comandos_samba4

  • Upload
    jcr0ch4

  • View
    215

  • Download
    0

Embed Size (px)

Citation preview

  • 7/22/2019 comandos_samba4

    1/20

    Comandos para gerenciamento de Usuarios no samba 4( Terminal )

    Digitando o comando# export PATH=$PATH:/opt/samba/bin:/opt/samba/sbin

    Trocar senha do usurio# samba-tool user setpassword s3nh4f0rt3 newpassword=1234.mvd4r.s3nh4

    Trocar senha do usurio e forca a troca no Prximo Login# samba-tool user setpassword s3nh4f0rt3

    newpassword=1234.mvd4r.s3nh4 must-change-at-next-loginDeletar Usurio# samba-tool user delete limpeza.ti

    Deletar Usurio e Deletar a sua pasta Home# samba-tool user delete limpeza.ti && rm -r/system/profile/limpeza.ti

    Listar Todos os Usurios do samba# samba-tool user list

    Desabilitar o Usuriocom essa opo a conta no pode ser utilizada mais permanece no servidor# samba-tool user disable limpeza.ti

    Habilitar Usurio# samba-tool user enable limpeza.ti

    Expirao de senha do usurioA expirao de senha para todos os usurios do domnio e feita com outro

    comando essa altera somente do usurio especificado ( bom para ser usadoem certas excees como por exemplo aquele diretor que insiste em ser umaexceo a regra ) 10 e o numero de dias em que a senha ira expirar# samba-tool user setexpiry limpeza.ti days=10

    Desabilitar a expirao de senha# samba-tool user setexpiry limpeza.ti noexpiry

    Grupos

    Criar um grupo

    # samba-tool group add diretoria

    Adicionar Vrios Grupos de uma vez

  • 7/22/2019 comandos_samba4

    2/20

    # samba-tool group add diretoria diretoria_ead

    Criar um grupo e adicionar um descrio ao grupo# samba-tool group add diretoria description=Grupo da diretoria

    Adicionar um membro a um grupo# samba-tool group addmembers diretoria mundoti

    Adicionar um Grupo dentro de Outro GrupoNo samba4 podemos adicionar um grupos dentro de outro isso e muito util# samba-tool group addmembers diretoria diretoria_ead

    Adicionar Vrios Membros a um grupo de uma vez s# samba-tool group addmembers diretoria mundoti,mundoti2

    Remover um grupo# samba-tool group delete diretoria

    Removendo Vrios grupos de uma vez# samba-tool group delete diretoria diretoria_ead

    Remover um membro de um grupo# samba-tool group removemembers diretoria mundoti

    Remover Membros de um grupo# samba-tool group removemembers diretoria mundoti,mundoti2

    Listar todos os grupos# samba-tool group list

    Listar Usurios pertencente a um grupo# samba-tool group listmembers diretoria

  • 7/22/2019 comandos_samba4

    3/20

    Gerenciando Seu servidor DNS pelo shell no samba4Publicado em porjeferson salles

    Objetivo:Explicar como Gerenciar Seu Servidor dns no samba4 pelo shell

    Introduo:Este Post tem como objetivo explicar:

    Adicionar uma zona Reversa Adicionar entradas no Zona primaria e reversa Consultar Informao sobre as zona de dns E outras

    No post anterior Criando usurio Pelo Shell no Samba4 expliquei como criarusurio pelo shell

    No post anterior Gerenciando usurios e grupos pelo shell no samba4expliquei como Gerenciar usurio e grupos pelo shell

    Cenrio:Servidor: Debian 7Verso do Samba: 4.0.3Faixa de ip da Zona reversa = 192.168.1.0/24 ( Classe C )Entrada a ser criada no Dns = roteador.empresa.casa

    Ip da entrada criada no Dns ( roteador.empresa.casa ) = 192.168.1.1Senha do usuario = Senha_do_usuario_administratorNome do dominio = empresa.casaDiretrio de instalao do samba = /opt/samba/

    *Obs: para executar esses comandos sem ter digitar o caminho completo

    Ex samba-tool /opt/samba/bin/samba-toolvoc tem que ter exporta a varivel path do local da instalao do samba4 issopode ser feito da seguinte forma.

