Discussion:
[Freeipa-users] Authenticating windows users
grace rante thompson
2017-03-23 18:38:47 UTC
Permalink
Hi,

We are primarily linux/osx shop and we currently have FreeIPA/IDM (ver 4.2)
as our master. I will need to add a handful of windows machines and been
trying to figure out how to authenticate our windows users with
FreeIPA/IDM. Is this even possible? I know Global Catalogs may not happen
anytime soon (sad face). I'm open to -all- ideas, even if it is a paid
solution (not sure if centrify and the likes can sync up to FreeIPA/IDM).

thanks
grace rante thompson
2017-03-23 18:48:10 UTC
Permalink
Thanks Jason, but those documents need AD as the primary authenticator.
This is not the case for us.
Post by grace rante thompson
We are primarily linux/osx shop and we currently have FreeIPA/IDM (ver
4.2) as our master. I will need to add a handful of windows machines and
been trying to figure out how to authenticate our windows users with
FreeIPA/IDM. Is this even possible? I know Global Catalogs may not happen
anytime soon (sad face). I'm open to -all- ideas, even if it is a paid
solution (not sure if centrify and the likes can sync up to FreeIPA/IDM).
https://www.freeipa.org/page/Windows_authentication_against_FreeIPA
https://www.freeipa.org/page/Implementing_FreeIPA_in_a_
mixed_Environment_(Windows/Linux)_-_Step_by_step
Jason B. Nance
2017-03-23 18:52:45 UTC
Permalink
Thanks Jason, but those documents need AD as the primary authenticator. This is
not the case for us.
I think you need to read them a bit closer. Very first line of first link says:

"This article describes direct integration between FreeIPA and Windows machine, i.e. without involving Active Directory server."
We are primarily linux/osx shop and we currently have FreeIPA/IDM (ver 4.2) as
our master. I will need to add a handful of windows machines and been trying to
figure out how to authenticate our windows users with FreeIPA/IDM. Is this even
possible? I know Global Catalogs may not happen anytime soon (sad face). I'm
open to -all- ideas, even if it is a paid solution (not sure if centrify and
the likes can sync up to FreeIPA/IDM).
[ https://www.freeipa.org/page/Windows_authentication_against_FreeIPA |
https://www.freeipa.org/page/Windows_authentication_against_FreeIPA ]
[
https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_(Windows/Linux)_-_Step_by_step
|
https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_(Windows/Linux)_-_Step_by_step
]
Standa Laznicka
2017-03-24 08:32:56 UTC
Permalink
I changed the text emphasis so that this is more clear in the future,
thanks for noticing.
Post by grace rante thompson
Thanks Jason, but those documents need AD as the primary
authenticator. This is not the case for us.
I think you need to read them a bit closer. Very first line of first
"This article describes direct integration between FreeIPA and Windows
machine, i.e. without involving Active Directory server."
On Thu, Mar 23, 2017 at 11:46 AM, Jason B. Nance
We are primarily linux/osx shop and we currently have
FreeIPA/IDM (ver 4.2) as our master. I will need to add a
handful of windows machines and been trying to figure out
how to authenticate our windows users with FreeIPA/IDM. Is
this even possible? I know Global Catalogs may not happen
anytime soon (sad face). I'm open to -all- ideas, even if
it is a paid solution (not sure if centrify and the likes
can sync up to FreeIPA/IDM).
https://www.freeipa.org/page/Windows_authentication_against_FreeIPA
https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_(Windows/Linux)_-_Step_by_step
<https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_%28Windows/Linux%29_-_Step_by_step>
grace rante thompson
2017-03-24 15:58:06 UTC
Permalink
sorry, I guess I should have been more clear that we needed more than just
Kerberos. Somebody suggested pGina so I'll give it a shot.

