12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

286CHAPTER 12Identity ManagementThe /etc/pam_smb.conf file should contain three lines. The first should be the workgroupname for the SMB server, and the next two lines should be the IP addresses or hostnamesof the primary and secondary domain controllers:The /etc/pam.d/system-auth file is the main PAM authentication configuration file. Ifyou view the contents of the other files in /etc/pam.d/, you will notice that most have aline to include this file. If you have used the authconfig tool as discussed in the “Enablingwith the Authentication Tool” section, this file is removed and symbolically linked to/etc/pam.d/system-auth-ac, which is modified by authconfig.Because using authconfig removes the /etc/pam.d/system-auth file and because youmight need to revert back to the original file, be sure to make a backup copy of the filebefore modifying it. Also, leave a terminal open with root already logged in while modifyingthe file until you have tested the new configuration to make sure you can still log into the system. If you create a syntax error in the file, you might not be able to log inagain and will need the already opened root terminal to fix the file.In /etc/pam.d/system-auth (or /etc/pam.d/system-auth-ac), add the following line toenable SMB authentication:auth sufficient pam_smb_auth.so use_first_pass nolocalThe users still need to be in /etc/passwd. Users with a starred password are authenticatedwith the SMB server. Otherwise, local authentication is used.Enabling WinbindEnabling Winbind is similar to enabling SMB authentication. Add the following line to/etc/pam.d/system-auth (or /etc/pam.d/system-auth-ac):auth sufficient pam_winbind.so use_first_pass nolocalThe Winbind users should not be added as local users, but their home directories asconfigured on the Samba server must be created on the <strong>Linux</strong> client. If the winbind usedefault domain option in smb.conf is set to false (the default), Winbind users must log inwith a username in the format + such as EXAMPLE+tfox for the tfoxuser.TIPFor more details about Winbind, refer to http://samba.org/samba/docs/man/Samba3-HOWTO/winbind.html.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!