Jump to content

Recommended Posts

Posted

Just about to give up with this on so any suggestions will be handy!

 

Running Openfiler to create a NAS box, but cannot get it to authenticate via AD. Tried every variation on configuration but nothing seems to work. No errors, no joining to AD and nothing to hint at what is going wrong.

 

Checked the usual like system clock and DNS resolving ok but I'm stumped. You don't seem to get any logging errors either which doesn't help.

Posted (edited)

I've been setting the options for 'Windows domain controller and authentication' and Kerberos. I've joined lots of hardware NAS boxes to our domain before with no issues (except clocks being out of sync!)

 

EDIT - its obviously goosed now, any configuration change I 'apply' simply results in a blank page being returned. FreeNAS anyone?!

Edited by GoldenWonder
Posted

I know it shouldn't make any difference but have you been using FQDN for your server and the Domain in CAPITALS as sometimes it can be fussy about these things.

 

Also if you are trying to configure openfiler through IE that also can complicate matter's, try using putty to SSH in or Firefox if you dont fancy the SSH method.

 

D

Posted

I've been using FQDN for server names, and have tried the domain in Caps and lower case.

 

I haven't tried using a different browser yet, might give Firefox a go once I've rebuilt it.

Posted

It must be a weird one, I've added what must be hundereds of NAS boxes to network over my years in IT and rarely have any issues apart from the obligitory time sync issues!

 

D

Posted (edited)

I looked through and the 'bug' with the realm name seems to have been resolved. Either that or it doesn't happen when I used Firefox. Now I have no errors, but when I open group list its empty!

 

I notice that although the guides recommend using the Join Domain option, my nas box still is not appearing in the domain. I guess this is part of the problem

 

The only error I can seem to get is if I try to add a new user:

 

Error adding new user.

ldap_add: No such object (32)

matched DN: DC=domainname,DC=org,DC=uk

additional info: 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:

'DC=domainname,DC=org,DC=uk'

Edited by GoldenWonder
Posted

Well I got a stage further. After a complete rebuild and reinstall I managed to get the OF box to see AD, and user groups appeared. However after creating shares and setting permissions I get variable results. I've given Domain Admins full rights and a staff group R/W rights. This generally either doesn't work and a Windows authentication box appears when trying to access the share (\\nas\share) or they get a Windows error saying that it could not connect to the resource (i.e as if the path was invalid)

 

I noticed that when I expanded the Domain Admins group in the OF gui, it only showed users in the same OU as the group - some of our accounts are in a sub-OU and they weren't showing. It looks like OF is like a lot of other linux/unix systems that will only read AD if everything is in a single OU

Posted

To close this one off (and if anyone else is thinking of using OF in an AD environment - don't bother!)

 

I got it working - sort of. But it stops working every so often (i.e the group list shows up empty and no one can access any shares) so I can only assume OF isn't ready for AD authentication yet. Shame really but this is what holds me back from using more linux based stuff here -theres always a catch getting it to work with existing kit!

Posted (edited)

I have to disagree. Our openfiler is used as server backup (server OU RW only), media library (pupil OU RO, staff OU RW) and staff shared work area (staff OU only) and pupils shared area (pupils OU read only, staff OU R/W). It is a 4x 1Tb drive software RAID1 array. Currently it is only an SMB share although I do intend on bringing an iSCSI array online in the coming year. Uptime is 121 days as of now, never missed a beat and groups work just fine.

 

I used the exact guide that librarian posted. "Use Windows domain controller and authentication": domain is my local "friendly" non FQDN name. DC is non-FQ friendly name. ADS realm is FQDN in capitals. Orginally I joined it to the domain. That was about that really.

Edited by KK20

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...