Episode 6 - An Open Source Domain Controller and Active Directory system with Zentyal!

Поділитися
Вставка
  • Опубліковано 16 лип 2024
  • As we build out our business running solely on open source, it's important to keep in mind that our clients may not be as open to using an open source operating system, and support for Windows will likely be very important.
    Today I bring you Zentyal, an open source, self hosted alternative to the Windows Domain Controller and Active Directory setup.
    ======== LINKS ========
    Zentyal Server Homepage
    zentyal.com/
    Zentyal Server Download
    zentyal.com/community/
    Get the AwesomeOpenSource Merchandise
    awesomeopensource.creator-spr...
    Support my Channel and ongoing efforts through Patreon:
    www.patreon.com/bePatron?u=23417
    Buy Me a Coffee or Beer
    paypal.me/BrianMcGonagill?cou...
    ======== TIMESTAMPS ========
    00:00 Beginning
    00:09 Introduction to Zentyal
    03:50 Getting the ISO on Proxmox
    04:30 Creating our Zentyal VM
    06:10 Zentyal Install
    07:45 Thank you to my Subscribers and Patrons over at Patreon
    08:23 Reboot after Install
    08:35 The Zentyal First Run Wizard and Web UI
    13:22 A warning about the Install Wizard
    17:40 The Zentyal Dashboard
    20:30 Setting Up Domain Users and Groups
    23:38 Setting Up Windows for Domain Login
    29:52 Setup Ubuntu for Domain Login
    === Contact ===
    Twitter: @mickintx
    Telegram: @MickInTx
    Mastodon: mastodon.partecipa.digital/ @MickInTX
    Try out SSDNodes VPS Services! Amazing Specs for incredibly low costs. I'm running a 32 GB RAM / $ CPU Server for only $9 a month! Seriously. FOr long term server usage, this is the way to go!
    www.ssdnodes.com/manage/aff.p...
    Get a $50.00 credit for Digital Ocean by signing up with this link:
    m.do.co/c/a6a61ae55242
    Use Hover as your Domain Name Registrar to get some great control over you domains / sub-domains:
    hover.com/SHPaiirr
    Support my Channel and ongoing efforts through Patreon:
    www.patreon.com/bePatron?u=23...
    What does the money go to?
    To Pay for Digital Ocean droplets, donations to open source projects I feature, any hardware I may need to purchase for future episodes (which I will then give to a subscriber in a drawing or contest).
    === Attributions ===
    Intro and Outro music provided by www.bensound.com
  • Наука та технологія

КОМЕНТАРІ • 212

  • @garryebenjamin2323
    @garryebenjamin2323 Рік тому +20

    Just saw your video and it is AWESOME. I've been looking for a way to implement AD without all the hassle of Microsoft and their licensing schemes for servers. As an IT Consultant I cater mostly to Small to Medium sized business and honestly the cost of licensing alone can be the biggest deterrent. I made the decision to look into and implement Opensource and its changed my business for the better believe me. So far, I have not been disappointed and neither are my clients so thank you for these great videos and the time you have taken to do the research so that you can share this information with us all. I look forward to more episodes of "Building a Business on Open Source". Let's keep building the dream we dream.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      I'm so glad you are getting something out of the series. I believe, that the more we all use open source, and eventually contribute back to it, then the more it can become the norm.

  • @chadmarkley
    @chadmarkley Рік тому +2

    I have loved this entire series!

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      So very happy to hear that. Stay tuned for more, and more, and more!

  • @wartlme
    @wartlme Рік тому +2

    I like open source. Thanks for posting. Glad this showed up in my feeds.

  • @zippi777
    @zippi777 Рік тому +1

    Great job man! Thanx for this AWESOME guide! 😃

  • @bobwong8268
    @bobwong8268 Рік тому +1

    👍👍👍👍👍Thx for this Awesome Series!
    This can be the beginning of something really Great & Awesome🍷🍾
    Cheers!

  • @michaelamos75
    @michaelamos75 Рік тому +5

    Wow, this is exactly what I have been looking for while struggling through FreeIPA and SAMBA4.

