For populating the posix attributes you can use the NIS migration tool that comes with IDMU. You do not have to activate NIS afterwards. Or write yourself some fancy shell/perl script (like I did) if you want more control of what is happening.


On 02/13/2013 12:28 PM, Longina Przybyszewska wrote:

As a continuation of sssd evaluatin we  plan migration  from NIS  to Active Directory+Kerberos.

Now again the question - what is the best approach and practice to migrate users ?

AD administrators enabled SFU, and we got extended schema with POSIX attributes.
I guess there might be some free or commercial tools for extracting data from NIS and loading into AD -ldap objects.

Our Linux users are dispersed in separated NIS domains, and all have  AD account beside the entry in NIS.
 Home directories are  NFS-mounted   with autofs  from Linux storage server but some users access  MSWin storage with smbclient.

Can you share experiences on assigning POSTFIX attributes in SSSD context,  best practice etc..? 
We would not like activate NIS services on AD server for migration.


