佳礼资讯网

 找回密码
 注册

ADVERTISEMENT

查看: 1957|回复: 6

samba 加入域的问题

[复制链接]
发表于 3-5-2010 08:11 PM | 显示全部楼层 |阅读模式
以下是我的配置文件:
  1. root@xxxSERVER02:/home# nano /etc/krb5.conf

  2. [logging]
  3.         default = FILE:/var/log/krb5libs.log
  4.         kdc = FILE:/var/log/krb5kdc.log
  5.         admin_server = FILE:/var/log/kadmind.log

  6. [libdefaults]
  7.         ticket_lifetime = 24000
  8.         default_realm = xxx.LOCAL
  9. [realms]
  10.         xxx.LOCAL = {
  11.                 kdc = 10.0.0.3:88
  12.                 admin_server = 10.0.0.3:464
  13.                 default_domain = xxx.LOCAL
  14.         }

  15. [domain_realm]
  16.         .xxx.local = xxx.LOCAL
  17.         xxx.local = xxx.LOCAL

  18. root@xxxSERVER02:/home# kinit Administrator
  19. Password for Administrator@xxx.LOCAL:
  20. root@xxxSERVER02:/home# klist
  21. Ticket cache: FILE:/tmp/krb5cc_0
  22. Default principal: Administrator@xxx.LOCAL

  23. Valid starting     Expires            Service principal
  24. 05/03/10 19:56:47  05/04/10 02:36:47  krbtgt/xxx.LOCAL@xxx.LOCAL
  25. nano /etc/samba/smb.conf

  26. [global]
  27.         workgroup = xxx
  28.         realm = xxx.LOCAL
  29.         security = ADS
  30.         password server = 10.0.0.3
  31.         restrict anonymous = 2
  32.         client NTLMv2 auth = Yes
  33.         idmap uid = 10000-20000
  34.         idmap gid = 10000-20000
  35.         template shell = /bin/bash
  36.         winbind separator = /
  37.         winbind enum users = Yes
  38.         winbind enum groups = Yes
  39.         winbind use default domain = Yes
  40. /etc/init.d/winbind stop
  41. /etc/init.d/samba restart
  42. /etc/init.d/winbind start
  43. root@xxxSERVER02:/home# kinit Administrator
  44. Password for Administrator@xxx.LOCAL:
  45. root@xxxSERVER02:/home# net ads join -U Administrator
  46. Enter Administrator's password:
  47. Using short domain name -- xxx
  48. Joined 'xxxSERVER02' to realm 'xxx.local'
  49. No DNS domain configured for xxxserver02. Unable to perform DNS Update.
  50. DNS update failed!
  51. root@xxxSERVER02:/home# wbinfo -u
  52. xxxSERVER02/sysadmin
  53. xxxSERVER02/new
  54. administrator
  55. guest
  56. .....
  57. root@xxxSERVER02:/home# wbinfo -g
  58. domain computers
  59. domain controllers
  60. schema admins
  61. ...
  62. root@xxxSERVER02:/home# getent passwd
  63. root:x:0:0:root:/root:/bin/bash
  64. daemon:x:1:1:daemon:/usr/sbin:/bin/sh
  65. bin:x:2:2:bin:/bin:/bin/sh
  66. sys:x:3:3:sys:/dev:/bin/sh
  67. sync:x:4:65534:sync:/bin:/bin/sync
  68. games:x:5:60:games:/usr/games:/bin/sh
  69. man:x:6:12:man:/var/cache/man:/bin/sh
  70. lp:x:7:7:lp:/var/spool/lpd:/bin/sh
  71. mail:x:8:8:mail:/var/mail:/bin/sh
  72. news:x:9:9:news:/var/spool/news:/bin/sh
  73. uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
  74. proxy:x:13:13:proxy:/bin:/bin/sh
  75. www-data:x:33:33:www-data:/var/www:/bin/sh
  76. backup:x:34:34:backup:/var/backups:/bin/sh
  77. list:x:38:38:Mailing List Manager:/var/list:/bin/sh
  78. irc:x:39:39:ircd:/var/run/ircd:/bin/sh
  79. gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
  80. nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
  81. libuuid:x:100:101::/var/lib/libuuid:/bin/sh
  82. syslog:x:101:103::/home/syslog:/bin/false
  83. mysql:x:102:105:MySQL Server,,,:/var/lib/mysql:/bin/false
  84. landscape:x:103:106::/var/lib/landscape:/bin/false
  85. postfix:x:104:110::/var/spool/postfix:/bin/false
  86. dovecot:x:105:112:Dovecot mail server,,,:/usr/lib/dovecot:/bin/false
  87. sysadmin:x:1000:1000:sysadmin,,,:/home/sysadmin:/bin/bash
  88. sshd:x:106:65534::/var/run/sshd:/usr/sbin/nologin
  89. messagebus:x:107:118::/var/run/dbus:/bin/false
  90. hplip:x:108:7:HPLIP system user,,,:/var/run/hplip:/bin/false
  91. avahi-autoipd:x:109:119:Avahi autoip daemon,,,:/var/lib/avahi-

