2 <html lang="en-us" itemscope itemtype="http://schema.org/Article">
5 <meta name="description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
6 <meta name="generator" content="Movable Type 5.2.3">
7 <title>Configuring Linux to Authenticate to Active Directory using Winbind - Status</title>
8 <link rel="alternate" type="application/atom+xml" title="Recent Entries" href="http://defaria.com/blogs/Status/atom.xml">
9 <link rel="canonical" href="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
10 <meta name="viewport" content="width=device-width,initial-scale=1">
11 <link rel="stylesheet" href="http://defaria.com/blogs/Status/styles.css">
13 <link rel="stylesheet" href="http://defaria.com/blogs/Status/styles_ie.css">
14 <script src="/mt/mt-static/support/theme_static/rainier/js/html5shiv.js"></script>
17 <link rel="start" href="http://defaria.com/blogs/Status/">
19 <link rel="prev" href="http://defaria.com/blogs/Status/2016/02/configuring-linux-to-authenticate-to-active-directory-using-winbind.html" title="Configuring Linux to Authenticate to Active Directory using Winbind">
21 <!-- Open Graph Protocol -->
22 <meta property="og:type" content="article">
23 <meta property="og:locale" content="en-us">
24 <meta property="og:title" content="Configuring Linux to Authenticate to Active Directory using Winbind">
25 <meta property="og:url" content="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
26 <meta property="og:description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
27 <meta property="og:site_name" content="Status">
28 <meta property="og:image" content="/mt/mt-static/support/theme_static/rainier/img/siteicon-sample.png">
30 <meta itemprop="description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
31 <link itemprop="url" href="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
32 <link itemprop="image" href="/mt/mt-static/support/theme_static/rainier/img/siteicon-sample.png">
37 <div id="container-inner">
38 <header id="header" role="banner">
39 <div id="header-inner">
40 <div id="header-content">
42 <a href="http://defaria.com/blogs/Status/">
51 <nav role="navigation">
53 <li><a href="http://defaria.com/blogs/Status/">Home</a></li>
62 <div id="content-inner">
63 <ul class="breadcrumb breadcrumb-list">
64 <li class="breadcrumb-list-item"><a href="http://defaria.com/blogs/Status/">Home</a></li>
65 <li class="breadcrumb-list-item">Configuring Linux to Authenticate to Active Directory using Winbind</li>
67 <div id="individual-main" class="main" role="main">
68 <article id="entry-1998" class="entry entry-asset asset hentry">
69 <div class="asset-header">
70 <h2 itemprop="name" class="asset-name entry-title">Configuring Linux to Authenticate to Active Directory using Winbind</h2>
71 <footer class="asset-meta">
72 <ul class="asset-meta-list">
73 <li class="asset-meta-list-item">Posted on <time datetime="2016-04-18T14:32:48-08:00" itemprop="datePublished">April 18, 2016</time></li>
74 <li class="asset-meta-list-item">by <span class="author entry-author vcard"></span></li>
81 <div class="entry-content asset-content" itemprop="articleBody">
82 <p>Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses Kerberos to perform authentication so you'll need to set that up. The above link talks about running authconf with lots of parameters to set it all up. That may be a better way in the end but I got it working starting with authconf then tweaking. Here are my resultant files that seem to work. Later I might figure out how to do it with authconfig.</p>
84 <li>First you'll need some software if it was not previously installed. The following installs all you need for CentOS (Ubuntu still needs to be investigated for the corresponding apt-get installation):<br /><br /><span style="line-height: 1.618;">Install software<br /><br /></span><span style="line-height: 1.618;">$ yum -y install authconfig krb5-workstation pam_krb5 samba-common<br /><br /></span></li>
85 <li><span style="line-height: 1.618;">Edit /etc/krb5.conf to look like:<br /><br /></span><span style="line-height: 1.618;">/etc/krb5.conf (Audience)</span></li>
87 <p style="margin-left: 30px;">[libdefaults]<br /><span style="line-height: 1.618;">default_realm = AUDIENCE.LOCAL<br /></span><span style="line-height: 1.618;">ns_lookup_realm = true<br />d</span><span style="line-height: 1.618;">ns_lookup_kdc = true<br /></span><span style="line-height: 1.618;">ticket_lifetime = 24h<br /></span><span style="line-height: 1.618;">renew_lifetime = 7d<br /></span><span style="line-height: 1.618;">forwardable = true</span></p>
88 <p style="margin-left: 30px;">[realms]<br /><span style="line-height: 1.618;">audience.com = {<br /></span><span style="line-height: 1.618;"> kdc = dc1.audience.local<br /></span><span style="line-height: 1.618;"> admin_server = dc1.audience.local<br /></span><span style="line-height: 1.618;">}</span></p>
89 <p style="margin-left: 30px;">/etc/krb5.conf (Knowles)</p>
90 <p style="margin-left: 30px;">[libdefaults]<br /><span style="line-height: 1.618;">default_realm = KNOWLES.COM<br /></span><span style="line-height: 1.618;">dns_lookup_realm = true<br /></span><span style="line-height: 1.618;">dns_lookup_kdc = true<br /></span><span style="line-height: 1.618;">ticket_lifetime = 24h<br /></span><span style="line-height: 1.618;">renew_lifetime = 7d<br /></span><span style="line-height: 1.618;">forwardable = true</span></p>
91 <p style="margin-left: 30px;">[realms]<br /><span style="line-height: 1.618;">knowles.com = {<br /></span><span style="line-height: 1.618;"> kdc = dc1.knowles.com<br /></span><span style="line-height: 1.618;"> admin_server = dc1.knowles.com<br /></span><span style="line-height: 1.618;">}</span></p>
94 <nav class="page-navigation entry-navigation pagination content-nav">
95 <ul class="page-navigation-list">
97 <li class="page-navigation-list-item page-navigation-prev"><a rel="prev" href="http://defaria.com/blogs/Status/2016/02/configuring-linux-to-authenticate-to-active-directory-using-winbind.html" title="Configuring Linux to Authenticate to Active Directory using Winbind">Previous entry</a></li>
