Active Directory with Open Source, Part 2: Real Member Server ACLs, GPOs Without the Hype, and the Second DC
In Part 1, we set up our Domain Controller correctly: an operational realm that bypasses the .local trap, signed time protocols, and a robust versioned backup routine. However, we explicitly left three core promises for later because they represent the exact threshold where superficial tutorials abandon the reader: the file server operating completely decoupled from the DC, role-based folder privileges that actually work, and high availability via a secondary DC. Here, we deliver on those promises. And, keeping with our house style, we do it without the marketing fluff—every milestone comes with its honest infrastructure caveat. ...