home news blogs forums events research newsletter whitepapers careers


UBM Network Computing
TechWeb
Visit our SOA/Web Services Immersion Center

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security
W O R K S H O P  
Modular Authentication for Linux

  March 4, 2002
  By Jeremy Impson

  >> continued from previous page

Windows Domain Authentication in PAM

Printer Print Full Article
Printer Print This Page
Printer Download the PDF
E-Mail E-Mail This URL
To authenticate any service in a Linux system against a Microsoft Windows domain, you need a PAM module that is not available from the Red Hat 7.2 Linux installation CD. Download it from ftp://ftp.samba.org/pub/samba/pam_smb/. As of this writing, version 1.1.6 is the latest. Put it on your Linux system, then run the following commands:

tar zxvf pam_smb-1.1.6.tar.gz

cd pam_smb

./configure

make

cp pam_smb_auth.so /lib/security/

You'll need to edit the file /etc/pam_smb.conf so it looks like this:

DOMAIN

PDC

BDC1

BDC2

DOMAIN is the name of the Windows domain, PDC is the NetBIOS name of the primary domain controller. The BDC lines, the NetBIOS names of backup domain controllers, are optional. In fact, any Windows NT or 2000 server can be used here, as long as it is in the same domain. By using the PDC and BDCs, you can be sure there is a server always up and responding. Finally, edit the file /etc/hosts and add the following lines:

192.168.1.1 pdc.domain.net pdc 192.168.1.2 bdc1.domain.net bdc1 192.168.1.3 bdc2.domain.net bdc2

The IP addresses you use are those of your PDC and BDCs, and the FQDNs (Fully Qualified Domain Names, pdc. domain.net) are the actual DNS names of those computers. The final name for each line is the NetBIOS name. This last step may not be necessary if the NetBIOS names match the DNS host name for each domain controller and if the Linux server resolves (via DNS) the domain controllersı names without using the fully qualified domain name. In other words, if the PDCıs NetBIOS name is PDC, then on the Linux server you should be able to type ping pdc and get a ping response. If not, you must edit /etc/hosts as described above. Then running ping pdc should work, as should pam_smb. See us1.samba.org/samba/ftp/docs/textdocs/ENCRYPTION.txt for more information on how the challenge-response authentication in a Windows domain works.


   Page: 1 | 2 | 3 | 4 | 5 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Media Kit  |   Briefing Centers
Other Techweb Sites:   InformationWeek Reports  |  Intelligent Enterprise  |  Light Reading  |  InformationWeek
Techweb  |  Dark Reading  |  Network Computing Germany  |   Byte & Switch  |  bMighty  |  Small Biz Resource  |  InformationWeek Analytics
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights