Kugadzira Active Directory dura neDebian uye Samba. Chikamu chekutanga

Mhoroi vanhu vese. Mune dzino dzakateedzana makosi ini ndiri kuenda kukudzidzisa iwe maitiro ekumisikidza server Active Directory yemambure nemakomputa Windows pasi Debian (Kana tichizogadzira sevha, tichazviita nemazvo, huni). Muchikamu chekutanga ichi ini ndichatsanangura kuisirwa uye kumisikidzwa kweseva uye mune yechipiri ini ndichadzidzisa mashandisiro e kure manejimendi ekushandisa de Windows 7 uye maitiro ekubatanidza makomputa kudomain (Windows 7 pachayo uye a Windows XP). Gare gare ini ndichagadzira chikamu chechitatu kunze kwekubatana nezvikwata neGNU / Linux sezvo chiri chinhu chandisati ndaedza.

Pfungwa iyi yakauya kwandiri pandiri (kana yaive, zvinoenderana kana iwe ukaverenga ichi posvo) kutora kosi padanho reMicrocomputer yekugadzirisa michina matekinari matinogadzira netiweki server ne Windows 2008 (kwete RC2) uye ini ndakatanga kutarisa kana ndichigona kuita zvakafanana pasi pe GNU / Linux uye mhedzisiro yacho yakanaka chaizvo, kunyangwe mudzidzisi wangu akashamisika nekumhanya kweseva.

Usati waenderera mberi, uye zvirokwazvo vazhinji venyu vanozvibvunza kuti, Chii chinonzi Active Directory? Zvakanaka, iri izwi rinoshandiswa neMicrosoft kutaura kune seti yayo yezvishandiso zveinetiweki manejimendi senge sevha DNS, iko kutungamira kwevanoshandisa network, nezvimwe.

Tichada zvinotevera:

  • Debian mubazi rayo rakagadzikana (mune yangu Wheezy 7.5 neXFCE senzvimbo yedesktop)
  • Samba 4
  • Mutengi ane Windows 7 / 8 / 8.1 nepakeji yekuisa iri kure server yekudzora mabasa (inodiwa kubata sevha, senge shandisa faira pamwe nevashandisi). Izvi zvichatsanangurwa mune inotevera dzidziso.

Kugadzira iyo server

Tisati taenderera mberi, isu tinofanirwa kugadzirisa mamwe mafaera kuti zvese zvishande, kunyanya kuitira kuti makomputa ari pamambure awane dura renzvimbo.

Chinhu chekutanga kupa server yedu kero yakagadziriswa IP. Muchiitiko chekuyedzwa kwangu kweDebian mu Virtualbox kumeso networking, zvinova izvo zvinobva pachigadziko, asi mune chaiyo server ndinoigadzirisa kubva Network maneja, saka ini ndichatsanangura maitiro anoitwa mune ese ari maviri.

Networking

Faira rekutanga ratichagadzirisa ndere / etc / network / interfaces.
# This file describes the network interfaces available on your system

and how to activate them. For more information, see interfaces(5).

The loopback network interface

auto lo
iface lo inet loopback

The primary network interface

auto eth0
iface eth0 inet static
address 192.168.0.67
netmask 255.255.255.0
gateway 172.26.0.1
dns-nameservers 192.168.0.67
dns-search clase.org
dns-domain clase.org

Kuva:

  • adresi: iyo IP yechikwata chedu.
  • netmask: iyo network mask. Mune diki kana imba network izvi kazhinji izvi.
  • gedhi: gedhi. Kazhinji ndiyo IP yeiyo router iyo inotipa iyo yekubuda kune iyo Internet.
  • dns-nameservers: Server ip DNS. Mune ino kesi iyo server, asi iwe unogona kuwedzera yechipiri, semuenzaniso veruzhinji ve Google.
  • Yekupedzisira 2 inoratidza iyo domain yekutsvaga zita uye iro zita rezita pacharo.

