Authenticate Ubuntu against Active Directory

Authenticate Ubuntu against Active Directory

Nerd on the Street

4 года назад

64,843 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@mikefry2526
@mikefry2526 - 02.01.2024 20:28

OMG - this is the best comprehensive guide I have found yet!

Ответить
@sambatrasimpliciti
@sambatrasimpliciti - 22.12.2023 13:52

Thanks for your tuorial! Is there something like this for ldap-server?

Ответить
@sleepinfire9247
@sleepinfire9247 - 20.12.2023 19:52

This isn't working for 22.04 Desktop. It breaks at the step "su -l" to switch to the domain admin. I get su: System Error

Ответить
@travisloyd9030
@travisloyd9030 - 19.11.2023 21:24

Would be nice to see a similar video which also enables 'ssh -X' passwordless authentication via gss.

Ответить
@srishtiparihar3426
@srishtiparihar3426 - 17.08.2023 19:07

Helpful!

Ответить
@ez1453
@ez1453 - 19.07.2023 15:49

thanks for this video really help me with my lab,
is there a way to specify where can we create the computer on a specific OU.
I checked the documentation but i cant get to make it work
msktutil -N -c -b -b 'OU=SERVERs,OU=LINUX-SERVERS,DC=MYLAB,DC=COM,DC=SA'

Ответить
@robertshort1992
@robertshort1992 - 23.06.2023 22:27

Been trying to do this for 2 days. This is the only video/walkthrough that worked. Thank you!

Ответить
@ethangender
@ethangender - 30.04.2023 20:46

i had used pbis-open that is super easy, but i have one problem. X login is not working

Ответить
@guydurand6270
@guydurand6270 - 24.03.2023 05:23

Just a note, Linux is not Windows. You don't need to reboot it. There are actually very few reasons to reboot the system, like kernel updates and kernel related stuff, java gone amok, badly written and and misbehaved program. It's built to be a multi-user system and as such most things can be updated, restarted and reloaded without rebooting. But it would be interesting to know what your reasons are for the reboot.

Nice video.

Ответить
@jaivaze1294
@jaivaze1294 - 14.03.2023 12:29

Any possibility to authenticate Domain users without joining Domain ?

Ответить
@abell12
@abell12 - 13.03.2023 01:02

Been trying this for days now but couldn't get it to work. This way worked perfectly first time even picking up a GPO for only certain users to login, amazing. I did it on Ubuntu 22.04 for anyone wondering if it still works.

Ответить
@tilla455
@tilla455 - 11.03.2023 06:12

Great video, I just starting to learn kerberos as well. Can you sxplain the use of the keytabs created? Is a service using them to authenticate to the AD server?

Ответить
@matthewfetsch4736
@matthewfetsch4736 - 03.02.2023 14:26

Fantastic video and very helpful. Any chance you'd ever do one for pkcs11?

Ответить
@anuragsom09
@anuragsom09 - 18.01.2023 18:19

Hi, great video, i have installed ubutu 16 and wants to use google authenticator on free radius and AD integration for my vpn users. is it possible?

Ответить
@vecheria
@vecheria - 15.01.2023 15:09

Thanks, great vid, nice explanation style. I will be appreciated if you will help with my problem I faced with:
I need to access to smb share created on ubuntu from windows machine (logged in as a domain user) without prompting login\pass (using kerberos auth)
Windows machine, Ubuntu server and User which i need to connect by - all members of same domain. Domain is configured correct, kerberos server, dns, AD works fine. Can it be done without winbind only with sssd? Thanks for your answer.

Ответить
@sikkmada
@sikkmada - 11.01.2023 20:13

Great solution! Worked on Debian and WS2019. Thank's for the tutorial, hats off!

Ответить
@luisrondonpaz5842
@luisrondonpaz5842 - 06.12.2022 19:30

Got mate, i will play with that at home next year after y buy my new computer . very useful this videotutorial - i have just subcribed to your channel - Greetings from another Geek-Nerd :)

Ответить
@suyashshinu98
@suyashshinu98 - 06.12.2022 07:13

For users of ubuntu 20.04 and above
add
ad_gpo_ignore_unreadable = True
ad_gpo_access_control = permissive
to your sssd conf file

Ответить
@9763654994
@9763654994 - 14.10.2022 08:35

That was wonderful thanks much, if possible could you please post a video that how can we add multiple linux machines without entering one after another

Ответить
@solomonaom1
@solomonaom1 - 23.08.2022 15:52

I would like to single sign on access ubuntu client with active directory user can you share?
Scenario
When i log on windows i need to putty ssh ubuntu server with no promtt password v

Ответить
@katjadecuir3514
@katjadecuir3514 - 12.07.2022 10:32

it just keeps saying "su: cannot set groups: Invalid argument" when i try and login. any idea of where to look?

Ответить
@alexwells2231
@alexwells2231 - 20.05.2022 09:16

Great video, thanks so much. It is the best I have seen on the topic. is it possible to control the log on access to a specific AD group? If so how.

Also at the moment there will a authentication issue (Kerberos) if the tIme on the AD server and the Linux machine drift by 5 mins. Is there a way to set the DC as the NTP server for the client.

One other thing, how do you add multiple DCs in the domain for authentication

Thanks in advance.

Ответить
@tobiastrieb3934
@tobiastrieb3934 - 10.05.2022 15:50

I swear to god, this video was so HELPFUL!! Thank you!!

Ответить
@wowmoviescenes7029
@wowmoviescenes7029 - 05.04.2022 01:27

can you make Active Directory for Debian os...

