<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Authenticating Active Directory users on Linux with Likewise Open</title>
	<atom:link href="http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/feed/" rel="self" type="application/rss+xml" />
	<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/</link>
	<description>random stuff from the mind of a twenty-something professional geek</description>
	<lastBuildDate>Fri, 16 Jul 2010 16:43:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: andrewe</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-943</link>
		<dc:creator>andrewe</dc:creator>
		<pubDate>Mon, 12 Jul 2010 01:59:11 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-943</guid>
		<description>Hi.

thanks for this. Worked like a treat in joining to the domain but now I can&#039;t access as root, I can only access as my domain account which has no authority to do anything on the box. If I try accessing as my original user account I get an authentication failure. I can&#039;t sudo under my domain account and obviously can&#039;t modify sudoers.

Any advice?

I&#039;m running Likewise 6 and Linux Mint 9.</description>
		<content:encoded><![CDATA[<p>Hi.</p>
<p>thanks for this. Worked like a treat in joining to the domain but now I can&#8217;t access as root, I can only access as my domain account which has no authority to do anything on the box. If I try accessing as my original user account I get an authentication failure. I can&#8217;t sudo under my domain account and obviously can&#8217;t modify sudoers.</p>
<p>Any advice?</p>
<p>I&#8217;m running Likewise 6 and Linux Mint 9.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andys</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-35</link>
		<dc:creator>andys</dc:creator>
		<pubDate>Mon, 22 Feb 2010 14:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-35</guid>
		<description>Hi Yvo,

Thanks for that - I&#039;ve updated the post with a link to your hint.

Cheers!</description>
		<content:encoded><![CDATA[<p>Hi Yvo,</p>
<p>Thanks for that &#8211; I&#8217;ve updated the post with a link to your hint.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yvo van Doorn</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-30</link>
		<dc:creator>Yvo van Doorn</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:02:30 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-30</guid>
		<description>If you want to get rid of the DOMAIN\ part…
edit the following file:
“vi /etc/likewise/lsassd.conf”
Find the line that says “assume-default-domain”
and set it to true or uncomment depending on the version of likewise.
It’s best to reboot after this just to deal with the change.
PS. This only works when your user account and computer account are part of the same domain</description>
		<content:encoded><![CDATA[<p>If you want to get rid of the DOMAIN\ part…<br />
edit the following file:<br />
“vi /etc/likewise/lsassd.conf”<br />
Find the line that says “assume-default-domain”<br />
and set it to true or uncomment depending on the version of likewise.<br />
It’s best to reboot after this just to deal with the change.<br />
PS. This only works when your user account and computer account are part of the same domain</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andys</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-18</link>
		<dc:creator>andys</dc:creator>
		<pubDate>Tue, 02 Feb 2010 17:20:19 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-18</guid>
		<description>Ooh... I wonder if it&#039;s baulking at the backslashes.

You can specify usernames in the form &lt;code&gt;user@domain&lt;/code&gt; (so &lt;code&gt;tso940@domain&lt;/code&gt; in your example) - that might work?

Failing that, try just specifying the UID (again, in your case 1115247694).</description>
		<content:encoded><![CDATA[<p>Ooh&#8230; I wonder if it&#8217;s baulking at the backslashes.</p>
<p>You can specify usernames in the form <code>user@domain</code> (so <code>tso940@domain</code> in your example) &#8211; that might work?</p>
<p>Failing that, try just specifying the UID (again, in your case 1115247694).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-17</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 02 Feb 2010 16:55:54 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-17</guid>
		<description>Thanks for the pointer.

We don&#039;t usually configure users with more than 8 characters for application compatibility but I&#039;ve changed my AIX 5.3 system to accept a 20 character user and although this works ok:

root@utajona2:/ # id domain\\tso940
uid=1115247694(domain\tso940) gid=1115161089(domain\domain^users) groups=1115243261(domain\cs-gpounrestricteduser),1115317722(domain\jlbrallowedrodcpasswordreplicationgroup),1115294180(domain\wrbrallowedrodcpasswordreplicationgroup),1115161766(domain\g_gpo-s-u^unres)

when I run the command to add my domain user to the local ldap group again, I get another (different) error:

root@utajona2:/ # usermod -G domain\\domain^users,domain\\cs-gpounrestricteduser,domain\\jlbrallowedrodcpasswordreplicationgroup,domain\\wrbrallowedrodcpasswordreplicationgroup,domain\\g_gpo-s-u^unres,ldap domain\\tso940

3004-687 User &quot;domaintso940&quot; does not exist.

Something malformed there...

Jon</description>
		<content:encoded><![CDATA[<p>Thanks for the pointer.</p>
<p>We don&#8217;t usually configure users with more than 8 characters for application compatibility but I&#8217;ve changed my AIX 5.3 system to accept a 20 character user and although this works ok:</p>
<p>root@utajona2:/ # id domain\\tso940<br />
uid=1115247694(domain\tso940) gid=1115161089(domain\domain^users) groups=1115243261(domain\cs-gpounrestricteduser),1115317722(domain\jlbrallowedrodcpasswordreplicationgroup),1115294180(domain\wrbrallowedrodcpasswordreplicationgroup),1115161766(domain\g_gpo-s-u^unres)</p>
<p>when I run the command to add my domain user to the local ldap group again, I get another (different) error:</p>
<p>root@utajona2:/ # usermod -G domain\\domain^users,domain\\cs-gpounrestricteduser,domain\\jlbrallowedrodcpasswordreplicationgroup,domain\\wrbrallowedrodcpasswordreplicationgroup,domain\\g_gpo-s-u^unres,ldap domain\\tso940</p>
<p>3004-687 User &#8220;domaintso940&#8243; does not exist.</p>
<p>Something malformed there&#8230;</p>
<p>Jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andys</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-16</link>
		<dc:creator>andys</dc:creator>
		<pubDate>Tue, 02 Feb 2010 14:50:34 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-16</guid>
		<description>Ah - I think that is the problem :-/

I&#039;m not sure on the limit these days under Linux - a quick Google suggests at least 32 characters is fine.

&lt;a href=&quot;http://www.unix.com/aix/56417-username-more-than-8-characters.html&quot; rel=&quot;nofollow&quot;&gt;This page&lt;/a&gt; seems to suggest that the limit in AIX was 8 character up until one of the 5.x releases, but it&#039;s now 255 characters...</description>
		<content:encoded><![CDATA[<p>Ah &#8211; I think that is the problem :-/</p>
<p>I&#8217;m not sure on the limit these days under Linux &#8211; a quick Google suggests at least 32 characters is fine.</p>
<p><a href="http://www.unix.com/aix/56417-username-more-than-8-characters.html" rel="nofollow">This page</a> seems to suggest that the limit in AIX was 8 character up until one of the 5.x releases, but it&#8217;s now 255 characters&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-15</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 02 Feb 2010 14:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-15</guid>
		<description>Thanks

that&#039;s pretty clearly working for you...my problem (and it could well be AIX) is that when I try to run this:-

root@utajona2:/ # usermod -G domain\\domain^users,domain\\cs-gpounrestricteduser,domain\\jlbrallowedrodcpasswordreplicationgroup,ldap domain\\username

I get the error:

3004-691 Error changing &quot;domainusername&quot; : Name is too long.

What&#039;s the max username length in the version of Linux you were using above?  In AIX it&#039;s 8 so that could be the limit I&#039;m hitting with this.

Cheers

Jon</description>
		<content:encoded><![CDATA[<p>Thanks</p>
<p>that&#8217;s pretty clearly working for you&#8230;my problem (and it could well be AIX) is that when I try to run this:-</p>
<p>root@utajona2:/ # usermod -G domain\\domain^users,domain\\cs-gpounrestricteduser,domain\\jlbrallowedrodcpasswordreplicationgroup,ldap domain\\username</p>
<p>I get the error:</p>
<p>3004-691 Error changing &#8220;domainusername&#8221; : Name is too long.</p>
<p>What&#8217;s the max username length in the version of Linux you were using above?  In AIX it&#8217;s 8 so that could be the limit I&#8217;m hitting with this.</p>
<p>Cheers</p>
<p>Jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andys</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-14</link>
		<dc:creator>andys</dc:creator>
		<pubDate>Tue, 02 Feb 2010 14:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-14</guid>
		<description>Hi Jon,

I did it with usermod - it seems to work fine. Here&#039;s what I&#039;ve just done to add my user to the local &#039;pulse&#039; group.

