<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[Linux Forum &mdash; Настройка Samba PDC + Ldap]]></title>
		<link>https://linuxforum.ru/viewtopic.php?id=23360</link>
		<atom:link href="https://linuxforum.ru/extern.php?action=feed&amp;tid=23360&amp;type=rss" rel="self" type="application/rss+xml" />
		<description><![CDATA[Недавние сообщения в теме «Настройка Samba PDC + Ldap».]]></description>
		<lastBuildDate>Tue, 17 Jul 2012 16:20:36 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Настройка Samba PDC + Ldap]]></title>
			<link>https://linuxforum.ru/viewtopic.php?pid=288490#p288490</link>
			<description><![CDATA[<p>Всем доброго времени суток.<br />Сори, проблема была в том, что были примонтированы сетевые диски, по этому он и не хотел вводить компьютер в домен. Еще раз прошу прощения за создание темы.</p><p>Собственно настраиваю данную связку, пользователи создаются, зайти на сервер под ними можно, директории домашние создаются, НО, прописать виндовую машину в домен не получается, выдает ошибку о множественном подключении. В логах пусто. <br />Сам сервер добавляется нормально.<br />smb.conf <br /></p><div class="codebox"><pre><code>[global]
    workgroup = SYS163
    realm = sys163.ru
    server string = Debian Linux Server
    interfaces = 192.168.10.0/24, 192.168.116.0/24, lo    
    bind interfaces only = Yes
    map to guest = Bad User
    syslog = 10
    time server = Yes
    log file = /var/log/samba/log.%m
    max log size = 1000
    socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
    add user script = /usr/sbin/smbldap-useradd -m %u -d /home/%u %u
    delete user script = /usr/sbin/smbldap-userdel %u -r %u
    add group script = /usr/sbin/smbldap-groupadd -p %g
    delete group script = /usr/sbin/smbldap-groupdel %g
    add user to group script = /usr/sbin/smbldap-groupmod -m %u %g
    delete user from group script = /usr/sbin/smbldap-groupmod -x %u %g
    set primary group script = /usr/sbin/smbldap-usermod -g %g %u
    add machine script = /usr/sbin/smbldap-useradd -t 0 -w %u
    domain logons = Yes
    os level = 255
    preferred master = Yes
    domain master = Yes
    dns proxy = No
    wins support = Yes
    passdb backend = ldapsam:ldap://127.0.0.1/
    pam password change = Yes
    passwd program = /usr/sbin/smbldap-passwd %u
    passwd chat = *New*password* %n\n *Retype*new*password* %n\n *all*authentication*tokens*updated*
    ldap admin dn = cn=admin,dc=sys163,dc=ru
    ldap delete dn = yes
    ldap group suffix = ou=Group
    ldap idmap suffix = ou=Idmap
    ldap machine suffix = ou=Computers
    ldap suffix = dc=sys163,dc=ru
    ldap ssl = no
    ldap user suffix = ou=Users
    ldap passwd sync = yes
    panic action = /usr/share/samba/panic-action %d
    map acl inherit = Yes
    case sensitive = No
    hide unreadable = Yes
    smb ports = 139 445
    idmap gid = 500-600
    idmap uid = 1000-2000
    obey pam restrictions = no
    security = user
        encrypt passwords = yes
        unix extensions  = no
    local master = yes
    admin users = root
    logon script = systest.bat    
    winbind uid = 10000-20000
    winbind gid = 10000-20000    </code></pre></div><p>slapd.conf<br /></p><div class="codebox"><pre><code># This is the main slapd configuration file. See slapd.conf(5) for more
# info on the configuration options.
 
#######################################################################
# Global Directives:
 
# Features to permit
#allow bind_v2
 
# Schema and objectClass definitions
include         /etc/ldap/schema/core.schema
include     /etc/ldap/schema/collective.schema
include     /etc/ldap/schema/corba.schema
include         /etc/ldap/schema/cosine.schema
include     /etc/ldap/schema/duaconf.schema
include     /etc/ldap/schema/dyngroup.schema
include         /etc/ldap/schema/nis.schema
include         /etc/ldap/schema/misc.schema
include     /etc/ldap/schema/java.schema
include         /etc/ldap/schema/inetorgperson.schema
include        /etc/ldap/schema/openldap.schema
include     /etc/ldap/schema/ppolicy.schema
include         /etc/ldap/schema/samba.schema

#include         /etc/ldap/schema/gosa/samba3.schema
include         /etc/ldap/schema/gosa/gosystem.schema
include         /etc/ldap/schema/gosa/gofon.schema
include         /etc/ldap/schema/gosa/gofax.schema
include         /etc/ldap/schema/gosa/goto.schema
include         /etc/ldap/schema/gosa/goserver.schema
include         /etc/ldap/schema/gosa/gosa-samba3.schema
include         /etc/ldap/schema/gosa/trust.schema
# Where the pid file is put. The init.d script
# will not stop the server if you change this.
pidfile         /var/run/slapd/slapd.pid
 
# List of arguments that were passed to the server
argsfile        /var/run/slapd/slapd.args
 
# Read slapd.conf(5) for possible values
loglevel 0
 
# Where the dynamically loaded modules are stored
modulepath /usr/lib/ldap
moduleload back_hdb
 
# The maximum number of entries that is returned for a search operation
sizelimit 296
 
# The tool-threads parameter sets the actual amount of cpu&#039;s that is used
# for indexing.
tool-threads 1
 
#######################################################################
# Specific Backend Directives for hdb:
# Backend specific directives apply to this backend until another
# &#039;backend&#039; directive occurs
backend hdb
 
#######################################################################
# Specific Backend Directives for &#039;other&#039;:
# Backend specific directives apply to this backend until another
# &#039;backend&#039; directive occurs
#backend    &lt;other&gt;
 
#######################################################################
# Specific Directives for database #1, of type hdb:
# Database specific directives apply to this databasse until another
# &#039;database&#039; directive occurs
database        hdb
 
# The base of your directory in database #1
suffix          &quot;dc=sys163,dc=ru&quot;
 
# rootdn directive for specifying a superuser on the database. This is needed
# for syncrepl.
rootdn          &quot;cn=admin,dc=sys163,dc=ru&quot;
rootpw          {MD5}hTkti4GE4uDcDpdCiEZeOw==
 
# Where the database file are physically stored for database #1
directory       &quot;/var/lib/ldap&quot;
 
# The dbconfig settings are used to generate a DB_CONFIG file the first
# time slapd starts.  They do NOT override existing an existing DB_CONFIG
# file.  You should therefore change these settings in DB_CONFIG directly
# or remove DB_CONFIG and restart slapd for changes to take effect.
 
# For the Debian package we use 2MB as default but be sure to update this
# value if you have plenty of RAM
dbconfig set_cachesize 0 2097152 0
 
# Sven Hartge reported that he had to set this value incredibly high
# to get slapd running at all. See *ссылко* for more
# information.
 
# Number of objects that can be locked at the same time.
dbconfig set_lk_max_objects 1500
# Number of locks (both requested and granted)
dbconfig set_lk_max_locks 1500
# Number of lockers
dbconfig set_lk_max_lockers 1500
 
# Indices to maintain for this database
index objectClass                       eq,pres
index ou,cn,sn,mail,givenname           eq,pres,sub
index uidNumber,gidNumber,memberUid     eq,pres
index loginShell                        eq,pres
## required to support pdb_getsampwnam
index uid                               pres,sub,eq
## required to support pdb_getsambapwrid()
index displayName                       pres,sub,eq
index nisMapName,nisMapEntry            eq,pres,sub
index sambaSID                          eq
index sambaPrimaryGroupSID              eq
index sambaDomainName                   eq
index default                           sub
index uniqueMember                      eq
index sambaGroupType                    eq
index sambaSIDList                      eq
 
# Save the time that the entry gets modified, for database #1
lastmod         on
 
# Checkpoint the BerkeleyDB database periodically in case of system
# failure and to speed slapd shutdown.
checkpoint      512 30
 
# Where to store the replica logs for database #1
# replogfile /var/lib/ldap/replog
 
# users can authenticate and change their password
    access to attrs=userPassword,sambaNTPassword,sambaLMPassword,sambaPwdMustChange,sambaPwdLastSet
    by anonymous auth
    by self write
    by * none
 
# those 2 parameters must be world readable for password aging to work correctly
# (or use a priviledge account in /etc/ldap.conf to bind to the directory)
    access to attrs=shadowLastChange,shadowMax
    by self write
    by * read
 
# all others attributes are readable to everybody
    access to *
    by dn=&quot;cn=root,ou=people,dc=sys163,dc=ru&quot; write
    by * read
 
# For Netscape Roaming support, each user gets a roaming
# profile for which they have write access to
#access to dn=uid=root,ou=people,dc=sys163,dc=ru by self write
#        by dn=&quot;cn=admin,dc=example,dc=com&quot; write
#        by dnattr=owner write
 
#######################################################################
# Specific Directives for database #2, of type &#039;other&#039; (can be hdb too):
# Database specific directives apply to this databasse until another
# &#039;database&#039; directive occurs
#database        &lt;other&gt;
 
# The base of your directory for database #2
#suffix &quot;dc=debian,dc=org&quot;</code></pre></div>]]></description>
			<author><![CDATA[null@example.com (imex)]]></author>
			<pubDate>Tue, 17 Jul 2012 16:20:36 +0000</pubDate>
			<guid>https://linuxforum.ru/viewtopic.php?pid=288490#p288490</guid>
		</item>
	</channel>
</rss>