103 <aside id="zenback" class="zenback feedback">
104 Please paste Zenback script code here.
111 <aside class="widgets related" role="complementary">
112 <nav class="widget-search widget">
113 <div class="widget-content">
114 <form method="get" id="search" action="http://defaria.com/mt/mt-search.cgi">
116 <input type="text" name="search" value="" placeholder="Search...">
118 <input type="hidden" name="IncludeBlogs" value="8">
120 <input type="hidden" name="limit" value="20">
121 <button type="submit" name="button">
122 <img alt="Search" src="/mt/mt-static/support/theme_static/rainier/img/search-icon.png">
128 <nav class="widget-archive-category widget">
129 <h3 class="widget-header">Categories</h3>
130 <div class="widget-content">
133 <ul class="widget-list">
136 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/ameriquest/">Ameriquest (99)</a>
144 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/audience/">Audience (4)</a>
152 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/broadcom/">Broadcom (76)</a>
160 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/gpdb/">GPDB (35)</a>
168 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/general-dynamics/">General Dynamics (61)</a>
176 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/general-electric/">General Electric (13)</a>
184 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/hewlett-packard/">Hewlett Packard (13)</a>
192 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/lynuxworks/">LynuxWorks (162)</a>
200 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/pqa/">PQA (35)</a>
208 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/salira/">Salira (79)</a>
216 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/tellabs/">Tellabs (2)</a>
224 <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/texas-instruments/">Texas Instruments (31)</a>
236 <nav class="widget-archive-dropdown widget">
237 <h3 class="widget-header">Archives</h3>
238 <div class="widget-content">
240 <option>Select a Month...</option>
242 <option value="http://defaria.com/blogs/Status/2016/04/">April 2016</option>
246 <option value="http://defaria.com/blogs/Status/2016/02/">February 2016</option>
250 <option value="http://defaria.com/blogs/Status/2014/09/">September 2014</option>
254 <option value="http://defaria.com/blogs/Status/2014/04/">April 2014</option>
258 <option value="http://defaria.com/blogs/Status/2014/03/">March 2014</option>
262 <option value="http://defaria.com/blogs/Status/2013/02/">February 2013</option>
266 <option value="http://defaria.com/blogs/Status/2012/09/">September 2012</option>
270 <option value="http://defaria.com/blogs/Status/2012/08/">August 2012</option>
274 <option value="http://defaria.com/blogs/Status/2012/05/">May 2012</option>
278 <option value="http://defaria.com/blogs/Status/2012/04/">April 2012</option>
282 <option value="http://defaria.com/blogs/Status/2012/02/">February 2012</option>
286 <option value="http://defaria.com/blogs/Status/2012/01/">January 2012</option>
290 <option value="http://defaria.com/blogs/Status/2011/10/">October 2011</option>
294 <option value="http://defaria.com/blogs/Status/2011/07/">July 2011</option>
298 <option value="http://defaria.com/blogs/Status/2010/09/">September 2010</option>
302 <option value="http://defaria.com/blogs/Status/2010/08/">August 2010</option>
306 <option value="http://defaria.com/blogs/Status/2010/04/">April 2010</option>
310 <option value="http://defaria.com/blogs/Status/2010/03/">March 2010</option>
314 <option value="http://defaria.com/blogs/Status/2010/02/">February 2010</option>
318 <option value="http://defaria.com/blogs/Status/2009/05/">May 2009</option>
322 <option value="http://defaria.com/blogs/Status/2009/04/">April 2009</option>
326 <option value="http://defaria.com/blogs/Status/2008/07/">July 2008</option>
330 <option value="http://defaria.com/blogs/Status/2008/05/">May 2008</option>
334 <option value="http://defaria.com/blogs/Status/2008/04/">April 2008</option>
338 <option value="http://defaria.com/blogs/Status/2008/03/">March 2008</option>
342 <option value="http://defaria.com/blogs/Status/2008/02/">February 2008</option>
346 <option value="http://defaria.com/blogs/Status/2008/01/">January 2008</option>
350 <option value="http://defaria.com/blogs/Status/2007/12/">December 2007</option>
354 <option value="http://defaria.com/blogs/Status/2007/11/">November 2007</option>
