Initial add of defaria.com
[clearscm.git] / defaria.com / blogs / Status / 2016 / 04 / configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html
1 <!DOCTYPE html>
2 <html lang="en-us" itemscope itemtype="http://schema.org/Article">
3   <head>
4     <meta charset="utf-8">
5     <meta name="description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
6     <meta name="generator" content="Movable Type 5.2.3">
7     <title>Configuring Linux to Authenticate to Active Directory using Winbind - Status</title>
8     <link rel="alternate" type="application/atom+xml" title="Recent Entries" href="http://defaria.com/blogs/Status/atom.xml">
9     <link rel="canonical" href="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
10     <meta name="viewport" content="width=device-width,initial-scale=1">
11     <link rel="stylesheet" href="http://defaria.com/blogs/Status/styles.css">
12     <!--[if lt IE 9]>
13     <link rel="stylesheet" href="http://defaria.com/blogs/Status/styles_ie.css">
14     <script src="/mt/mt-static/support/theme_static/rainier/js/html5shiv.js"></script>
15     <![endif]-->
16     
17     <link rel="start" href="http://defaria.com/blogs/Status/">
18
19     <link rel="prev" href="http://defaria.com/blogs/Status/2016/02/configuring-linux-to-authenticate-to-active-directory-using-winbind.html" title="Configuring Linux to Authenticate to Active Directory using Winbind">
20     
21     <!-- Open Graph Protocol -->
22     <meta property="og:type" content="article">
23     <meta property="og:locale" content="en-us">
24     <meta property="og:title" content="Configuring Linux to Authenticate to Active Directory using Winbind">
25     <meta property="og:url" content="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
26     <meta property="og:description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
27     <meta property="og:site_name" content="Status">
28     <meta property="og:image" content="/mt/mt-static/support/theme_static/rainier/img/siteicon-sample.png">
29     <!-- Metadata -->
30     <meta itemprop="description" content="Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses...">
31     <link itemprop="url" href="http://defaria.com/blogs/Status/2016/04/configuring-linux-to-authenticate-to-active-directory-using-winbind-1.html">
32     <link itemprop="image" href="/mt/mt-static/support/theme_static/rainier/img/siteicon-sample.png">
33     
34   </head>
35   <body>
36     <div id="container">
37       <div id="container-inner">
38         <header id="header" role="banner">
39           <div id="header-inner">
40             <div id="header-content">
41               <h1>
42                 <a href="http://defaria.com/blogs/Status/">
43
44                   Status
45
46                 </a>
47               </h1>
48               
49             </div>
50
51             <nav role="navigation">
52           <ul>
53             <li><a href="http://defaria.com/blogs/Status/">Home</a></li>
54
55
56           </ul>
57         </nav>
58
59           </div>
60         </header>
61         <div id="content">
62           <div id="content-inner">
63             <ul class="breadcrumb breadcrumb-list">
64               <li class="breadcrumb-list-item"><a href="http://defaria.com/blogs/Status/">Home</a></li>
65               <li class="breadcrumb-list-item">Configuring Linux to Authenticate to Active Directory using Winbind</li>
66             </ul>
67             <div id="individual-main" class="main" role="main">
68               <article id="entry-1998" class="entry entry-asset asset hentry">
69                 <div class="asset-header">
70                   <h2 itemprop="name" class="asset-name entry-title">Configuring Linux to Authenticate to Active Directory using Winbind</h2>
71                   <footer class="asset-meta">