  • @dawnS33ker
    @dawnS33ker Рік тому +1

    Thank you for doing this video. Awesome

  • @tropicalgeek2787
    @tropicalgeek2787 Рік тому +5

    Great video! Zentyal is super easy to setup, I've been using it for awhile. I didn't see you include it but it also works with MacOS just in case anyone has that question.

  • @wizecajurao775
    @wizecajurao775 Рік тому +1

    Thank you! Great help.

  • @tokoshiro5
    @tokoshiro5 Рік тому +1

    man, so much stuff in this channel, I hope I can watch and absorb it all ahahhaha (strugglin to finish my home server but a lot to do in my irl career etc damn)
    thanks a lot

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      Totally understand my friend. I have a full time job, plus I do some IT work for a few clients on the side, make these videos, and have a family I love to spend time with. Life is a giant, delicious sandwich, so take one bite at a time.

    • @tokoshiro5
      @tokoshiro5 Рік тому

      @@AwesomeOpenSource yep, sometimes I get overwhelmed, but I just need to breath a little
      I got super curious about your physical hardware, maybe that would be a cool video : your home's infrastructure :D (I've saw some videos about Pis, yet curious to see if you have some xeon etc there ahaha)

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      @@tokoshiro5 the hardware video is coming next week. Stay tuned.

  • @nicoladellino8124
    @nicoladellino8124 Рік тому +1

    Very nice video, TNX.

  • @bdjobstv8575
    @bdjobstv8575 Рік тому +1

    That was great. Thank you.

  • @parthdholakiya1814
    @parthdholakiya1814 5 місяців тому +2

    Perfect Step by step guide

  • @mrj80
    @mrj80 11 місяців тому +1

    Well done!

  • @belallbasha
    @belallbasha Рік тому +1

    This helped a lot thank you

  • @unmatal
    @unmatal Рік тому +1

    Good Demo
    Thank you

  • @nunoalexandre6408
    @nunoalexandre6408 Рік тому +1

    Brilliant!!

  • @nalle475
    @nalle475 Рік тому +1

    Nice to see the new improved installation. Installed a few more than 10 years ago, it wasn’t this easy, definitely not. Our bulk was MS and a few ClerOS that I really liked and then some odd Zentyal now and then. Z was a good set and it seems to have matured exceptionally well.
    Setting upp MS Office with centralized resources was easier on Zentyal and Clear.
    10-15 years ago having data on a server was more secure than on PC’s in many ways.

  • @thush_boy
    @thush_boy Рік тому +1

    working fine thank you

  • @MsRope93
    @MsRope93 Рік тому +1

    Thanks a lot fro this review.

  • @UnmuteCommunity
    @UnmuteCommunity Рік тому +1

    thanks alot for this video!!

  • @webertonteixeira9098
    @webertonteixeira9098 Рік тому +1

    Thanks Bruu

  • @hatemabdulghani1511
    @hatemabdulghani1511 Рік тому +1

    now i am in a good mood

  • @arcadiosincero
    @arcadiosincero Рік тому +4

    I manually setup a Samba active directory server to act as a centralized authentication server for my Linux and Windows VMs. I chose this approach because Windows can authenticate against it right out of the box, and Linux can authenticate against it by simply installing the appropriate PAM module. While setting it up by hand was educational, it was relatively tedious. Plus theres no pretty web UI to admin things. I think I will switch to Zentyal.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Give it a shot, and let me know how it goes. I'm always interested in some solid compare and contrast information!

    • @BogdanCostin
      @BogdanCostin Рік тому +1

      @@AwesomeOpenSource Congrats for the nice work! You should try and compare with NethServer. Really interested in your comparison of the two.

  • @SB-qm5wg
    @SB-qm5wg Рік тому +2

    Very cool. I think one missing item that would drive MIS away is lack of group policy controls.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      So, I didn't get into all of the nitty gritty yet, but you can actually setup one of your Windows machines to set and dispense group policies, and more.

  • @cm5569
    @cm5569 Рік тому +1

    Awesome stuff, I do wonder if this can be done using a different dns server and not one running on Zentyal.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I think it can, but you need to make sure Zentyal is aware of the DNS server.

  • @zanewebb2316
    @zanewebb2316 Рік тому +1

    if not mentioned below, this domain join for windows PCs only works on pro versions of MS Windows, any windows home edition cannot join a domain. having said that, this is a good video, keen to try it in my Linux environment

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Yes, sadly, Microsoft sees Domain joining as a cost addition. No idea why, but that's why it's so great to have open source options.

  • @RandyHanley
    @RandyHanley Рік тому +1

    Really cool for me to see a Linux machine joining a Windows domain. Great video!

  • @yourpcmd
    @yourpcmd Рік тому +8

    I'd be interested in a follow-up video going over the Mail, FTP, and Jabber.
    Edit: Will this work also for users offsite, like the same company but in different locations? Also, how about nginx to get to the dashboard instead of an IP so an admin can access it from anywhere?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +3

      I think we can eventually get there. But this was a big one for me to put together, and I just didn't want to lose people with too much at once.

    • @yourpcmd
      @yourpcmd Рік тому

      @@AwesomeOpenSource I hear you. This series is very intriguing.

  • @saichand1985
    @saichand1985 Рік тому

    Excellent Video! Can you pls also cover the process/steps for joining Ubuntu machine to zentyal DC through shell.
    Also see if you can demonstrate the Additional Domain Controller setup by spinning up second instance.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      We'll see how far we get in the series, and maybe we can tackle all of those requests.

  • @barefooter2222
    @barefooter2222 2 місяці тому

    I have been using Zentyal for a while now and with a new build, I wanted to get Zentyal 8 up and running with 2 domain controllers. Has anyone had any luck with getting 2 domain controllers joined on the same domain? I've fought it about half a dozen different times and it keeps getting messed up around the Samba config. Overall, Zentyal has been very great in v6 which I've used for a while, but v8 seems to be needing some love around additional DCs

  • @liveting4579
    @liveting4579 Рік тому +2

    Can you incorporate something like MDT for easier OS installs and autopilot for auto enrolment of devices with this? It would be interesting to see how to achieve something like this with open source.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      I'll have to see what MDT and autopilot are. I'm not familiar with those systems. But I'll look into it and see what I can figure out.

    • @sethlerman5005
      @sethlerman5005 Рік тому +1

      MDT Shouldn't be a problem. You don't actually have to install MDT on a server. You can just install it (and the required ADK) on a Windows client PC to do all your work and configuration and still keep the DeploymentShare on the server for clients being built to access it.

  • @knightwolf8877
    @knightwolf8877 7 місяців тому +1

    Question, in the bottom right corner of your taskbar you have a system monitor which is a little graph that's running across. I was wondering if you have the name of it because I can't seem to find one like that for KDE

    • @AwesomeOpenSource
      @AwesomeOpenSource  7 місяців тому

      That's just a task panel widget that I found builtinto kde. I think you can set some settingson it to show the chart or the percentages, etc.

  • @hotstovejer
    @hotstovejer Рік тому +1

    So, freeipa is great for LDAP, RBAC, HBAC, and Linux controls. If you need to mix in users from freeipa into a Windows domain, you need to use AD trust. Don't know if this can be used for that, but it's an option.
    Also, there is Nethserver and UCS. UCS is HEAVY, but has neat things in it.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      Yep, I want to expand on these capabilities in the future. I also want to cover nethserver. It's on my list.

    • @hotstovejer
      @hotstovejer Рік тому

      @@AwesomeOpenSource I'm actually thinking about demoing Nethserver 8 since the older version is based off of CentOS 8, and it feels a bit long in the tooth.

  • @PongoXBongo
    @PongoXBongo 3 місяці тому +1

    This was a great video. I'm Microsoft trained and certified in Active Directory but have been on the lookout for open-source alternatives for my small to midsize clients. Finally, there is a proper, polished solution that doesn't require a PhD in Linux-ology to implement.
    I only wish it had an equivalent to Domain Local groups. Being able to separate user groups (Payroll-Mgr) and resource-access groups (Payroll-Records-Modify) is a godsend when auditing time rolls around (nesting, FTW).

    • @AwesomeOpenSource
      @AwesomeOpenSource  3 місяці тому +1

      There is also UCS Univention Corp Services. I'm working on a video on it as well, and it offers similar functionality. You may want to look into it as well.

    • @YourDogDoc
      @YourDogDoc 2 місяці тому

      @@AwesomeOpenSource will eagerly await this video AND an updated Zentyal 8.0 setup, too ;-)

  • @crashtfa
    @crashtfa Рік тому +1

    FreeIPA is the way to go, zentyal was good for it’s time, but now FreeIPA does so much more and is what redhat uses for RedHat IDM

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I like Free IPA, but definitely not so friendly for Windows client setup.

  • @datSpookyDude
    @datSpookyDude Рік тому +1

    I believe you can use Copilot to join a domain after setup

  • @cdoublejj
    @cdoublejj Рік тому

    anyone had any luck binding with sso like say jelly fin or nextcloud?? anyone able to bind vmware vsphere to this?

  • @mihaylovg.m.
    @mihaylovg.m. Рік тому +1

    It’s okay to feel that why. I felt like that sowh

  • @1diyproject
    @1diyproject Рік тому +1

    I just installed this in a VM last week to test it out. Was that windows home or pro in the setup? If it was home, were there additional installs required?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +2

      Just a win 10 VM. I don't really know what version it is actually. Home may not have the domain level login available.

    • @1diyproject
      @1diyproject Рік тому +1

      @@AwesomeOpenSource I agree, Windows Home does not have it. Great work on this product.

  • @MindzGroupTech
    @MindzGroupTech Рік тому

    Can we get a video on publically available domain controller and at the same time securing it from attacks

  • @techiemike9483
    @techiemike9483 Рік тому +1

    Great video, there is a bug in the webadmin. The only problem I have is trying to get the RSAT tool to work via windows 10, not sure if it because I am using a made up domain techie.local, I can join the domain but if I try to use RSAT it says the domain cannot be found, same setup using server 2022 no issues, not sure if you had similar issues?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I haven't tried it myself, as I don't use Windows generally, but was just passing along that the project says RSAT can be used, but if Server 2022 for Windows has the same issue, I'm guessing it's not a Zentyal issue alone.

  • @christopherklein3829
    @christopherklein3829 Рік тому +1

    Pls have a look to nethserver 8, too

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      This is also on my list. I'm excited to see what they can do with Docker as a base.

  • @TheGreatestMajesty
    @TheGreatestMajesty Рік тому +2

    You may have answered this question, so sorry if I missed it. Is there a Docker Alternativeor containerized version?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Not that I know of, but I didn't really look. Since you can install it on top of ubuntu, I suppose it could be dockerized if it isn't already.

    • @TheGreatestMajesty
      @TheGreatestMajesty Рік тому +1

      @@AwesomeOpenSource Thanks again my good sir. Salute!

  • @ccraw
    @ccraw Рік тому +1

    What OS/desktop or thame are you running on your local desktop?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Kubuntu 22.04 with KDE.... just modified my taskbar a little.

  • @infotechsavvy4981
    @infotechsavvy4981 Рік тому +2

    The Platform is very great and cheap setup for Domain Controller & Active Directory. The only lacking with this one is the Group Policy Object. I think that's the beauty of Windows Server vs. Zentyal.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      You can do group policy from any connected windows machine. You just need to install that function into windows, but you can manage it from there.

    • @dumitrugritcan3150
      @dumitrugritcan3150 Рік тому

      Show us an guide how to do That , please )

  • @heaton922
    @heaton922 Рік тому +2

    I just try with zentyal. I dunno why the username & pw is incorrect when joining the domain. I am pretty sure the pw is correct. And I go to github saw the same issue and still have some bugs with zentyal. hopefully, zentyal will fix that.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      Sorry you are having trouble. I didn't run into that issue. I also hope they'll fix some of these little quirks.

  • @LazySusanInventor
    @LazySusanInventor 11 місяців тому +1

    Can you add a nas to the domain ?

  • @k36242
    @k36242 Рік тому +1

    Can you do a video about, Nethserver, ClearOS, Endian please. Thanks

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      NethServer is in my plan, so I'll lok at the others. Thanks for the suggestions.

  • @rollyes_
    @rollyes_ 10 місяців тому +1

    Is it possible to log in with a smartcard?

    • @AwesomeOpenSource
      @AwesomeOpenSource  10 місяців тому

      Mmmm, don't know. Didn't see anything for that when I was working on the video.

