{"id":1693,"date":"2025-07-10T17:26:01","date_gmt":"2025-07-10T20:26:01","guid":{"rendered":"https:\/\/www.nerdadas.com\/blog\/?p=1693"},"modified":"2025-07-10T17:36:06","modified_gmt":"2025-07-10T20:36:06","slug":"usuarios-y-permisos-en-linux-con-grupos-de-active-directory","status":"publish","type":"post","link":"https:\/\/www.nerdadas.com\/blog\/usuarios-y-permisos-en-linux-con-grupos-de-active-directory\/","title":{"rendered":"Usuarios y Permisos en Linux con Grupos de Active Directory"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Llega la etapa donde la <strong>autenticaci\u00f3n basada en roles(RBAC) <\/strong>en la empresa debe llegar a <strong>Linux <\/strong>y te guste o no<strong> Active Directory<\/strong> es un mal necesario. (Ya hablaremos en alg\u00fan otro momento de OpenLDAP o similares).<\/p>\n\n\n\n<p>Ten\u00e9s un mont\u00f3n de servidores Linux y ahora necesitas permisos centralizados. <\/p>\n\n\n\n<p>Vamos a crear en Active Directory un grupo de usuarios con permisos limitados(<strong>linux-user<\/strong>) y uno con permisos \u00absudo\u00bb(<strong>linux-root<\/strong>). Los usuarios de ambos acceder\u00e1n por<strong> ssh<\/strong> a los servidores linux de la empresa. En este caso, los servidores linux ser\u00e1n <strong>Debian 12 <\/strong>y el <strong>DC <\/strong>(Controlador de Dominio) un <strong>Windows Server 2019.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/06\/rbac_linux.png\"><img loading=\"lazy\" decoding=\"async\" width=\"823\" height=\"447\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/06\/rbac_linux.png\" alt=\"\" class=\"wp-image-1694\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/06\/rbac_linux.png 823w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/06\/rbac_linux-300x163.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/06\/rbac_linux-768x417.png 768w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><\/a><\/figure>\n\n\n\n<p>Hoy voy a los bifes!.<\/p>\n\n\n\n<p>Configuramos el <strong>DC midominio.com.ar<\/strong><\/p>\n\n\n\n<p>Voy a pasar r\u00e1pido los pasos para agregar un equipo al dominio ya que no es el foco de este lab pero es necesario para realizarlo. Muy sencillo, el viejo y efectivo DCPromo pero con la hermosa GUI de Windows Server 2019.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image.png\"><img loading=\"lazy\" decoding=\"async\" width=\"705\" height=\"563\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image.png\" alt=\"\" class=\"wp-image-1700\" style=\"width:840px;height:auto\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image.png 705w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-300x240.png 300w\" sizes=\"auto, (max-width: 705px) 100vw, 705px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-2.png\"><img loading=\"lazy\" decoding=\"async\" width=\"793\" height=\"547\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-2.png\" alt=\"\" class=\"wp-image-1702\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-2.png 793w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-2-300x207.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-2-768x530.png 768w\" sizes=\"auto, (max-width: 793px) 100vw, 793px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-3.png\"><img loading=\"lazy\" decoding=\"async\" width=\"793\" height=\"547\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-3.png\" alt=\"\" class=\"wp-image-1703\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-3.png 793w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-3-300x207.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-3-768x530.png 768w\" sizes=\"auto, (max-width: 793px) 100vw, 793px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-4.png\"><img loading=\"lazy\" decoding=\"async\" width=\"799\" height=\"546\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-4.png\" alt=\"\" class=\"wp-image-1704\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-4.png 799w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-4-300x205.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-4-768x525.png 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/a><\/figure>\n\n\n\n<p>Siguiente&gt;Siguiente&gt;&#8230;&gt;Install y reiniciar.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-5.png\"><img loading=\"lazy\" decoding=\"async\" width=\"639\" height=\"455\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-5.png\" alt=\"\" class=\"wp-image-1705\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-5.png 639w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-5-300x214.png 300w\" sizes=\"auto, (max-width: 639px) 100vw, 639px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Configuramos los grupos<\/h2>\n\n\n\n<p>Vamos a configurar los grupos de usuarios contra los que validaremos en Linux<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-6.png\"><img loading=\"lazy\" decoding=\"async\" width=\"821\" height=\"448\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-6.png\" alt=\"\" class=\"wp-image-1706\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-6.png 821w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-6-300x164.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-6-768x419.png 768w\" sizes=\"auto, (max-width: 821px) 100vw, 821px\" \/><\/a><\/figure>\n\n\n\n<p>user1 ser\u00e1 miembro de linux-root y user2 ser\u00e1 miembro de linux-user.