72                     <ul class="asset-meta-list">
73                       <li class="asset-meta-list-item">Posted on <time datetime="2016-04-18T14:32:48-08:00" itemprop="datePublished">April 18, 2016</time></li>
74                       <li class="asset-meta-list-item">by <span class="author entry-author vcard"></span></li>
75
76   
77
78                    </ul>
79                 </footer>
80                 </div>
81                 <div class="entry-content asset-content" itemprop="articleBody">
82                   <p>Under Linux, you can use winbind from the Samba suite of tools to authenticate with Windows Active Directory. Refer to Setup CentOS to authenticate via Active Directory for how to set up CentOS to authenticate to Active directory. Windows uses Kerberos to perform authentication so you'll need to set that up. The above link talks about running authconf with lots of parameters to set it all up. That may be a better way in the end but I got it working starting with authconf then tweaking. Here are my resultant files that seem to work. Later I might figure out how to do it with authconfig.</p>
83 <ol>
84 <li>First you'll need some software if it was not previously installed. The following installs all you need for CentOS (Ubuntu still needs to be investigated for the corresponding apt-get installation):<br /><br /><span style="line-height: 1.618;">Install software<br /><br /></span><span style="line-height: 1.618;">$ yum -y install authconfig krb5-workstation pam_krb5 samba-common<br /><br /></span></li>
85 <li><span style="line-height: 1.618;">Edit /etc/krb5.conf to look like:<br /><br /></span><span style="line-height: 1.618;">/etc/krb5.conf (Audience)</span></li>
86 </ol>
87 <p style="margin-left: 30px;">[libdefaults]<br /><span style="line-height: 1.618;">default_realm = AUDIENCE.LOCAL<br /></span><span style="line-height: 1.618;">ns_lookup_realm = true<br />d</span><span style="line-height: 1.618;">ns_lookup_kdc = true<br /></span><span style="line-height: 1.618;">ticket_lifetime = 24h<br /></span><span style="line-height: 1.618;">renew_lifetime = 7d<br /></span><span style="line-height: 1.618;">forwardable = true</span></p>
88 <p style="margin-left: 30px;">[realms]<br /><span style="line-height: 1.618;">audience.com = {<br /></span><span style="line-height: 1.618;">  kdc = dc1.audience.local<br /></span><span style="line-height: 1.618;">  admin_server = dc1.audience.local<br /></span><span style="line-height: 1.618;">}</span></p>
89 <p style="margin-left: 30px;">/etc/krb5.conf (Knowles)</p>
90 <p style="margin-left: 30px;">[libdefaults]<br /><span style="line-height: 1.618;">default_realm = KNOWLES.COM<br /></span><span style="line-height: 1.618;">dns_lookup_realm = true<br /></span><span style="line-height: 1.618;">dns_lookup_kdc = true<br /></span><span style="line-height: 1.618;">ticket_lifetime = 24h<br /></span><span style="line-height: 1.618;">renew_lifetime = 7d<br /></span><span style="line-height: 1.618;">forwardable = true</span></p>
91 <p style="margin-left: 30px;">[realms]<br /><span style="line-height: 1.618;">knowles.com = {<br /></span><span style="line-height: 1.618;">  kdc = dc1.knowles.com<br /></span><span style="line-height: 1.618;">  admin_server = dc1.knowles.com<br /></span><span style="line-height: 1.618;">}</span></p>
92                   
93                 </div>
94                 <nav class="page-navigation entry-navigation pagination content-nav">
95                   <ul class="page-navigation-list">
96
97                     <li class="page-navigation-list-item page-navigation-prev"><a rel="prev" href="http://defaria.com/blogs/Status/2016/02/configuring-linux-to-authenticate-to-active-directory-using-winbind.html" title="Configuring Linux to Authenticate to Active Directory using Winbind">Previous entry</a></li>