  92. autoipd:/bin/false
  93. avahi:x:110:120:Avahi mDNS daemon,,,:/var/run/avahi-daemon:/bin/false
  94. couchdb:x:111:121:CouchDB Administrator,,,:/var/lib/couchdb:/bin/bash
  95. haldaemon:x:112:122:Hardware abstraction layer,,,:/var/run/hald:/bin/false
  96. speech-dispatcher:x:113:29:Speech Dispatcher,,,:/var/run/speech-

  97. dispatcher:/bin/sh
  98. kernoops:x:114:65534:Kernel Oops Tracking Daemon,,,:/:/bin/false
  99. saned:x:115:123::/home/saned:/bin/false
  100. pulse:x:116:124:PulseAudio daemon,,,:/var/run/pulse:/bin/false
  101. gdm:x:117:126:Gnome Display Manager:/var/lib/gdm:/bin/false
  102. ftp:x:118:127:ftp daemon,,,:/srv/ftp:/bin/false
  103. new:x:1001:1001::/home/new:/bin/sh
  104. administrator:*:10000:10009:Administrator:/home/xxx/administrator:/bin/bash
  105. guest:*:10002:10016:Guest:/home/xxx/guest:/bin/bash
  106. ...


  107. ---------
  108. \\10.0.0.6
  109. No Process is on the other end of the pipe


复制代码

---------
当我访问该服务器是出现以下错误
\\10.0.0.6
No Process is on the other end of the pipe

请问谁有实战经验。。。

先谢谢了
回复

使用道具 举报


ADVERTISEMENT

发表于 12-5-2010 01:03 PM | 显示全部楼层
Y u using kerberos
回复

使用道具 举报

发表于 12-5-2010 05:57 PM | 显示全部楼层
回复 2# Alrick

不用kerberos可以join domain?
回复

使用道具 举报

发表于 13-5-2010 09:11 AM | 显示全部楼层
回复 3# chfl4gs_


    你用samba version 几?
    Join Domain 只须winbind.
回复

使用道具 举报

发表于 13-5-2010 03:20 PM | 显示全部楼层
回复  chfl4gs_


    你用samba version 几?
    Join Domain 只须winbind.
Alrick 发表于 13-5-2010 09:11 AM


议题LZ要的是Active Directory Service (ADS),你可以只用winbind来join?
回复

使用道具 举报

发表于 13-5-2010 03:27 PM | 显示全部楼层
回复 1# 黑马骑士

加入区域后再启动samba,winbind。

还有要注意的是,如果是加入w2k3 server的区域,smb.conf的[global]最好加上

client use spnego = no
server signing = auto
回复

使用道具 举报

Follow Us
 楼主| 发表于 13-5-2010 09:15 PM | 显示全部楼层
是join to windows server 2008 r2
我的步骤是配置了kerberos,然后用kinit登入成功后才启动samba,winbind过后才用net ads join 来zoin to domain。虽然成功join(看到用户和用户组列表了)但是却无法访问samba。这个时候我回去改security = ADS 成server就可以使用ad登陆了,但是当认证过期后却无法重新认证。

如果依照chfl4gs_大哥的加入domain后再启动samba,winbind,可是net ads join不是依照/etc/samba/smb.conf的配置的吗?。

不过明天回去公司在试试,回来再跟各位报告rfrf
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

 

ADVERTISEMENT



ADVERTISEMENT



ADVERTISEMENT

ADVERTISEMENT


版权所有 © 1996-2023 Cari Internet Sdn Bhd (483575-W)|IPSERVERONE 提供云主机|广告刊登|关于我们|私隐权|免控|投诉|联络|脸书|佳礼资讯网

GMT+8, 17-6-2024 05:05 PM , Processed in 0.056403 second(s), 24 queries , Gzip On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表