    Digitando o comando# export PATH=$PATH:/opt/samba/bin:/opt/samba/sbin

    No Vamos Criar a zona primaria porque a mesma j foi criadaautomaticamente pelo samba

    http://www.mundotibrasil.com.br/author/jefferson/http://www.mundotibrasil.com.br/criando-usuari%E2%80%A6hell-no-samba4/http://www.mundotibrasil.com.br/gerenciando-usuarios-e-grupos-pelo-shell-no-samba4/http://www.mundotibrasil.com.br/wp-content/uploads/2013/01/logo-samba.pnghttp://www.mundotibrasil.com.br/criando-usuari%E2%80%A6hell-no-samba4/http://www.mundotibrasil.com.br/gerenciando-usuarios-e-grupos-pelo-shell-no-samba4/http://www.mundotibrasil.com.br/author/jefferson/
  • 7/22/2019 comandos_samba4

    4/20

    Como Podemos ver

    # samba-tool dns zonelist 127.0.0.1 auto -U Administrator password=Senha_do_usuario_administrator

    Saida do comando

    2 zone(s) found

    pszZoneName : empresa.casaFlags : DNS_RPC_ZONE_DSINTEGRATED DNS_RPC_ZONE_UPDATE_SECUREZoneType : DNS_ZONE_TYPE_PRIMARYVersion : 50dwDpFlags : DNS_DP_AUTOCREATED DNS_DP_DOMAIN_DEFAULTDNS_DP_ENLISTEDpszDpFqdn : DomainDnsZones.empresa.casapszZoneName : _msdcs.empresa.casaFlags : DNS_RPC_ZONE_DSINTEGRATED DNS_RPC_ZONE_UPDATE_SECUREZoneType : DNS_ZONE_TYPE_PRIMARYVersion : 50dwDpFlags : DNS_DP_AUTOCREATED DNS_DP_FOREST_DEFAULT DNS_DP_ENLISTEDpszDpFqdn : ForestDnsZones.empresa.casa

    Vamos Criar uma zona reversa

    Criar zona reversa# samba-tool dns zonecreate 127.0.0.1 1.168.192.in-addr.arpa -UAdministrator password=Senha_do_usuario_administrator

    Obs a zona reversa criada foi para uma faixa de ip 192.168.1.0/24 ( Classe C )Outro exemplo para uma rede classe A 10.0.0.0

    # samba-tool dns zonecreate 127.0.0.1 10.in-addr.arpa -UAdministrator password=Senha_do_usuario_administrator

    Verificando se a zona foi criada corretamente.# samba-tool dns zonelist 127.0.0.1 reverse -U Administrator password=Senha_do_usuario_administrator

    Saida do comando

    pszZoneName : 1.168.192.in-addr.arpa

    Flags : DNS_RPC_ZONE_DSINTEGRATED DNS_RPC_ZONE_UPDATE_SECUREZoneType : DNS_ZONE_TYPE_PRIMARYVersion : 50dwDpFlags : DNS_DP_AUTOCREATED DNS_DP_DOMAIN_DEFAULTDNS_DP_ENLISTEDpszDpFqdn : DomainDnsZones.empresa.casa

    Criar uma entrada no dns

    # samba-tool dns add 127.0.0.1 empresa.casa roteador.empresa.casaA 192.168.1.1 -U Administrator password=Senha_do_usuario_administrator

    Testando se a entrada foi criada corretamente.

    # dig roteador.empresa.casa

    Saida do comando

    ; DiG 9.8.4-rpz2+rl005.12-P1 roteador.empresa.casa;; global options: +cmd;; Got answer:

  • 7/22/2019 comandos_samba4

    5/20

    ;; ->>HEADER

  • 7/22/2019 comandos_samba4

    6/20

    1 uptime2 yum update -y3 vim /etc/security/limits.conf4 yum install vim5 ls6 clear7 ls8 cd anaconda-ks.cfg9 ls10 vim /etc/security/limits.conf11 ls12 chkconfig iptables off13 chkconfig ip6tables off14 vim /etc/sysconfig/selinux15 reboot16 history17 tune2fs -l /dev/mapper/vg_dominio01-LogVol0 |grep options18 tune2fs -l /dev/mapper/vg_dominio01-LogVol00 |grep options

