Blogs Classifieds Downloads FlashChat Gallery Googlemap Invite Friends Links Projects Reviews Wiki
 


Welcome to the pSeries Tech Forums, our free peer-based support site for administrators, engineers and architects working with IBM pSeries servers and software.

You are currently viewing our site as a guest which gives you limited access to view most discussions, articles, tutorials and access our other free features. By joining our community you will be able to collaborate with administrators, engineers and architects charged with designing, delivering or maintaining IBM pSeries server environments.

Founded by a recognized IBM pSeries consultant and IBM Redbook author, pSeries Tech Forums was developed with the single mission of bringing IBM pSeries professionals together into a single self-help community.

Registration is fast, simple and absolutely free to all IT professionals with responsibility for or interest in IBM pSeries servers. We invite you to join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Our Sponsors
Want to advertise?  


Comment
 
LinkBack (1) Tutorial Tools
Microsoft Windows 2003 Active Directory integration
Fred Sherman, pSeries Engineer
FASherman
June 24th, 2006
This tutorial will help you integrate your AIX 5L hosts into an existing Microsoft Windows 2003 Active Directory (MSAD) environment. When complete, AIX 5L user will authenticate against the Microsoft KDC and all user information will be stored in the Microsoft Active Directory. User administration...
  #20  
By skol on August 23rd, 2007
Re: Microsoft Windows 2003 Active Directory integration

Hi
your krb5.conf looks fine.
May you try the command:
kinit -k #(without -t /etc/krb5/krb5.keytab)
This takes the default location.
And afterwards check with "klist".

Regards
Stefan
Reply With Quote
  #21  
By cjs226 on August 23rd, 2007
Re: Microsoft Windows 2003 Active Directory integration

# kinit -k /etc/krb5/krb5.keytab
Unable to obtain initial credentials.
Status 0x96c73a9a - Cannot find KDC for requested realm.

# klist
Unable to get cache name (ticket cache: /var/krb5/security/creds/krb5cc_0).
Status 0x96c73ac3 - No credentials cache found.

# ls -al /var/krb5/security/creds/
total 0
drwxrwxrwt 2 root security 256 Aug 20 09:41 .
drwxr-xr-x 4 root security 256 Aug 20 09:41 ..
Reply With Quote
  #22  
By izax_max on December 5th, 2007
Re: Microsoft Windows 2003 Active Directory integration

Hi uGuys,

I have been working with the IBM stuff more and more lately and i am like any other person sometimes in need of great information. I found the forum when i was searching for some answers on kerberos and AIX -> w2003 R2.



Thanx for allowing me to join.


IzaX_Max
Reply With Quote
  #23  
By ravikumar on February 26th, 2008
Re: Microsoft Windows 2003 Active Directory integration

Hi Fida,

I am trying to implement the AIX and AD integration using the doc. I am facing the problem
Unable to obtain initial credentials.
Status 0x96c73a06 - Client not found in Network Authentication Service database or client locked out.

Can you let me know how you resolved the problem.

Best Regards,

Ravikumar
Reply With Quote
  #24  
By stoggy on April 27th, 2008
Re: Microsoft Windows 2003 Active Directory integration

I have never used aix so maybe you guys dont have these problems. but i have been searching for a long time to get this to work and maybe someone here knows. And I think something like this would be a problem in AIX too.

i have solaris and linux machines i want to authenticate to AD.

1. in AD as far as i can tell you cant have a user called root and a group called root. so how are you making users and groups that have the same names? The only thing i can think of is make group root be something like groot but that sucks...

2. some of the uids/gids in solaris and linux dont match up. For instance in solaris uid 5 is uucp and in linux uid 5 is sync. have you dealt with this? I know i can change them and then relabel the fs but then what about updates? In ldap i just created a new ou and put solaris in it and linux in another. But I dont see a way to do this in AD and the AD admins go nuts if i even mention making a new domain, but i am not sure if even that would work.

I can set system auth to use the passwd files for system accounts and not put the system accounts in AD, but this seems dangerous if an account gets deleted from the passwd file then it will authenticate against ad and either not work or authenticate wrong. hasn't been a problem in solaris but i have dealt with this in linux. user rpc got deleted by an rpm update and so it auth'd to my ldap server. i had user rpc in ldap and everything worked fine, i didnt even know there was a problem until i tried to update rpc again and the rpm failed because there was no user rpc in the passwd file.


thanks for any help.
Reply With Quote
  #25  
By alexisl on April 28th, 2008
Re: Microsoft Windows 2003 Active Directory integration

First, you would not want root to log in through AD. That should be done ONLY on the local machine. Also you would not want the system users such a uucp to log in through AD. It is only meant for actual users like jdoe (john doe). The gid and uid don't seem to matter but the name of the group does, we use users as the name of our groups.

As far as system accounts, yes set them manually through either chuser or by editting /etc/security/user
Reply With Quote
Comment

Bookmarks

These are the 100 most searched terms
Search Cloud
0042-001 0042-001 nim 0513-001 the system resource controller daemon is not active 0513-001 the system resource controller daemon is not active. 0514-061 0514-061 cannot find a child device 0514-061 cannot find a child device. 0516-787 0516-787 extendlv 0516-787 extendlv: maximum allocation for logical volume 110000ac aa00e1f3 aio aix aix aio aix freeware aixif_arp_dup_addr b150f22a b181fb53 ba010004 c1001020 d133c002 dacnone dcb47997 dlpar fcp_array_err6 fget_config gnu tar aix gsclvmd gtar aix hi yall hmc root password hmc vmware hscl05db ibm p6 ibm p6 520 libpopt aix libpopt.a libpopt.a(libpopt.so.0) is needed by rsync-2.6.2-1 migratelv mksysb navisphere agent nim server pseries pseriestech rsync aix sc_disk_err4 scan_error_chrp vio server websm xhost file ... powered by Simple Search Cloud


LinkBacks (?)
LinkBack to this Thread: http://www.pseriestech.org/forum/tutorials/microsoft-windows-2003-active-directory-integration-65.html
Posted By For Type Date
Discover From Your Favorite Topic or Web Page: subversion Windows Active Directory This thread Refback June 17th, 2008 08:01

Currently Active Users Viewing This Tutorial: 1 (0 members and 1 guests)
 
Tutorial Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Tutorial Tutorial Starter Category Comments Last Post
Knocks Solutions KNOCKSsolutions Announcements 0 June 9th, 2007 05:49
Active Directory Authentication bebenianne AIX for POWER Systems 4 June 6th, 2007 09:43
CIFS NFS V4 Windows 2003 server Clients John G Harney AIX for POWER Systems 0 September 20th, 2006 16:14



Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Powered by vbWiki Pro 1.3 RC5. Copyright ©2006-2007, NuHit, LLC

vBulletin Skin developed by: vBStyles.com

Tutorial powered by GARS 2.1.8m ©2005-2006


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50