Samba in the Enterprise : Samba 3.0 and beyond



Similar documents
Integration with Active Directory. Jeremy Allison Samba Team

OpenVMS Update & OpenVMS Common Internet File System based on SAMBA

Open Directory. Apple s standards-based directory and network authentication services architecture. Features

Windows Services. Support Windows and mixed-platform workgroups with high-performance, affordable network services. Features

Red Hat Enterprise ipa

SuSE File and Print Services with

(june > this is version 3.025a)

Samba as an Active Directory Domain Controller

Using Samba to play nice with Windows. Bill Moran Potential Technologies

Univention Corporate Server. Operation of a Samba domain based on Windows NT domain services

IBM TRAINING L13. Replacing Windows Servers with Linux. Mark Post. Orlando, FL Mark Post

Active Directory Comapatibility with ExtremeZ-IP A Technical Best Practices Whitepaper

Integrating UNIX and Linux with Active Directory. John H Terpstra

Samba. Samba. Samba 2.2.x. Limitations of Samba 2.2.x 1. Interoperating with Windows. Implements Microsoft s SMB protocol

Charles Firth Managing Macs in a Windows World

Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting

Red Hat Enterprise IPA Identity & Access Management for Linux and Unix Environments. Dragos Manac

IPA Identity, Policy, Audit Karl Wirth, Red Hat Kevin Unthank, Red Hat

<Samba status report>

Samba 4 AD + Fileserver

Setting up a DNS MX Record for mail.corp.com p. 327 Installing Fedora on the Front-End Mail Server with the Postfix and SpamAssassin Packages

Active Directory and DirectControl

Functions of NOS Overview of NOS Characteristics Differences Between PC and a NOS Multiuser, Multitasking, and Multiprocessor Systems NOS Server

Transparent fileservices for Windows, Unix and Mac

File Services. File Services at a Glance

Mac OS X Directory Services

Network operating systems typically are used to run computers that act as servers. They provide the capabilities required for network operation.

Using LDAP Authentication in a PowerCenter Domain

Open Server-based Desktop Freiburg im Breisgau, Germany

Cross-Realm Trust Interoperability, MIT Kerberos and AD

User Pass-Through Authentication in IBM Cognos 8 (SSO to data sources)

1. Installation Overview

Common Internet File System

Installing Management Applications on VNX for File

Enabling Active Directory Authentication with ESX Server 1

Active Directory and Linux Identity Management

Quick Start - NetApp File Archiver

Lecture No 01 Novell Products Open Enterprise Server 2 Preview By Haim Malool. Main features Preview

Installation Overview

Red Hat Enterprise Linux as a

Active Directory Integration

Configuring IBM Cognos Controller 8 to use Single Sign- On

Active Directory Compatibility with ExtremeZ-IP

Integrating Linux systems with Active Directory

White Paper. Managing Group Policies for Non Windows Computers through Microsoft Active Directory

Citrix ICA UNIX Client Quick Reference Card

storage elements and computer systems so that data transfer is secure and robust."

elan Technology White Paper Why Linux?

Going in production Winbind in large AD domains today. Günther Deschner (Red Hat / Samba Team)

Advanced Authentication

Using Single Sign-on with Samba. Appendices. Glossary. Using Single Sign-on with Samba. SonicOS Enhanced

SMB in the Cloud David Disseldorp

Mac OS X and Directory Services Integration

Novell Open Enterprise Server

Managing Group Policies for Non-Windows Computers through Microsoft Active Directory

Other documents in this series are available at: servernotes.wazmac.com

Single Sign-on (SSO) technologies for the Domino Web Server

Active Directory Compatibility with ExtremeZ-IP. A Technical Best Practices Whitepaper

Using SUSE Linux Enterprise Desktop with Microsoft * Active Directory Infrastructure

Migration of Windows Intranet domain to Linux Domain Moving Linux to a Wider World

Understand Troubleshooting Methodology

Centralized Mac Home Directories On Windows Servers: Using Windows To Serve The Mac

Why is it a better NFS server for Enterprise NAS?

