Which Directory Service do you use for your network?
Submitted by debianuser0 on Tue 15 Jul 2008
| None |
![]() 21% | 185 votes |
| NIS |
![]() 4% | 41 votes |
| LDAP |
![]() 22% | 189 votes |
| LDAP + Kerberos |
![]() 7% | 61 votes |
| Samba |
![]() 20% | 174 votes |
| Active Directory |
![]() 20% | 171 votes |
| eDirectory |
![]() 1% | 16 votes |
| other |
![]() 1% | 16 votes |
| Total 853 votes |
[ Parent ]
[ Parent ]
good its by anonymous would be embarising. But ok, nobody is perfect!
to be honest, I voted AD since we run win2k3 domains, so I usually join sambas and firewalls etg to the MS AD.
for other projects and privat ones I prefer ldap. back in the day novell.... muhaaa
[ Parent ]
Hi altogether,
if you selected "other", please explain what it is.
It's sad but true, MS Active Directory seems to be the easiest, most secure solution to handle a small to medium size(20-30) bunch of users and their machines(?)
It brings all the needed technologies under one cup.
LDAP + Kerberos is more complicated to setup separately.
I installed the combination under OpenSuse using mix of the Yast Interface and the steps in the manual and it was very error prone and the whole procedure looks premature.
Made also installations under debian with only a few machines. Took also a while.
Routine operations are not supported in a user friendly way (Mean things like adding or removing users and resources etc).
I tried webmin as frontend. But that's
no permanent solution either.
Is there a secure, comfortable, robust, enterprise approved open source all in one package for the tasks of user and resource management and all associated stuff?
I mean including installation and configuration of kerberos and ldap for example.
Okay, a step by step manual that 100% works would be enough.
For a secure(TLS/SSL) LDAP Setup alone it's taking quite a lot of time to find one.
(Think of generating Certs using openssl, what a turd, there are 10^32 different descriptions and none really works out of the box)
I tried:
- passwd/shadow, distributed with rdist > doesn't scale + unsecureó> NO SOLUTION
- NIS, easy to setup, sometimes strange unpredictable behaviour when used in a master / slave configuration. Beside that, insecure -> NO SOLUTION
- LDAP alone: a bit more difficult to setup. Without encryption also unsecure.
--> NO SOLUTION
- LDAP + Kerberos: difficultò to setup. insufficient comfortable support for all days tasks.
--> BARELY SOLUTION
So our windows AD admins laughing at me.
they have a nice interface, easy to setup(a drunken ape could operate on it) and the whole thing is more secure than a hand weaved solution.
the dictum i heard most often last time was:
"open source is only for free if your time is worth nothing"
And in a way I recognize what they mean.
Any example to prove the opposite?
desperate,
Josh
[ Parent ]
[ Parent ]
http://hannibal.solstice.nl/hannibalwiki/doku.php?id=hannibal:fds
It`s on my todo - looks really interestring.
7horsten
[ Parent ]
[ Parent ]
[ Parent ]
[ Parent ]
I'm sure if it were re-done from scratch with current tools, it'd be much more manageable. As for AD, I've worked with it just enough to know that it very quickly gets out of hand, especially if you start monkeying with policies.
[ Parent ]
Usermanagement is no uncommon task. Why is there no free, simple and secure way to proceed yet? One working bullet proof solution would be enough.
maybe fedora-ds helps - i did not really checked out yet. cause it's seems to need a setup fedora system. Anyone successfully tried that hannibal project above?
bye, josh
Josh
[ Parent ]
That seems to be what the commercial solutions have going for them.
[ Parent ]
[ Parent ]
Or if any of the people who voted "LDAP + Kerberos" have the time, I'm sure an article about it would make a good addition to the site.
[ Parent ]

21%