Winchester: Schema mapping and ID mapping for AD Interoperability

Winchester: Schema mapping and ID mapping for AD Interoperability

NOTE: The winchester project is no longer active on this website so information here may be out of date. Current Oracle Solaris 11 product documentation can be found here. Information about downloading Oracle Solaris 11 can be found here.

Introduction

The goal of this project was to enable Solaris to operate in a native Active Directory (AD) environment by providing the following components:

  • New name service switch module to perform direct mapping from AD native schema to Solaris equivalents for passwd, shadow and groups
  • ID mapping facility to map Windows Security Identifiers (SIDs) to POSIX Identifiers (UIDs/GIDs) and vice-versa
  • AD Domain join.

As of now, all the above components have been integrated and are available in OpenSolaris starting from version 2008.11. See Documentation below for links to the appropriate documentation.

Documentation

  • Solaris machine can be joined to an Active Directory domain using the kclient(1M) script. Previously we provided an adjoin script for testing purpose. Note that the adjoin script is not supported and no longer maintained. 
  • This troubleshooting, getting started, and what's new information is available for update by the community at http://www.genunix.org.
  • This document shows the relationship between various name service and PAM enhancements projects.
Tags:
Created by on 2009/10/26 11:40
Last modified by Cathleen Reiher on 2009/10/28 23:22

Collectives


XWiki Enterprise 2.7.1.34853 - Documentation