[Samba] Is it possible to make Samba4 use an external LDAP server for authN, and its own internal LDAP server for all other LDAP purposes?

Jon Detert jdetert at infinityhealthcare.com
Mon May 6 14:09:11 MDT 2013


My company uses 389-ds for its LDAP service, and all services are configured to use that LDAP for authentication.

I'd like to start using Samba4 as an AD DC, in order to control/manage MsWin computers.

It was simplest to me to install Samba4 configured to use its own internal LDAP server, rather than make it use my existing 389-ds LDAP server.

However, I want Samba4 to authenticate to the 389-ds, since that is where the user passwords are, and:
a) I don't know how to extract the passwords into a format that Samba4 could use, and
b) Even if I did, I don't want to maintain the passwords in 2 places (389-ds and Samba4).

Hence the question:

Is it possible to make Samba4 use an external LDAP server for authentication, and its own LDAP server for all other LDAP purposes (e.g. authorization; user-object data; computer-object data; etc.)?

Thanks,
-- 
Jon Detert
Sr. Systems Administrator
Infinity Healthcare
Milwaukee, Wisconsin
414-290-6759


More information about the samba mailing list