CIFS Server Administrator's Guide Version A.03.02.00 (5900-2578, January 2013)
Running logon scripts when logging on.................................................................................68
Home drive mapping support...................................................................................................68
Trust relationships...................................................................................................................69
Configuring smb.conf for trusted users..................................................................................69
Establishing a trust relationship on an HP CIFS PDC with another Samba Domain......................69
Establishing a trust relationship on an HP CIFS PDC with an NT domain....................................70
Trusting an NT Domain from a Samba Domain.................................................................70
Trusting a Samba Domain from an NT domain..................................................................70
Establishing a trust relationship on an HP CIFS member server of a Samba Domain or an NT
domain............................................................................................................................70
5 Windows 2003 and Windows 2008 domains.............................................71
Introduction............................................................................................................................71
HP CIFS and other HP-UX Kerberos applications co-existence........................................................71
HP-UX Kerberos client software and LDAP integration software dependencies..................................71
Strong authentication support ..................................................................................................72
Steps to install Certification Authority (CA) on a Windows ADS server......................................72
Steps to download the CA certificates from Windows CA server..............................................73
Configuring HP CIFS server to enable startTLS........................................................................73
Joining an HP CIFS server to a Windows 2003 and Windows 2008 domain.................................74
Configuration parameters....................................................................................................74
Setting permissions for a user..............................................................................................75
Step-by-step procedure.......................................................................................................76
Trust relationships...................................................................................................................78
Establishing external trust relationships between HP CIFS PDCs and Windows 2003 and Windows
2008 domains..................................................................................................................78
Establishing a trust relationship on an HP CIFS member server of a Windows 2003 or Windows
2008 domain...................................................................................................................79
6 LDAP integration support...........................................................................81
Overview..............................................................................................................................81
HP CIFS server advantages.................................................................................................82
Network environments.............................................................................................................82
Domain model networks.....................................................................................................82
CIFS Server acting as the Primary Domain Controller (PDC)................................................82
CIFS Server acting as the member server..........................................................................82
CIFS Server acting as Backup Domain Controller (BDC) to Samba PDC................................82
CIFS server acting as an Active Directory Service (ADS) member server................................82
Workgroup model networks................................................................................................83
UNIX user authentication - /etc/passwd, NIS migration..........................................................83
The CIFS authentication with LDAP integration........................................................................83
Summary of installing and configuring......................................................................................84
Installing and configuring your directory server...........................................................................84
Installing the directory server...............................................................................................84
Configuring your directory server.........................................................................................85
Verifying the directory server...............................................................................................85
Installing LDAP-UX client services on an HP CIFS server................................................................85
Configuring the LDAP-UX client services.....................................................................................85
Quick configuration............................................................................................................86
Enabling Secure Sockets Layer (SSL)..........................................................................................89
Configuring the directory server to enable SSL.......................................................................89
Configuring the LDAP-UX client to use SSL..............................................................................90
Configuring HP CIFS Server to enable SSL.............................................................................90
Extending the Samba subschema into your directory server..........................................................91
Samba subschema differences between HP CIFS Server versions..............................................91
Procedures to extend the Samba subschema into your directory...............................................91
Contents 5