Custom PAM module to use in Samba

Rowland Penny rpenny at samba.org
Tue Jul 10 11:57:33 UTC 2018


On Tue, 10 Jul 2018 13:41:20 +0200
Volker Lendecke via samba-technical <samba-technical at lists.samba.org>
wrote:

> On Tue, Jul 10, 2018 at 11:43:36AM +0100, Daniel Iwan wrote:
> > Thanks for confirming Volker.
> > What would be he best option to integrate Samba with 3rd party
> > authentication service?
> > Is it possible to plug something into winbind?
> > Is this even feasible?
> 
> If the 3rd party auth service requires plain text passwords -- no,
> this is not feasible.
> 
> Samba as an authentication service (a domain controller) can be
> configured to pass the passwords for the users it hosts in plain text
> to the 3rd party. And if that 3rd party can ship plain text or the NT
> hash to Samba as a DC, we would also have a chance. But that's two
> auth services replicating passwords to each other.
> 
> Volker
> 

Hi Volker, funnily enough, that is basically what I have already told
him, replace everything with an Samba AD DC.

Rowland



More information about the samba-technical mailing list