{"id":307,"date":"2016-04-19T07:17:08","date_gmt":"2016-04-19T07:17:08","guid":{"rendered":"http:\/\/www.howtolearnlinux.com\/?p=307"},"modified":"2016-12-13T11:23:44","modified_gmt":"2016-12-13T11:23:44","slug":"centos-7-authentication-using-active-directory","status":"publish","type":"post","link":"http:\/\/shijuvarghese.com\/?p=307","title":{"rendered":"CentOS 7 authentication using Active Directory"},"content":{"rendered":"<p>Though Linux hosts has its own local authentication mechanism, as times requirements will arise where Windows Active Directory authentication will be required. For example, if a\u00a0Linux host needs\u00a0access to the NTFS folders shared by a Windows host\u00a0in a Windows domain, Active Directory authentication will be required.<\/p>\n<p>&nbsp;<\/p>\n<p>The following lists the steps required to enable a CentOS 7 host use\u00a0Active Directory for authentication. Here the Windows AD domain name used is <em><strong>myntp.local<\/strong><\/em><\/p>\n<p>Add the Linux host in windows AD via the AD Users and Computers management tool.<\/p>\n<p>#] <strong>yum -y install authconfig krb5-workstation pam_krb5 samba-common oddjob-mkhomedir sudo ntp samba-winbind-modules<\/strong><\/p>\n<p>#] <strong>mkdir \/home\/<em>myntp.local<\/em><\/strong><\/p>\n<p>[<em>NOTE: In the below command all flags are defined using &#8220;- -&#8221; and not &#8220;-&#8220;<\/em>]<\/p>\n<p>#] <strong>authconfig &#8211;disablecache &#8211;enablewinbind &#8211;enablewinbindauth &#8211;smbsecurity=ads &#8211;smbworkgroup=MYNTP &#8211;smbrealm=MYNTP.LOCAL &#8211;enablewinbindusedefaultdomain &#8211;winbindtemplatehomedir=\/home\/myntp.local\/%U &#8211;winbindtemplateshell=\/bin\/bash &#8211;enablekrb5 &#8211;krb5realm=MYNTP.LOCAL &#8211;enablekrb5kdcdns &#8211;enablekrb5realmdns &#8211;enablelocauthorize &#8211;enablemkhomedir &#8211;enablepamaccess &#8211;updateall<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Note: <\/strong>In the above command the parameters after authconfig is<strong>\u00a0&#8220;- -&#8221; <\/strong>instead of<strong> &#8216;-&#8216;<\/strong><\/p>\n<p>Verify and ensure the\u00a0<em><strong>\/etc\/krb5.conf<\/strong><\/em> looks as below:<\/p>\n<p>#] <strong>cat \/etc\/krb5.conf<\/strong><\/p>\n<p><em>[logging]<\/em><br \/>\n<em> default = FILE:\/var\/log\/krb5libs.log<\/em><br \/>\n<em> kdc = FILE:\/var\/log\/krb5kdc.log<\/em><br \/>\n<em> admin_server = FILE:\/var\/log\/kadmind.log<\/em><\/p>\n<p><em>[libdefaults]<\/em><br \/>\n<em> default_realm =\u00a0MYNTP.LOCAL<\/em><br \/>\n<em> dns_lookup_realm = true<\/em><br \/>\n<em> dns_lookup_kdc = true<\/em><br \/>\n<em> ticket_lifetime = 24h<\/em><br \/>\n<em> renew_lifetime = 7d<\/em><br \/>\n<em> forwardable = true<\/em><\/p>\n<p><em>[realms]<\/em><br \/>\n<em>MYNTP.LOCAL\u00a0= {<\/em><br \/>\n<em> admin_server =\u00a0pdc.myntp.local<\/em><br \/>\n<em> kdc_server = pdc.myntp.local<\/em><br \/>\n<em> }<\/em><\/p>\n<p><em>myntp.local\u00a0= {<\/em><br \/>\n<em> }<\/em><\/p>\n<p><em>[domain_realm]<\/em><br \/>\n<em>myntp.local = MYNTP.LOCAL<\/em><br \/>\n<em> .myntp.local = MYNTP.LOCAL<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Note: <\/strong>Ensure youo can ping the domian name.<\/p>\n<p>#] <strong>kinit domain_admin<\/strong><br \/>\n#] <strong>ntpdate\u00a0pdc.myntp.local<\/strong><br \/>\n#] <strong>net ads join myntp.local\u00a0-U\u00a0domain_admin<\/strong><br \/>\n#] <strong>net ads testjoin<\/strong><br \/>\n#] <strong>chmod 777 \/home\/myntp.local\/<\/strong><\/p>\n<p>#]<strong> chkconfig oddjobd on<\/strong><br \/>\n#] <strong>chkconfig winbind on<\/strong><br \/>\n#] <strong>chkconfig messagebus on<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>#] <strong>useradd &lt;domain user&gt;<\/strong><\/p>\n<p>Reboot the host, and try logging with &lt;domain user&gt; name now.<\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Though Linux hosts has its own local authentication mechanism, as times requirements will arise where Windows Active Directory authentication will be required. For example, if <a class=\"mh-excerpt-more\" href=\"http:\/\/shijuvarghese.com\/?p=307\" title=\"CentOS 7 authentication using Active Directory\">[&#8230;]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":260,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"_links":{"self":[{"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/posts\/307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=307"}],"version-history":[{"count":10,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/posts\/307\/revisions"}],"predecessor-version":[{"id":378,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/posts\/307\/revisions\/378"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=\/wp\/v2\/media\/260"}],"wp:attachment":[{"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=307"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/shijuvarghese.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}