Zvino isu tinofanirwa kuwedzera inotevera mitsara ku / etc / mauto:
127.0.0.1 Matrix.clase.org Matrix
192.168.0.67 Matrix.clase.org Matrix

Nezvo, zita rezita rinogadziriswa kuitira kuti riwanikwe pane network. Matrix ndiro zita randakapa server.

Pakupedzisira isu tinogadzirisa /etc/resolv.conf:

nameserver 192.168.0.13

Mune mamwe ma tutorials andakawana, ivo vakawedzera imwe nameserver tambo uye mamwe akati wandei akasiyana, asi mune yangu nyaya chete tambo yaive yakakwana.
Iye zvino tinotangazve sevhisi sevhisi uye ndizvozvo:

/etc/init.d/networking restart

Network maneja

Dzvanya-kurudyi kunetiweki icon uye sarudza Edza kubatana. Tichawana maratidziro atakagadzira, asi isu tinongofarira chete kufona Wired network 1 kana chero chawakatumidza zita racho. Tinobaya kaviri pairi uye hwindo idzva richaonekwa uye tichaenda IPv4 marongero. En nzira tinosarudza manyuwari. Zvino tinya Wedzera uye zadza minda yese:
ACDC Debian - Network Manager


Iye zvino tinoenda kune iyo tebhu General uye tinova nechokwadi chekuti yakanyorwa Vese vashandisi vanofanirwa kubatana kunetiweki iyi. Dzvanya pa Chengetedza ndokubva taenda.

Kuisa Samba 4

Muchiitiko chedu tichaenda kurodha pasi nekunyora Samba 4 kubva papeji rayo nekuti muDebian inongowanikwa chete kuburikidza neyekuchengetedza Backports uye zvakandipa matambudziko ekutsamira.

Tiri kuenda http://samba.org kurodha yazvino vhezheni vhezheni uye unzip pasuru yacho mufaira.

Iyo yazvino vhezheni yakagadziriswa panguva yekunyora chinyorwa ichi 4.1.8 saka chichava icho chatinoshanda nacho.

Kuti tizviunganidze isu tinofanirwa kuisa anotevera mapakeji:

apt-get install build-essential libacl1-dev libattr1-dev \
libblkid-dev libgnutls-dev libreadline-dev python-dev libpam0g-dev \
python-dnspython gdb pkg-config libpopt-dev libldap2-dev \
dnsutils libbsd-dev attr krb5-user docbook-xsl libcups2-dev acl

Pane imwe nguva yakadhindwa uye isina kuvharwa, tinozarura sarudzo uye tiende kune faira uye tiite mirairo inotevera:
./configure --enable-debug
make
make install

Iko kuseta kwekumisikidza kuri mu  / usr / yemuno / samba. Ipo ichitsigira iyo -prefix = / usr paramende HERE inoiisa mumadhairekita anoenderana (semuenzaniso mabhinari haaise mukati / usr / bin)

Iye zvino tinowedzera nzira itsva mu PATH. Mune mhaka yangu mu /etc/bash.bashrc kushandisa kune vese vashandisi, kusanganisira mudzi.

export PATH=$PATH:/usr/local/samba/bin:/usr/local/samba/sbin

Uye isu zvakare tinogadzira chinongedzo mukati / nezvimwe zveSamba kuti uwane iyo yekumisikidza faira:

ln -s /usr/local/samba/etc/ /etc/samba

Tichagadzirisa Samba server. Kune izvi isu tinoita:

samba-tool domain provision --realm=clase.org --domain=CLASE --adminpass=Contraseña --use-rfc2307

kupi:

  • –Dunhu: izita rezita rakazara.
  • –Domain: ndiyo duraini. Inofanira kunge iri mukati mavara makuru
  • –Adminspass: ndiyo password ye network network.
  • -Shandisa-rfc2307: kushandisa AC.

Kana zvese zvikafamba mushe mushure mekanguva Samba inopedza kuzvimisikidza pachayo. Kana iwe uchida kuziva dzese dzinogona kuita sarudzo, ingo mhanya:

samba-tool domain provision -h

Iye zvino tava kuzogadzirisa iyo faira /etc/samba/smb.conf. Parizvino chinotifadza iwo mutsara unotevera:
dns forwarder = 192.168.0.1

Iyi tambo inofanirwa kunongedza kune server yeDNS inotipa mukana wekupinda muInternet (mune ino kesi, iyo router). Samba inotora kumisikidza kusarongeka kwenetiweki asi zvinokurudzirwa kuti zviongorore.

Iye zvino isu tinotanga sevhisi:

samba

uye isu tinotarisa kubatana nekuita:

smbclient -L localhost -U%

Uye kana zvese zviri zvechokwadi tichaona chimwe chinhu chakafanana neichi:
kutarisa kuti samba iri kumhanya


Kana ikatipa kukanganisa kwekubatanidza, tinoongorora matanho epfungwa yapfuura. Irogi yeSamba iri mu /usr/local/samba/var/log.samba

Iye zvino tave kuzoteedzera iyo faira /usr/local/samba/private/krb5.conf a / nezvimwe. Iye zvino tichaenda kutarisa kuti tinokwanisa kubatana here:

kinit administrator@CLASE.ORG

Ojo, dura racho rinofanirwa kuverengerwa.

Ipapo ichatibvunza isu password yemushandisi (mune ino kesi yemaneja) uye kana isu tikawana meseji yakafanana neiyo «Yambiro: password yako ichapera mumazuva makumi mana musi waMu Jul 40 14:13:57 10» ndeyekuti yakabuda nemazvo.

Uye kusvika ikozvino chikamu chekutanga chedzidziso. Tinoverenga mune zvinotevera.

Ini ndanga ndatotaura nezvazvo kanoverengeka mumashoko, asi ini ndaiisa pano. Nekuti ini parizvino handina zviwanikwa zvinodiwa (ini ndinongova nePC kumba uye izvi zvakaiswa mukati mekosi) uye kuti kuzviita mumishini chaiyo kunonetsa, hazvigone kuti ndienderere mberi. Kana mumwe munhu ane ruzivo uye nechikwata achida kuenderera izvi, vakasununguka kuzviita)

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako

  1.   lol akadaro

    Inonakidza kwazvo, ini ndaigara ndichida kuziva kuti izvi zvakaitwa sei.

    Zvinoita here kuti uzviite uchishandisa SSH panzvimbo yeSamba?

    Ini ndinonzwisisa kuti inokurumidza uye yakachengeteka.

    1.    Claudio Concepcion placeholder mufananidzo akadaro

      Wadiwa Lolo, izvo hazvigoneke, sezvo SSH ichibvumidza chikamu (uye zvimwe zvinhu, sekutamisa mafaera nekushandisa) kuburikidza neiyo terminal pakati pemakomputa neGNU Linux. Ipo Samba ichiita imwe nzira yeGNU Linux yeMicrosoft's Active Directory system.

      Son Link izvo zvaakagadzira is a domain controller in GNU Linux.

  2.   Antonio akadaro

    Yakanaka kwazvo tuto. Izvo zvakanaka kune vanhu vakaita seni vane mhando yegirini pairi. Ndotenda zvikuru

  3.   Claudio Concepcion placeholder mufananidzo akadaro

    Ndatenda! Yakanaka gwara. Bvumira…

  4.   adiazc87 akadaro

    Ndatenda shamwari, wakanaka kwazvo mutungamiri wako.Ndinovimba chikamu chechipiri, nenzira yawamuita kuti ashande ne ldap?

    Thanks.

