Ukusetha i-Active Directory server nge-Debian ne-Samba. Ingxenye yokuqala

Sanibonani nonke. Kulolu chungechunge lwezifundo ngizokufundisa ukuthi ungayisetha kanjani iseva I-Active Directory yamanethiwekhi anamakhompyutha Windows phansi Debian (Uma sizosetha isiphakeli, sizokwenza kahle, izinkuni zokubasa). Kulesi sitolimende sokuqala ngizochaza ukufakwa nokulungiswa kweseva kuthi kwesibili ngifundise ukuthi isetshenziswa kanjani ifayili le- amathuluzi okuphatha akude de Windows 7 nokuthi uwajoyina kanjani amakhompyutha kusizinda (iWindows 7 uqobo ne-a Windows XP). Kamuva ngizokwenza isitolimende sesithathu ngaphandle kokuthi ngingawajoyina kanjani amaqembu ane-GNU / Linux ngoba kuyinto okusamele ngiyivivinye.

Lo mqondo weza kimi ngenkathi ngikhona (noma ngangikhona, kuya ngokuthi ufunda nini lokhu okuthunyelwe) ngithatha isifundo esitelekeni sikachwepheshe wokulungisa imishini ye-Microcomputer lapho sakha khona iseva yenethiwekhi nge Windows 2008 (hhayi i-RC2) futhi ngaqala ukubheka ukuthi ngingaqalisa yini okufanayo ngaphansi I-GNU / Linux futhi umphumela muhle impela, ngisho nothisha wami wamangala ngejubane leseva.

Ngaphambi kokuqhubeka, futhi ngokuqinisekile iningi lenu lizibuza ukuthi, Yini i-Active Directory? Yigama elisetshenziswa yiMicrosoft ukubhekisa kusethi yayo yamathuluzi wokuphathwa kwenethiwekhi njengeseva DNS, ukuphathwa kwabasebenzisi benethiwekhi, njll.

Sizodinga okulandelayo:

  • Debian egatsheni layo elizinzile (kimi Wheezy 7.5 ngeXFCE njengendawo yedeskithophu)
  • I-Samba 4
  • Iklayenti eline- IWindows 7 / 8 / 8.1 ngephakeji ukufaka imisebenzi yokulawula iseva eyihlane (edingekayo ukuphatha iseva, njenge yabelana ngefolda nabasebenzisi). Lokhu kuzochazwa esifundweni esilandelayo.

Ukusetha iseva

Ngaphambi kokuqhubeka, kufanele sihlele amanye amafayela ukuze konke kusebenze, ikakhulukazi ukuze amakhompyutha akule nethiwekhi athole i-server yesizinda.

Into yokuqala ukunikeza iseva yethu ikheli Fixed IP. Endabeni yokuhlolwa kwami ​​kwe-Debian ku I-Virtualbox sebenzisa ukuxhumana, okuvela kusisekelo, kepha kuseva yangempela ngiyilungiselela kusuka Umphathi Wenethiwekhi, ngakho-ke ngizochaza ukuthi kwenziwa kanjani kuzo zombili.

Izingosi

Ifayela lokuqala esizohlela ukuthi / njll / inethiwekhi / ukuxhumana.
# This file describes the network interfaces available on your system

and how to activate them. For more information, see interfaces(5).

The loopback network interface

auto lo
iface lo inet loopback

The primary network interface

auto eth0
iface eth0 inet static
address 192.168.0.67
netmask 255.255.255.0
gateway 172.26.0.1
dns-nameservers 192.168.0.67
dns-search clase.org
dns-domain clase.org

Ukuba:

  • ikheli: i-IP yethimba lethu.
  • inetha: imaski yenethiwekhi. Enethiwekhi encane noma ekhaya imvamisa lokhu.
  • isango: isango. Imvamisa yi-IP yomzila osinika ukuphuma ku-inthanethi.
  • i-dns-nameservers: Iseva ip DNS. Kulokhu iseva, kepha ungangeza isekhondi, ngokwesibonelo imiphakathi ye- -Google.
  • I-2 yokugcina ikhombisa igama lokusesha lesizinda negama lesizinda uqobo.

