ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat...

44
ID Mapping of Active Directory users with Sumit Bose Red Hat [email protected]

Transcript of ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat...

Page 1: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

ID Mapping ofActive Directory users with

Sumit BoseRed Hat

[email protected]

Page 2: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

is a client for FreeIPA

Page 3: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 4: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

DNSNTP

Integrated Solution

=

Page 5: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Identity

Who you are

Page 6: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 7: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 8: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 9: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 10: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 11: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 12: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 13: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 14: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

VT100 anyone ?$ ipa user-find admin--------------1 user matched-------------- User login: admin Last name: Administrator Home directory: /home/admin Login shell: /bin/bash UID: 747400000 GID: 747400000 Account disabled: False Password: True Kerberos keys available: True----------------------------Number of entries returned 1----------------------------

Page 15: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Policy

What you are allowed to do

Page 16: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 17: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 18: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 19: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 20: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 21: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Audit

What you have done

Page 22: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 23: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

PAM

NSS sudoSELinux

automountssh

InfoPipe

IPA Server

Page 24: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

PAM

NSS sudoSELinux

automountssh

InfoPipe

IPA ServerOther ServerIPA, LDAP, AD

Page 25: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you
Page 26: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

PAMNSS sudo

SELinux

automountssh

InfoPipe

IPA Server

app1

app2 app3

app4

Page 27: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Tomorrow

Page 28: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

ActiveDirectory

Forest Trust

Page 29: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Tomorrow

Page 30: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

ID-Mapping

SIDs POSIX IDs

Page 31: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

1028 : 1

128bits 32bits

Page 32: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

SID POSIX ID

Algorithmic Mapping

Page 33: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

posixAccount

Manual MappingManaged in AD

Page 34: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

FreeIPA CIFS-ClientAD DC

File-Server

IPA Server

IPA Client

Page 35: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

cifs-utils

Kernel-

User-Space

cifs.idmapidmapwb.socifs_idmap_sss.so

Page 36: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

FreeIPA CIFS-ServerAD DC

AD Client

IPA Server

IPA Client

Page 37: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

smbd wbinfo

libwbclient.so.0

winbindd

Samba File-Server

Page 38: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

smbd wbinfo

libwbclient.so.0

Samba File-ServerOn a FreeIPA Client

libwbclient-sssd.so.0

Page 39: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Tomorrow

Page 40: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

libwbclient-sssdcommon ID/SID lookup

authenticationutilities

Page 41: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

libwbclient-sssdLimitations

Trust MgmtNTLMWINS ID alloc

Page 42: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

pam_winbind.solibnss_winbind.so

pam_sss.solibnss_sss.so socket

socket winbindd

Next Plans

Page 43: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

pam_socket.solibnss_socket.so socket

winbindd

Unified PAM/nss Client

Page 44: ID Mapping of Active Directory users with · Active Directory users with Sumit Bose Red Hat sbose@redhat.com. is a client for FreeIPA. DNS NTP Integrated Solution = Identity Who you

Thank you :-)

Any questions please?