NS8 + LDAP Account Provider + Linux Clients (Issue)

Hi everyone,

Here again, so thanks again for the great product. I love the server!

Let me explain the issue I’m having. I installed NS8 in my lab to authenticate a few Linux clients. I chose AlmaLinux 10 for the clients and Rocky Linux 9 for NS8. Since my goal is to connect only using pure Linux clients, I originally wanted to go with the OpenLDAP Account Provider. However, I know you guys disabled that option.

Because of that, I thought about using the SAMBA Account Provider instead. My idea was to still have the clients connect using pure OpenLDAP client tools, since Samba uses LDAP in the backend. Unfortunately, I cannot make this work.

To make sure I wasn’t doing something wrong, I set up a quick LDAP server using Turnkey Linux as a test, and my clients connected to it perfectly.

Please advise. What am I missing to get this working with Samba?

LAB System HOST:
Virt-Manager / KVM / QEMU
Network / NAT with DHCP

Hi Giancarlos, please check log messages from Alma Linux clients, e.g.:

journalctl -u sssd --since "10 minutes ago"

Or

journalctl -b --since "10 minutes ago" | grep -i -E 'ldap|sssd|tls'

Samba DC does not allow clear-text LDAP binds, and maybe Samba’s self-signed certificate is not accepted by Alma Linux clients.