  5.   Sebastian akadaro

    Inonakidza kwazvo, ini ndiri kumirira kuenderera. Ndinokutendai

    PS: Ini ndinofunga pane diki rekodhi kukanganisa mune / etc / network / interfaces kumisikidzwa, inoti dns-domian pazvinoratidzika kwandiri kuti dns-domain inofanirwa kuenda.

  6.   Wilson ruiz akadaro

    Ndakaona ichi chinyorwa chichifadza zvikuru. Sezvo ini ndiri muchikamu chekudzidza uye handina ruzivo rwakawanda mune iyi nyaya uye ndinoda kudzidza zvakawanda nezve manejimendi uye manejimendi eanoshanda masystem.

  7.   eliotime3000 akadaro

    Izvo zvinobatsira pakugadzira akagovaniswa maforodha muDebian kana kuri kungoenda kune imwe dzidziso icho chinhu?

  8.   Gonzalo akadaro

    Iko kugoverwa kweLinux kunonzi Resara Server kunoenderana neUbuntu iyo inoshandiswa chete kuvaka domain controller, ndakaiyedza uye zviri nyore kushandisa, ndakakwanisa kujoinisa makomputa kudomain neiyo server, ndinosiya pano mafambiro , pamwe mumwe munhu anoishandisa - http://ostechnix.wordpress.com/2012/12/31/resara-server-an-alternative-opensource-linux-domain-controller-for-windows-active-directory-controller/

    1.    ichit akadaro

      Ah !!! Hukuru, mupiro wezuva .. Maita basa 😉

      1.    Gonzalo akadaro

        Munogamuchirwa! 😀

    2.    The_Mastersok akadaro

      Kutenda nekugovana !!!
      Reply with quote

  9.   Oscar akadaro

    Yakanaka dzidziso, ini ndinenge ndakamirira zororo. Ndinoyeuka pandakaisa PDF muDebian 6 ine samba 3 uye ldap. Yakashanda asi ini ndaifanirwa kushandisa iyo .pol matemplate kugadzirisa mirairo. Mune ino kesi, aya marongero anoitwa sei?

  10.   Mario Guillermo Zavala Silva akadaro

    Rakanakisa ruzivo ... Ndatenda neizvi ...

    MUFARO!!!

  11.   Cesar akadaro

    Zvakanaka…. Ndiri kufarira kwazvo izvi ……. kwechikamu chechipiri riinhi ??? kana kana iwe uine bhuku reizvi titumire kwandiri neemail ... ndapota !!!! ndatenda

  12.   The_Mastersok akadaro

    Kudzidzisa kwakanakisa….
    Ndinovimba rimwe zuva kuti ndiise mukuita ..
    Kwazisai uye kumirira chikamu chechipiri !!!!

  13.   Leandro akadaro

    Ichokwadi ndechekuti ndakazviita izvi kamwe chete, asi handina kupinda mune chero chinhu ... ini ndoda kukurudzira / iwe chishandiso, handizive kana uchizviziva kana kwete, ini handizive zvadzinogumira, asi kubatanidza kune Active Directory dura ndakanga ndisina dambudziko, ndakayedza iyo kukoreji uye yakashanda chaizvo. Chirongwa chinonzi Saizvozvowo, chinoita zvakafanana nezvose zvawakaita neSamba, hapana chimwe kunze kwekusagadzirisa zvakanyanya, icho chimwe chinhu chakapfupikiswa, zvirokwazvo unogona kugadzirisa zvaunoda mukuda kwako 🙂

    Ndinovimba izvi zvinogona kukubatsira! Mufaro

  14.   César akadaro

    Chinyorwa chinonakidza kwazvo, ini ndichatarisira chikamu chechipiri. Kwakave kushamisika kukuru kuziva kuti zvinokwanisika kubata dhairekitori "remazuva ano" rinoshanda neGnu / Linux, ndinorangarira ndichizviita nguva refu yapfuura neye NT 4 mhando dhairekitori rinoshanda uye kwaive kusuwa kukuru kusakwanisa teedzera iyo Microsoft payakachinja "chimiro" cheLDD yako paWindows 2000 Server.

