Samba 4.0 released
samba.org
samba.org
So many examples come to mind that it is hard to pick just one or two... consider an organization that configures access to Windows event logs (audit trails) and SMB signing requirements via GPO; will Samba 4 Domain Controllers honor that? What does it even mean to have access to modify the security auditing policy on a Samba DC without totally reimplementing the eventing system (syslog is not even close)?
In other words, AD sits on top of a ton of mature but sophisticated Windows services, the failure of any of which could be a critical problem, and make for a tough sell unless one has a pathological hatred of Microsoft yet still wishes to use AD anyway.
I've done a lot of work with other directory servers too, and AD does the best job of any when it comes to multimaster replication and a few other things. However, using it purely for LDAP for an environment full of Linux and OS X machines is a tough call...
Linux support for AD also allows incremental migration of this infrastructure.
I personally am going to give Samba 4 a look.
1. Directory services/DC
2. Windows file shares
3. Exchange
I have to buy user CALs for #1 and #2. One CAL gives me the right to connect that user to any of our file shares and to AD. IIRC, that cost when we last purchased was around $50/user.
We also have to buy a separate CAL for Exchange.
I would love to replace AD and our Windows file shares with Samba 4, provided that it was a stable, viable replacement which didn't add a lot of overhead for our admins. Exchange is a separate issue, and one we're currently exploring Zimbra as a possibility. It's early days yet there.
Almost everything else in our environment is Linux.
But I do agree with the dbrain's sentiment. If it was going to have a significantly higher TCO, I wouldn't do it.
All that being said, I'm also underpaid (80% regional average). Maybe that's the real reason they keep me around.
1) It's probably not enough money to hire even one extra IT person to deal with new issues that will arise with Samba 4
2) Linux sysadmins are more expensive than Windows sysadmins.
3) Cost of retraining existing IT staff.
4) Potential loss of productivity of your 2500 users
5) Lack of commercial support options.
6) Uncertainty about the future of Samba in general (release time tables, feature support, etc)
2. Bad Windows sysadmins are less expensive than good Linux sysadmins. I agree with you there. Good Windows admins, however, are just as expensive. Trust me...I've hired quite a few.
3. Again, I have well-trained Linux guys on staff.
4. This is a very valid possibility we'll need to consider.
5. Not worried about that at all. We use a lot of open source without commercial support options, and our experience with Microsoft support is four hours of scripted troubleshooting on average, with about a 60% success rate of resolution.
6. Not concerned with this at all. Samba has been here for a long while and I don't think it's going anywhere.
2) You need an IT dept., not a monkey dept.
3) If your IT staff doesn't understand Linux already, see 2.
4) FUD
5) FUD
6) FUD
Here for us (not OEM) the whole AD stack you mentioned is completely overkill, and the stuff implemented by this Samba release looks terribly like covering 99% of what we use and need in our half windows (customer TSE access, networked file store), half linux (web hosting + many services) infrastructure.
Most people try to measure the cost benefit of free software, with TCOs, CALs, admin salaries etc. That is fine, but the true benefit of free and open source software in my experience:
1) The absence of license considerations in designing and developing systems; this frees the designer's mind in planning, and building. Now the system components can be planned without fear of a multitude of diverse, artificial license schemes.
2) The absence of a license-selling company; this frees the management's mind in estimating and revising the costs moving ahead. License-sellers like Oracle, Microsoft are well known for figuring out diverse sets of confusing licensing schemes. They spend their money in hiring the best sales people which are famous for hunting and then farming clients in the span of 5-10 years ahead by first locking them down.
Well, there is this: http://www.debian.org/ports/hurd/
From GNU/Hurd TODO list :)
bugs in select() cornercases
is the thing that stands out to me. Seems like I would want select() to be pretty solid to consider this a viable alternative.That said, hurd is essentially abandoned at this point. Even RMS has accepted that it will never be completed, and has said that it really doesn't matter since there's already a free kernel available (linux).
Practical example: http://en.thewitcher.com/forum/index.php?/topic/33183-red-en...
Cannot communicate securely with peer: no common encryption algorithm(s).
(Error code: ssl_error_no_cypher_overlap)
I went to about:config and turned on all the default-disabled ssl ciphers (per https://support.mozilla.org/es/questions/818578 ) but it didn't resolve the trouble.UPDATE: I tried restarting my browser, and then it worked BUT after trying to do a binary search on which cipher setting was the "fix", I got to where everything was back to default, and the site still works. Probably there was a site problem that was fixed in the interim.
For groups who aren't fully invested in AD, or need compatibility with those who are, this is a major win.
Small companies don't have the expertise, large companies can't afford the risk.
(Google Docs is, as far as I know, OpenOffice for example)
I've never heard about this before, and if true, would be really interested in knowing more about the story behind this.
Got some choice links?
Now when you consider that managing unix machines requires much less work to begin with, you can't look at "quite cheap" the same way anymore - it's actually "quite expensive".
Not to mention I often see improved performance of server applications just by switching them to a linux host. Samba 4 is indeed very good news.
http://www.amazon.com/Exchange-Standard-2010-English-User/dp...
A Windows server CAL is about $20 per device.
http://www.newegg.com/Product/Product.aspx?Item=N82E16832416...
Windows licensing is somewhat a mess, between user CALs, device CALs, processor CALs, or combinations thereof. You can see why Google's $50/user/year price is attractive - no hardware to buy, no CALs to buy, no client software to buy.
Fortuitously for this article, I've spent the entire day today trying to get samba sharing with AD. Oh, NT_USER_NOT_PERMITTED? Bbbut, the user is there; I even have it working on another server!
I'm sure it's my fault, but still, as of this moment, I hate samba more than almost everything.
At any rate, congrats.
Seriously, how do you expect someone to give you a useful reply?