<\/p>\n\n\n\n<p>Los usuarios de linux-root podr\u00e1n conectarse por ssh y hacer sudo mientras que los miembros de linux-user solo tendr\u00e1n acceso ssh sin privilegios<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-7.png\"><img loading=\"lazy\" decoding=\"async\" width=\"862\" height=\"469\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-7.png\" alt=\"\" class=\"wp-image-1707\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-7.png 862w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-7-300x163.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-7-768x418.png 768w\" sizes=\"auto, (max-width: 862px) 100vw, 862px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Configuramos Linux (debian)<\/h2>\n\n\n\n<p>Vamos a instalar todo lo que necesitamos<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update<br \/>sudo apt install -y sudo realmd sssd sssd-tools libnss-sss libpam-sss adcli oddjob oddjob-mkhomedir samba-common-bin krb5-user packagekit<\/code><\/pre>\n\n\n\n<p>Cuando te pregunte, complet\u00e1 con:<br \/>Dominio Kerberos: MIDOMINIO.COM.AR<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-8.png\"><img loading=\"lazy\" decoding=\"async\" width=\"715\" height=\"450\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-8.png\" alt=\"\" class=\"wp-image-1709\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-8.png 715w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-8-300x189.png 300w\" sizes=\"auto, (max-width: 715px) 100vw, 715px\" \/><\/a><\/figure>\n\n\n\n<p>Servidor: lo pod\u00e9s dejar vac\u00edo si DNS apunta al controlador de dominio.(O directamente no te preguntar\u00e1 nada.)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-9.png\"><img loading=\"lazy\" decoding=\"async\" width=\"713\" height=\"456\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-9.png\" alt=\"\" class=\"wp-image-1710\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-9.png 713w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-9-300x192.png 300w\" sizes=\"auto, (max-width: 713px) 100vw, 713px\" \/><\/a><\/figure>\n\n\n\n<p>Si pregunta por el server, ponemos la ip.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-10.png\"><img loading=\"lazy\" decoding=\"async\" width=\"726\" height=\"431\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-10.png\" alt=\"\" class=\"wp-image-1711\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-10.png 726w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-10-300x178.png 300w\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/a><\/figure>\n\n\n\n<p>Igual ac\u00e1. Tambi\u00e9n corregimos los dns sino lo hicimos antes:<br \/><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-11.png\"><img loading=\"lazy\" decoding=\"async\" width=\"670\" height=\"463\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-11.png\" alt=\"\" class=\"wp-image-1712\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-11.png 670w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-11-300x207.png 300w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\" \/><\/a><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Unir al dominio<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo realm join -U administrator@MIDOMINIO.COM.AR MIDOMINIO.COM.AR<\/code><\/pre>\n\n\n\n<p>Us\u00e1 una cuenta de AD con permisos para unir equipos al dominio.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Editar \/etc\/sssd\/sssd.conf<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nano \/etc\/sssd\/sssd.conf<\/code><\/pre>\n\n\n\n<p>Debe quedar as\u00ed.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;sssd]\ndomains = MIDOMINIO.COM.AR\nconfig_file_version = 2\nservices = nss, pam, ssh, sudo\n\n&#91;domain\/MIDOMINIO.COM.AR]\ndefault_shell = \/bin\/bash\nkrb5_store_password_if_offline = True\ncache_credentials = True\nkrb5_realm = MIDOMINIO.COM.AR\nrealmd_tags = manages-system joined-with-adcli\nid_provider = ad\nfallback_homedir = \/home\/%u@%d\nad_domain = MIDOMINIO.COM.AR\nuse_fully_qualified_names = False\ndefault_domain_suffix = MIDOMINIO.COM.AR\nldap_id_mapping = True\naccess_provider = simple\nsimple_allow_groups = linux-user, linux-root\n&#91;pam]\npam_mkhomedir = True<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Asegurate de que los nombres de grupo est\u00e9n bien escritos y existan en AD.<br \/>Dale permisos correctos:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo chmod 600 \/etc\/sssd\/sssd.conf<\/code><\/pre>\n\n\n\n<p>Reiniciar SSSD<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl restart sssd<\/code><\/pre>\n\n\n\n<p>Verificar usuarios y grupos<br \/>Comprob\u00e1 que los grupos est\u00e9n disponibles:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>getent group linux-user<br \/>getent group linux-root<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-12.png\"><img loading=\"lazy\" decoding=\"async\" width=\"423\" height=\"113\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-12.png\" alt=\"\" class=\"wp-image-1713\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-12.png 423w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-12-300x80.png 300w\" sizes=\"auto, (max-width: 423px) 100vw, 423px\" \/><\/a><\/figure>\n\n\n\n<p>Y que tu usuario est\u00e9 en alguno de esos grupos:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>id user1<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-13.png\"><img loading=\"lazy\" decoding=\"async\" width=\"916\" height=\"108\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-13.png\" alt=\"\" class=\"wp-image-1714\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-13.png 916w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-13-300x35.