98
99
100                   </ul>
101                 </nav>
102                 <!--
103 <aside id="zenback" class="zenback feedback">
104   Please paste Zenback script code here.
105 </aside>
106 -->
107                 
108                 
109               </article>
110             </div>
111             <aside class="widgets related" role="complementary">
112               <nav class="widget-search widget">
113   <div class="widget-content">
114     <form method="get" id="search" action="http://defaria.com/mt/mt-search.cgi">
115       <div>
116         <input type="text" name="search" value="" placeholder="Search...">
117
118         <input type="hidden" name="IncludeBlogs" value="8">
119
120         <input type="hidden" name="limit" value="20">
121         <button type="submit" name="button">
122           <img alt="Search" src="/mt/mt-static/support/theme_static/rainier/img/search-icon.png">
123         </button>
124       </div>
125     </form>
126   </div>
127 </nav>
128 <nav class="widget-archive-category widget">
129   <h3 class="widget-header">Categories</h3>
130   <div class="widget-content">
131     
132       
133     <ul class="widget-list">
134       
135       
136       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/ameriquest/">Ameriquest (99)</a>
137       
138       
139       </li>
140       
141     
142       
143       
144       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/audience/">Audience (4)</a>
145       
146       
147       </li>
148       
149     
150       
151       
152       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/broadcom/">Broadcom (76)</a>
153       
154       
155       </li>
156       
157     
158       
159       
160       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/gpdb/">GPDB (35)</a>
161       
162       
163       </li>
164       
165     
166       
167       
168       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/general-dynamics/">General Dynamics (61)</a>
169       
170       
171       </li>
172       
173     
174       
175       
176       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/general-electric/">General Electric (13)</a>
177       
178       
179       </li>
180       
181     
182       
183       
184       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/hewlett-packard/">Hewlett Packard (13)</a>
185       
186       
187       </li>
188       
189     
190       
191       
192       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/lynuxworks/">LynuxWorks (162)</a>
193       
194       
195       </li>
196       
197     
198       
199       
200       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/pqa/">PQA (35)</a>
201       
202       
203       </li>
204       
205     
206       
207       
208       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/salira/">Salira (79)</a>
209       
210       
211       </li>
212       
213     
214       
215       
216       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/tellabs/">Tellabs (2)</a>
217       
218       
219       </li>
220       
221     
222       
223       
224       <li class="widget-list-item"><a href="http://defaria.com/blogs/Status/texas-instruments/">Texas Instruments (31)</a>
225       
226       
227       </li>
228       
229     </ul>
230       
231     
232   </div>
233 </nav>
234   
235
236 <nav class="widget-archive-dropdown widget">
237   <h3 class="widget-header">Archives</h3>
238   <div class="widget-content">
239     <select>
240       <option>Select a Month...</option>
241     
242       <option value="http://defaria.com/blogs/Status/2016/04/">April 2016</option>
243     
244   
245     
246       <option value="http://defaria.com/blogs/Status/2016/02/">February 2016</option>
247     
248   
249     
250       <option value="http://defaria.com/blogs/Status/2014/09/">September 2014</option>
251     
252   
253     
254       <option value="http://defaria.com/blogs/Status/2014/04/">April 2014</option>
255     
256   
257     
258       <option value="http://defaria.com/blogs/Status/2014/03/">March 2014</option>
259     
260   
261     
262       <option value="http://defaria.com/blogs/Status/2013/02/">February 2013</option>
263     
264   
265     
266       <option value="http://defaria.com/blogs/Status/2012/09/">September 2012</option>