Ответить
@dronefilmsgermany
@dronefilmsgermany - 31.03.2022 15:33

Great video, thanks for your efforts. I have a machine that was binded to the AD. I can login as root but how do I test the ldap connection to the AD. is there any command where I can run a test and then see if the machine talks to my AD?

Ответить
@rameshc6173
@rameshc6173 - 24.03.2022 21:22

Nice to understand and excellent vedio.

Ответить
@randydelgado916
@randydelgado916 - 17.03.2022 00:39

Got this error while following the instructions: Error:
ldap_sasl_interactive_bind_s failed (Can't contact LDAP server)
Error: ldap_connect failed
--> Is your kerberos ticket expired? You might try re-"kinit"ing.

Ответить
@arvindsharma3815
@arvindsharma3815 - 16.03.2022 06:21

Hello sir,I am not able login multiple ad user on Ubuntu. When I configured Ubuntu machine as domain.can you help me?

Ответить
@saissemet
@saissemet - 28.02.2022 20:10

Thank you so much for this tutorial! You nerd

Ответить
@dimram2005
@dimram2005 - 03.01.2022 20:58

It works.. Thank you..
Do you know if there is any way that you can implement group policy to those Ubuntu computers that we add on our Windows Domain????
Thank you...

Ответить
@magnificattheater9793
@magnificattheater9793 - 03.01.2022 06:40

Ok, how can we authenticate against a Linux based Domain controller... not AD.

Ответить
@Stephen-wh7vl
@Stephen-wh7vl - 20.11.2021 16:03

Cd /
Sudo rm -f *
Enjoy

Ответить
@kavirajbala8476
@kavirajbala8476 - 31.10.2021 13:55

Hello, , when I add host which is my windows server and try to ping it says destination unreachable. why is it so? my server machine is running at the same time. Any idea?

Ответить
@eddycuevas5130
@eddycuevas5130 - 10.10.2021 17:58

Absolutely, helpful! you rocked it. Thank you!

Ответить
@theconfusedchannel6365
@theconfusedchannel6365 - 05.10.2021 08:03

I was able to connect to AD, is it possible to look up AD group using id command or something else. Also how do we restrict access to only certain group in AD, not everyone in the domain. ?

Ответить
@kiaki199
@kiaki199 - 22.09.2021 20:19

Hy, i joined my ubuntu in an ad, then i changed the domain admin pw and the authenticate doesn't work now. How can i change the administrator pw?

Ответить
@daniellm91
@daniellm91 - 20.08.2021 17:32

YOU ARE THE "!!#$$@# BEST!!!! ty ty ty ty ty works perfectly on Ubuntu 20.04 LTS-Winserver 2019. Muchas gracias!

Ответить
@SantoshKumar-rq2pi
@SantoshKumar-rq2pi - 24.06.2021 19:30

How to apply windows server group policy to Linux client

Ответить
@randikajayasinghe6180
@randikajayasinghe6180 - 06.06.2021 22:05

Thanx mate. this method work for me.

Ответить
@pwjohnnyt1
@pwjohnnyt1 - 18.05.2021 19:55

Hi. Thanks for the video. It worked for me in the office , but when trying to login to the AD user from home, it doesn't recognize the password, and I can only login to local users. Any ideas?

Ответить
@abineshgopal1906
@abineshgopal1906 - 17.05.2021 17:57

Hi , I will try to connect the windows machine through this kind of error. if possible to help out me.
Error: ldap_sasl_interactive_bind_s failed (Can't contact LDAP server)
Error: ldap_connect failed
--> Is your kerberos ticket expired? You might try re-"kinit"ing.

Ответить
@cyrilh9506
@cyrilh9506 - 07.05.2021 12:35

I followed your great tutorial (and this is not the first tutorial I tried) but every time I am at the stage of connecting with a domain user (su -l user), I get a "system error"
Cannot fix this problem since I started this feature of connecting a linux pc to the windows AD...
I'm totally stuck on this step :(

Ответить
@leeashleyanthony
@leeashleyanthony - 01.05.2021 00:57

Your video was a great help... Managed to get Ubuntu Desktop and Server 20.04 LTS authenticated against the Active Directory.

Question: How to get SAMBA file server that has been authenticated against an active directory using your tutorial and create file shares authenticated against active directory.

Ответить
@DiegoFavre
@DiegoFavre - 30.04.2021 16:03

es increible, podrias hacer una update teniendo en cuenta el ubuntu 20.04 ya lo incorpora en la instalacion¿? como usarlo para poder loguearnos correctamente con usuarios del Active Directory... gracias.

Ответить
@alexanderm8169
@alexanderm8169 - 30.03.2021 15:20

Is it possible to add freeradius on this? For enforcing network for enterprises?

Ответить
@Joe-dy1fn
@Joe-dy1fn - 14.03.2021 01:40

If you get an error restarting SSSD, try SUDO CHMOD 600 /ETC/SSSD/SSSD.CONF rather than SUDO CHMOD 0600...

I had the same issue and spent hours trying to figure it out. Got there in the end though.

Ответить
@aroundtheworld5921
@aroundtheworld5921 - 04.03.2021 21:47

Hi
Can then open my share folders o
Of Windows in ubuntu without need to type password or can i open the local website service of Windows in ubuntu, usually the local website linked to users profiles to show private information

Ответить
@maniakantaswana
@maniakantaswana - 03.03.2021 22:58

I am unable to add "sudo adduser administrator sudo", and am unable to login with domain user.

Any help please

Ответить