LDAP problem

Added by Rudy Dajoh over 2 years ago

Hello,

I am in a big problem here. We have an LDAP server up and running, and serving 2 OpenFiler's Samba, Radius, and Kerberos authentication, so we definitely depends on this LDAP server. Now, we want to setup NexentaStor as our test project.

I have succesfully connect NexentaStor into our LDAP, and all our users and groups are properly detected. Now even though every single user detected, I can't login to any of the shares (FTP and Samba) using those LDAP logins. I have tried to make a Unix login, and I could login successfully. I believe that I couldn't integrate LDAP into Samba and FTP. I have also tried to look for smb.conf files to check on samba configuration, but couldn't find any. 2 config files I've found had nothing to do with samba, and didn't reflect any changes I made on console.

Can someone please help me? I am at lost here.

Thank you.


Replies

RE: LDAP problem - Added by Rudy Dajoh over 2 years ago

Oh, I forgot one more thing. We also have old Windows 98 clients. Can NexentaStor setup to allow lanman auth for samba?

RE: LDAP problem - Added by Dmitry Yusupov over 2 years ago

NexentaStor using its own in-kernel fast CIFS implementation. It would be interesting to figure out if we could make it work via LDAP. Certainly, it could work as AD Computer - which is LDAP based. But how to integrate LDAP with Workgroup mode?

RE: LDAP problem - Added by support support over 2 years ago

Same problem here, i would REALLY love to have this feature...

I'm using a SAMBA domain with several SAMBA file servers and OpenLDAP , but i can't integrate successfully Nexentastor with even if LDAP users show up... it's a pity to see that it is possible with Windows AD !!

RE: LDAP problem - Added by Mike Fisher over 2 years ago

Can somebody provide an ETA for when this will be addressed (ballpark)?

I just went through a few weeks-worth of evenings and weekends setting up OpenLDAP on my home network solely for the purpose of using it with Nexenta CIFS. I need centralized user/group management - so also interested in hearing about alternatives, workarounds, etc.

Thanks

RE: LDAP problem - Added by Mike Fisher over 2 years ago

I'm relatively new here - is it normal to have these questions go unanswered for this long? Is there really a 'community' built around Nexenta? Is there someplace I should go for guidance?

RE: LDAP problem - Added by support support over 2 years ago

Hi,

I'm quite new here too, but as long as i can see, the community is not very active, and it seems like there is a lack of "power users", i mean people with a good experience in Solaris / Nexenta. Anyway, the product is stable and effective, and the Solaris community is of good help for ZFS tuning/configuration and other Solaris features.

In fact, it seems that the community version is for people with good Solaris/NAS knowledge who does need minimal support, others will have to go to Enterprise version with payed support option.

RE: LDAP problem - Added by Georgy Malakyan over 2 years ago

Hi all. 1) For integrate samba with LDAP (f.e. openldap) you must remove kernel-cifs and install normal samba (and use smb.conf for ldap settings ). 2) With Windows AD you can "integrate" cifs-server but you must manualy add users for system and create id-maps (http://nexenta.com/corp/documentation/product-documentation "Windows Active Directory Integration User Guide" ) 3) Probably full LDAP-integration will be in next version of Nstor. Sorry for delay.

RE: LDAP problem - Added by Mike Fisher over 2 years ago

Thanks for the response!

I'm relatively comfortable with Solaris / ZFS - but because this is a custom kernel implementation of CIFS there isn't much I can really do. I figured the samba route was going to be the recommended workaround for the time being, I'll give that a shot.

What sort of timetables are you guys looking at for the next release of Nstore?

Thanks, Mike

RE: LDAP problem - Added by Georgy Malakyan over 2 years ago

Next release will be around June-July.

RE: LDAP problem - Added by support support over 2 years ago

Thank you for your answers.

RE: LDAP problem - Added by Micah Tinkler about 1 year ago

Does anyone have a write-up as to how to disable the kernel-cifs module? Or an updated timeframe for being able to use an OpenLDAP/SMB Domain Controller with a Nexenta share?