Manje kufanele sengeze imigqa elandelayo ku / njll / Sebawoti:
127.0.0.1 Matrix.clase.org Matrix
192.168.0.67 Matrix.clase.org Matrix

Ngalokhu, igama lesizinda lizoxazululwa ukuze litholakale kunethiwekhi. Matrix igama engilinike iseva.

Ekugcineni siyahlela /etc/resolv.conf:

nameserver 192.168.0.13

Kokunye ukufundisa engikutholile, bangeze omunye umugqa we-nameserver nokuhlukahluka okumbalwa, kepha kimi kuphela ulayini owodwa ubanele.
Manje siqala kabusha insiza yenethiwekhi futhi yilokho kuphela:

/etc/init.d/networking restart

Umphathi Wenethiwekhi

Chofoza inkinobho yegundane kwesokudla kusithonjana senethiwekhi bese ukhetha Hlela ukuxhumana. Sizothola amanethiwekhi esiwamisile, kepha sinentshisekelo kuphela kukholi Inethiwekhi enentambo 1 noma yini oyiqambe ngegama. Sichofoza kabili kuyo bese kuvela iwindi elisha bese siya kulo Izilungiselelo ze-IPv4. e indlela sikhetha Manual. Manje chofoza ku Faka bese ugcwalisa zonke izinkambu:
I-AC DC Debian - Umphathi Wenethiwekhi


Manje siya kuthebhu General futhi senza isiqiniseko sokuthi imakiwe Bonke abasebenzisi kumele baxhume kule nethiwekhi. Chofoza ku- Gcina sahamba ke.

Ukufaka iSamba 4

Esimweni sethu sizolanda futhi sihlanganise iSamba 4 ekhasini layo ngoba kuDebian itholakala kuphela endaweni yokugcina izinto Izikhumulo ezingemuva futhi kwanginikeza izinkinga zokuncika.

Siya http://samba.org ukulanda uhlobo lwakamuva oluzinzile bese uvula iziphu kufolda.

Uhlobo lwakamuva oluzinzile ngesikhathi sokubhala lo mbhalo ngu 4.1.8 ngakho-ke kuzoba yilowo esisebenza naye.

Ukuyihlanganisa sizodinga ukufaka amaphakheji alandelayo:

apt-get install build-essential libacl1-dev libattr1-dev \
libblkid-dev libgnutls-dev libreadline-dev python-dev libpam0g-dev \
python-dnspython gdb pkg-config libpopt-dev libldap2-dev \
dnsutils libbsd-dev attr krb5-user docbook-xsl libcups2-dev acl

Uma sesilandile futhi savulwa uziphu, sivula ukuphela bese sidlulela kufolda bese senza imiyalo elandelayo:
./configure --enable-debug
make
make install

Ukufakwa okuzenzakalelayo kufakiwe  / usr / wendawo / samba. Ngenkathi isekela ipharamitha engu- –prefix = / usr CHA iyifaka kwizikhombisi ezihambisanayo (ngokwesibonelo ama-binaries awawafaki / usr / bin)

Manje sengeza imizila emisha kufayela le- PATH. Endabeni yami ku /etc/bash.bashrc ukufaka isicelo kubo bonke abasebenzisi, kufaka phakathi izimpande.

export PATH=$PATH:/usr/local/samba/bin:/usr/local/samba/sbin

Futhi sakha isixhumanisi ngaphakathi / njll seSamba ukuthola ifayela lokumisa:

ln -s /usr/local/samba/etc/ /etc/samba

Sizomisa iseva ye-Samba. Ngenxa yalokhu senza lokhu:

samba-tool domain provision --realm=clase.org --domain=CLASE --adminpass=Contraseña --use-rfc2307

kuphi:

  • Indawo: igama eligcwele lesizinda.
  • Isizinda: yisizinda. Kufanele ibe ku ofeleba
  • –I-Adminspass: iphasiwedi yomlawuli wenethiwekhi.
  • Sebenzisa i-rfc2307: ukwenza kusebenze i-AC.

Uma konke kuhamba kahle ngemuva kwesikhashana uSamba uzoqeda ukuzilungiselela. Uma ufuna ukwazi zonke izinketho ezingenzeka, vele usebenzise:

samba-tool domain provision -h

Manje sizohlela ifayela /etc/samba/smb.conf. Okwamanje okusithandayo yilayini olandelayo:
dns forwarder = 192.168.0.1

Lo mugqa kufanele ukhombe kuseva ye-DNS esinikeza ukufinyelela kwi-Intanethi (kulokhu, i-router). I-Samba ithatha ukumiswa kwenethiwekhi okuzenzakalelayo kepha kunconywa ukukuqinisekisa.

Manje siqala insiza:

samba

futhi sihlola ukuxhumana ngokwenza:

smbclient -L localhost -U%

Futhi uma konke kulungile, sizobona okufana nalokhu:
ukubheka ukuthi i-samba iyasebenza yini


Uma kwenzeka isinikeze iphutha lokuxhuma, siqinisekisa izinyathelo zephuzu langaphambilini. Igogi le-Samba lise- / usr / indawo / isamba /var /log.samba

Manje sizokopisha ifayela /usr/local/samba/private/krb5.conf a / njll. Manje sizohlola ukuthi singaxhuma yini:

kinit administrator@CLASE.ORG

Ojo, isizinda kufanele senziwe ngofeleba.

Ngemuva kwalokho izosicela iphasiwedi yomsebenzisi (kulokhu eyomlawuli) futhi uma sithola umyalezo ofana noka «Isexwayiso: Iphasiwedi yakho izophelelwa yisikhathi ezinsukwini ezingama-40 ngoMsombuluko ngoJulayi 14 13:57:10 2014» ukuthi liphume kahle.

Futhi kuze kube manje ingxenye yokuqala yesifundo. Sifunde kokulandelayo.

Ngivele ngiphawule ngaso kaningana kumazwana, kepha ngikubeka lapha. Ngenxa yokuthi njengamanje anginazo izinsizakusebenza ezidingekayo (ngine-PC ekhaya kuphela futhi lokhu kufakwa phakathi nezifundo) nokuthi ukukwenza emishinini ebonakalayo kunzima, akunakwenzeka ukuthi ngiqhubeke. Uma umuntu onolwazi neqembu efuna ukuqhubeka nalokhu, bakhululekile ukwenza njalo)

Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.

  1.   Lolo kusho

    Kuyathakazelisa kakhulu, bengihlala ngifuna ukwazi ukuthi lokhu kwenziwe kanjani.

    Kungenzeka ukukwenza usebenzisa i-SSH esikhundleni seSamba?

    Ngiyaqonda ukuthi iyashesha futhi iphephe kakhulu.

    1.    Claudio Concepcion indawo yokubamba indawo kusho

      Lolo othandekayo, lokho akunakwenzeka, ngoba i-SSH ivumela iseshini (nezinye izinto, njengokudlulisa amafayela nezinhlelo zokusebenza) ngokusebenzisa i-terminal phakathi kwamakhompyutha ane-GNU Linux. Ngenkathi iSamba yini enye indlela ye-GNU Linux yohlelo lwe-Microsoft Directory olusebenzayo.

      INdodana Xhumanisa lokho ekwenzile yisilawuli sesizinda ku-GNU Linux.

  2.   Antonio kusho

    I-tuto enhle kakhulu. Kuhle kubantu abanjengami abaluhlaza okotshani kuyo. Ngibonga kakhulu

  3.   Claudio Concepcion indawo yokubamba indawo kusho

    Ngiyabonga! Umhlahlandlela omuhle kakhulu. Vumela…

  4.   adiazc87 kusho

    Ngiyabonga mngani, umuhle kakhulu umhlahlandlela wakho.Ngithemba ukuthi ingxenye yesibili, by the way ingabe umenze wasebenza ne-ldap?

    Ukubingelela

  5.   Sebastian kusho

    Kuyathakazelisa kakhulu, ngilinde ukuqhubeka. Ngiyabonga

    I-PS: Ngicabanga ukuthi kunephutha elincane lokuloba ekucushweni kwe- / etc / network / interfaces, lithi dns-domian lapho kubonakala kimi ukuthi kufanele ihambe dns-domain.

  6.   Wilson ruiz kusho

    Ngithole lesi sihloko sithakazelisa kakhulu. Njengoba ngisemgudwini wokufunda nje futhi anginalo ulwazi oluningi ngalolu daba futhi ngifuna ukufunda kabanzi ngokuphathwa nokuphathwa kwezinhlelo ezisebenzayo.

  7.   eliotime3000 kusho

    Ngabe lokho kuyasiza ekwenzeni amafolda abiwe ku-Debian noma kumane kwenzelwa esinye isifundo leso sici?

  8.   Gonzalo kusho

    Kukhona ukusatshalaliswa kweLinux okubizwa ngeResara Server okususelwe ku-Ubuntu okusetshenziswa kuphela ukwakha isilawuli sesizinda, ngiyizamile futhi kulula kakhulu ukuyisebenzisa, ngikwazile ukujoyina amakhompyutha esizindeni naleyo seva, ngishiya lapha indlela , mhlawumbe othile uzokusebenzisa - http://ostechnix.wordpress.com/2012/12/31/resara-server-an-alternative-opensource-linux-domain-controller-for-windows-active-directory-controller/

    1.    izinga kusho

      Hawu !!! Kuhle, umnikelo wosuku .. Ngiyabonga 😉

      1.    Gonzalo kusho

        Wamukelekile! 😀

    2.    The_Mastersok kusho

      Siyabonga ngokwabelana !!!
      Phendula ngokucaphuna

  9.   oscar kusho

    Isifundo esihle kakhulu, ngizobe ngilinde okusele. Ngikhumbula lapho ngifaka i-PDF ku-Debian 6 ene-samba 3 ne-ldap. Kusebenzile kepha bekufanele ngisebenzise izifanekiso ze-.pol ukuhlela izinkomba. Kulokhu, ziphathwa kanjani lezi zinqubomgomo?

  10.   UMario Guillermo Zavala Silva kusho

    Ulwazi oluhle kakhulu ... Ngiyabonga ngalokhu ...

    CHEERS !!!

  11.   Cesar kusho

    Kuhle kakhulu…. Nginentshisekelo kulokhu ……. ngoba ingxenye yesibili ??? noma uma unencwajana yalokhu ngithumele yona nge-imeyili ... ngiyacela !!!! ngiyabonga

  12.   The_Mastersok kusho

    Isifundo esihle kakhulu….
    Ngiyethemba ngolunye usuku ukukusebenzisa ..
    Ngiyabingelela futhi ngilinde ingxenye yesibili !!!!

  13.   Leandro kusho

    Iqiniso ukuthi ngikwenze lokhu kanye, kepha angizange ngingene cishe kunoma yini ... Ngifuna ukukuncoma / wena ithuluzi, angazi noma uyalazi noma cha, angazi ukulinganiselwa kwalo, kepha ukuxhuma kuseva ye-Active Directory angibanga nankinga, ngiyizamile ekolishi futhi yasebenza kahle kakhulu. Uhlelo lubizwa ngokufanayo, lwenza ngokufana nakho konke okwenze ngeSamba, akukho okungaphezu kokungakulungisi kangako, kuyinto efingqiwe kakhulu, impela ungakushintsha okudingayo ngendlela oyithandayo

    Ngiyethemba ukuthi lokhu kungakusiza! Jabulela

  14.   Caesar kusho

    I-athikili ethakazelisa kakhulu, ngizobheka phambili kwisitolimende sesibili. Kube isimanga esikhulu ukuthola ukuthi kungenzeka ukuphatha umkhombandlela osebenzayo "wesimanjemanje" ngeGnu / Linux, ngiyakhumbula ukukwenza kudala ngohla lwemibhalo olusebenzayo lohlobo lwe-NT 4 futhi kube ukudumala okukhulu ukungakwazi ulingise lapho iMicrosoft ishintsha "isakhiwo" se-LDAP yakho ku-Windows 2000 Server.

    Ukubingelela okuvela e-Ecuador =]

  15.   mmm kusho

    Sawubona. Ngibonga kakhulu!
    Nginokungabaza okumbalwa… yini ngempela isiqondisi esisebenzayo?
    Ngakolunye uhlangothi, ungafundisa, uma ukwazi, ukuthi ungakwenza kanjani ukucwaninga okwenziwa abasebenzisi?
    Ukubingelela nokubonga.

    Mina ngomsindo ngisebenzise lokhu: http://chicheblog.wordpress.com/2011/01/21/como-auditar-la-actividad-de-los-usuarios-en-samba/
    Kepha uma ungayikhulisa, noma ungeze okuthile okwaziyo, kuyaziswa!
    imikhonzo

  16.   URaulBaca kusho

    Ubusuku obuhle, Sanibonani abavela ePeru.
    Nginombuzo ohluke kancane kukho konke okushicilelwe, bheka ukuze ngichaze kancane, bheka nginale folda elungiselelwe kufayela /etc/samba/smb.conf

    [Okuyimfihlo]
    comment = Ifolda yangasese
    indlela = / home / Private
    funda kuphela = yebo
    ibhekabheka = yebo
    isivakashi ok = cha
    umphakathi = cha
    bhala uhlu = @comercial, @gestion
    abasebenzisi abavumelekile = @comercial, @gestion
    dala imaski = 0777
    umkhombandlela wesikhombi = 0777

    Manje umbuzo wami uyahamba, yonke into isebenza kahle kepha uma ngisuka kwikhompyutha ngingena ngemvume nomsebenzisi «pepe» weqembu «comercial» futhi kusuka kwenye ikhompyutha ngingena ngemvume nomsebenzisi «coco» weqembu «gestion», okulandelayo kwenzeka lapho ngakha ifayili noma ifolda kusuka kumsebenzisi "imeyili" futhi ngifuna ukususa lo mkhombandlela noma ifayela elenziwe kusuka kwenye i-PC elinomsebenzisi "coco" lingitshela ukuthi angikwazi ngoba anginayo amalungelo, kepha umbhali uqobo angalisusa leli fayela noma umkhombandlela, ofinyelela kuwo.

    Ifolda eyimfihlo yakhiwe ngale ndlela elandelayo:
    chmod -R 777 / home / Okuyimfihlo
    Basebenza ngaphansi kwenethiwekhi efanayo ye-LAN.
    Ngisebenzisa iDistro Ubuntu Server 14.xx
    Kumele kuqashelwe ukuthi engikufunayo ukuthi le folda YANGasese iphathwe ngabasebenzisi ababili noma ngaphezulu lapho umqondo wokusebenzisana namaQembu kepha kubukeka sengathi kukhona engikushodayo noma engikushiyayo, ngiyethemba ukuthi uzonginaka nami hlala unake imibono yakho.

    1.    ongcwele kusho

      Umngani ongamzuza ngokususa okhefana
      ngale ndlela.

      bhala uhlu = @comercial @gestion
      abasebenzisi abavumelekile = @comercial @gestion

  17.   URaúl Baca Centeno kusho

    Sawubona Sthandwa,

    Ngingathanda ukwazi ukuthi ngabe ingxenye yesibili yesifundo isalindile, ngilalele imibono yakho futhi ngiyabonga.

  18.   UMiguel kusho

    Sawubona ntambama, namhlanje nje ngifunde konke ukuphawula futhi nginomshini olungiselelwe ingxenye, ngenxa yalesi sizathu ngithola ukuthi ngeke uyishicilele ingxenye yesibili futhi ngifuna ukwazi ukuthi ungaba nomphumeleli kufolda ne-dbf eminingana amatafula, ukufinyelela kusuka kumakhompyutha amaningi.
    Sicela uphendule ngokushesha okukhulu.

  19.   URaul Baca kusho

    Sawubona,
    Ngingathanda ukwazi ukuthi ngabe ingxenye yesibili yalesi sifundo esithakazelisayo isalindile, ngiyabonga kusengaphambili ngokunakwa kwakho.
    I-gracias.

  20.   i-jaraneda kusho

    Isifundo esihle kakhulu, ngethemba ukuthi uyakhuthaza ingxenye yesibili, ungangitshela ukuthi yimaphi amathuluzi wokulawula iseva akude ukuwalanda nokuwahlola.

    Ukubingelela

  21.   BETO kusho

    Ngiyakuhalalisela, nengxenye yesibili?

  22.   UDaniel Bernal kusho

    I-athikili ethokozisayo, ngabe uyikhiphile inguqulo elandelayo?

  23.   intela kusho

    Isifundo esihle kakhulu, umbuzo owodwa nje ingxenye yesibili, kungaba kanjani noma ngalesi sifundo siphela?

  24.   SARA kusho

    NGITHANDA UMCABANGO WOKUFUNDA IZINTO EZINTSHA, NGIYABONGA UDAVIDE NGOKWABELA ULWAZI LAKHO,
    I-GREETINGS

    I-POSTSCRIPT: NGESIHLOKO SOKUFUNDA NGIZOZAMA UKUKWENZA EMAKHATHINI WAMI WAMAVIKI WAMADEBHIYA NJENGESERVER NANGAMAQEMBU AMAKlayenti AMAVIRTUAL, AMANYE ANQOBE I-WIN7 KANYE NOMUNYE WIN8.

  25.   edgar kusho

    Lo mhlahlandlela awuphelele, awucacisi izinkomba, ushiya izinto zingahleliwe, ukube benginguwe bengizokuphinda

    1.    izinga kusho

      Noma ungayiqedela bese uzibhalela ngokwakho, sizokuthokozela ukukushicilela.

  26.   udonga lwe-ada kusho

    ungamisa kanjani iseva ku-debian 5 ukuze ukwazi ukuxhuma ukude kwi-xp

  27.   i-francisco kusho

    sawubona kanjani lapho ngenza:
    impande @ pdc: ~ # apt-get ukufaka ukwakha okubalulekile libacl1-dev libattr1-dev libblkid-dev \ libgnutls-dev libreadline-dev python-dev libpam0g-dev \ python-dnspyth gdb pkg-config libpopt-dev libldap2-dev \ dnsutils libbsd-dev attr krb5-umsebenzisi docbook-xsl libcups2 ac1
    ungitshela:
    Uhlu lokufunda iphakethe… Kwenziwe
    Isihlahla sokuthembela ekwakheni
    Ukufunda ulwazi lombuso ... Kwenziwe
    Iphakheji yokwakha-ebalulekile ayitholakali, kepha idluliselwa kwelinye iphakheji.
    Lokhu kungasho ukuthi iphakethe alikho, liphelelwe yisikhathi, noma
    itholakala kuphela komunye umthombo
    E: Ukwakhiwa okubalulekile kwephakeji akunamkhawulo wokufakwa

    noma yiluphi usizo? ngiyabonga

  28.   engaziwa kusho

     

    1.    engaziwa kusho

      izinqolobane azilungiselelwe

  29.   Carlos kusho

    Ngiyazi ukuthi ngeke ushicilele ukuphawula kwami. I-athikili yimbi kabi, ngaphandle kokusho ukuthi ama-kerberos amiswa kanjani, ngoba uwasebenzisa kuzidingo. Kungani uhlanganisa iSamba? Inguqulo yesi-4 isiyatholakala. Ngokumisa okusethiwe, i-Kinit ikunikeza iphutha elihleliwe NT_STATUS_DENIED!. Okwabo bonke abanentshisekelo yokuqalisa: https://help.ubuntu.com/lts/serverguide/samba-dc.html