267     
268   
269     
270       <option value="http://defaria.com/blogs/Status/2012/08/">August 2012</option>
271     
272   
273     
274       <option value="http://defaria.com/blogs/Status/2012/05/">May 2012</option>
275     
276   
277     
278       <option value="http://defaria.com/blogs/Status/2012/04/">April 2012</option>
279     
280   
281     
282       <option value="http://defaria.com/blogs/Status/2012/02/">February 2012</option>
283     
284   
285     
286       <option value="http://defaria.com/blogs/Status/2012/01/">January 2012</option>
287     
288   
289     
290       <option value="http://defaria.com/blogs/Status/2011/10/">October 2011</option>
291     
292   
293     
294       <option value="http://defaria.com/blogs/Status/2011/07/">July 2011</option>
295     
296   
297     
298       <option value="http://defaria.com/blogs/Status/2010/09/">September 2010</option>
299     
300   
301     
302       <option value="http://defaria.com/blogs/Status/2010/08/">August 2010</option>
303     
304   
305     
306       <option value="http://defaria.com/blogs/Status/2010/04/">April 2010</option>
307     
308   
309     
310       <option value="http://defaria.com/blogs/Status/2010/03/">March 2010</option>
311     
312   
313     
314       <option value="http://defaria.com/blogs/Status/2010/02/">February 2010</option>
315     
316   
317     
318       <option value="http://defaria.com/blogs/Status/2009/05/">May 2009</option>
319     
320   
321     
322       <option value="http://defaria.com/blogs/Status/2009/04/">April 2009</option>
323     
324   
325     
326       <option value="http://defaria.com/blogs/Status/2008/07/">July 2008</option>
327     
328   
329     
330       <option value="http://defaria.com/blogs/Status/2008/05/">May 2008</option>
331     
332   
333     
334       <option value="http://defaria.com/blogs/Status/2008/04/">April 2008</option>
335     
336   
337     
338       <option value="http://defaria.com/blogs/Status/2008/03/">March 2008</option>
339     
340   
341     
342       <option value="http://defaria.com/blogs/Status/2008/02/">February 2008</option>
343     
344   
345     
346       <option value="http://defaria.com/blogs/Status/2008/01/">January 2008</option>
347     
348   
349     
350       <option value="http://defaria.com/blogs/Status/2007/12/">December 2007</option>
351     
352   
353     
354       <option value="http://defaria.com/blogs/Status/2007/11/">November 2007</option>
355     
356   
357     
358       <option value="http://defaria.com/blogs/Status/2007/10/">October 2007</option>
359     
360   
361     
362       <option value="http://defaria.com/blogs/Status/2007/09/">September 2007</option>
363     
364   
365     
366       <option value="http://defaria.com/blogs/Status/2007/08/">August 2007</option>
367     
368   
369     
370       <option value="http://defaria.com/blogs/Status/2007/07/">July 2007</option>
371     
372   
373     
374       <option value="http://defaria.com/blogs/Status/2007/06/">June 2007</option>
375     
376   
377     
378       <option value="http://defaria.com/blogs/Status/2007/05/">May 2007</option>
379     
380   
381     
382       <option value="http://defaria.com/blogs/Status/2007/04/">April 2007</option>
383     
384   
385     
386       <option value="http://defaria.com/blogs/Status/2007/03/">March 2007</option>
387     
388   
389     
390       <option value="http://defaria.com/blogs/Status/2007/01/">January 2007</option>
391     
392   
393     
394       <option value="http://defaria.com/blogs/Status/2006/12/">December 2006</option>
395     
396   
397     
398       <option value="http://defaria.com/blogs/Status/2006/11/">November 2006</option>
399     
400   
401     
402       <option value="http://defaria.com/blogs/Status/2006/10/">October 2006</option>
403     
404   
405     
406       <option value="http://defaria.com/blogs/Status/2006/09/">September 2006</option>
407     
408   
409     
410       <option value="http://defaria.com/blogs/Status/2006/07/">July 2006</option>
411     
412   
413     
414       <option value="http://defaria.com/blogs/Status/2006/06/">June 2006</option>
415     
416   
417     
418       <option value="http://defaria.com/blogs/Status/2006/05/">May 2006</option>
419     
420   
421     
