Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 30th October 2006, 07:03 AM
Kai-india Offline
Registered User
 
Join Date: Oct 2006
Location: Auckland, New Zealand
Age: 31
Posts: 9
Exclamation winbind and getting Active Directory Group information

Hi,

I have setup a Fedora Core 5 box running SAMBA (security = ADS), KRBv5 and SQUID with NTLM authentication. Using various guide on google I have managed to join the linux box to Windows 2003 Active directory. I did this so that I am able to use Squid to restrict certain Active directory groups from accessing the internet.

I have managed to get the ACL's in squid working fine and have tested them against different ADS groups. The problem (I think) is with winbind.

For instance I created two new ADS groups called Proxyboys and Internet on the Windows 2003 PDC. Next I created four users jack, tom, dick, harry and joined them by pair respectively to Proxyboys and Internet. I setup Squid to allow Internet group full access to the internet and Proxyboys to have no access to the internet. When I did this it worked fine. Using wbinfo -r I can see the respective group ID's of these users. In all their cases they showed with

Next I removed Harry from Internet. I restarted smb and winbind services and did a wbinfo -r harry This command still shows Harry as being of Internet group. I restarted PDC and my linux box but there is no change. I went ahead and added Harry to Proxyboys group so that he does not have internet access. Restarted smb, winbind and squid and used a XP client machine to login as Harry. PROBLEM: Harry still has internet access. I think the REASON for this is what I described above. Any group membership changes I make to users on Active Directory do not seem to replicate to the linux box.

To summarise:
1. If I add a new user or goup to Active Directory, restart winbind and use wbinfo -g or wbinfo -u, the new user or group can be seen in the list.
2. If I change an existing user's group membership, restart winbind and use wbinfo -r on the user, the user's group ID's DO NOT CHANGE. They remain the same as if the user's group membership never changed.
3. getent passwd lists users and group ID's and these are incorrect
4. getent group lists groups, the group ID and its members and this is correct.

Any help in getting this resolved will be much appreciated as I am doing this in a test environment for my degree project. I apologise if I am being vague and for not posting any .conf files but please let me know what you need. Thank you in advance
Reply With Quote
Reply

Tags
active, directory, group, information, winbind

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Kopete forgets group information for WLM/MSN contacts SpectrumDT Using Fedora 0 1st March 2009 03:54 PM
Winbind - Active Directory - Profiles AdamK Using Fedora 0 16th January 2009 11:45 AM
winbind- cannot make user authentication with Active Directory chenboly Servers & Networking 0 9th April 2008 11:08 AM
Winbind and Active Directory updates Kai-india Servers & Networking 3 1st November 2006 02:30 PM
Using FC4 with Active Directory mjarz Security and Privacy 0 29th November 2005 08:42 PM


Current GMT-time: 21:51 (Tuesday, 18-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat