migration from samba3 -> 4 architecture question (and IPA?)
Hello all,
this is my case:
I manage like 400 employes in one company with the help of
- 389 Directory server
- Samba 3.6.9 PDC (primary domain controller + 2x BDC)
- SSSD daemon
With the 389 Directory server as backend, i achieved united authentication for users (samba + ldap backend for windows workstations and SSSD daemon + ldap backend for unix / linux authentication)
Currently i'm process of creating another 389 DS (slave) server to add robustness.
After tunning of smb.conf and linux kernel parameters i achieve up to 75MB/s transfer speed of files over CIFS (this is top for one big file, meaning it's always less) so the network speed over CIFS is still issue (compared eg. to NFS4).
Situation now:
I have Hardware planned for new servers in like 8months (which would go nicely with RHEL 7.1 or 7.2).
Because of the LAN speed limits with SMB1 protocol with Samba 3 i started looking after the Samba4, which has the access to SMB2 an SMB3 protocols with hopes of higher LAN speed data transfers.
Problem?:
My concern is now, that Samba4 is a very different beast and i'm not entirely sure, the AD should be my goal in mixed environment of windows and unix servers and windows and unix workstations (yes there are also Linux workstations).
On top of things, Samba4 AD (active directory) mode means basically ditching existing architecture, as it has it's own LDAP, Kerberos and DNS server all bundled together.
This means i can basically ditch current architecture, ditch 389DS etc.
questions i'm basically thinking over lately:
-
if i go with Samba4 AD scenario migration - is SSSD Linux daemon able to authenticate users against LDAP server bundled with Samba?
-
is it possible to update Samba3 - Samba4 while retain 'classic' NTv4 like domain architecture? (the internet search didn't turn with examples of ppl doing this - everyone goes 'crazy' for Samba4 AD from SAmba 3).
This is actually my main question - because if this is possible, this would give me (correct me if wrong)
- the access to new SMB 2 and 3 protocols, while not breaking current setup architecture
- achieve higher LAN transfer speeds in 'faster' time horizon
- give to time to rethink over/test the migration process to AD (if i decide i need it)
- gain time to wait for new HW planned for RHEL 7.x servers and yet have Samba4 LAN speeds
- because again, if i decide to switch to AD i'd like to do this on new RHEL 7.x servers and not on 6x (distro lifetime cycle is getting shorter and shorter) and this means wait until RHEL gets to version 7.1 or 7.2 and is stable and bug free enough for this
-
this question follows previos - if i go with Samba4 'classic' domain, is it doable (hard / easy?) to switch it to AD afterwards?
-
should i go for some MS windows course to get better understanding of AD in case i decide to 'go for it'?
-
how is IPA working with Samba 4? these 2 products now seams to me to be more like 2 competitive products ?
So basically you see, future is?:
- Rhel 7.x Plus SAmba4 classic domain or
- Samba 4 AD ?
- or RHEL 7x with IPA and Samba4 classic domain?
which way to go and be on the 'winner's side? :]]]
Maybe some of you guys have some experience with similar scenarios, i'd appreciate any discussion regarding these matters, because big changes are ahead .. Samba4 out, RHEL 7 out ... and poor sysadmin now need to 'know it all' :]]
Thank you guys for reading this far :]
Responses