查看: 1957|回复: 6
|
samba 加入域的问题
[复制链接]
|
|
以下是我的配置文件:
- root@xxxSERVER02:/home# nano /etc/krb5.conf
- [logging]
- default = FILE:/var/log/krb5libs.log
- kdc = FILE:/var/log/krb5kdc.log
- admin_server = FILE:/var/log/kadmind.log
- [libdefaults]
- ticket_lifetime = 24000
- default_realm = xxx.LOCAL
- [realms]
- xxx.LOCAL = {
- kdc = 10.0.0.3:88
- admin_server = 10.0.0.3:464
- default_domain = xxx.LOCAL
- }
- [domain_realm]
- .xxx.local = xxx.LOCAL
- xxx.local = xxx.LOCAL
- root@xxxSERVER02:/home# kinit Administrator
- Password for Administrator@xxx.LOCAL:
- root@xxxSERVER02:/home# klist
- Ticket cache: FILE:/tmp/krb5cc_0
- Default principal: Administrator@xxx.LOCAL
- Valid starting Expires Service principal
- 05/03/10 19:56:47 05/04/10 02:36:47 krbtgt/xxx.LOCAL@xxx.LOCAL
- nano /etc/samba/smb.conf
- [global]
- workgroup = xxx
- realm = xxx.LOCAL
- security = ADS
- password server = 10.0.0.3
- restrict anonymous = 2
- client NTLMv2 auth = Yes
- idmap uid = 10000-20000
- idmap gid = 10000-20000
- template shell = /bin/bash
- winbind separator = /
- winbind enum users = Yes
- winbind enum groups = Yes
- winbind use default domain = Yes
- /etc/init.d/winbind stop
- /etc/init.d/samba restart
- /etc/init.d/winbind start
- root@xxxSERVER02:/home# kinit Administrator
- Password for Administrator@xxx.LOCAL:
- root@xxxSERVER02:/home# net ads join -U Administrator
- Enter Administrator's password:
- Using short domain name -- xxx
- Joined 'xxxSERVER02' to realm 'xxx.local'
- No DNS domain configured for xxxserver02. Unable to perform DNS Update.
- DNS update failed!
- root@xxxSERVER02:/home# wbinfo -u
- xxxSERVER02/sysadmin
- xxxSERVER02/new
- administrator
- guest
- .....
- root@xxxSERVER02:/home# wbinfo -g
- domain computers
- domain controllers
- schema admins
- ...
- root@xxxSERVER02:/home# getent passwd
- root:x:0:0:root:/root:/bin/bash
- daemon:x:1:1:daemon:/usr/sbin:/bin/sh
- bin:x:2:2:bin:/bin:/bin/sh
- sys:x:3:3:sys:/dev:/bin/sh
- sync:x:4:65534:sync:/bin:/bin/sync
- games:x:5:60:games:/usr/games:/bin/sh
- man:x:6:12:man:/var/cache/man:/bin/sh
- lp:x:7:7:lp:/var/spool/lpd:/bin/sh
- mail:x:8:8:mail:/var/mail:/bin/sh
- news:x:9:9:news:/var/spool/news:/bin/sh
- uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
- proxy:x:13:13:proxy:/bin:/bin/sh
- www-data:x:33:33:www-data:/var/www:/bin/sh
- backup:x:34:34:backup:/var/backups:/bin/sh
- list:x:38:38:Mailing List Manager:/var/list:/bin/sh
- irc:x:39:39:ircd:/var/run/ircd:/bin/sh
- gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
- nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
- libuuid:x:100:101::/var/lib/libuuid:/bin/sh
- syslog:x:101:103::/home/syslog:/bin/false
- mysql:x:102:105:MySQL Server,,,:/var/lib/mysql:/bin/false
- landscape:x:103:106::/var/lib/landscape:/bin/false
- postfix:x:104:110::/var/spool/postfix:/bin/false
- dovecot:x:105:112:Dovecot mail server,,,:/usr/lib/dovecot:/bin/false
- sysadmin:x:1000:1000:sysadmin,,,:/home/sysadmin:/bin/bash
- sshd:x:106:65534::/var/run/sshd:/usr/sbin/nologin
- messagebus:x:107:118::/var/run/dbus:/bin/false
- hplip:x:108:7:HPLIP system user,,,:/var/run/hplip:/bin/false
- avahi-autoipd:x:109:119:Avahi autoip daemon,,,:/var/lib/avahi-
- autoipd:/bin/false
- avahi:x:110:120:Avahi mDNS daemon,,,:/var/run/avahi-daemon:/bin/false
- couchdb:x:111:121:CouchDB Administrator,,,:/var/lib/couchdb:/bin/bash
- haldaemon:x:112:122:Hardware abstraction layer,,,:/var/run/hald:/bin/false
- speech-dispatcher:x:113:29:Speech Dispatcher,,,:/var/run/speech-
- dispatcher:/bin/sh
- kernoops:x:114:65534:Kernel Oops Tracking Daemon,,,:/:/bin/false
- saned:x:115:123::/home/saned:/bin/false
- pulse:x:116:124:PulseAudio daemon,,,:/var/run/pulse:/bin/false
- gdm:x:117:126:Gnome Display Manager:/var/lib/gdm:/bin/false
- ftp:x:118:127:ftp daemon,,,:/srv/ftp:/bin/false
- new:x:1001:1001::/home/new:/bin/sh
- administrator:*:10000:10009:Administrator:/home/xxx/administrator:/bin/bash
- guest:*:10002:10016:Guest:/home/xxx/guest:/bin/bash
- ...
- ---------
- \\10.0.0.6
- No Process is on the other end of the pipe
复制代码
---------
当我访问该服务器是出现以下错误
\\10.0.0.6
No Process is on the other end of the pipe
请问谁有实战经验。。。
先谢谢了 |
|
|
|
|
|
|
|
发表于 12-5-2010 01:03 PM
|
显示全部楼层
|
|
|
|
|
|
|
发表于 12-5-2010 05:57 PM
|
显示全部楼层
|
|
|
|
|
|
|
发表于 13-5-2010 09:11 AM
|
显示全部楼层
回复 3# chfl4gs_
你用samba version 几?
Join Domain 只须winbind. |
|
|
|
|
|
|
|
发表于 13-5-2010 03:20 PM
|
显示全部楼层
回复 chfl4gs_
你用samba version 几?
Join Domain 只须winbind.
Alrick 发表于 13-5-2010 09:11 AM
议题LZ要的是Active Directory Service (ADS),你可以只用winbind来join? |
|
|
|
|
|
|
|
发表于 13-5-2010 03:27 PM
|
显示全部楼层
回复 1# 黑马骑士
加入区域后再启动samba,winbind。
还有要注意的是,如果是加入w2k3 server的区域,smb.conf的[global]最好加上
client use spnego = no
server signing = auto |
|
|
|
|
|
|
|
楼主 |
发表于 13-5-2010 09:15 PM
|
显示全部楼层
是join to windows server 2008 r2
我的步骤是配置了kerberos,然后用kinit登入成功后才启动samba,winbind过后才用net ads join 来zoin to domain。虽然成功join(看到用户和用户组列表了)但是却无法访问samba。这个时候我回去改security = ADS 成server就可以使用ad登陆了,但是当认证过期后却无法重新认证。
如果依照chfl4gs_大哥的加入domain后再启动samba,winbind,可是net ads join不是依照/etc/samba/smb.conf的配置的吗?。
不过明天回去公司在试试,回来再跟各位报告rfrf |
|
|
|
|
|
|
| |
本周最热论坛帖子
|