CentOS Icon CentOS Logo
CentOS Text
   
  
www.centos.org Forum Index
   CentOS 5 - Server Support
  Replace Active Directory How to

 

 Bottom   Previous Topic   Next Topic
  •  Rate Thread
      Rate this Thread
      Excellent
      Good
      Average
      Bad
      Terrible
Poster Thread
  •  bbehrendt
      bbehrendt
Replace Active Directory How to
#1
Newbie
Joined: 2009/11/4
From
Posts: 1
I am soon going to need to either replace my Windows 2003 active directory with 2008 server or find another solution. I would prefer to use a linux server for authentication but I will need the same configuration features.

I have been looking for a good guide to setting up CentOS as an alternative to Active Directory, but have not found one yet.

The features I want to see.
1. works with Windows clients.
2. Network Home folders (does not neessisarly need to hold profile information)
3. Logon scripts for clients.
4. shared printers
5. shared folders.
6. can log linux boxes in with the same credentials and logon scripts.

-bj
Posted on: 2009/11/4 18:07
Create PDF from Post Print
Top
  •  scottro
      scottro
Re: Replace Active Directory How to
#2
Professional Board Member
Joined: 2007/9/3
From NYC
Posts: 666
There are several directory servers that should be able to do this.

OpenLdap, Centos or Fedora Directory Server, Sun Directory Server, Sun OpenDirectory (I think that's the name).

As for documentation comparable to Windows documentation in setup--hrrm, if you find it, let me know. I would say out of the bunch that Fedora Directory server is probably the best documented.

DISCLAIMER--I've only used OpenLDAP and Sun Directory server, and have not done all the things mentioned in your requirements.

I think I would start by reading the docs for Fedora Directory server, and see if it's worth a try. I recommend it over the CentOS one simply because it's been around a bit longer. (It's now called the 389 directory server.)

http://directory.fedoraproject.org/
Posted on: 2009/11/4 18:22
Create PDF from Post Print
Top
  •  arrfab
      arrfab
Re: Replace Active Directory How to
#3
Moderator
Joined: 2005/1/3
From /country/belgium
Posts: 859
Here are the answers (based on Samba/OpenLDAP backend)

1. works with Windows clients. -> yes
2. Network Home folders (does not neessisarly need to hold profile information) -> yes
3. Logon scripts for clients. -> yes (for windows machines)
4. shared printers -> yes
5. shared folders. -> yes
6. can log linux boxes in with the same credentials and logon scripts. -> yes

But forget about all those AD only features like GPOs.
You have to know that there is no way to migrate from AD to Samba/Openldap meaning that you have to create a new domain and "migrate" all users/groups/machines from AD to the Samba "NT4 style" domain, etc, etc ...
_________________
idea=`grep -i clue /dev/brain` ; test -z "$idea" && echo "sorry, init 6 in progress" || sh ./answer-the-forum
Posted on: 2009/11/4 19:18
Create PDF from Post Print
Top
  •  yyagol
      yyagol
Re: Replace Active Directory How to
#4
Professional Board Member
Joined: 2006/6/10
From Tel-Aviv ,Israel
Posts: 769
One solution i found for GPOs is
by running them at login script on group based as simple registry batch editing lines
but it takes long time to figure all keys
_________________
P Save a tree...please don't print this unless you really need to
Posted on: 2009/11/6 21:47
Create PDF from Post Print
Top
 Top   Previous Topic   Next Topic

 


 You cannot start a new topic.
 You can view topic.
 You cannot reply to posts.
 You cannot edit your posts.
 You cannot delete your posts.
 You cannot add new polls.
 You cannot vote in polls.
 You cannot attach files to posts.
 You cannot post without approval.




"Linux" is a registered trademark of Linus Torvalds. | All other trademarks are property of their respective owners. | All other content is Copyright @ 2004-2009 by the CentOS Project or "each individual contributor (forums, comments, etc.) unless otherwise assigned".| Theme based on a theme by 7dana.com