Samba LDAP + SSL support on Oracle Solaris 10

Hello there.

I did it ;)

after more than a year of hard working with this project, and I am glad to announce that Oracle Solaris 10 is now supporting Sun LDAP oDSEE and SSL/StartTLS on Samba >3.6.15 !!!

... as of 21 of August 2013 !!! yes, you read it: Oracle Directory Server Enterprise Edition (formerly SUN Directory Server Enterprise Edition) is now supported by Samba 3.6.x

and also SSL/StartTLS too !! I will publish a blog about it soon with all the instructions. But it´s certainly a more secure setup to deploy ! You will probably need a MOS My Oracle Support valid account. Click the following short links to obtain the patches, SPARC: patch 119757-28 http://bit.ly/19IKOyT X86: patch 119758-28 http://bit.ly/14BKj1C

--> To avoid any problems, make sure to use Solaris 10 update >11.

Note: I have done and run some tests with Solaris u8 and u9 (patched with the latest patchset) successfully.

Comments:

Wow great work, what about samba 4.x? We use zfs 7420, but there are still use cases for samba

Thanks,
Eli

Posted by Eli Kleinman on August 21, 2013 at 02:27 PM CEST #

Hello Eli,

Samba 4.x has not been tested yet. It might be interesting to give it a try since Samba 4 has its own AD.
I am also guessing it is a little bit early to have the Samba folks porting the "Samba 3 Solaris SSL changes" to Samba 4.
We are working on a setup with ZFS array, Kerberos, NFS and Samba (not SMB). If it works fine, I´ll publish a note about that. Right now our setup uses a dedicated server for Samba (and NFS with automount) without AD.

Posted by Jimmy on August 21, 2013 at 02:42 PM CEST #

Hello Jim

I've been banging my head against the wall over this issue for some time now. Do you know if this patch might be massaged onto a solaris 11 box?

Derek

Posted by guest on August 29, 2013 at 07:03 AM CEST #

Hi

This is great.

I'm having the same problems with solaris 11. Is there a chance that this might be applied to a solaris 11 patch too?

Derek

Posted by derek on August 29, 2013 at 08:19 AM CEST #

Unfortunately, this is a very recent patch for Solaris 10 update 11. (I did some tests and it did work on update 8 with the newest patchset applied).

The Solaris 11 version is NOT yet available but I will update this blog if I get more information from engineering.

By the way, make sure you get the differences between "samba" and the Solaris 11 CIFS "SMB" implementation.
It´s not the same. The patch and the solution I am referring TO is about "Samba" 3.x from Samba.org (so it´s not the Solaris 11 CIFS/SMB kernel service)

Posted by Jimmy on August 29, 2013 at 11:08 AM CEST #

It should be noted that this patch breaks DSEE 6.3.1.1.2 if you are still using that version (which I am). I just had to pack that patch out to get DSEE working again. You'll get errors like this:

# ./start-slapd
ld.so.1: ns-slapd: fatal: libldap60.so: version 'LDAPCSDK_5.10' not found (required by file ns-slapd)
ld.so.1: ns-slapd: fatal: libldap60.so: open failed: No such file or directory
Killed
Server not running!! Failed to start ns-slapd process.

Added here incase someone hits the same issue.

Posted by Simon C on September 05, 2013 at 07:39 AM CEST #

Thanks Simon for reporting this. I will inform the package maintainer. If you can raise a Service Request in My Oracle Support http://support.oracle.com this will allow the support engineer to raise a new bug (if any) and this certainly will help to get this fixed with the next Oracle Solaris Samba release (3.6.18 of Samba for Solaris 10).

By the way guys, Solaris 11 should also get it mid october.

Posted by Jimmy on September 05, 2013 at 11:43 AM CEST #

Post a Comment:
Comments are closed for this entry.
About

Principal Systems Technologist Engineer for Oracle Global IT. Sun Microsystems software and hardware specialist. I am based in Spain but currently manage projects and systems around the world. I am very often involved to mentor the new engineers joining the forces of Oracle. I come from the Linux sysadmin world... and will be definitively thankfulness for all the great things I've been learning the past 15 years...

Search

Categories
Archives
« April 2014
SunMonTueWedThuFriSat
  
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
   
       
Today