Before the change:-

&lt;pre&gt;root@therapy:~# &lt;b&gt;id HMS\\asmith&lt;/b&gt;
uid=1794114690(HMS\asmith) gid=1794114049(HMS\domain^users)&lt;br&gt;
groups=1794114049(HMS\domain^users),104(lpadmin),123(scard),&lt;br&gt;
1794114673(HMS\hmstest),1794114048(HMS\domain^admins)&lt;/pre&gt;

Adding my account to the &#039;pulse&#039; group:-

&lt;pre&gt;root@therapy:~# &lt;b&gt;usermod -G HMS\\domain^users,lpadmin,scard,&lt;br&gt;
HMS\\hmstest,HMS\\domain^admins,pulse HMS\\asmith&lt;/b&gt;&lt;/pre&gt;

And now checking the account afterwards:-

&lt;pre&gt;root@therapy:~# &lt;b&gt;id HMS\\asmith&lt;/b&gt;&lt;br&gt;
uid=1794114690(HMS\asmith) gid=1794114049(HMS\domain^users) &lt;br&gt;
groups=1794114049(HMS\domain^users),104(lpadmin),117(pulse),&lt;br&gt;
123(scard), 1794114673(HMS\hmstest), 1794114048(HMS\domain^admins)&lt;/pre&gt;

Looking at /etc/group shows we&#039;ve been added:-

&lt;pre&gt;root@therapy:~# &lt;b&gt;grep &quot;^pulse:&quot; /etc/group&lt;/b&gt;
pulse:x:117:HMS\asmith&lt;/pre&gt;

This is under Linux though, so I don&#039;t know if AIX treats things differently - my AIX exposure is limited to a handful of boxes I had to manage a few years back ;-)

What do you get if you type &lt;b&gt;id DOMAINNAME\\jon&lt;/b&gt; - does the ldap group show up as one of the user&#039;s groups?</description>
		<content:encoded><![CDATA[<p>Hi Jon,</p>
<p>I did it with usermod &#8211; it seems to work fine. Here&#8217;s what I&#8217;ve just done to add my user to the local &#8216;pulse&#8217; group.</p>
<p>Before the change:-</p>
<pre>root@therapy:~# <b>id HMS\\asmith</b>
uid=1794114690(HMS\asmith) gid=1794114049(HMS\domain^users)
groups=1794114049(HMS\domain^users),104(lpadmin),123(scard),
1794114673(HMS\hmstest),1794114048(HMS\domain^admins)</pre>
<p>Adding my account to the &#8216;pulse&#8217; group:-</p>
<pre>root@therapy:~# <b>usermod -G HMS\\domain^users,lpadmin,scard,
HMS\\hmstest,HMS\\domain^admins,pulse HMS\\asmith</b></pre>
<p>And now checking the account afterwards:-</p>
<pre>root@therapy:~# <b>id HMS\\asmith</b>
uid=1794114690(HMS\asmith) gid=1794114049(HMS\domain^users) 
groups=1794114049(HMS\domain^users),104(lpadmin),117(pulse),
123(scard), 1794114673(HMS\hmstest), 1794114048(HMS\domain^admins)</pre>
<p>Looking at /etc/group shows we&#8217;ve been added:-</p>
<pre>root@therapy:~# <b>grep "^pulse:" /etc/group</b>
pulse:x:117:HMS\asmith</pre>
<p>This is under Linux though, so I don&#8217;t know if AIX treats things differently &#8211; my AIX exposure is limited to a handful of boxes I had to manage a few years back <img src='http://andys.org.uk/bits/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>What do you get if you type <b>id DOMAINNAME\\jon</b> &#8211; does the ldap group show up as one of the user&#8217;s groups?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-13</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 02 Feb 2010 11:15:29 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-13</guid>
		<description>Andy

usermod only seems to be valid for local users/groups.  Did you make your group change by editing /etc/group (or Ubuntu equivalent) directly?

This is what I added to /etc/group:

ldap:!:206:DOMAINNAME\\jon

but when I try to access files with read permission assigned to the ldap group, I get permission denied.

Jon</description>
		<content:encoded><![CDATA[<p>Andy</p>
<p>usermod only seems to be valid for local users/groups.  Did you make your group change by editing /etc/group (or Ubuntu equivalent) directly?</p>
<p>This is what I added to /etc/group:</p>
<p>ldap:!:206:DOMAINNAME\\jon</p>
<p>but when I try to access files with read permission assigned to the ldap group, I get permission denied.</p>
<p>Jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andys</title>
		<link>http://andys.org.uk/bits/2010/01/28/likewise-open-and-linux/comment-page-1/#comment-12</link>
		<dc:creator>andys</dc:creator>
		<pubDate>Mon, 01 Feb 2010 16:16:15 +0000</pubDate>
		<guid isPermaLink="false">http://andys.org.uk/bits/?p=20#comment-12</guid>
		<description>Jon,

Just realised that I have done this under Ubuntu, and it works.

Do you have any joy using usermod -G?</description>
		<content:encoded><![CDATA[<p>Jon,</p>
<p>Just realised that I have done this under Ubuntu, and it works.</p>
<p>Do you have any joy using usermod -G?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