    Kwaziso kubva kuEcuador =]

  15.   Mmm akadaro

    Mhoro. Ndotenda zvikuru!
    Ndine kusahadzika kwakati… chii chaizvo chiri dhairekitori rinoshanda reiyo?
    Uye kune rimwe divi, unogona here kudzidzisa, kana uchikwanisa, maitiro ekuita ongororo zvinoitwa nevashandisi?
    Kwazisai uye kuvonga.

    Ini yeaudio ndakaisa izvi: http://chicheblog.wordpress.com/2011/01/21/como-auditar-la-actividad-de-los-usuarios-en-samba/
    Asi kana iwe uchikwanisa kuiwedzera, kana kuwedzera chimwe chinhu chaunoziva, chinoongwa!
    Kwazisa

  16.   raulbaca akadaro

    Husiku Husiku, Kwaziso kubva kuPeru.
    Ndine mubvunzo wakasiyana zvishoma nezvose zvakaburitswa, ona kutsanangura zvishoma, ona ndine folda iyi yakagadzirirwa mu /etc/samba/smb.conf faira

    [Pachivande]
    comment = Yakavanzika Dhairekitori
    nzira = / imba / Yakavanzika
    verenga chete = hongu
    browseable = hongu
    muenzi ok = kwete
    yeruzhinji = kwete
    nyora rondedzero = @comercial, @gestion
    vanoshanda vanoshandisa = @comercial, @gestion
    gadzira mask = 0777
    dhairekitori mask = 0777

    Iye zvino mubvunzo wangu unoenda, zvese zvinoshanda mushe asi kana ndichibva pakombuta ini ndinopinda nemushandisi «pepe» iri yeboka «comercial» uye kubva kune imwe komputa ini ndinopinda nemushandisi «coco» ari weboka «gestion», zvinotevera zvinoitika pandinogadzira faira kana dhairekitori kubva kumushandisi "pepe" uye ini ndoda kudzima dhairekitori iri kana faira rakagadzirwa kubva kune imwe PC nemushandisi "coco" zvinondiudza kuti handikwanise nekuti handina rombo rakanaka, asi munyori mumwechete anogona kudzima iyi faira kana dhairekitori iwe raunosvika.

    Iyo yakavanzika folda yakagadzirwa kubva nenzira inotevera:
    chmod -R 777 / imba / Yakavanzika
    Ivo vanoshanda pasi peiyo imwechete LAN network.
    Ini ndinoshandisa Distro Ubuntu Server 14.xx
    Izvo zvinofanirwa kucherechedzwa kuti chandiri kuda ndechekuti iyi PRIVATE dhairekitori itungamirirwe nevaviri kana vanopfuura vashandisi ipapo pfungwa yekushanda nemaGroup asi zvinoita sekunge pane chimwe chinhu chandiri kusuwa kana kusiya, ndinovimba tarisiro yako neni ramba uchiteerera kumashoko ako.

    1.    mutsvene akadaro

      Shamwari yaunokwanisa kuwana nekubvisa makoma
      nenzira iyi.

      nyora rondedzero = @comercial @gestion
      vanoshanda vanoshandisa = @comercial @gestion

  17.   Raul Baca Centeno akadaro

    Mhoro vadikani,

    Ndinoda kuziva kana chikamu chechipiri chedzidzo chichakamirira, ndinoteerera kumashoko ako uye ndinokutendai.

  18.   Miguel akadaro

    Manheru akanaka, nhasi chaiye ndakaverenga zvese zvakataurwa uye ndine hafu-yakagadzirirwa muchina, nekuda kweichi chikonzero ini ndinoona kuti hausi kuzoburitsa chikamu chechipiri uye ndinoda kuziva kana uchigona kuita inozadzikiswa mufaira uye akati wandei dbf matafura, kuwana kubva kumakomputa akati wandei.
    Ndokumbira upindure nekukurumidza sezvazvinogona.