    19 tune2fs -l /dev/mapper/vg_dominio01-LogVol01 |grep options20 tune2fs -l /dev/mapper/vg_dominio01-LogVol02 |grep options21 vim /etc/fstab22 mount -o remount /23 # Foi colocado na linha do / ext4 user_xattr,acl,default 1 124 instalando_samba4.sh25 vim instalando_samba4.sh26 sh instalando_samba4.sh27 cat instalando_samba4.sh28 yum -y install compat-glibc-headers29 vim instalando_samba4.sh

    30 sh instalando_samba4.sh31 clear32 vim instalando_samba4.sh33 sh instalando_samba4.sh34 vim instalando_samba4.sh35 sh instalando_samba4.sh36 vim instalando_samba4.sh37 sh instalando_samba4.sh38 vim instalando_samba4.sh39 sh instalando_samba4.sh40 vim instalando_samba4.sh41 sh instalando_samba4.sh42 vim instalando_samba4.sh43 sh instalando_samba4.sh

  • 7/22/2019 comandos_samba4

    7/20

    44 vim instalando_samba4.sh45 sh instalando_samba4.sh46 vim instalando_samba4.sh47 sh instalando_samba4.sh48 vim instalando_samba4.sh49 sh instalando_samba4.sh

    50 vim instalando_samba4.sh51 sh instalando_samba4.sh52 vim instalando_samba4.sh53 sh instalando_samba4.sh54 vim instalando_samba4.sh55 sh instalando_samba4.sh56 vim instalando_samba4.sh57 sh instalando_samba4.sh58 vim instalando_samba4.sh59 sh instalando_samba4.sh60 vim instalando_samba4.sh61 sh instalando_samba4.sh62 vim instalando_samba4.sh63 sh instalando_samba4.sh64 vim instalando_samba4.sh65 sh instalando_samba4.sh66 vim instalando_samba4.sh67 sh instalando_samba4.sh68 vim instalando_samba4.sh69 sh instalando_samba4.sh70 sh instalando_samba4.sh |grep "nao Instalado

    71 sh instalando_samba4.sh |grep "nao Instalado"72 yum -y install compat-glibc-headers setroubleshoot-server73 vim instalando_samba4.sh74 sh instalando_samba4.sh75 vim instalando_samba4.sh76 sh instalando_samba4.sh77 vim instalando_samba4.sh78 sh instalando_samba4.sh79 ls80 vim instalando_samba4.sh81 sh instalando_samba4.sh

    82 vim instalando_samba4.sh83 sh instalando_samba4.sh84 vim instalando_samba4.sh85 sh instalando_samba4.sh86 vim instalando_samba4.sh87 sh instalando_samba4.sh88 vim instalando_samba4.sh89 yum install -y wget && sh instalando_samba4.sh90 tar xzf samba-latest.tar.gz -C /usr/local/src/91 cd /usr/local/src/samba-4.0.9/92 ls93 ./configure94 ./configure --enable-debug --enable-selftest95 make

  • 7/22/2019 comandos_samba4

    8/20

    96 make install97 ls98 cd docs99 ls100 cd manpages/101 ls

    102 for i in 1 5 7 8;do cp *.$i /usr/share/man/man$i;done103 man samba-tool104 #/usr/local/samba/bin/samba-tool domain provision105 ls106 cd /etc/107 ls108 cd /usr/local/src/samba-4.0.9/109 ls110 clear111 ls112 cd swat/113 ls114 cd include/115 ls116 cd ..117 ls118 cd images/119 ls120 cd ..121 ls122 cd help/

    123 ls124 cd ..125 ls126 cd ..127 ls128 cd examples/129 ls130 cd autofs/131 ls132 less auto.smb133 clear

    134 ls135 cd ..136 ls137 clear138 ls139 cd logon/140 ls141 cd ntlogon/142 ls143 cat ntlogon.conf144 ls145 cd ..146 ls147 cd genlogon/

