URL is prompting for a user id and password. Is there an open access to this?
Re: OpenLDAP and LDAP integration documentation
I suggest to everyone, who think deal with ldap, read this great document. Thank you.
Re: OpenLDAP and LDAP integration documentation
Really impressive, good work.
Re: OpenLDAP and LDAP integration documentation
Perfect !!!, great presentation !!!!, Thanks.
Re: OpenLDAP and LDAP integration documentation
Thank you, great work!
Doubt regarding connections
Hi,
How can i increase the openldap connections now it seems to be supporting 64 connections.
Ram.S