Ponder This

All | Personal | Sun
« I'm slacking but VDI... | Main | New York - New York »
20060504 Thursday May 04, 2006

Sun Ray's with LDAP Authentication

I am really trying to close the gap between sharing and not sharing here with the blog.  I really struggle with it. There is a lot I want to share regarding my thoughts on Desktop Virtualization.

A big area I think we can improve on regarding sharing, is how we solve things and do things.  I feel it is way to hard to find information even with Google. ThinGuy has been doing a really good job and I am trying to follow his example more often. I find it remarkably hard to get cookbooks and white papers pushed through the system. I suspect customers and partners are dying for this stuff.

One of the biggest topics I hear time and time again is authenticating users in a Sun Ray environment via LDAP. I hear is over and over. I will agree it is not always a simple task. I have  just completed a draft cookbook on this subject. It covers LDAP Client configuration, What too look out for if Access Manager is used, Executable Automount Home Directories, Account Management, Password Aging and a couple other topics.

It offers an example PAM.conf file and sample automounter script. It is by no means an exhaustive guide but gets you going in the right direction. If you are interested in it let me know and I will send it to you. Possible I will post it here after I have cleaned it up a little more. It been requested that I expand it to cover IDM and Active Directory which I am looking into.



Posted by ponderthis ( May 04 2006, 12:00:00 AM EDT ) Permalink Comments [18]

Trackback URL: http://blogs.sun.com/ponderthis/entry/sun_ray_s_with_ldap
Comments:

I've just found this blog entry (relatively late). I really wish that it was easier to find good information on Sun Ray. ThinGuy's blog has been a huge improvement on this, but I have a feeling that there's still a lot of good lore out there in Sun-land that's not getting out to us users -- yes, we are "dying for this stuff"! I am interested in seeing your SunRay/LDAP writeup. Does the offer still stand? thanks!

Posted by tom on July 03, 2006 at 04:53 PM EDT #

Tom shoot me your email... warren.ponder@sun.com

Posted by Warren on July 07, 2006 at 07:04 AM EDT #

on its way... Thanks!

Posted by tom on July 25, 2006 at 12:55 AM EDT #

Warren, I just found this as well. How is the SunRay/LDAP writeup coming along? I am very interested, looking at moving my environment over to Solaris 10 / SJS .

Posted by Roger on July 28, 2006 at 03:30 PM EDT #

Good jolly, that is what i call late. I have just discovered this entry (and your blog as well) and am very interested in your findings, Tom. Could you send me the draft(?) too? Thanks in advance! Christian

Posted by Stotti on September 28, 2006 at 02:40 AM EDT #

Does this draft still available, please drop me a copy

Posted by Bas on November 22, 2007 at 07:43 PM EST #

Hi Warren, I too am struggling with setting up a SunRay svr with LDAP authentication and would be very interested in your write-up. Could you email me your findings? Thanks in advance.

Cindy (cindy.osmon@sun.com)

Posted by Cindy Osmon on February 06, 2008 at 03:46 PM EST #

I am really interested in this topic. I tried to set it up, but without success. I will be very appreciative for any hints. Thanks in advance.

Posted by Miroslav Oravec on March 31, 2008 at 10:36 AM EDT #

Well I see that it's been a little over 2 years since you wrote this. Hopefully the thread and the project has not died; I'd wish that it was completed but something tells me that it's probably still a work in progress.

If you have any sort of information on LDAP directory authentication with SRSS (4) and SunRays I would be very interested in seeing it. I spent forever getting our SRSS server cluster migrated to using LDAP for authentication and thought that with PAM it'd be a simple plugin and the SunRay/gdm combo would be able to authenticate against it to. Unfortunately this is definitely not the case!

Without this setup working we're going to have to go with some serious workarounds that'll push us back months beyond when we wanted to have this infrastructure stabilized and scaleable. I'd appreciate anything you can point me to or toss my way.

Thank you.

Damon Getsman
dgetsman@amirehab.net

Posted by Damon Getsman on May 26, 2008 at 04:21 PM EDT #

Hi Warren,

will the LDAP integration work with Linux's SRSS GDM? If so, will like a copy of your draft write up.

thanks,
James Tan

Posted by James Tan on June 11, 2008 at 12:35 AM EDT #

Warren,

Wow, I would really appreciate a copy of your write up.

Thanks,
Jon Oliver

Posted by Jon Oliver on June 18, 2008 at 04:09 PM EDT #

Hello,

please send me you scripts. I am trying to authenticate user with nis+ and ldap.

thanks
Joachim Graeser

Posted by Joachim Graeser on July 02, 2008 at 10:44 AM EDT #

Hi Warren,

have you tried on 64bi linux? E.g. RHEL 4 x86_64?

I've read "http://www.mail-archive.com/sunray-users@filibeto.org/msg09781.html" and it mentioned no support for 64bit OS/pam modules.

thanks,
James Tan

Posted by James Tan on July 07, 2008 at 06:04 AM EDT #

Hi Warren,

I would really appreciate a copy of your write up, too ...

Many thanks,
Jan Ars

Posted by Jan on August 01, 2008 at 02:55 AM EDT #

Warren,
I have been struggling with sun ray users auth to ldap. Please send me a copy of your cookbook.

Thanks,
Clinton

Posted by Clinton on September 10, 2008 at 04:15 PM EDT #

Hi,
perhaps it's too old... but i really like to have a copy of your cookbook.
Can you send it to me ?
thanks in advance
Johan

Posted by Jo on July 06, 2009 at 12:38 PM EDT #

Warren, I'd love a copy too, if it's still available.

Thanks,

Alex

Posted by Alex on July 07, 2009 at 02:50 PM EDT #

Hi, I'm messing around with SRSS 4 and LDAP at the moment. It would be great to get a copy of your cookbook.

Posted by Sven on August 18, 2009 at 09:05 AM EDT #

Post a Comment:

Name:
E-Mail:
URL:

Your Comment:

HTML Syntax: NOT allowed

Calendar

RSS Feeds

Search

Links

Navigation

Referers