  19.   Raul baca akadaro

    Anodiwa,
    Ndinoda kuziva kana chikamu chechipiri cheiyi inonakidza dzidziso ichakamirira, ndinokutendai pamberi pekufunga kwako.
    thanks.

  20.   mafaro akadaro

    Yakanaka dzidziso, tinovimba unokurudzira chikamu chechipiri, ungandiudza here kuti ndeapi ari kure server chengetedzo maturusi ekuti utore nekuvaedza

    Thanks.

  21.   BETO akadaro

    Ndinokukorokotedza iwe, uye chikamu chechipiri?

  22.   Daniel Bernal akadaro

    Chinyorwa chinonakidza, iwe waburitsa inotevera vhezheni?

  23.   vanhu vechibharo akadaro

    Yakanaka kwazvo dzidziso, mubvunzo mumwe chete wechipiri chikamu, zvingave sei kana neiyi dzidziso inopera?

  24.   SARA akadaro

    NDINODA ZANO ROKUDZIDZA ZVITSVA ZVITSVA, NDINOTENDA WADAVHIDHI KUGADZIRA ZIVO RAKO
    MAGAZINI

    POSTSCRIPT: PANZVIMBO YOKUDZIDZA NDICHAEDZA KUZVIITIRA PAMUSORO WANGU WEMAHARA MADHEBHANI ASESERI UYE NEMA GROUPS EVIRITUAL CLIENTS, IMWE NE WIN7 UYE ANOTHER NE WIN8.

  25.   Edgar akadaro

    Iri gwaro harina kukwana, hautsanangure madhairekitori, unosiya zvinhu zvisina kurongeka, dai ndiri iwe ndaizvidzokorora

    1.    ichit akadaro

      Kana iwe unogona kuipedzisa uye kuzvinyora iwe pachako, isu tichafara kuburitsa iyo iwe.

  26.   ada wall akadaro

    maitiro ekugadzirisa sevha mu debian 5 kuti ugone kubatanidza uri kure kune xp

  27.   francisco akadaro

    Mhoro zvakadii pandinoita:
    midzi @ pdc: ~ # apt-tora kuisa kuvaka-kwakakosha libacl1-dev libattr1-dev libblkid-dev \ libgnutls-dev libreadline-dev python-dev libpam0g-dev \ python-dnspyth gdb pkg-config libpopt-dev libldap2-dev \ dnsutils libbsd-dev attr krb5-mushandisi docbook-xsl libcups2 ac1
    anondiudza:
    Kuverenga mapepa mapoka ... Akaitwa
    Kuvaka muti unovimba
    Kuverenga zvemashoko enyika ... Akaitwa
    Pasuru kuvaka-kwakakosha hakuwanikwi, asi kunotaurwa kune imwe pasuru.
    Izvi zvinogona kureva kuti pasuru yacho yashayikwa, yave neyakarembera, kana
    inowanikwa chete kubva kune imwe nzvimbo
    E: Package inovaka-yakakosha haina wekumisikidza mukwikwidzi

    chero rubatsiro? ndatenda

  28.   kusazivikanwa akadaro

     

    1.    kusazivikanwa akadaro

      zvinyorwa hazvina kugadziridzwa

  29.   Carlos akadaro

    Ndinoziva iwe hausi kuzoburitsa chirevo changu. Chinyorwa ichi chakaipa, chinoenda pasina kutaura kuti kerberos inogadziridzwa sei, nekuti iwe unoishandisa mune izvo zvinodiwa. Nei uchiumbiridza Samba? Shanduro 4 yave kuwanikwa. Nekugadziriswa kwamakaisa, iyo Kinit inokupa yakatarwa kukanganisa NT_STATUS_DENIED!. Kune vese avo vanofarira kutanga: https://help.ubuntu.com/lts/serverguide/samba-dc.html