Samba's AD DC: Samba 4.2 and Beyond. Presented by Andrew Bartlett of Catalyst //

CONFIGURING ACTIVE DIRECTORY IN LIFELINE

DB2 Connect for NT and the Microsoft Windows NT Load Balancing Service

Introduction to Computer Administration. System Administration

Whitepaper: Centeris Likewise Identity 3.0 Security Benefits

History of Windows. INLS 576 Spring 2009 Tuesday, 1/13/2009

Running Linux in a Windows World. John H Terpstra, CTO Primastasys Inc. jht@primastasys.com

Active Directory Change Notifier Quick Start Guide

Implementing Active Directory Hurdles, Obstacles, and the Finish Line. Jim McDonough Samba Team IBM Linux Technology Center April 6, 2004

Integration for Open Text Fax Appliance and Open Text Fax Appliance, Premier Edition

Working Together - Your Apple Mac and Microsoft Windows

SerNet. Samba Status Update. Munich 13. March Volker Lendecke SerNet Samba Team. Network Service in a Service Network

Investigation of the EU Commission towards Microsoft

Q&A Session for Understanding Atrium SSO Date: Thursday, February 14, 2013, 8:00am Pacific

Mac OS X. Playing nice in a heterogeneous world PRESENTED BY:Charles Edge 318.COM

Active Directory Implemenation

Active Directory Synchronization with Lotus ADSync

Managing Celerra for the Windows Environment

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

owncloud Architecture Overview

Single Sign-On for Kerberized Linux and UNIX Applications

technical brief Multiple Print Queues

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

What we are going to cover...

Getting Started Guide

SSSD Active Directory Improvements

identity management in Linux and UNIX environments

System Compatibility. Enhancements. Security. SonicWALL Security Appliance Release Notes

FreeIPA 3.3 Trust features

The Integration of LDAP into the Messaging Infrastructure at CERN

Integrating Red Hat Enterprise Linux 6 with Microsoft Active Directory Presentation

SMB a protocol example

SerNet. Samba Status Update. Linuxkongress Hamburg October 10, Volker Lendecke SerNet Samba Team. Network Service in a Service Network

Small Systems Solutions is the. Premier Red Hat and Professional. VMware Certified Partner and Reseller. in Saudi Arabia, as well a competent

KASPERSKY LAB. Kaspersky Administration Kit version 6.0. Administrator s manual

Measurably reducing risk through collaboration, consensus & practical security management CIS Security Benchmarks 1

White Paper BMC Remedy Action Request System Security

Transcription:

Samba in the Enterprise : Samba 3.0 and beyond By Jeremy Allison jra@samba.org jeremy.allison@hp.com

Where we are now : Samba 2.2 The current Samba is a credible replacement for a Windows server providing file and print services. More robust than Windows, scales to larger machines than Windows. Provides better performance than Windows on identical hardware (when used with Linux). See : PC Magazine report (details on next slides). Samba certainly can't be beaten on cost.

Performance Figures (thoughput) From PC Magazine.

Performance Figures (response time).

Moving beyond the workgroup As Linux expands into the Enterprise, Samba must change in order to grow with it. Directory services, single sign on, account controls become much more important. Integration with Enterprise security systems such as Kerberos are needed. Better management and configuration tools are needed to handle large number of servers.

Samba 3.0 Roadmap Currently in alpha, rapidly moving towards production release. The aim is to ship in spring 2003. This is software, don't take the above seriously. Uses UNICODE in talking to clients. Allows true multi-lingual file name storage (when file names are in UTF8 the default in RedHat 8). Full Kerberos 5 and NTLMv2 support. Single sign-on when using a Windows 2000 Domain.

