4 ms·
Why are people running Windows in the first place? On a server it's just crazy. Microsoft has thoroughly proven that they have no clue how to make a mail serve
by jgaa 4y ago
Why are people running Windows in the first place?
On a server it's just crazy. Microsoft has thoroughly proven that they have no clue how to make a mail server, remote desktop server or network services that can be safely connected to a public network.
On a PC it's also a privacy nightmare.
- prmoustache 4y agoActive Directory, Exchange and to a lower level Citrix are the answer. Very few businesses think they can do without those. IT history of these 30 last years have kind of segregated sysadmin/architects types. The one focused on internal IT / desktop services solutions are typically more knowledgeable in Microsoft technologies while unix/linux sysadmins usually focus on the non desktop/office related stuff. Despite decent solutions existing without Microsoft, very few people know enough about them to recommend them.
- jve 4y agoWhat is your AD replacement in Linux env?
- hansel_der 4y agosamba?
- prmoustache 4y agoOnly talking about on-premises tools: Samba (if you need GPO supports for windows desktops), 389 Server, redhat directory server, openldap can work with Keycloak to provide saml2/openid authentication for individual applications. Most emails clients support ldap for contacts with additional carddav server to sync personnal contacts accross devices, Sogo groupware works well for that , add a fairly decent webmail interface and has an outlook connector for easy configuration of microsoft desktops but if you need office 365 functionnalities, Nextcloud would be the way to go imho. It is available as a service too and is cheaper than Microsoft 365. I am not sure how an on premise Nextcloud would scale to huge companies (but enteprise offering say it scales to hundreds of millions of users) but for small businesses it is easy to set up.
- jve 4y agoI really only have experience administering windows AD desktop - mostly LDAP/GPO/DNS, some Share and thankfully no Print I would really like some comparison from administration effort: 1. How easy it is to tie those things together? Like installing that Linux AD server components 2. How easy from deployment POV it is to join computers to network and start using a networked user account? 3. How easy it is to use print server connected to domain? 4. How easy it is for member servers within domain to start accepting SSO connections from those clients/servers? 5. How easy it is to have centralized configuration for linux host and target them? I mean using Linux tools as I suppose linux env won't have gpmc.msc. Let's say you would like all your client hosts, all software to talk TLS1.2+ only. 6. How easy would it be to establish internal certification authority with certificate auto renewal? I'm aware of paid solutions, but just from marketing material, so no clue how it behaves in real life and how far it goes. Please don't assume I'm starting flamewars. I just see a great value within Windows AD environment that is easy to set up but as we see from article, takes effort to configure and maintain secure and consistent environment. My experience with Linux is limited in domain area, and I haven't been familiar with centralized configuration options - I just want to see if it takes 1x/2x/10x effort to do the same in Linux env.
- neurostimulant 4y agoOpenLDAP and Keycloack have docker images that can be used to deploy them pretty easily, at least if you're comfortable with container-based deployment. I knew nothing about both and able to deploy them in a few hours. Connecting individual servers / applications to OpenLDAP and Keycloack varies widely though, not all apps has OIDC support but you can put them behind an authenticating proxy like oauth2-proxy. Can't comment on how easy it would be to join desktops and print servers though as I never did it myself.
- prmoustache 4y agoIt is really complicated to answer. There are things that are super easy. For example samba is a real dropin replacement for an AD, you can join windows computer to it very easily. Similarly, the bigger distros all have easy setup to enable joining a linux desktop to an Active Directory for auth. I have used centralized configuration management tool such as puppet, cfengine, saltstack and ansible for years. I did the exercise of managing desktops with them and it was fairly easy. Hey I even deployed windows servers with foreman and puppet. But for you it might be a nightmare to have to learn a new domain specific language.
- arminiusreturns 4y agoIdeally you move completely away from AD. I've used Pgina before for alternative auth methods when you have to deal with a dozebox but it has major issues that make it not worth it, so in reality you usually have a virtualized samba domain that pulls from FreeIPA (389 ldap underneath). (and if you have a windows admin on staff who can't write a GPO by hand you can virtualize the DC admin doze machine and ensure good rbac.)
- jgaa 4y agoBack in the days there was a saying "Nobody will lose their job for choosing IBM". I guess Microsoft has been the new IBM for a while. I'm just praying that their decline will be imminent and fast. It's still sad that incompetent people get to choose rotten technology - often burning tax payers money (or even religious donations).
- Shorel 4y agoMicrosoft has been the new IBM for a few decades already. In fact, this is considered ancient history nowadays.
- jgaa 4y ago
- todorus 4y agoPlease become familiar with the guidelines. Your comments show you aren't, or show a complete disregard for it. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html