1. Open the Run command and type "secpol.msc".
2. Press "continue" when prompted by Windows 7.
3. Click on "Local Policies" --> "Security Options"
4. Navigate to the policy "Network Security: LAN Manager authentication level" and open it.
5. By default Windows 7 sets the policy to "NTVLM2 responses only". Change this to "LM and NTLM – use NTLMV2 session security if negotiated".
http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
Zobrazují se příspěvky se štítkemSamba. Zobrazit všechny příspěvky
Zobrazují se příspěvky se štítkemSamba. Zobrazit všechny příspěvky
pondělí 8. února 2010
středa 19. srpna 2009
Mapování skupin
groupadd DomainAdmins net groupmap add rid=512 type=domain ntgroup="Domain Admins" unixgroup=DomainAdmins groupadd DomainUsers net groupmap add rid=513 type=domain ntgroup="Domain Users" unixgroup=DomainUsers groupadd DomainGuests net groupmap add rid=514 type=domain ntgroup="Domain Guests" unixgroup=DomainGuests groupadd DomainComputers net groupmap add rid=515 type=domain ntgroup="Domain Computers" unixgroup=DomainComputers
čtvrtek 16. července 2009
Přihlášení Samby do win domény
http://developer.novell.com/wiki/index.php/HOWTO:_Configure_Ubuntu_for_Active_Directory_Authentication
1) /etc/resolv.conf
search domena.local
nameserver IPA.DRE.SAP.DC
2) /etc/smb.conf
[global]
server string =
encrypt passwords = Yes
netbios name = LINUX
security = domain
workgroup = SKUPINA
password server = Název serveru
realm = DNS název domény
winbind use default domain = Yes
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users=yes
winbind enum groups=yes
winbind nested groups = Yes
winbind separator = +
interfaces = eth1
bind interfaces only = yes
log level = 3
log file = /var/log/samba/log.%m
store dos attributes = yes
create mask = 770
force create mode = 770
directory mask = 770
3)
[libdefaults]
clockskew = 600
default_realm = DOMENA.LOCAL
[realms]
DNS NÁZEV DOMÉNY = {
kdc = PDC
default_domain = DOMENA
kpasswd_server = PDC.DOMENA.LOCAL
}
[domain_realm]
.domena.local = DOMENA.LOCAL
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[appdefaults]
pam = {
ticket_lifetime = 1d
renew_lifetime = 1d
forwardable = true
proxiable = false
retain_after_close = false
minimum_uid = 0
debug = false
}
4) /etc/pam.d/samba
//pridat na zacatek
auth required /lib/security/pam_winbind.so
account required /lib/security/pam_winbind.so
5) prihlaseni do domeny
net rpc join -S PDC -U administrator
net rpc join -W DOMENA -U administrator
6) /etc/nsswitch.conf
passwd: files winbind
group: files winbind
hosts: files dns winbind
7) wbinfo
wbinfo --set-auth-user=administrator%'bigsecret'
8) test
nmbd; smbd; winbindd;
wbinfo -u //uzivatele
wbinfo -g //skupiny
9) problemy
-debug mod winbodd
+/etc/init.d/winbindd stop
winbindd -d 3 -i
-pripoji se ale nenacte uzivatele (wbinfo -u) (~win 2000)
+do smb.conf pridat client schannel = no
(http://www.gatago.com/linux/samba/14514734.html,
http://kbase.redhat.com/faq/FAQ_85_5515.shtm)
-zadani skupiny s mezerou v nazvu do valid users
+valid users = "@domain admins"
-windows 7
=upravit nastavení NTLM http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
-------------------------
http://lilly.csoft.net/~vdebaere/handleiding/samba-activedirectory/index_en.html
http://us1.samba.org/samba/docs/man/Samba-Guide/unixclients.html#ch9-adssdm
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/InterdomainTrusts.html#id2587424
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/FastStart.html#id2523211
do smb.conf (http://www.wlug.org.nz/ActiveDirectorySamba)[vubec nevim co sem tim chtel rict]
-------------------------
/etc/resolv.conf
/etc/samba/smb.conf
/etc/pam.d/samba
/etc/nsswitch.conf
/etc/krb5.conf
1) /etc/resolv.conf
search domena.local
nameserver IPA.DRE.SAP.DC
2) /etc/smb.conf
[global]
server string =
encrypt passwords = Yes
netbios name = LINUX
security = domain
workgroup = SKUPINA
password server = Název serveru
realm = DNS název domény
winbind use default domain = Yes
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users=yes
winbind enum groups=yes
winbind nested groups = Yes
winbind separator = +
interfaces = eth1
bind interfaces only = yes
log level = 3
log file = /var/log/samba/log.%m
store dos attributes = yes
create mask = 770
force create mode = 770
directory mask = 770
3)
sudo apt-get install heimdal-clients libpam-heimdal/etc/krb5.conf
[libdefaults]
clockskew = 600
default_realm = DOMENA.LOCAL
[realms]
DNS NÁZEV DOMÉNY = {
kdc = PDC
default_domain = DOMENA
kpasswd_server = PDC.DOMENA.LOCAL
}
[domain_realm]
.domena.local = DOMENA.LOCAL
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[appdefaults]
pam = {
ticket_lifetime = 1d
renew_lifetime = 1d
forwardable = true
proxiable = false
retain_after_close = false
minimum_uid = 0
debug = false
}
4) /etc/pam.d/samba
//pridat na zacatek
auth required /lib/security/pam_winbind.so
account required /lib/security/pam_winbind.so
5) prihlaseni do domeny
net rpc join -S PDC -U administrator
net rpc join -W DOMENA -U administrator
6) /etc/nsswitch.conf
passwd: files winbind
group: files winbind
hosts: files dns winbind
7) wbinfo
wbinfo --set-auth-user=administrator%'bigsecret'
8) test
nmbd; smbd; winbindd;
wbinfo -u //uzivatele
wbinfo -g //skupiny
9) problemy
-debug mod winbodd
+/etc/init.d/winbindd stop
winbindd -d 3 -i
-pripoji se ale nenacte uzivatele (wbinfo -u) (~win 2000)
+do smb.conf pridat client schannel = no
(http://www.gatago.com/linux/samba/14514734.html,
http://kbase.redhat.com/faq/FAQ_85_5515.shtm)
-zadani skupiny s mezerou v nazvu do valid users
+valid users = "@domain admins"
-windows 7
=upravit nastavení NTLM http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
-------------------------
http://lilly.csoft.net/~vdebaere/handleiding/samba-activedirectory/index_en.html
http://us1.samba.org/samba/docs/man/Samba-Guide/unixclients.html#ch9-adssdm
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/InterdomainTrusts.html#id2587424
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/FastStart.html#id2523211
do smb.conf (http://www.wlug.org.nz/ActiveDirectorySamba)[vubec nevim co sem tim chtel rict]
-------------------------
/etc/resolv.conf
/etc/samba/smb.conf
/etc/pam.d/samba
/etc/nsswitch.conf
/etc/krb5.conf
pátek 5. prosince 2008
Migrace samba PDC na nový server
Postup
- Přenos konfigurace /etc/samba
- Přenos souborů
- Přenos uživatelských účtů /etc/passwd a skupin /etc/group
- Nastavení mapování skupin net groupmap
- Nastavení SID původního PDC
Přesun SID domény
na původním serverunet getlocalsid net getdomainsidna novém serveru
rm /var/lib/samba/* net setlocalsid net setdomainsid
Odkazy
http://www.microsoft.com/technet/sysinternals/Utilities/NewSid.mspxhttp://sarwiki.informatik.hu-berlin.de/Windows_Domain_Migration_--_after-thought_edition
http://www.tek-tips.com/viewthread.cfm?qid=1316498&page=5
http://kb.nitix.com/2567
http://directory.fedora.redhat.com/wiki/Howto:Samba
http://www.linuxcommand.org/man_pages/pdbedit8.html
http://www.linuxcommand.org/man_pages/net8.html
http://www.microsoft.com/technet/sysinternals/Utilities/NewSid.mspx
Přihlásit se k odběru:
Příspěvky (Atom)