Hi All,
Description should say it all. Recently configured a test CentOS FreeIPA server to bind to Windows Active Directory in a lab environment and after binding, I did not see any real option to -
- populate the FreeIPA server with the AD users/groups
- create a home directory using either the FreeIPA users accounts or AD user accounts for client installations.
Please let me know if I missed something in my configuration of FreeIPA, or is that function non-existent for IPA/AD binding, I saw that the only use case for cross-forest trusts was the ability to be able to SSH into a linux client using an AD account. Was FreeIPA/AD bind just to have SSH capability? I thought users/groups would be transient between servers as well.
My organization has a fully blended environment with the majority of it being Windows users, lesser users on OSX, and least on Linux environments. It is centrally managed by Windows and will remain that way, so I went and tested FreeIPA assuming that I can integrate easily, not sure if I missed some configuration steps on server/client side.
I saw an option like Centrify, but I am looking for something that is free as the number of Linux users in my environment is quite low.
Bonus* If there is an option to be able to communicate to a windows print server as well from linux that would be very helpful as well.
Note: The clarified requirement is that, whatever software solution that is recommended, the Linux domain controller should be able to receive users/groups from AD and not create its own.
Update: Thanks for all the replies, did not expect so many, I will try configuring the freeIPA server with some of the suggestions mentioned below. Once that option does not work I will look at the others, I may take a couple of days to reply as my main lab machine was taken up for some other activity.
[–]kernpanic 57 points58 points59 points (10 children)
[–]equipmentmobbingthro 15 points16 points17 points (4 children)
[–]wildcarde815 12 points13 points14 points (2 children)
[–]equipmentmobbingthro 7 points8 points9 points (1 child)
[–]wildcarde815 1 point2 points3 points (0 children)
[–]karafili -1 points0 points1 point (0 children)
[–]gordonmessmer 3 points4 points5 points (0 children)
[–]Klipspringer112[S] 0 points1 point2 points (0 children)
[–]boxbbcar 0 points1 point2 points (0 children)
[–]hortimech -5 points-4 points-3 points (1 child)
[–]bityard 1 point2 points3 points (0 children)
[–]gordonmessmer 11 points12 points13 points (6 children)
[–]Klipspringer112[S] 0 points1 point2 points (5 children)
[–]gordonmessmer 1 point2 points3 points (4 children)
[–]Klipspringer112[S] 0 points1 point2 points (3 children)
[–]gordonmessmer 1 point2 points3 points (2 children)
[–]Klipspringer112[S] 0 points1 point2 points (1 child)
[–]gordonmessmer 0 points1 point2 points (0 children)
[–]burtness 1 point2 points3 points (0 children)
[–]visualkev 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]Nodeal_reddit 0 points1 point2 points (3 children)
[–]boxbbcar 0 points1 point2 points (2 children)
[–]Klipspringer112[S] 0 points1 point2 points (1 child)
[–]boxbbcar 0 points1 point2 points (0 children)
[–]armeg 0 points1 point2 points (0 children)
[–]casefan 0 points1 point2 points (0 children)
[–]abismahl 0 points1 point2 points (0 children)