Journal 28 Dec 2005 03:27 pm

SAMBA 3 Authenticating to a Windows 2003 Active Directory HOWTO

Finally got a good method down and it works consistantly… You can read it in straight HTML too.

Continue Reading »

Geek & Journal 15 Dec 2005 04:55 pm

Samba3 using a Windows AD LDAP server

I finally got one of my Linux servers to successfully, and somewhat stable, connect to the state’s AD servers and use them for account authentication. Unfortunately, I did it on a machine that I have already monkeyed around with a bit, so I don’t have a document for it yet. I am going to try it on a clean machine Monday to see if I can replicate it.

So far though the speeds off of it seem to beat similarly spec’ed Windows machines by about 6-7 secs for a 650meg file. We using Gigabit Ethernet to connect the two and off of our Windows server we are looking at about 27 secs while off of this machine we are pulling 20 secs.

This is a big deal though because off of our STI server we are looking at times around 2m29s. So moving STI over to a server similar to these has become a big priority.

Hopefully, I will be following this up with some information soon.

Geek 23 Jun 2003 12:41 pm

Defeated

I am walking away with my tail between my legs on this one. Since last Friday I have been endeavoring to install onto DeathstarII and having it working. Now installing itself is not really that difficult, but getting to work with a Windows2000 AD and understand Windows ACL control lists, now that is a completely different matter.

To start with I thought I would go ahead and get 3.0 running on it, since it boasts AD integration and I have never really been that happy with the NT4.0 domain integration that was in the 2.2 series. Well by the end of the deal I was wishing for the integration that 2.2 had. It took forever to get 3.0 to work correctly, partially because I missed a section of the docs, partially because stuff just isn’t right in it. It is almost like the team has left the idea of letting Linux server out files with Windows and moved on to making Linux be a PDC for a Windows domain. That seems to be their biggest goal in life now.
Once I got it to connect correctly I needed to recompile it for ACL support. Well doing that ended up not giving me ADS support. After several tries and lots of recompiles, I gave up on it. Their rpm building system is screwed up and wouldn’t produce a correct rpm (IMO).

So I dropped back to 2.2.8a only to find that I also couldn’t compile ACL support into it and that it had trouble accepting logins from different computers, depending on if they used the netbios name or the IP. So I said fuck it and am currently installing 2000 server on it. I need this to work, and I don’t have time to screw around with the developers while they try and get their shit together. It is no wonder people think Linux is such a joke, one of the biggest projects that we have in our camp, can’t even get it right. Grrr…….

Journal 23 Jun 2003 09:26 am

Defeated

I am walking away with my tail between my legs on this one. Since last Friday I have been endeavoring to install onto DeathstarII and having it working. Now installing itself is not really that difficult, but getting to work with a Windows2000 AD and understand Windows ACL control lists, now that is a completely different matter.

To start with I thought I would go ahead and get 3.0 running on it, since it boasts AD integration and I have never really been that happy with the NT4.0 domain integration that was in the 2.2 series. Well by the end of the deal I was wishing for the integration that 2.2 had. It took forever to get 3.0 to work correctly, partially because I missed a section of the docs, partially because stuff just isn’t right in it. It is almost like the team has left the idea of letting Linux serve out files with Windows and moved on to making Linux be a PDC for a Windows domain. That seems to be their biggest goal in life now.

Once I got it to connect correctly I needed to recompile it for ACL support. Well doing that ended up not giving me ADS support. After several tries and lots of recompiles, I gave up on it. Their rpm building system is screwed up and wouldn’t produce a correct rpm (IMO).

So I dropped back to 2.2.8a only to find that I also couldn’t compile ACL support into it and that it had trouble accepting logins from different computers, depending on if they used the netbios name or the IP. So I said fuck it and am currently installing 2000 server on it. I need this to work, and I don’t have time to screw around with the developers while they try and get their shit together. It is no wonder people think Linux is such a joke, one of the biggest projects that we have in our camp, can’t even get it right. Grrr…….

