Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Use windows domain services without joining the domain

 
   Soft32 Home -> Linux -> General Discussions RSS
Next:  [PATCH 0/12] cleanup __build_sched_domains()  
Author Message
Lars Uffmann

External


Since: Feb 03, 2009
Posts: 24



(Msg. 1) Posted: Tue Aug 18, 2009 9:20 am
Post subject: Use windows domain services without joining the domain
Archived from groups: alt>os>linux>debian (more info?)

Hi everyone!

Simple question, and - I'm afraid - not a simple answer:

Let's say I want to hook up to a domain for network services, but do not
want to allow domain logins on my box, to protect my data, because the
domain administrators are not trustworthy.

Is there a way to give my linux networking the domain login information
so that the desired services (intranet, mail authentication and the
likes) will consider me registered in the domain, but where the only way
to log on to the system is via locally registered useraccounts?

Obviously, the computer should only be registered to the domain when
desired, and *after* a local user has logged in.

I am thinking along the lines of this:
- local user logs onto the debian box
- debian box has a daemon running that handles access to domain services
- when local user accesses a domain service, the daemon either uses
stored domain logon information (machine account needs to be stored
somewhere after generation, user login is up to the users taste I
guess), or asks the user for login information
- local user can access domain services as he desires
- after some timeout (optional), the machine unregisters from the domain
(if desired)

I am researching what I can find on the web on this topic in parallel,
but I thought I'd ask here already, in case someone knows right away
what to do.

Best Regards,

Lars
Back to top
Login to vote
Günther

External


Since: Oct 10, 2006
Posts: 32



(Msg. 2) Posted: Tue Aug 18, 2009 3:20 pm
Post subject: Re: Use windows domain services without joining the domain [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Lars Uffmann wrote:

> Simple question, and - I'm afraid - not a simple answer:

> I am thinking along the lines of this: - local user logs onto the debian
> box - debian box has a daemon running that handles access to domain
> services - when local user accesses a domain service, the daemon either
> uses stored domain logon information (machine account needs to be stored
> somewhere after generation, user login is up to the users taste I
> guess), or asks the user for login information - local user can access
> domain services as he desires - after some timeout (optional), the
> machine unregisters from the domain (if desired)

That is not the way a Windows domain works. Once set up a machine account
will be persistent. You might be able, however, to use shares on a user
basis without joining the machine to the domain. Did you try
# smbclient -U name //domain_name/name
where name is your login name for the domain?
Depending on the setup of the domain this might give you access to your
Windows home directory on a user basis.
It might be worth posting the question to one of the Samba groups, also.

Günther
Back to top
Login to vote
Display posts from previous:   
Related Topics:
printer - is brother better than hp for debian? i want all in one.

printer - all in one is brother better easier than hp to run?

How to download youtube video into Adobe Premiere - How to download youtube video into Adobe Premiere I like to lounge around online and youtube is my favorite. Sometimes...

[Samba] Joining to Windows 2000 domain - Hi I am trying to join Samba 2.23 to W2K domain. After creating a computer account on the PDC I run: sudo smbpasswd -j...

[Samba] Error on joining domain - 'System computer account.. - I'm running Samba 2.2.8a as a PDC on Red Hat 8, connecting to a Sun ONE Directory Server on a separate Sun box. ..

[Samba] Problems joining ADS domain in windows 2000 / 2003 - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In windows 2000 I'm getting: FAiled to verify incoming ticket! in..
       Soft32 Home -> Linux -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
  Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]