4 ms·
The problem with AD is that it is for windows only. It does not fly for managing Mac and Linux desktops. So that gives us salt for example, which has clients fo
by ratiolat 7y ago
The problem with AD is that it is for windows only. It does not fly for managing Mac and Linux desktops. So that gives us salt for example, which has clients for all three.
The second problem with ad is that if you need to manage any complex settings, you'll need to write your own templates. The included group policies are only for basic level os management + some for basic level Microsoft office managment stuff. Anything else and it's scripting + manual work and AD is only for distribution and selecting hosts/users where to apply those settings.
And yes, I've managed multi thousand workstation networks with AD. Do not recommend it.
- issati 7y agoAD isn't just for Windows, which would be weird since it is mostly a fancy key value store (with associated functions and services of course). SSSD for example can use AD. The problem is that Linux itself doesn't support the same functionality client side, which using a configuration manager doesn't really solve. And question wasn't if you have used AD, but if you have managed Linux desktop deployments without it. Since your claim is that it is better.
- ratiolat 7y agoI'm in the process of bulding a solution for managing all three OS'es. AD is not on the table because theres nothing to do with kerberos in our network and AD would be a "windows only" solution.
- gmueckl 7y agoLinux can totally run in a AD domain with auth managed by AD. Client side SMB is also not bad. But you are excluding Kerberos for some unrelated reason, right?
- deleted 7y ago[deleted]
- kerng 7y agoWhy is AD a Windows only solution? Large corporations and startups use it to run tens of thousands of Macs and Linux machines in addition to Windows. In fact, I can't think of a single large company that does not use it. Its basically the core for many.