Nested Groups

Added by churnd . over 3 years ago

I've looked, but have not found a clear answer. Does Nexenta support nested groups? In other words, can I add an Active Directory user to a local group on the Nexenta server?


Replies

RE: Nested Groups - Added by Dmitry Yusupov over 3 years ago

Yes. But you need to manage your AD users on AD Server. NexentaStor is just a "Computer" object.

RE: Nested Groups - Added by churnd . over 3 years ago

Yes, that is what I would be doing.

I have been doing research and I'm finding that Nexenta customers are having widely mixed results in an Active Directory environment regarding user ACLs not working correctly. Something about the way opensolaris does kerberos...? Can anyone shed any light on this?

RE: Nested Groups - Added by Ryan W over 3 years ago

Christopher Hearn wrote:

Yes, that is what I would be doing.

I have been doing research and I'm finding that Nexenta customers are having widely mixed results in an Active Directory environment regarding user ACLs not working correctly. Something about the way opensolaris does kerberos...? Can anyone shed any light on this?

The kerberos ticketing bugs really have nothing to do with ACL's. If your kerberos tickets are broken on opensolaris you won't even be able to access the SAN via CIFS to do anything ACL related anyway.

Good news is, the outstanding kerberos that I've been struggling with has been fixed in snv_137 for OpenSolaris. I'm hoping Nexenta will have it backported into a minor update soon.

RE: Nested Groups - Added by Dmitry Yusupov over 3 years ago

Yes, CIFS updates are coming...

RE: Nested Groups - Added by churnd . over 3 years ago

Dmitry Yusupov wrote:

Yes, CIFS updates are coming...

Very promising. Any idea when?

RE: Nested Groups - Added by Dmitry Yusupov over 3 years ago

Very promising. Any idea when?

Possibly early next week.

RE: Nested Groups - Added by churnd . over 2 years ago

Dmitry Yusupov wrote:

Very promising. Any idea when?

Possibly early next week.

Any word on whether or not 3.0.2 is better with Kerberos in AD?

RE: Nested Groups - Added by Dmitry Yusupov over 2 years ago

It is better. Some large patches went into 134e kernel, you can verify it by running "uname -a"

On 05/27/2010 01:09 PM, NexentaStor.org wrote:

http://www.nexentastor.org/boards/2/topics/96 Christopher Hearn

Dmitry Yusupov wrote:

Very promising. Any idea when?

Possibly early next week.

Any word on whether or not 3.0.2 is better with Kerberos in AD?