| United States-English |
|
|
|
![]() |
HP CIFS Server 3.0g Administrator's Guide version A.02.03.01: HP-UX 11i v1, v2 and v3 > Chapter 9 HP CIFS Deployment ModelsUnified Domain Model |
|
You can use the Unified Domain Deployment Model in environments with the following characteristics:
The Unified Domain Model provides the following benefits:
Figure 9-9 shows the Unified Domain Deployment Model as follows: The Unified Domain Model consists of a Windows 200x server with Active Directory Services (ADS) configured as a Domain Controller (DC), and a single or multiple HP CIFS member servers. To use the Windows 200x ADS server as a data repository to consolidate Windows and UNIX user accounts, you need to install the Services for UNIX (SFU) add-on package which extends the Active Directory schema based on RFC 2307 to allow integration of POSIX attributes. All user management is unified on the Windows 2000/2003 ADS Server; winbind is not required. You must install and configure the LDAP-UX Integration software on your HP CIFS member server. The LDAP-UX Integration software helps HP CIFS Server machine access UNIX user account data from the ADS Server. "LDAP-UX Client Service with Micrsoft Windows 2000 Active Directory Administrator's Guide", available at http://docs.hp.com, provides help for HP-UX ADS client configurations. The HP CIFS member server operating in a unified domain depends on the ADS to be aided by Services For UNIX (SFU). SFU provides the required management of UNIX UID and GID to Windows SID mappings. SFU and accompanying documentation is available for download at http://www.microsoft.com/windows/sfu. Because all user management is unified on the Windows 2000/2003 ADS server, winbind is not required and there are no ID consistency issues regardless of the number of HP CIFS member servers. HP CIFS Server uses Kerberos security in a Windows Unified Domain setup. For more information on how to join an HP CIFS Server to a Windows 200x Domain using Kerberos security, see Chapter 5 “Windows 2000/2003 Domains”. You need to set up and configure the following components to deploy an Unified Domain Model using Windows Services For UNIX (SFU):
In the Unified domain model, you integrate HP CIFS domain member servers with the Windows 200x ADS to centralize managemnt of user accounts databases. You must install the HP LDAP-UX integration software B.03.20 or later, and configure the LDAP-UX client.This permits the consolidation of Posix and Windows user accounts on the ADS directory. You also need to configure the /etc/krb5.conffile to authenticate users using Kerberos. The following summarizes major steps you need to take to install and configure an LDAP-UX Client Services. For detailed instructions on how to install and configure LDAP-UX Client Services to work with Windows 2000 ADS, refer to chapter 2, "Installing LDAP-UX Client Services" in LDAP-UX Client Services with Microsoft Windows 2000 Active Directory Server Administrator's Guide, available at http://docs.hp.com.
On your HP CIFS Server, you need to create the Kerberos configuration file, /etc/krb5.conf, which specifies the default realm, the location of a Key Distribution Center (KDC) server and the logging file names. The Kerberos client depends on the configuration to locate the realm's KDC. The following is an example of /etc/krb5.conf which has the realm CIFSW2KSFU.ORG.HP.COM, and machine hostA.org.hp.com as a KDC:
POSIX accounts have some attributes, such as user ID, login shell, and home directory, which are not used by Windows 2000 or 2003. To use Active Directory as a data repository for HP-UX users, you must install SFU Version 3.5 on a Windows 2000 or 2003 doman controller. SFU is used to extend the Active Directory schema to include the POSIX schema. For detailed installation instructions for SFU 3.5, refer to Chapter 2 "Installing LDAP-UX Client Services", in LDAP-UX Client Services with Windows 2000 Active Directory Server Administrator's Guide, available at http://docs.hp.com. For more information on SFU, refer to the Microsoft web site at http://www.microsoft.com/windows2000/sfu/.
Figure 9-10 shows an example of the Unified Domain Model which has the realm named HPCIFSW2KSFU.ORG.HP.COM, an ADS domain controller machine hpntcdn, an HP CIFS Server machinehostD acting as a member server and the Windows NT machine with IP address 1.13.112.166 as the WINs server. The following is a sample Samba configuration File, /etc/smb.conf, used for an HP CIFS Server machine hostD acting as an ADS member server in the sample Unified Domain Model shown in Figure 9-10:
On your HP CIFS Server acting as a ADS member server, you need to create the Kerberos configuration file, /etc/krb5.conf, which specifies the name of the realm, the location of a Key Distribution Center (KDC) server and the logging file names. The following is a sample /etc/krb5.conf which has the realm CIFSW2KSFU.ORG.HP.COM, and the machine hpntcdn.org.hp.comas a KDC:
In the Unified Domain Model, you must configure the /etc/nsswitch.conf file to specify the LDAPname service and other name services you want to use . The following is a sample /etc/nsswitch.conf used in the sample Unified Domain Model shown in Figure 9-10:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||