[Samba] splitting services in samba4

2012-07-11 Thread Quinn Plattel
Question:  Right now samba4 is great as in all-in-one solution (samba,
kerberos, ldap, dns) into one service.
Is it possible to split it up so that for example, I run openldap on one
server, kerberos on another server, and then dns/samba on a third server?

br,
Quinn
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] splitting services in samba4

2012-07-11 Thread Quinn Plattel
Thanks for the quick response.

So I guess if you wanted high availability, you would either have to
implement a PDC/BDC solution with samba4 or use samba4 on top of a
corosync/pacemaker cluster.  Is this correct?

br,
Quinn


On Wed, Jul 11, 2012 at 10:43 AM, Gémes Géza g...@kzsdabas.hu wrote:

 2012-07-11 10:27 keltezéssel, Quinn Plattel írta:

  Question:  Right now samba4 is great as in all-in-one solution (samba,
 kerberos, ldap, dns) into one service.
 Is it possible to split it up so that for example, I run openldap on one
 server, kerberos on another server, and then dns/samba on a third server?

 br,
 Quinn

 Short answer: NO
 Longer: Windows clients expect kerberos, ldap and samba rpc+filesharing
 services on the same host, so if you need AD functionality you couldn't
 separate them. They also expect a schema (the AD schema) which is
 incompatible with OpenLDAP.

 Regards

 Geza




-- 
Best regards/Med venlig hilsen,
Quinn Plattel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Re: [Samba] splitting services in samba4

2012-07-11 Thread Gémes Géza

Hi Quinn,

Thanks for the quick response.

So I guess if you wanted high availability, you would either have to
implement a PDC/BDC solution with samba4 or use samba4 on top of a
corosync/pacemaker cluster.  Is this correct?

br,
Quinn


On Wed, Jul 11, 2012 at 10:43 AM, Gémes Géza g...@kzsdabas.hu wrote:


2012-07-11 10:27 keltezéssel, Quinn Plattel írta:

  Question:  Right now samba4 is great as in all-in-one solution (samba,

kerberos, ldap, dns) into one service.
Is it possible to split it up so that for example, I run openldap on one
server, kerberos on another server, and then dns/samba on a third server?

br,
Quinn


Short answer: NO
Longer: Windows clients expect kerberos, ldap and samba rpc+filesharing
services on the same host, so if you need AD functionality you couldn't
separate them. They also expect a schema (the AD schema) which is
incompatible with OpenLDAP.

Regards

Geza






The multiple AD DC (in active directory every (non readonly) DC is a 
sort of PDC) is the tried and recommended method (even by M$)


Regards

Geza
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Re: [Samba] splitting services in samba4

2012-07-11 Thread Ben Metcalfe
Assuming samba 4 supports them, watch out for your FSMO roles; each role
will be specific to one server in the domain. Recovering from the loss of a
server that currenty owns one or more of the FMSO roles is a little
trickier than just booting another peer-DC to handle requests.

On Wednesday, 11 July 2012, Gémes Géza wrote:

 Hi Quinn,

 Thanks for the quick response.

 So I guess if you wanted high availability, you would either have to
 implement a PDC/BDC solution with samba4 or use samba4 on top of a
 corosync/pacemaker cluster.  Is this correct?

 br,
 Quinn


 On Wed, Jul 11, 2012 at 10:43 AM, Gémes Géza g...@kzsdabas.hu wrote:

  2012-07-11 10:27 keltezéssel, Quinn Plattel írta:

   Question:  Right now samba4 is great as in all-in-one solution (samba,

 kerberos, ldap, dns) into one service.
 Is it possible to split it up so that for example, I run openldap on one
 server, kerberos on another server, and then dns/samba on a third
 server?

 br,
 Quinn

  Short answer: NO
 Longer: Windows clients expect kerberos, ldap and samba rpc+filesharing
 services on the same host, so if you need AD functionality you couldn't
 separate them. They also expect a schema (the AD schema) which is
 incompatible with OpenLDAP.

 Regards

 Geza




 The multiple AD DC (in active directory every (non readonly) DC is a sort
 of PDC) is the tried and recommended method (even by M$)

 Regards

 Geza
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  
 https://lists.samba.org/**mailman/options/sambahttps://lists.samba.org/mailman/options/samba
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba