ad - Active Directory as a naming repository
Solaris clients can obtain naming information from Active Directory (AD) servers, allowing the use of Windows-style name@domain names for users and groups with no corresponding UNIX user or group.
The Solaris system must first join an AD domain and then add the ad keyword to the appropriate entries in the nsswitch.conf(5) file. The Solaris system joins the AD domain by using the smbadm(8) utility. The AD name service only supports the naming databases for passwd and group.
The AD server schema requires no modification because the AD client works with native AD schema. The Solaris AD client uses the idmap(8) service to map between Windows security identifiers (SIDs) and Solaris user identifiers (UIDs) and group identifiers (GIDs). User names and group names are taken from the sAMAccountName attribute of the AD user and group objects and then tagged with the domain where the objects reside. The domain name is separated from the user name or group name by the @ character.
Configuration file for the name-service switch.
Sample configuration file for the name-service switch configured with ad, dns and files.
Name service switch module for AD.