Merge lp:~markthomas/serverguide/serverguide-review-7.5 into lp:serverguide
| Status: | Merged |
|---|---|
| Merged at revision: | 243 |
| Proposed branch: | lp:~markthomas/serverguide/serverguide-review-7.5 |
| Merge into: | lp:serverguide |
| Diff against target: |
223 lines (+215/-0) 1 file modified
serverguide/C/network-auth.xml (+215/-0) |
| To merge this branch: | bzr merge lp:~markthomas/serverguide/serverguide-review-7.5 |
| Related bugs: |
| Reviewer | Review Type | Date Requested | Status |
|---|---|---|---|
| Peter Matulis | 2015-02-13 | Approve on 2015-02-26 | |
|
Review via email:
|
|||
Description of the Change
This is a new section describing how to configure Trusty to authenticate against Active Directory with sssd. It did not fit into any previously-existing section (i.e. no section for sssd existed).
| Doug Smythies (dsmythies) wrote : | # |
| Peter Matulis (petermatulis) wrote : | # |
A wonderful contribution! Thank you Mark. A few comments below.
1. wording
(a)
"This section covers the use of sssd to authenticate user logins against an Active Directory via sssd and PAM using sssd's "ad" provider."
Maybe:
"This section describes the use of sssd and PAM for authenticating users against Microsoft Active Directory."
(b)
"This guide assumes that a working Active Directory domain already configured."
Maybe:
"This guide assumes that a working Active Directory domain is already configured.
(c)
"The domain and kerberos realm used in this example is myubuntu.
Maybe the realm should be in all caps. You mention both domain and realm so not sure.
(d)
"Add an alias /etc/hosts specifying the FQDN."
Maybe:
"Add an entry to /etc/hosts for specifying the FQDN."
(e)
"kerberos" should be capitalized everywhere: Kerberos.
2. format
(a) All commands should be formatted like so:
<screen>
<command>
</screen>
(b) All filenames should be formatted like so:
<filename>
(c) References should be hyperlinks. See end of this page as an exemplar:
https:/
Long ugly URLs should also not be exposed to the reader.
| Doug Smythies (dsmythies) wrote : | # |
Mark: Are you going to get to this today or tomorrow? We are wanting to do a point release of the serverguide, and had originally intended string freeze for yesterday. String freeze will be pushed at least until tomorrow now. If you cannot get to this, I will fix it.
| Doug Smythies (dsmythies) wrote : | # |
Mark: What is the status of this?
| Mark Thomas (markthomas) wrote : | # |
I never received a notification on this for some reason. I will be addressing this ASAP.
- 238. By Mark Thomas on 2015-02-26
-
Changes based on feedback in LP
| Mark Thomas (markthomas) wrote : | # |
Content changes:
(a) I implemented a variation of that change. It is important to highlight that the “ad” provider is what is being covered—the use of the “ldap” provider in sssd for AD authentication is quite different, older, and more difficult. I did omit the name “Microsoft”, as it is also possible to use Samba4 as an AD domain controller. Do you think it is needed?
(b) Fixed
(c) Modified for clarification. I am not trying to specify formatting—that is covered soon after. I am providing the value used rather than have it just “show up” as I’ve seen in other documentation.
One thing I did here was to use a “subdomain” for the Active Directory domain. So often, I see just “example.com”. If someone wants to implement the AD domain as a subdomain, as is often done, I didn’t want it left an an exercise for the reader to figure out what the realm should be by “trial and error” as I’ve had to do.
(d) Modified for clarification.
(e) Fixed
2. format
(a) Fixed
(b) Fixed
(c) Fixed
| Doug Smythies (dsmythies) wrote : | # |
Mark, Thanks very much.
Peter: O.K. we will now call 12.04 and trunk (14.04) serverguides as in string freeze until the point release is done.

Peter: Do you want to try to include this one in our pending point release, for which string freeze is tomorrow? It looks pretty good to me.