Samba 3.0 Roadmap (continued). Full support for LDAP directory infrastructure using standard LDAP v3 calls. Provided by any LDAP directory server with correct schema. Windows 2000 ADS OpenLDAP Other proprietary LDAP servers (Novell, IPlanet etc.). Dynamic password backend selection. Plug-ins with fallback support.

Samba 3.0 File and Print Enhancements. Better mapping from Windows access control lists (ACLs) to POSIX ACLs. POSIX ACLs are starting to ship as standard in many Linux distributions. 'Stacking' VFS (virtual file system) layer allows dynamic checking of file access. Virus scanning, auditing, security. Scalable printing Major goal for HP. The aim is to support more than 1000 print queues. Integrated Microsoft DFS support.

Samba 3.0 Example Module Stack Windows Client Open/Write Request Samba Server Storage Filesystem Audit Module Anti-Virus Module Secure log area. Virus Checking Program

Domain Integration Account Control Samba 3.0 will support all the restrictions a Windows 2000 server does. Password expiration, logon time restrictions, client machine restrictions etc. All can be retrieved from an Active Directory PDC or set locally in Samba's own account databases. Windows Domain groups can be mapped onto local UNIX groups for greater control. Similar to 'Local'groups on a Windows server. Idea is to make integrating Samba servers easy.

Kerberos and NTLMv2 Security Samba 3.0 uses MIT Kerberos libraries to interoperate with Windows 2000 Domains. Despite what you may hear, Microsoft Kerberos is standard enough to support UNIX kerberos. So long as you're not trying to serve logons to Microsoft clients... Just tell the Samba server your Kerberos Realm name then add it to the Windows 2000 Domain (using the new 'net'command). New NTLMv2 code allows security to be 'upgraded'on Windows networks So long as you don't have Win9x clients.

Management and Configuration Tools. The new 'net'command. Allows command line manipulation of a Windows or Samba file and print server. Designed to be familiar to Windows administators moving to Linux. Several Microsoft Management (MMC) plugins work against Samba servers. The goal over the 3.0 series is to keep adding additional MMC support to Samba. Currently all good Enterprise level file server configuration tools are proprietary.

Samba as a Domain Controller Replacement. Potentially the most useful Samba function. Frees an Enterprise from paying Microsoft client license fees. Currently only older Domain protocols supported. Windows 2000 protocols are (of course) undocumented. Support for Windows 2000 clients as an Active Directory replacement with OpenLDAP is being actively worked on. New 'net vampire'command allows Domain account information to be transparently moved to Samba.

Samba as a Print Server Samba now supports all the Windows printer driver download calls. Most Windows printer functions can be replaced with Samba. The only issue is printer driver initialization on non- Intel platforms. Due to Linux/UNIX scalability, Samba serves many more print clients than Windows. HP is testing 1000 simultaneous print queue systems using large HPUX servers.

HP Samba Sucesses HP ships CIFS/9000 a Samba product on HPUX Replaces old Windows code based product. Some typical uses : 5-node rp7400 (N-Class) cluster serving 8000 clients. 3-node rp5400 (L-Class) cluster serving 2000 clients. 3 rp5400 (L-Class) servers, 500 users each. Serving everything from Microsoft Office, to CAD/CAM to ClearCase files... If an application works to a Windows file server, it'll work to a Samba file server.

Samba Development Who is involved? HP employs 5 full time Samba developers Not even counting the CIFS/9000 Team. IBM employs 3 full time Samba developers. SGI, Sun and Apple all have people assigned to Samba on permanent staff. Linux Vendors perform security audits against Samba (SuSE, SCO in particular). In addition to the 'students living in basements' Samba installation and configuration help can be found worldwide.

Samba is everywhere... (even if users don't know it ) HP Print Server Appliance All Linux based NAS Servers. Sun/Cobalt Servers PizzaBox Server

References Samba web site : www.samba.org World wide mirrors. Samba mailing list : samba@samba.org Samba developers mailing list : samba-technical@samba.org

Questions?