[Samba] NTLM auth, better on a DC or on a DM?

Andrew Bartlett abartlet at samba.org
Fri Sep 7 18:18:39 UTC 2018


On Fri, 2018-09-07 at 20:14 +0200, Luca Olivetti via samba wrote:
> El 7/9/18 a les 17:59, Marco Gaiarin via samba ha escrit:
> 
> > It is better to install squid/freeradius in the same host of a DC, or
> > don't bother at all so they can be installed also on a DM?
> 
> I don't know if it's better but I'm running freeradius with ntlm_auth on 
> a different host.

I would do that, it allows you to have the FreeRADIUS fail over to
another DC when you are upgrading Samba, and choose to upgrade Samba's
base OS without consideration for the Squid/FreeRADIUS stack.

Andrew Bartlett
-- 
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba





More information about the samba mailing list