thanks
Post by grace rante thompson
Thanks Jason, but those documents need AD as the primary authenticator.
This is not the case for us.
I think you need to read them a bit closer. Very first line of first link
"This article describes direct integration between FreeIPA and Windows
machine, i.e. without involving Active Directory server."
Post by grace rante thompson
We are primarily linux/osx shop and we currently have FreeIPA/IDM (ver
4.2) as our master. I will need to add a handful of windows machines and
been trying to figure out how to authenticate our windows users with
FreeIPA/IDM. Is this even possible? I know Global Catalogs may not happen
anytime soon (sad face). I'm open to -all- ideas, even if it is a paid
solution (not sure if centrify and the likes can sync up to FreeIPA/IDM).
https://www.freeipa.org/page/Windows_authentication_against_FreeIPA
https://www.freeipa.org/page/Implementing_FreeIPA_in_a_
mixed_Environment_(Windows/Linux)_-_Step_by_step
Jason B. Nance
2017-03-24 16:10:15 UTC
Permalink
That, too, is in the first document I linked, plus it also lists the option of standing up a Samba 4 to emulate an AD domain that trusts FreeIPA.




From: "grace rante thompson" <***@gmail.com>
To: "Jason Nance" <***@tresgeek.net>
Cc: freeipa-***@redhat.com
Sent: Friday, March 24, 2017 10:58:06 AM
Subject: Re: [Freeipa-users] Authenticating windows users

sorry, I guess I should have been more clear that we needed more than just Kerberos. Somebody suggested pGina so I'll give it a shot.
thanks


On Thu, Mar 23, 2017 at 11:52 AM, Jason B. Nance < [ mailto:***@tresgeek.net | ***@tresgeek.net ] > wrote:




BQ_BEGIN

Thanks Jason, but those documents need AD as the primary authenticator. This is not the case for us.



I think you need to read them a bit closer. Very first line of first link says:

"This article describes direct integration between FreeIPA and Windows machine, i.e. without involving Active Directory server."



BQ_BEGIN


On Thu, Mar 23, 2017 at 11:46 AM, Jason B. Nance < [ mailto:***@tresgeek.net | ***@tresgeek.net ] > wrote:

BQ_BEGIN


BQ_BEGIN

We are primarily linux/osx shop and we currently have FreeIPA/IDM (ver 4.2) as our master. I will need to add a handful of windows machines and been trying to figure out how to authenticate our windows users with FreeIPA/IDM. Is this even possible? I know Global Catalogs may not happen anytime soon (sad face). I'm open to -all- ideas, even if it is a paid solution (not sure if centrify and the likes can sync up to FreeIPA/IDM).

BQ_END

I would start here:

[ https://www.freeipa.org/page/Windows_authentication_against_FreeIPA | https://www.freeipa.org/page/Windows_authentication_against_FreeIPA ]

[ https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_(Windows/Linux)_-_Step_by_step | https://www.freeipa.org/page/Implementing_FreeIPA_in_a_mixed_Environment_(Windows/Linux)_-_Step_by_step ]


BQ_END


BQ_END



BQ_END

Loris Santamaria
2017-03-23 18:53:33 UTC
Permalink
Hi, 
this is not a scalable solution in any way but it may work for you if
you just have a couple of windows machines:
https://www.redhat.com/archives/freeipa-users/2013-September/msg00226.h
tml
Loris
Post by grace rante thompson
Hi, 
We are primarily linux/osx shop and we currently have FreeIPA/IDM
(ver 4.2) as our master. I will need to add a handful of windows
machines and been trying to figure out how to authenticate our
windows users with FreeIPA/IDM. Is this even possible? I know Global
Catalogs may not happen anytime soon (sad face).  I'm open to -all-
ideas, even if it is a paid solution (not sure if centrify and the
likes can sync up to FreeIPA/IDM). 
thanks
-- 
Loris Santamaria   linux user #70506   xmpp:***@lgs.com.ve
Links Global Services, C.A.            http://www.lgs.com.ve
Tel: 0286 952.06.87  Cel: 0414 095.00.10  sip:***@lgs.com.ve
------------------------------------------------------------
"If I'd asked my customers what they wanted, they'd have said
a faster horse" - Henry Ford
Continue reading on narkive:
Loading...