  • @jomijohn7068
    @jomijohn7068 Рік тому +1

    can you suggest a best opensource Documentation Software

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      That's a huge question. It really depend on your needs. I have really fallen in love with BookStack. It has some incredible features, and really makes keeping a documentation site up and running pretty easy. I have an older video on it, but need to do an update. There are, however, some other great videos that go through the "superuser" type features of it.

  • @surisurendrababu
    @surisurendrababu Рік тому +1

    Hi can you demonstrate the same in cloud vm with publicip and domain ?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I'll see what I can do in the next video I make on the topic.

    • @surisurendrababu
      @surisurendrababu Рік тому

      @@AwesomeOpenSource thank you

    • @surisurendrababu
      @surisurendrababu Рік тому

      @@AwesomeOpenSource and please try to sync users from azure ad to zentyal

  • @trksoft3320
    @trksoft3320 Рік тому +1

    I installed zentyal on a proxmox container but I have an authentication problem ?!

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      If you'll jump over to discuss.opensourceisawesome.com and post about the issue, maybe I, or someone on the boards can help.

  • @benjaminberisha1
    @benjaminberisha1 Рік тому +1

    Very Nice Software! Is it necessary to use .loc in the Domain Name?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      no, I just had my domain set to that in my network already. You can use either a public or private domain, so make it what you want.

  • @krdesigns
    @krdesigns Рік тому +1

    so far no luck installing the software properly. Upon install should I restart the server its either zentyal lost IP or lost internet connection. Unsure on what happen.

    • @krdesigns
      @krdesigns Рік тому

      yes, did more testing and zentyal have problem. Upon setup and input the IP etc, it stuck just like in your youtube on webadmin. I can refresh as follow. Then basically now the proxmox VM have no access to internet. Updating is basically impossible. Unsure what is being changes, that disable the connection to outside world

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Yes, I did have to kind of work through a couple of times, but did get it to work. Never lost connection completely though.

    • @krdesigns
      @krdesigns Рік тому

      @@AwesomeOpenSource could you tell us how you solve the problem.. Because it giving me a headache. Been trying to fixed without any right solutions. Furthermore it wont allow the domain admin to login from Windows 11 Pro. Keep saying wrong password

  • @amadoumane7600
    @amadoumane7600 Рік тому +1

    Can you provide us the open source of SIEM, IDS, IPS? I would like to train on these tools. Thank you

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      There are several tools for doing this. They are all available in OPNSense / pfSense firewalls, either built in, or as plug-in / add-ons. Suricata is one option for IPS/IDS. Takes time and tuning, but it's touted heavily by pros.

    • @amadoumane7600
      @amadoumane7600 Рік тому +1

      @@AwesomeOpenSource thank you so much

  • @jasonji1152
    @jasonji1152 Рік тому +2

    Univention UCS is my go-to domain controller choice

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Is it open source? I'll look into it for sure.

    • @jasonji1152
      @jasonji1152 Рік тому +1

      @@AwesomeOpenSource It's free to use, and pay for support if needed. Yes, it's open source. I used it for LDAP, AD, and Kopano Mail Server. it's very user friendly.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      That's Awesome! Will definitely look into it! Thanks for the suggestion.

  • @LehmannMr
    @LehmannMr Рік тому +1

    I used the iso to create Vmware Workstation Machine -- but everything gets installed automatically and after it finishes I only get a shell window --- what am I missing here ?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I'm not sure. Shouldn't install everything by default. Did you miss a screen somehow? Maybe the wizard didn't run, so the services are all there technically, just not started?

    • @LehmannMr
      @LehmannMr Рік тому

      @@AwesomeOpenSource I tried it twice. There are some installation screens shown but everything is installed automatically. At the end there is only a prompt.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I'm sorry you're running into that. I never experienced that issue. Not sure why it would be happening.

    • @LehmannMr
      @LehmannMr Рік тому

      @@AwesomeOpenSource Maybe someone else here will check it.
      Apart from that my conclusion from all the comments over here that this project is no longer very well maintained and the only reasonable option is to buy a windows server licence.

  • @navedwaris2363
    @navedwaris2363 Рік тому +1

    Can we apply group policy through this server???

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      You can using some tools that you would install into one of your windows clients. You'd login to it using the Domain Admin account, then install the Remote Server Admin Tools for Windows. From there, if your domain, and dc are setup properly, the tools will identify your server and any group policies you create will be applied on the server and to your other machines / users.

  • @theterriblegamer1228
    @theterriblegamer1228 Рік тому +1

    Is this Windows 11 Compatible? Having issues with Synology Directory Services accepting Windows 11 clients

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I don't have a Windows 11 machine to test, but someone else mentioned they didn't think it would be an issue...I don't think they tested it though...so just don't know.

    • @theterriblegamer1228
      @theterriblegamer1228 Рік тому +1

      @@AwesomeOpenSource I was able to connect a windows 11 VM last night, however it's one that I had previously made some settings changes to in order to try and connect it to a different AD. Will need to clean install the VM and try again to be sure. Microsoft offers a win11 ISO on their website as a free download. Win11 has made some significant changes to how it authenticates with ADCs.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Thanks for the info and update. Let me know how the clean install goes.

  • @lewiskelly14
    @lewiskelly14 Рік тому +1

    So are there any group policies???

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      You can add a package to one of the Windows machines to use as a master machine, and push out group policies with it.

  • @cluberic
    @cluberic 4 місяці тому +1

    what about group policy?

    • @AwesomeOpenSource
      @AwesomeOpenSource  4 місяці тому +1

      You can add the functions to any Windows 10 PC and then manage group policy from there. I believe they have instructions on how to do it on their site as well.

  • @akurenda1985
    @akurenda1985 Рік тому +28

    Zentyal is still on the domain and forest level of 2008 R2(Equivalent of Windows 2012 R2, since 2016 to 2022 are all on 2016 domain and forest levels). I love the idea of the software, but you are very limited on what you can do with it. Also, I would never put this in a client's infrastructure. If they can't afford actual Windows Licensing, I'm not going to piece meal them. AAD Connect does not work with Zentyal, and it's literally a must if you are a 365 shop. l love the concept of "I want to use all open source software", but everything is literally revolving around cyber insurance requirements and security frameworks, so it's literally a pipe dream for most people in IT.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +19

      I completely understand where you are coming from, and there may not be as many open source projects as we need. But, as I've always said, just because it's closed source doesn't make it better. A lot of compliance and standards are set by arbitrary boards that then charge incredible amounts fo money to get through the compliance or certification process. It's generally an issue of not being able to afford to go through the process for most projects more than it being the project wouldn't be able to pass, or at the very least fix any issue identified. Theere's this line in the movie "Willy Wonka and the Chocolate Factory" that has stuck with me since I was a kid... "We are teh music-makers, and we are the dreamers of the dreams." Unless we start dreaming the dream, we cannot build up what we dream of. I'm just trying to help people realize the dream, and we will build it as we can.

    • @akurenda1985
      @akurenda1985 Рік тому +6

      Please don't misunderstand. I love open source. I have a VCP-DCV and I'd rather run Proxmox or XCP-NG for my personal use any day of the week. But when you're dealing with insurance companies, HIPAA audits, FDIC audits, pretty much ANY audit, this will be flagged for a ton of issues. Not only that, but if you have a BAA with your clients, you're going to have a hard time even running this yourself for your own infra, because YOU have to also pass the audits. Having been through SOC2 compliance, FDIC audits for credit unions and banks, and dealing with many large healthcare orgs, I have a much more cynical view of open source in a real enterprise setting. Speaking of quotes, my step dad used to tell me the same thing every time I really "wanted" something and I couldn't get it "Son, wish in one hand and shit in the other. See which one gets filled the quickest".

    •  Рік тому +6

      You're talking about the biggest companies as a client of yours, when this (Zentyal) and similar projects made for the smallest companies to spare the money they must spend on a single Windows Server licence they ever may need. Of course, anyone who would like to integrate thing with MS's own cloud or other systems, must purchase and run original MS software. And of course, who must certify on specific topics (which usually have a list of accepted solutions) also buy from the accepted solutions list to pass that certification.
      But everyone else can use open source software, and this "everyone else" is a very big set not a marginal one...

