CentOS 6 AD Authentication

Issues related to applications and software problems
Post Reply
ekatz
Posts: 10
Joined: 2017/07/12 14:43:00

CentOS 6 AD Authentication

Post by ekatz » 2017/07/14 20:03:01

Hello guys,

We had a working procedure to integrate Linux boxed into our AD (using the following packages: authconfig krb5-workstation pam_krb5 samba-common oddjob-mkhomedir sudo ntp) - a few weeks ago we had to disable SMB v1 on our domain controllers due to vulnerability, any suggestions how to resolve this? first thing I found was samba v3 has difficulty living without SMB 1.0...

Thanks!

User avatar
TrevorH
Site Admin
Posts: 33218
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CentOS 6 AD Authentication

Post by TrevorH » 2017/07/14 21:04:27

Your first step is to make sure you have the latest samba\* packages and kernel by running yum update
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

ekatz
Posts: 10
Joined: 2017/07/12 14:43:00

Re: CentOS 6 AD Authentication

Post by ekatz » 2017/07/14 21:17:23

It is up to date (running samba-common-3.6.23-43.el6_9.x86_64 / samba-winbind-3.6.23-43.el6_9.x86_64 / samba-winbind-clients-3.6.23-43.el6_9.x86_64) - it will only work if i enable SMBv1 on the domain controller...
If there a way around it? should I look into an alternative way? (maybe sssd?)

User avatar
TrevorH
Site Admin
Posts: 33218
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CentOS 6 AD Authentication

Post by TrevorH » 2017/07/14 22:03:22

I don't know of a solution or even if there is one but I do know that the latest samba on el6 is required for some of the more recent MS fixes and also that part of the communication path goes via the kernel 'cifs' module so you definitely need the latest kernel running too if you haven't already got it.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply