8

I have quite a few Ubuntu Server 17.04 hosts that must be joined to an existing Windows AD domain (Windows Server 2016). I've never done it before, but I'm aware about several ways to achieve this, such as: Likewise, Centrify, SSSD and Winbind.

Could you share your general experience and tell how reliable, easy to configure / maintain are each of these solutions?

Would be also great if you can share any links to the up-to-date articles/manuals that cover this topic as I can only find a couple of 3 to 5-year-old ones and they don't really work as expected.

Thank you so much for assistance!

Ashton R.
  • 83
  • 1
  • 1
  • 4

4 Answers4

6

I've actually used Centrify commercial version and can totally recommend it. However, it's not worth buying the full version for a pair of Linux hosts, really.

Winbind is a good free alternative though. Here's an updated guidance on how to deploy and configure it: https://www.starwindsoftware.com/blog/ubuntu-join-a-server-to-an-active-directory-domain

Mr. Raspberry
  • 3,878
  • 12
  • 32
3

Sssd was pretty simple on Ubuntu. I followed the docs on their site https://help.ubuntu.com/lts/serverguide/sssd-ad.html and it worked perfectly. I liked that it was very simple to implement and there were no changes required to the DCs.

Jim B
  • 23,938
  • 4
  • 35
  • 58
  • I don't know how you managed to get Ubuntu to join AD using those instructions. I've tried running through it several times using both Mint and Ubuntu and neither one would allow me to authenticate after joining the domain. – Mirrana Jun 10 '18 at 19:02
3

I would second Mr. Raspberry's comment that Centrify is a good option for joining linux/unix hosts to an AD domain.

In my opinion, Centrify has a few advantages over SSSD.

  • Its easy to implement and maintain and not just for a few systems (like SSSD 30 machine limit), but enterprise wide as well.

  • It works on well on complex systems that are not your basic vanilla setup (ie. multi-forest, one-way trusts, read only domain controllers (RODC), etc)

  • It works on multiple OS types (Mac OSX, Linux, Unix and Windows)

  • It has also been around for awhile (10+ years), so it has been tried and tested

  • Centrify covers the classic "Triple A's" of secure Access Control; Authentication, Authorization and Auditing, instead of just authentication with SSSD.

  • Centrify addresses the issue with Linux environments that have complex UID namespaces.

  • There is also have a free version, Centrify Express, that has most of the same functionality as the paid version.

http://blog.centrify.com/centrify-vs-sssd-for-integrating-linux-with-active-directory/

climb4fun
  • 31
  • 3
0

Friend, Did you try: "https://sourceforge.net/projects/c-i-d/" ? Is a completelly bash based solution, very useful for this case.