422       <option value="http://defaria.com/blogs/Status/2006/04/">April 2006</option>
423     
424   
425     
426       <option value="http://defaria.com/blogs/Status/2006/03/">March 2006</option>
427     
428   
429     
430       <option value="http://defaria.com/blogs/Status/2006/02/">February 2006</option>
431     
432   
433     
434       <option value="http://defaria.com/blogs/Status/2006/01/">January 2006</option>
435     
436   
437     
438       <option value="http://defaria.com/blogs/Status/2005/12/">December 2005</option>
439     
440   
441     
442       <option value="http://defaria.com/blogs/Status/2005/11/">November 2005</option>
443     
444   
445     
446       <option value="http://defaria.com/blogs/Status/2005/10/">October 2005</option>
447     
448   
449     
450       <option value="http://defaria.com/blogs/Status/2005/09/">September 2005</option>
451     
452   
453     
454       <option value="http://defaria.com/blogs/Status/2005/08/">August 2005</option>
455     
456   
457     
458       <option value="http://defaria.com/blogs/Status/2005/07/">July 2005</option>
459     
460   
461     
462       <option value="http://defaria.com/blogs/Status/2005/06/">June 2005</option>
463     
464   
465     
466       <option value="http://defaria.com/blogs/Status/2005/05/">May 2005</option>
467     
468   
469     
470       <option value="http://defaria.com/blogs/Status/2005/04/">April 2005</option>
471     
472   
473     
474       <option value="http://defaria.com/blogs/Status/2005/03/">March 2005</option>
475     
476   
477     
478       <option value="http://defaria.com/blogs/Status/2005/02/">February 2005</option>
479     
480   
481     
482       <option value="http://defaria.com/blogs/Status/2005/01/">January 2005</option>
483     
484   
485     
486       <option value="http://defaria.com/blogs/Status/2004/12/">December 2004</option>
487     
488   
489     
490       <option value="http://defaria.com/blogs/Status/2004/09/">September 2004</option>
491     
492   
493     
494       <option value="http://defaria.com/blogs/Status/2004/08/">August 2004</option>
495     
496   
497     
498       <option value="http://defaria.com/blogs/Status/2004/07/">July 2004</option>
499     
500   
501     
502       <option value="http://defaria.com/blogs/Status/2004/06/">June 2004</option>
503     
504   
505     
506       <option value="http://defaria.com/blogs/Status/2004/05/">May 2004</option>
507     
508   
509     
510       <option value="http://defaria.com/blogs/Status/2004/04/">April 2004</option>
511     
512   
513     
514       <option value="http://defaria.com/blogs/Status/2004/03/">March 2004</option>
515     
516   
517     
518       <option value="http://defaria.com/blogs/Status/2004/02/">February 2004</option>
519     
520   
521     
522       <option value="http://defaria.com/blogs/Status/2004/01/">January 2004</option>
523     
524   
525     
526       <option value="http://defaria.com/blogs/Status/2003/12/">December 2003</option>
527     
528   
529     
530       <option value="http://defaria.com/blogs/Status/2003/11/">November 2003</option>
531     
532     </select>
533   </div>
534 </nav>
535     
536   
537
538 <div class="widget-syndication widget section">
539   <div class="widget-content">
540     <p><img src="http://defaria.com/mt/mt-static/images/status_icons/feed.gif" alt="Subscribe to feed" width="9" height="9" /> <a href="http://defaria.com/blogs/Status/atom.xml">Subscribe to this blog's feed</a></p>
541
542   </div>
543 </div>
544
545             </aside>
546           </div>
547         </div>
548         <footer id="footer" role="contentinfo">
549           <div id="footer-inner">
550             <div id="footer-content">
551   <nav role="navigation">
552           <ul>
553             <li><a href="http://defaria.com/blogs/Status/">Home</a></li>
554
555
556           </ul>
557         </nav>
558
559   <p class="license">&copy; Copyright 2016.</p>
560   <p class="poweredby">Powered by <a href="http://www.movabletype.org/">Movable Type</a></p>
561 </div>
562           </div>
563         </footer>
564       </div>
565     </div>
566     <script src="http://defaria.com/mt/mt-static/jquery/jquery.min.js"></script>
567     <script src="http://defaria.com/blogs/Status/mt-theme-scale2.js"></script>
568   </body>
569 </html>