Re: [Nolug] Radius & Tacacs+

From: Dustin Puryear <dustin_at_puryear-it.com>
Date: Mon, 19 Jan 2009 12:16:46 -0600
Message-ID: <4974C38E.1070301@puryear-it.com>

I'm not sure what you mean by "Samba can be used to validate a non-Samba
login?" Samba will authenticate any SMB/CIFS client and it will serve as
a PDC for an NT domain. You can plop it on top of your existing LDAP
user directory if you have one.

If you don't already have an LDAP store, then I'd probably consider just
doing AD. It's really not expensive and if you have several or more
Windows boxes then the increase in Windows desktop and server
manageability is really significant.

I STILL want to see you use RADIUS/TACACS+ to auth Windows clients. That
would be cool! Also, as an FYI, you can plug Windows boxes into a kerb
environment even if you aren't running AD, but then you just get authn
and nothing else.

John Souvestre wrote:
> Hi Dustin.
>
> > pam_radius_auth. Cool!
>
> Yep, it looks easy and is from a reliable source. :)
>
> > If you want to properly manage Windows boxes you will need Samba or AD.
>
> Samba can be used to validate a non-Samba login?
>
> John
>
> John Souvestre - Integrated Data Systems - (504) 355-0609
>
>
> ___________________
> Nolug mailing list
> nolug@nolug.org
>
> --
> This message was scanned by ESVA and is believed to be clean.
> Click here to report this message as spam.
> http://esva.puryear-it.com/cgi-bin/learn-msg.cgi?id=
>
>

-- 
Dustin Puryear
President and Sr. Consultant
Puryear Information Technology, LLC
225-706-8414 x112
http://www.puryear-it.com
Author, "Best Practices for Managing Linux and UNIX Servers"
  http://www.puryear-it.com/pubs/linux-unix-best-practices/
___________________
Nolug mailing list
nolug@nolug.org
Received on 01/19/09

This archive was generated by hypermail 2.2.0 : 02/17/09 EST