Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Solaris 9 authentication and access control into Active Directory |
|---|---|
| Date: | Wed, 15 Sep 2004 09:22:25 -0400 |
1. Use Kerberos on Solaris 9 via PAM to authenticate to AD using the Windows username/password.
http://www.microsoft.com/windows2000/techinfo/planning/security/kerbsteps.asp
http://ist.uwaterloo.ca/security/howto/drafts/2002-08-23/
2. Use LDAP through NSS to get /etc/passwd and /etc/group type data from AD.
3. Use Solaris RBAC to group the Windows userids into roles that will manage the systems.
4. Have a very difficult root password (hopefully using MD5) on the local machine in case AD is not available. I will use this authentication only as a last resort.
From what I've read the MIT version of Kerberos works better with AD, but the Solaris SEAM version of Kerberos works better with Solaris. From someone who's been there done that, MIT or SEAM?
The vendor provided stuff worked fine for me.
I've read the Microsoft document on integrating Unix into Windows 2003. They either have SFU or recommend purchasing VAS. I know that there is also PAM SMB authentication, but I don't believe that I want to do that.
Thanks Ron Ogle
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Solaris 9 authentication and access control into Active Direc tory, Ted Rodriguez-Bell |
|---|---|
| Next by Date: | RE: Solaris 9 authentication and access control into Active Directory, Myers, Mike |
| Previous by Thread: | Re: Solaris 9 authentication and access control into Active Directory, Kai Howells |
| Next by Thread: | RE: Solaris 9 authentication and access control into Active Directory, Myers, Mike |
| Indexes: | [Date] [Thread] [Top] [All Lists] |