358 <option value="http://defaria.com/blogs/Status/2007/10/">October 2007</option>
362 <option value="http://defaria.com/blogs/Status/2007/09/">September 2007</option>
366 <option value="http://defaria.com/blogs/Status/2007/08/">August 2007</option>
370 <option value="http://defaria.com/blogs/Status/2007/07/">July 2007</option>
374 <option value="http://defaria.com/blogs/Status/2007/06/">June 2007</option>
378 <option value="http://defaria.com/blogs/Status/2007/05/">May 2007</option>
382 <option value="http://defaria.com/blogs/Status/2007/04/">April 2007</option>
386 <option value="http://defaria.com/blogs/Status/2007/03/">March 2007</option>
390 <option value="http://defaria.com/blogs/Status/2007/01/">January 2007</option>
394 <option value="http://defaria.com/blogs/Status/2006/12/">December 2006</option>
398 <option value="http://defaria.com/blogs/Status/2006/11/">November 2006</option>
402 <option value="http://defaria.com/blogs/Status/2006/10/">October 2006</option>
406 <option value="http://defaria.com/blogs/Status/2006/09/">September 2006</option>
410 <option value="http://defaria.com/blogs/Status/2006/07/">July 2006</option>
414 <option value="http://defaria.com/blogs/Status/2006/06/">June 2006</option>
418 <option value="http://defaria.com/blogs/Status/2006/05/">May 2006</option>
422 <option value="http://defaria.com/blogs/Status/2006/04/">April 2006</option>
426 <option value="http://defaria.com/blogs/Status/2006/03/">March 2006</option>
430 <option value="http://defaria.com/blogs/Status/2006/02/">February 2006</option>
434 <option value="http://defaria.com/blogs/Status/2006/01/">January 2006</option>
438 <option value="http://defaria.com/blogs/Status/2005/12/">December 2005</option>
442 <option value="http://defaria.com/blogs/Status/2005/11/">November 2005</option>
446 <option value="http://defaria.com/blogs/Status/2005/10/">October 2005</option>
450 <option value="http://defaria.com/blogs/Status/2005/09/">September 2005</option>
454 <option value="http://defaria.com/blogs/Status/2005/08/">August 2005</option>
458 <option value="http://defaria.com/blogs/Status/2005/07/">July 2005</option>
462 <option value="http://defaria.com/blogs/Status/2005/06/">June 2005</option>
466 <option value="http://defaria.com/blogs/Status/2005/05/">May 2005</option>
470 <option value="http://defaria.com/blogs/Status/2005/04/">April 2005</option>
474 <option value="http://defaria.com/blogs/Status/2005/03/">March 2005</option>
478 <option value="http://defaria.com/blogs/Status/2005/02/">February 2005</option>
482 <option value="http://defaria.com/blogs/Status/2005/01/">January 2005</option>
486 <option value="http://defaria.com/blogs/Status/2004/12/">December 2004</option>
490 <option value="http://defaria.com/blogs/Status/2004/09/">September 2004</option>
494 <option value="http://defaria.com/blogs/Status/2004/08/">August 2004</option>
498 <option value="http://defaria.com/blogs/Status/2004/07/">July 2004</option>
502 <option value="http://defaria.com/blogs/Status/2004/06/">June 2004</option>
506 <option value="http://defaria.com/blogs/Status/2004/05/">May 2004</option>
510 <option value="http://defaria.com/blogs/Status/2004/04/">April 2004</option>
514 <option value="http://defaria.com/blogs/Status/2004/03/">March 2004</option>
518 <option value="http://defaria.com/blogs/Status/2004/02/">February 2004</option>
522 <option value="http://defaria.com/blogs/Status/2004/01/">January 2004</option>
526 <option value="http://defaria.com/blogs/Status/2003/12/">December 2003</option>
530 <option value="http://defaria.com/blogs/Status/2003/11/">November 2003</option>
538 <div class="widget-syndication widget section">
539 <div class="widget-content">
540 <p><img src="http://defaria.com/mt/mt-static/images/status_icons/feed.gif" alt="Subscribe to feed" width="9" height="9" /> <a href="http://defaria.com/blogs/Status/atom.xml">Subscribe to this blog's feed</a></p>
548 <footer id="footer" role="contentinfo">
549 <div id="footer-inner">
550 <div id="footer-content">
551 <nav role="navigation">
553 <li><a href="http://defaria.com/blogs/Status/">Home</a></li>
559 <p class="license">© Copyright 2016.</p>
560 <p class="poweredby">Powered by <a href="http://www.movabletype.org/">Movable Type</a></p>
566 <script src="http://defaria.com/mt/mt-static/jquery/jquery.min.js"></script>
567 <script src="http://defaria.com/blogs/Status/mt-theme-scale2.js"></script>