I’m having trouble with connecting my OpenSUSE leap 5 desktop to my UCS domain.
i will really appreciate your help if you guys can guide me on how to do that.

be sure to have the UCS DC as parimary DNS server configured on your opensuse machine

Open Yast
under network services select windows Domain membership
under domain/workgroup enter the domain name full qualified and select join
give domain administrator and password
thats it

after that you may login with user e.g. domain\username

Im looking for a way to connect Opensuse to UCS with LDAP (like they do with Univention domain join assistant to join ubuntu machine)

its very difficult to do that with Linux distributions unless you have Ubuntu.
I couldn’t find any documentation or guides to do that (in the UCS docs they dont really explain)

OpenSuse, I am not really familiar with, however, connecting Ubuntu and Zorin (also Ubuntu based) works like a charm, following instructions from here
Important: you need to add the primary domain server to /etc/hosts

but in want to find a way to connect Opensuse to UCS with LDAP and not with Active Directory.

someone here knows how to?

This shoud also be possible throu yast - network settings - ldap & kerberos auth

but did not try this as my ucs servers acts as windows AD (samba4) servers


How and what you want to connect? Where exactly is the problem?

Im Trying to connect to ucs with ldap and not with active directory.

the main problems with connecting with ad:
1.users does not connect with the shell and the home directory i chose on ucs user options (account -> Posix(linux/unix)

2.after connecting to the domain with ad opensuse sees the group id’s as active directory domain id’s which is problem for me because we have lots of data in share folders with unix group id’s.

I’ve tried to connect with ldap many times but with no success…
i’d really appreciate it if you guys help me figure out how to do that…


Yes, only Ubuntu has a fully automated join script. So every other distro is more difficult.

As it wasn’t linked here:
This would be the documentation.

Depending on how fit you are with bash-scripts and Opensuse package management, perhaps you can rewrite the scripts from or at least use parts for the Openldap configuration.
But true: a misreading of §2.4 and §2.5 has the potential of messing up your system - including: being locked out for good - if you don’t fully understand nss and pam (or at least handle every change with care and backup strategy).

That beeing said: after adjusting the system as described in the not so difficult parts §§2.1-2.3 - I would start with the LDAP configuration and there the crutial part will be:

  • Registering your Opensuse-Computer as a Linux Computer on the UCS master-server
  • Copy the CAcert from master-server to opensuse and
  • Modify your Openldap config and test it with different accounts.

All that being said - isn’t it perhaps more promising to follow the Opensuse-way and use AD ?

I’m not sure what you mean by that. How should they login and what home directory do you wish to use? Is the setting you made in UCS not working? If so - this would be a well defined problem for a single thread here in the forum.
EDIT: How is your computer registered in UCS, when you just join from OpenSuse? As windows- or linux-computer? Are some of the following problems due to a ‘misregistration’ of opensuse as windows-computer? Have you tried to register opensuse from UMC first as linux-computer?

Ok - so there is a NAS that is not joined to the domain? How is the current user mapping between NAS and UCS - manual, LDAP? Why not join it to UCS AD?
But also here - perhaps a question for a single help thread?

