Linux?
| ドメイン名 | domain.tar3.net |
| ADサーバのIPアドレス1 | 192.168.7.5 |
| ADサーバのIPアドレス2 | 192.168.7.5 |
| ADサーバのホスト名1 | addc1.domain.tar3.net |
| ADサーバのホスト名2 | addc2.domain.tar3.net |
| 共有ディレクトリローカルPATH | /mnt/share |
| 共有フォルダ名 | share |
| Client Host名 | client1.domain.tar3.net |
192.168.7.5;192.168.7.6
sudo apt-get install winbind libpam-winbind samba krb5-user
デフォルトのケルベロスバージョン 5 レルム
DOMAIN.TAR3.NET
[global]
workgroup = DOMAIN
max protocol =SMB2
realm = DOMAIN.TAR3.NET
security = ads
allow trusted domains = No
idmap uid = 10000-99999
idmap gid = 10000-99999
idmap backend = rid
winbind use default domain = yes
winbind enum users = yes
winbind enum groups = yes
winbind nested groups = yes
winbind expand groups = yes
winbind refresh tickets = yes
winbind offline logon = yes
server string = %h server (Samba, Ubuntu)
dns proxy = no
log file = /var/log/samba/log.%m
max log size = 1000
syslog = 0
panic action = /usr/share/samba/panic-action %d
server role = standalone server
passdb backend = tdbsam
obey pam restrictions = yes
unix password sync = yes
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\s*\spassword:* %n\n *Retype\snew\s*\spassword:* %n\n *password\supdated\ssuccessfully* .
pam password change = yes
map to guest = bad user
usershare allow guests = yes
[Share]
comment=
path=/mnt/share
writable=Yes
dramsuko@client1:$ sudo net ads join -U Administrator Enter Administrator's password: Using short domain name -- DOMAIN Joined 'CLIENT1' to dns domain 'domain.tar3.net' DNS Update for client1.tar3.net failed: ERROR_DNS_GSS_ERROR DNS update failed: NT_STATUS_UNSUCCESSFUL
[libdefaults]
default_realm = DOMAIN.TAR3.NET
krb4_config = /etc/krb.conf
krb4_realms = /etc/krb.realms
kdc_timesync = 1
ccache_type = 4
forwardable = true
proxiable = true
#dns_lookup_realm = false
dns_lookup_realm = true
#dns_lookup_kdc = false
dns_lookup_kdc = true
#ticket_lifetime = 24h
ticket_lifetime = 1h
renew_lifetime = 7d
#forwardable = true
v4_instance_resolve = false
v4_name_convert = {
host = {
rcmd = host
ftp = ftp
}
plain = {
something = something-else
}
}
fcc-mit-ticketflags = true
[realms]
DOMAIN.TAR3.NET = {
kdc = ADDC1.DOMAIN.TAR3.NET
admin_server = ADDC1.DOMAIN.TAR3.NET
}
[domain_realm]
.domain.tar3.net = DOMAIN.TAR3.NET
domain.tar3.net = DOMAIN.TAR3.NET
[login]
krb4_convert = true
krb4_get_tickets = falsesudo service smbd restart sudo service nmbd restart sudo service winbind restart
#passwd: compat passwd: compat winbind #group: compat group: compat winbind #shadow: compat shadow: compat winbind #hosts: files dns hosts: files dns wins networks: files protocols: db files services: db files ethers: db files rpc: db files netgroup: nis
session required /lib/x86_64-linux-gnu/security/pam_mkhomedir.so skel=/etc/skel umask=0077
sudo apt-get install sysv-rc-conf