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-13-768x91.png 768w\" sizes=\"auto, (max-width: 916px) 100vw, 916px\" \/><\/a><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Habilitar creaci\u00f3n de home autom\u00e1ticamente<br \/>Esto ya est\u00e1 activado con pam_mkhomedir = True, pero confirmalo en:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo grep pam_mkhomedir.so \/etc\/pam.d\/common-session<\/code><\/pre>\n\n\n\n<p>Debe contener:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>session required pam_mkhomedir.so skel=\/etc\/skel\/ umask=0077<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-14.png\"><img loading=\"lazy\" decoding=\"async\" width=\"562\" height=\"518\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-14.png\" alt=\"\" class=\"wp-image-1715\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-14.png 562w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-14-300x277.png 300w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/a><\/figure>\n\n\n\n<p>Si no, agregalo manualmente.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SSH: permitir acceso<\/h2>\n\n\n\n<p>Asegurate de que el demonio SSH permite login de cualquier usuario v\u00e1lido:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n\n\n\n<p>Estas opciones deben estar as\u00ed:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>UsePAM yes<br \/>PermitRootLogin no<br \/>PasswordAuthentication yes<\/code><\/pre>\n\n\n\n<p>No uses AllowUsers salvo que lo necesites. Reinici\u00e1 SSH:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl restart ssh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Sudo solo para linux-root<\/p>\n\n\n\n<p>Edit\u00e1 sudoers usando visudo:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo visudo<\/code><\/pre>\n\n\n\n<p>Agreg\u00e1 al final:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>%linux-root ALL=(ALL) ALL<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-15.png\"><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"549\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-15.png\" alt=\"\" class=\"wp-image-1716\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-15.png 603w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-15-300x273.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/a><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">El momento de la verdad!!!!<\/h2>\n\n\n\n<p>Inici\u00e1 sesi\u00f3n SSH con un usuario del grupo linux-user o linux-root:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh user1@192.168.0.254<\/code><\/pre>\n\n\n\n<p>Comprob\u00e1 que se crea \/home\/user1.<\/p>\n\n\n\n<p>Si el usuario pertenece a linux-root, prob\u00e1:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo whoami<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-16.png\"><img loading=\"lazy\" decoding=\"async\" width=\"290\" height=\"114\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-16.png\" alt=\"\" class=\"wp-image-1717\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-17.png\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"76\" src=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-17.png\" alt=\"\" class=\"wp-image-1718\" srcset=\"https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-17.png 885w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-17-300x26.png 300w, https:\/\/www.nerdadas.com\/blog\/wp-content\/uploads\/2025\/07\/image-17-768x66.png 768w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\" \/><\/a><\/figure>\n\n\n\n<p>Si est\u00e1 fuera de ambos grupos, el acceso SSH fallar\u00e1 con:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pam_sss(sshd:account): Access denied for user\u2026<\/code><\/pre>\n\n\n\n<p>El acceso es rechazado en la fase account de PAM si no pertenece a los grupos permitidos.<\/p>\n\n\n\n<p>El acceso local frente al equipo puede funcionar aunque SSH lo niegue. Record\u00e1 que PAM valida usuarios siempre contra AD. (Ahora que lo configuramos as\u00ed)<\/p>\n\n\n\n<p>Si agreg\u00e1s un nuevo grupo en AD para habilitar acceso, record\u00e1 reiniciar sssd.<\/p>\n\n\n\n<p>Y si necesitas una mano no dudes en escribir<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Llega la etapa donde la autenticaci\u00f3n basada en roles(RBAC) en la empresa debe llegar a Linux y te guste o no Active Directory es un mal necesario. (Ya hablaremos en alg\u00fan otro momento de OpenLDAP o similares). Ten\u00e9s un mont\u00f3n de servidores Linux y ahora necesitas permisos centralizados. Vamos a crear en Active Directory un [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1724,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1223,161,17,804],"tags":[1373,823,1374,37,1230,242,1372,569,869,1375],"class_list":["post-1693","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-redes","category-seguridad","category-tecnologia","category-ti","tag-active-directory","tag-debian","tag-ldap","tag-linux","tag-mikrotik","tag-network","tag-rbac","tag-redes","tag-seguridad","tag-windows-server"],"_links":{"self":[{"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/posts\/1693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/comments?post=1693"}],"version-history":[{"count":8,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/posts\/1693\/revisions"}],"predecessor-version":[{"id":1723,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/posts\/1693\/revisions\/1723"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/media\/1724"}],"wp:attachment":[{"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/media?parent=1693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/categories?post=1693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nerdadas.com\/blog\/wp-json\/wp\/v2\/tags?post=1693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}