Thoughts 15 Dec 2002 12:56 pm

Microsoft making Linux products

Recently, there have been a group of people predicting that MS would start selling Linux versions of its software in the future. This prompted a lot of talk on slashdot and a few of my friends over at the lovely company of , started tossing around the idea. Since it seems that people are in the mood to believe guesses, I would like to take this moment and my space on the web to tell you, MS will not start selling Linux products for any kind of monetary gains. They might sell them for other reasons, try to disprove monopolist ideas, draw Linux users to Windows, or to destroy the space-time continuum, but they aren’t going to sell them for a direct profit. There is no way that MS could make a profit on selling apps for Linux. Follows are reasons why:

There are two types of apps MS could sell for Linux, desktop and server. Lets break each up for a closer look, since they have different fundamental reasons.

Desktop: It is pretty much a given that right now MS holds the desktop market in a stranglehold, that, despite the recent DOJ ruling, they have no reason to give up. They are losing some people to Linux on the desktop but a good percentage of Linux users are stuck using Windows at work and/or home, because they have to have the Office apps to work with the business. In the end it is difficult to convince a “suit” that OpenOffice or StarOffice will work flawlessly with other MS Office users. It is equally hard to convince them to give up the effects of Outlook for meetings and such, or even to purchase Ximian Connector to enable Evolution to do the deal. So they run Windows and their company (or them) pays for the license to MS. So what happens if MS makes Office for Linux? All the geeks and techs that want to can now switch to Linux and their companies can stop paying for Windows licenses. The only way MS can keep their revenues the same is to tack the cost of a Windows license into the purchase price of Office for Linux. If that is done then there is no reason for people to purchase Office for Linux from a company standpoint since it will cost the same to have their workers use Windows. Yeah they get the added stability of Linux, but most suits aren’t going to see that.

Server: Right now, according to all the surveys, this is where Windows is really starting to lose its foothold to Linux. Linux is eating up not only Windows server share but also other Unix style systems. If that is the case then why would anyone want to have MS stuff on Linux? Right now it seems that people are perfectly happy to switch out to Linux and what it has to offer, so why do they need the Windows server stuff at all? Well people like to use what they are familiar with and for a lot of server admins that is Windows. So perhaps they might take a robust server off of their Linux machine and install IIS with all of its security issues and problems, or perhaps exchange is really what they want and it will get installed on a Redhat box, but wait we forgot one important thing… MS again has no reason to make these products. Right now if you want/have to use exchange you have to not only purchase Exchange Server 2000 (or XP or .net or whatever), but you also have to purchase a Server License and Client Access Licenses for every computer that will connect to that machine. And that is the same for every Windows Server. No matter if it is filesharing, print sharing, domain controller, or proxy. If you know can just put one Windows thing on a Linux box, do you then have to buy CALs? It is obvious you don’t have to buy a server license. If you put this stuff on a Linux machine it is awfully easy for you to just turn on sharing and not pay the CALs for another Windows box to be your fileserver. See by enabling people to pick what OS they run for these Windows servers they are enabling people to avoid paying them money that they would normally get. People run exchange for its groupware effects, therefore they pay MS for all the Windows stuff mentioned earlier. If they can run that on Linux and get all the groupware effects without paying all the MS stuff, they have little reason to pay it and MS loses money. Therefore MS has little reason to make it.

Journal 15 Nov 2002 11:28 am

Linux and Power Steering

Odd combo for a subject huh?

Well today and the last few days/weeks have been rather interesting. The talk went well and has started a new wave of attacks on the status quo for my skills and ideas. I have another post that I was working that ties into this hopefully I will get it up soon.

I have developed a pretty cool backup system for Edmonson County Schools using linux and rsync to backup a program called STI. STI is not a very good program, but we are mandated to use it. Rock/hard place insert us. Therefore we often have to go back to backups and this is a lengthy process that often doesn’t work since everyone has to be out of it to get it to backup correctly. Thus I came up with this system to back up every 4 hours and for 7 days onto disk. This makes it quicker to restore from back up the files that we need. Everything is working ok on that and we talked to some of the other DTCs in about it so hopefully that will go over big and I can help put Linux into some other peoples schools and stuff.

Now the bad news. The sunfire has developed a very bad power steering leak. A very bad leak. Such that I drove home tonight with no power steering. Hopefully this will be a fix that is not too costly and works out ok in the end. It is enough to make you a nervous wreck though, because it is something that you hate to have happen and you can’t correct yourself.

Journal 05 Apr 2002 08:18 am

Streaks and Geeks

So for a while now I have been suffering through my job at , with little to do and less to think about. So I started reading some different material (I will talk about this in another post) and that has sort of jump started my brain a little. I picked up some documentation on iptables (firewalling tools) and started working through it. I dropped this though as the How-To that I am looking at is formated wrong for my learning style. So I started working on Diablo to make him better. I realized that I hadn’t tried the second IDE controller that the board had under Linux so I started messing with that. I had to pick up an auxillery power supply from some old dell machine to power all of the drives. So then I had 4 hard drives in but they were all different sizes and that was annoying. Having remembered some stuff I read I picked up some docs for LVM (Logical Volume Manager) for Linux and I read through it. Picked it up pretty nice and started working on it. I probably wouldn’t have been able to focus on it much except for I dug up some KMFDM mp3s and started jamming. In the end I now have one drive of 47 gigs and one virtual drive of 87 gigs. This drive is composed of a 60g, a 17g, and a 10g drive. I have been working on getting some GUI type programs to work so that I can get some screen shots of this for those that want a graphical idea of what it looks like. This is a perfect example of the streaky-ness of my life and moods. A couple of weeks ago I was in a depression and now I am feeling pretty good. I think it is because there are a couple potential jobs on the horizion that I would be willing to get out of for. Hopefully they will come in and I can be back to my happy go lucky self.

Journal 02 Dec 2001 02:15 pm

Ah… a weekend of relaxation

This was the first weekend in probably 6-8 weeks were I have not had something going on. I spent most of the weekend chilling at the in my PJs working on Diablo. He is tweaked out now. I started out at the bottom and worked my way up to the top. Had to flash the bios on the Dragon board, flashed my modem, and my video card all up to the latest bios. With that done I then preceeded to setup , HTTP, Rsync, and Accelerated X on the Linux side. I next booted into Windows and updated all the for the video and everything. Mechwarrior 4 smokes now!!! Got the new expansion pack for it and I have been playing the shit out of it this weekend. Got back into linux and setup some stuff with the media side of things. Ripped a couple CDs and burnt one. Working on getting the Dxr3 board that I have working so that I can watch my DVDs and stuff without using windows. Tried to setup that up, but somehow it screwed my Font server and X wouldn’t run. I couldn’t get it to come back up so I tar’ed the /etc and /root directories up and sent them to another machine and rebuilt it again. Dumped the tar back and had the same machine again. I have completely accomplished my attempt to use Linux for everything. Well everything except for playing games. I had a moment of weakness and almost wiped W2k from my machine and put 98 on it so that I really wouldn’t use it for anything else, but I fought back and rationalized it by saying that I used W2k at work so I needed to keep it on here.
On another side of the coin of life (and one of the sides I don’t mention much) I am somewhat worried about and I. Friday I told Frank and that I would take them out to dinner. That ended up costing me quite a bit as Frank inivted Rob, not that I didn’t want Rob to go but I had planned on paying and for the second time Frank threw Rob into that. Also Jeremiah decided he wanted to go as well so I paid for his too. But anyway back to what I was actually writing about… So I told about that and ask her if she would wait till about 8:30 or so and I would come pick her up and we could come back over here and spend some time together. She said that she was going to go to Morgantown. I didn’t have a problem with that. I ask her if she was going to be coming back over here on Saturday because I thought we could go out shopping and stuff. She veto’ed that idea saying that she was going to spend time with her . So I called this morning to see if she wanted to go out with me because I needed to pick up some shirts. I found out that she went to Louisville with some guy to see one of her friends. Not sure how it is that I feel about that, but I am sure that it isn’t happy. Lately I have become paraniod about her and the possibility of her cheating on me. I am not sure why, but the feeling persists anyway. Maybe that isn’t the best thing to say into such a public forum, but I try to keep this as an open journal so I guess I need to. puts a lot into sun signs and Zodiac in relation to how people act. While I don’t put as much into it I do think that people often times act in manners that could be explained by that, wither it is because of it or just because they do. Regardless one of the things that just about everything I have ever read about Leo signed people is that they like to be the only one in their mates life. In this sense I am truely like that and it drives me nuts to think of even the remotest possiblity that she might be seeing someone else.

Journal 20 Nov 2001 08:57 am

11/20/2001

Well I would like to thank for a fun weekend. He flew up here for the weekend to chill out with me and we had a blast. Now I have a few more things to add to the list of stuff on his page : ). Also I have gotten a external modem for Diablo and I am now able to use it to get on the internet in Linux. That coupled with the fact that I am having minor issues with Diablo in Windows has made me decide to try and switch to linux for my desktop. I have also written a new script which is about as large scale as anything else I have written. BootRip might be close, but it is not as neat and organized as this is so that might be part of it. The new script is called SMess which is short for Messaging. Hit the link to open the page with its info. I have said this with all the other stuff I have written, but I hope to be able to write a GUI frontend for it.

Journal 14 Nov 2001 08:01 am

11/14/2001

I would say that I have slacked off again, but man it seems they all start that way anymore. Of couse I am not as bad as my friend maxx yet and let my life go for a year with out writing in here, but I digress. Since I wrote last, there have been a few developments. First my new machine lives… built a system out of the SOYO Dragon motherboard. It is a sweet system. Unfortunately when I was getting ready to move my hardrive over to it… it crashed!!! 40 Gigs of data pretty much gone. Rebuilt the system in time to run the swim meet the next day and rebuilt the swim meet database for that meet. I have lost a little bit of luster for work now days. I get tired of the duality of the place. At one time they want me to be a “Smart little technician” and solve the problems that they can’t or don’t have time to do, but when it comes to something that they think is “Extremely Important” they want me to be a good little robot and click the buttons to run the stuff without asking “why?” or “what is this going to do?”. Recently one of the Domain Admins (who so far has had a lot of trouble getting his scripts to work correctly) sent us a link to a script he wrote. This script was located in a directory which everyone had full access to (meaning that they could have changed his script if they wanted to), which no one else had looked at and which didn’t meet any of the parameters for what he was trying to do. I was talking to my boss about it and how I didn’t think we should run it without more information since it could potentially screw up our image on the machines. My boss, which doesn’t want us to do anything to the image without his say so, told us to run it and then ask tomorrow what it did. I said it would be too late then since it might have already screwed everything up. He didn’t seem to care and told me to run it anyway. I told him I was clocking out and he could have the other tech (Jeremiah) run it if he wanted to. Maybe it wasn’t the best thing to do, but I wasn’t going to be the one to screw up the machines, since it WOULD be listed as my fault and not the domain admins who would have screwed up the script. I hate stuff like that. So today I went back to writing scripts. It seems to be the haven for my mind when I no longer am interested in the task at hand. Two new scripts are being born from this… SmbTable and SMess. SmbTable is a somewhat trivial smbstatus formater and organizer, while SMess might be a pretty cool system in the end. It will be a clean Linux based system to allow the AMs to send messages to the reps out on the floor. Hopefully I can get it all worked out rather quickly. Most of my work now is working with and trying to get diablonetwork.net off the ground. I am also working on a HOW-TO on and Windows Domains. It is really a document on how to hide a linux machine inside a Windows network.