Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Sun
[Top] [All Lists]

Re: Solaris 9 authentication and access control into Active Directory

Subject: Re: Solaris 9 authentication and access control into Active Directory
Date: Wed, 15 Sep 2004 16:12:26 +1000
Okay, basically I don't believe that what you want to do can be done out of the box.
I've done a fair bit of work along these lines, except using Mac OS X to auth to AD.


The most reliable way to do it is to extend the schema in AD to add a few essential unix fields, like UID. Alternatively, if you're actually on OS X (not Solaris) there's some 3rd party software that helps things greatly, but that's no help to this discussion.

The main problem with this (extending the schema) is that it scares the MCSEs - never mind that installing Exchange adds another 100+ objects to the schema, it all happens behind the scenes.

On this page: http://www.shukwit.com/index.php is a whole heap of stuff from a dude at Apple who's delving far deeper into AD/LDAP than I ever want to go, but he's come up with some scripts that are pure gold. There are even some DLLs that extend the manage Users thingy in Windows Server to add another pane to the window with the Unix/Mac specific fields so you can easily populate them, as well as scripts to add the necessary changes to the AD schema.

Now, I've used all this with Mac OS X, and it seems to work quite well in my test environment, but haven't tried to use Solaris to auth to it, although *in theory* it should all work =)

Cheers,
Kai

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>