[Samba] Re: Winbind/PAM Question

Alexander E. Patrakov patrakov at ums.usu.ru
Wed Aug 18 09:12:06 GMT 2004


Robert Balbir-Brott wrote:
> Hi All,
> 
>>From the Official Samba-3 HOWTO, section 24.1:
> 
> "Winbind - The pam_winbind.so module allows Samba to obtain
> authentication from any MS Windows Domain Controller. It can just as
> easily be used to authenticate users for access to any PAM-enabled
> application."
> 
> I understand the second part to this sentence.  That is, Samba
> provides 'pam_winbind.so' which allows, through PAM, users for
> PAM-aware applications to be authenticated via WinBind to a Windows
> NT/200x box.  What I don't quite grasp is why the module "allows Samba
> to obtain authentication information from any MS Windows Domain
> Controller".  I searched the mailing list, and found a thread in which
> John Terpstra had said that "smbd can use winbind directly"
> (http://lists.samba.org/archive/samba/2003-May/066636.html)
> 
> So, if smbd can indeed use winbind directly, why would the PAM
> interface to winbind be needed when simply allowing Samba to obtain
> authentication information from a Windows box?

Winbindd is not for SAMBA. It's for things like "login", "sshd" - this 
way they can let Windows domain users in.

-- 
Alexander E. Patrakov



More information about the samba mailing list