Is Samba 4 AD Ready for Global Enterprise? It is with the ONE WEIRD - - PowerPoint PPT Presentation

is samba 4 ad ready for global enterprise it is with the
SMART_READER_LITE
LIVE PREVIEW

Is Samba 4 AD Ready for Global Enterprise? It is with the ONE WEIRD - - PowerPoint PPT Presentation

Is Samba 4 AD Ready for Global Enterprise? It is with the ONE WEIRD TRICK click here But first... Disclaimer This presentation, the content and opinions contained within are the author's own and do not reflect the views or opinions of


slide-1
SLIDE 1

Is Samba 4 AD Ready for Global Enterprise?

slide-2
SLIDE 2

It is… with the ONE WEIRD TRICK click here

slide-3
SLIDE 3

But first...

slide-4
SLIDE 4

Disclaimer

This presentation, the content and opinions contained within are the author's own and do not reflect the views or opinions of Indeed, Inc.

slide-5
SLIDE 5

Kevin Kunkel

IT Systems, Indeed Inc.

slide-6
SLIDE 6

About

  • Windows 95 converted me to Linux
  • Software Engineering at RIT, BS CS from Mercy College
  • 11 years of Systems Administration

○ Linux SysAdmin ○ Windows SysAdmin ○ B2B SMB consulting

slide-7
SLIDE 7

About Indeed

slide-8
SLIDE 8
slide-9
SLIDE 9

Key Metrics

slide-10
SLIDE 10
slide-11
SLIDE 11

But really, how about you?

slide-12
SLIDE 12

This is for you.

slide-13
SLIDE 13

You

  • Samba Team
  • Samba Developers
  • Samba Users
  • Enterprises without Active Directory willing to try Samba
  • Organizations with a vested interest in Samba
slide-14
SLIDE 14

Why does this matter?

slide-15
SLIDE 15

Why Active Directory?

slide-16
SLIDE 16

Minimum Level of Competency

  • IT Support staff familiar with RSAT
  • Microsoft tools are well documented
  • No command line knowledge required.
slide-17
SLIDE 17

Application Integration

  • OneLogin
  • Sophos Enterprise Console
  • PacketFence
  • Pretty much any application that supports external

authentication

slide-18
SLIDE 18

MSCHAPv2 and 802.1x

  • For user-based 802.1x,

PEAP-EAP-MSCHAPv2 is the universally supported method, despite its insecurity

  • No more Pre-Shared Key

wifi!

  • Ability to map username

to IP

slide-19
SLIDE 19

Why not Microsoft?

slide-20
SLIDE 20

Microsoft Licensing

  • Few people truly understand this black magic
  • OS licensing, plus CALs
  • All users that could use a DC must have a CAL, all servers

must have CALs

  • For example: 5000 users, 50 servers, at $16/CAL

(https://www.cdw.com/shop/products/Microsoft-Windows

  • Server-Client-Access-License-User/488489.aspx)

○ 5000 x 50 X $16 = $4M

slide-21
SLIDE 21

https://blogs.technet.microsoft.com/volume-licensing/2014/03/10/lic ensing-how-to-when-do-i-need-a-client-access-license-cal/

Microsoft Client Access Licenses (CALs)

slide-22
SLIDE 22

Indeed Culture

  • Start-up mentality
  • Generally Build over Buy
  • No Vendor Lock-In
  • Very Pro-OpenSource (http://opensource.indeedeng.io/)

○ Proctor ○ Imhotep

slide-23
SLIDE 23

Does it Work?

slide-24
SLIDE 24

Samba 4.0 to Samba 4.2

slide-25
SLIDE 25

Small Beginnings

  • An intern project in the summer of 2013
  • Largest office with 95%+ Windows 7 clients
  • 2 Domain controllers
slide-26
SLIDE 26

NETLOGON and GPO

  • Password Complexity - No more auto-login with

passwordless Windows accounts

  • ScreenSaver settings
  • Windows Firewall port control for Sophos
  • But what else...
slide-27
SLIDE 27

SUCCESS!

  • Minor expansion
  • FreeRADIUS
  • SerNet RPMs

(For free!)

  • Let’s scale!
slide-28
SLIDE 28

Expansion pains

  • Fully meshed replication topology.
  • “Denial of Service Distributed”
  • We need help
  • Who can help us?
slide-29
SLIDE 29

Samba 4.3 to Samba 4.5

slide-30
SLIDE 30

The Great Expansion

  • From 12 DCs to 30+
  • Regional replication hubs
  • Bridgehead servers
  • Linked attribute hell
  • Deleted linked attributes
slide-31
SLIDE 31

Samba 4.6 and beyond

slide-32
SLIDE 32

Scaling out

  • DCs joins during business hours!
  • Domain joins ~ 30-45 minutes
  • 45 domain controllers on 5 continents
  • 6,252 User/Group objects , 37,625 group memberships
slide-33
SLIDE 33

The future

  • More performant replication
  • Better KCC controls
  • Better audit logging
  • 2012 Schema
  • Maybe SYSVOL replication?
slide-34
SLIDE 34

So is it ready?

slide-35
SLIDE 35

My Opinion

  • It’s not a 100% complete drop-in

replacement for AD

  • It’s close enough, and if that’s

acceptable, then it is

slide-36
SLIDE 36

My Suggestions

  • Support Contract
  • Sponsor Development
  • Monitoring

○ Health Checks ○ Log aggregation

slide-37
SLIDE 37

Current Issues

  • Documentation is shifting sand
  • Joining DCs in rapid succession is still very error prone.
  • KCC inconsistent
slide-38
SLIDE 38
slide-39
SLIDE 39
slide-40
SLIDE 40

All in all

slide-41
SLIDE 41

Active Directory is here to stay

  • Widespread adoption and almost universal integration
  • It really has become a standard enterprise product.
  • We can’t kill off Windows client devices.

○ MS Office on Windows is preferred by power Excel users ○ Many Network Admin tools are Windows-based

  • And Samba can be a viable alternative if...
slide-42
SLIDE 42

Your Organization:

  • Can tolerate authentication system failure(s).
  • Can quickly respond to outages.
  • Can afford to pay for support and development.
slide-43
SLIDE 43

Thank you

slide-44
SLIDE 44

Thank you

  • Catalyst
  • SerNet
  • Samba community
  • And Indeed
slide-45
SLIDE 45
slide-46
SLIDE 46

Q & A