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +10

      I 100% understand. Seriously. I work (in my day job) in software for public safety, which has all kinds of audits, and compliance requirements. I'm always looking for the Open Source that will make the grade, but in so many cases, you're right, the audits just don't allow for it. I appreciate you sharing what you know about the subject. I'm always the first to say that I in no way, shape, or form, know everything. I try to learn something new everyday, so seriously, thank you for sharing.

    • @jgould30
      @jgould30 Рік тому +2

      @ No that's the thing. I work with a very small (25 employees) clinical laboratory that must meet regulatory requirements (HIPAA) and another (

  • @mjackstewart
    @mjackstewart Рік тому

    Can you move the FSMO roles?

    • @jarosawm.55
      @jarosawm.55 Рік тому

      Można przenosić role FSMO, wszystko opisane jest w dokumentacji zentyal dodatkowo polecam wspomagać się dokumentacją od samba

  • @uae7001
    @uae7001 Рік тому +1

    i wish if you show us how to install Zentyal on a LXC Container

  • @ThierryC2373
    @ThierryC2373 Рік тому +1

    How about AD policies?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      This can be done by installing the RAST (Remote Tools) on one of your Windowss machines, and logging into it as a Domain Admin.

    • @ThierryC2373
      @ThierryC2373 Рік тому +1

      @@AwesomeOpenSource no, I meant if you use this as a domain controller, how do you manage the AD policies which must reside on a domain controller? This looks more like LDAP than Active Directory to me.

  • @MrHoshani
    @MrHoshani Рік тому +1

    soft source?

  • @n0madtv
    @n0madtv Рік тому +1

    Unfortunately you can't add existing windows pc's to the domain without giving them a whole new user/profile. I tried zentyal but it was pointless since I wasn't willing to re-do every pc on my network with a fresh install. Note; this is a windows domain problem, not a zentyal problem.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Interesting to know. When you say whole new user / profile, do you want to login to the domain using your current local user?

    • @n0madtv
      @n0madtv Рік тому +1

      ​@@AwesomeOpenSource Yeah, active directory doesn't allow adding an existing local user. All new users have to be created in the domain. The only workaround, aside from reinstalling the windows client and starting from scratch, is to create a new user/profile in windows. Some people do this for work purposes (ie: second profile for logging into domain, first profile for home use), but otherwise the windows domain has to be built from day 1 from the controller outward. If that makes sense....

  • @zohrabmi5767
    @zohrabmi5767 Рік тому +2

    Unfortunately Linux is not world-wide desktop OS alike Windows

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      True, but the more we use it, the more it can become a bigger part of the world computing landscape.

    • @kristopherleslie8343
      @kristopherleslie8343 Рік тому +1

      Zohrab, i have to disagree. 80% roughly of the entire world is on Linux, saying Linux isn't on a desktop, is like a meme. Almost anything you can imagine or use is running on Linux at some level. Microsoft runs on Linux.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Agree, when you consider servers, Linux runs the world and the interneet. But if you only look at desktop usage, people don't use Linux but about 2.2% overall. So I see the OP's point.

  • @kristopherleslie8343
    @kristopherleslie8343 Рік тому +2

    Definitely wouldn't be using this anymore. Better alternatives but would probably suggest a cloud based solution

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +2

      If you know of any open source cloud based solutions, please point them out. I'm always happy to look into more options.

    • @kristopherleslie8343
      @kristopherleslie8343 Рік тому +1

      @@AwesomeOpenSource will do gotta dust some links off

    • @kristopherleslie8343
      @kristopherleslie8343 Рік тому +1

      Could have sworn i posted links but I ill try to get them again.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +2

      UA-cam deletes comments with links from anyone who isn't the video owner. Sorry, forgot about that. If you'll just give me the names of the software, I"m happy to do some digging.

    • @kristopherleslie8343
      @kristopherleslie8343 Рік тому

      @@AwesomeOpenSource Jumpcloud can get you started

  • @Ne0_Vect0r
    @Ne0_Vect0r Рік тому +2

    Better use Univention Corporate Server

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Indeed, I will do a video on it in the future. Thanks for the suggestion, and for watching.

  • @RockFordCademce
    @RockFordCademce Рік тому +1

    is it free?

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      It's open source software. You can use a good portion of it at no cost, but keeping the software going depends on financial backing just like any project.

  • @ubaidrahman4198
    @ubaidrahman4198 Рік тому

    Mlk, se pá que o canal foi hackeado

  • @supremeshadow
    @supremeshadow Рік тому +2

    after zentyal 4.0 devs become very greed, most of usefull options not free.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Sorry to hear that... but I don't know if it's greed. Open Source projects are very hard to maintain. Most people work on a project as their side hobby...and if we want them to continue the project, build it up, make it better, then we want them to make it their full time job, and that costs money. I can see why it becomes a value add type system after a while, and that's why it's importatn for us to be advocates of open source, and pay for the software we love to use, adn donate where we can.

  • @MrBross-ey8yp
    @MrBross-ey8yp Рік тому +2

    dont be the type of person to use roaming profiles

  • @cdoublejj
    @cdoublejj Рік тому +1

    ...An Open Source Domain Controller and Active Directory........BULLSHIT!!!! ...35 minutes... what the!???? Gotta check this out!!!!!!

  • @j_r_-
    @j_r_- Рік тому +1

    Mailcow

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому +1

      I'll cover it in the future. Thanks for the suggestion.

    • @j_r_-
      @j_r_- Рік тому +2

      @@AwesomeOpenSource Thanks I use it for my mail server its perfect. Way better than iredmail and mail in a box

  • @Foiliagegaming
    @Foiliagegaming Рік тому +1

    This is a cool set up. But you are able to get cheap keys

  • @bryanb3352
    @bryanb3352 Рік тому +3

    Just stand up a Windows domain controller. This thing is nothing but a pain in the butt. If you just want to play around, fine, but don't use it for anything that you need to work consistently.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      Sorry you had a bad experience with Zentyal. I, thus far, have had no issues other than the odd install wizard quirk I mentioned in the video.

  • @udirt
    @udirt Рік тому +1

    This looks like a child toy. Would recommend people to squint for a moment and use a reasonably good NAS to provide AD services instead.

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      If you know of an Open Source NAS that has the ability, please let me know. Would love to cover that.

  • @oneito947
    @oneito947 Рік тому +1

    you should have gone with Nethserver, has awesome community as well as very active development and amazing people

    • @AwesomeOpenSource
      @AwesomeOpenSource  Рік тому

      I'll definitely cover Nethserver in a future video! Thanks for watching.

  • @ewenchan1239
    @ewenchan1239 8 місяців тому +1

    Did you ever get around to making the video of how to modify an existing Ubuntu user account so that it will use the Active Directory Domain Controller rather than the local Linux PAM authentication?

    • @AwesomeOpenSource
      @AwesomeOpenSource  8 місяців тому +1

      I thought I added it to the end of this one. I know I did record it. Been so long, don't really recall. But, you need to set it up on install of Ubuntu if you want to use the GUI tools, otherwise there's a whole set of commands to get it setup. Not sure why it matters when you setup the account, but that's how it was when I originally did this video.

    • @ewenchan1239
      @ewenchan1239 8 місяців тому +1

      @@AwesomeOpenSource
      I think that towards the end of this video, you mentioned that you might make a separate video of how to modify an existing Ubuntu user account, so I am just following up on that remark.

    • @AwesomeOpenSource
      @AwesomeOpenSource  8 місяців тому

      Ok, I re-watched, and refreshed myself, and I did say that, but I did not ever follow up. I still notice that it's from the initial setup / install that it's right in the GUI. If you're adding a new user to the machine (in 23.10 at least), you can also choose Enterprise Login and add them to a domain that way. Here's a link on how to do it help.ubuntu.com/stable/ubuntu-help/user-add.html.en, but if it's an existing user, there are a lot of steps to follow to change how they login as far as I can tell.

    • @ewenchan1239
      @ewenchan1239 8 місяців тому +1

      @@AwesomeOpenSource
      "but if it's an existing user, there are a lot of steps to follow to change how they login as far as I can tell."
      Thank you.
      I was under the impression that you might have conducted the research already in regards to how to modify an existing user account to have it join an Active Directory domain.
      But based on your reply, it sounds like that my assumption may be incorrect.
      Thank you, for your help.