  • 7/22/2019 comandos_samba4

    9/20

    148 ls149 cat genlogon.pl150 clear151 ls152 cd ..153 ls

    154 cd mklogon/155 ls156 cat mklogon.pl157 clear158 ls159 cat mklogon.conf160 clear161 ls162 cd ..163 ls164 cd ..165 ls166 cd scripts/167 ls168 cd users_and_groups/169 ls170 cd ..171 ls172 cd ..173 ls174 misc/

    175 ls176 cd misc/177 ls178 cd ..179 ls180 cd ..181 ls182 clear183 ls184 cd codepages/185 ls

    186 cd ..187 ls188 clear189 ls190 cd include/191 ls192 cd public/193 ls194 cd samba/195 ls196 cd ..197 ls198 cd util/199 ls

  • 7/22/2019 comandos_samba4

    10/20

    200 cd ..201 ls202 find .203 cd ..204 ls205 cd ..

    206 ls207 cd packaging/208 ls209 cd RHEL210 ls211 cd setup/212 ls213 cd ..214 ls215 cd ..216 ls217 cd Example/218 ls219 cd ..220 ls221 cd ..222 ls223 cd bin/224 ls225 cd de226 cd default/

    227 ls228 cd file_server/229 ls230 cd ..231 ls232 cd auth/233 lks234 ls235 cd credentials/236 ls237 cd ..

    238 ls239 cd ..240 ls241 cd ..242 ls243 cd dynconfig/244 ls245 file wscript246 less wscript247 ls248 cd ..249 ls250 cd libgpo/251 ls

  • 7/22/2019 comandos_samba4

    11/20

    252 cd gpext/253 ls254 cd ..255 ls256 cd bin/257 ls

    258 cd ..259 ls260 cd261 ls262 vim instalando_samba4.sh263 history264 history |grep wget265 vim instalando_samba4.sh266 #tar xzf samba-latest.tar.gz -C /usr/local/src/267 echo "tar xzf samba-latest.tar.gz -C /usr/local/src/"

    >>instalando_samba4.sh268 vim instalando_samba4.sh269 echo "./configure --enable-debug --enable-selftest "

    >>instalando_samba4.sh270 #make install271 vim instalando_samba4.sh272 #echo "./configure --enable-debug --enable-selftest "

    >>instalando_samba4.sh273 s274 vim instalando_samba4.sh275 clear

    276 ls277 cat 1278 rm -f 1279 ls280 cat instal281 date282 cat instalando_samba4.sh283 vim instalando_samba4.sh284 ls285 clear286 ls

    287 shutdown -h now288 ifconfig289 iptables -L290 service iptables stop291 service sshd status292 ls293 clear294 ls295 history

    SCRIPT para instalao do SAMBA 4

    #!/bin/bash#

  • 7/22/2019 comandos_samba4

    12/20

    # Variaveis do sistema#

    # PACOTES NECESSARIOS PARA A INSTALAAO DO SAMBA 4 ( CENTOS6.4 )pacotes="compat-glibc-headers cups-devel cyrus-sasl-devel gcc gdb

    gnutls-devel kernel-devel keyutils-libs-devel krb5-workstation libacl-devel libaio-devel libattr-devel libblkid-devel libcap-devel libidn-devellibpcap-devel libsemanage-python libsepol-devel libtirpc-devellibxml2-devel libxslt openldap-devel pam-devel pkgconfigpolicycoreutils-python popt-devel python-devel readline-devel setools-libs setools-libs-python setroubleshoot-plugins setroubleshoot-serversqlite-devel zlib-devel vim wget"

    instalar=" "

    for i in $pacotesdo

    echo "Pesquisando pacote $i"resultado=`rpm -qa |grep $i`

    if test -z "$resultado" ; thenecho "Pacote nao Instalado : $i "# CASO O PACOTE NAO EXISTA REALIZA A INSTALAAO

    instalar="$i $instalar"

    #um -y $ifidone

    # Executando a instalacao dos pacotes necessarios para o Sambaif test -z "$instalar";then

    echo "Executando a instalacao dos pacotes"echo $instalarread zyum -y $instalar

    fi

    # Download Samba4echo "Efetuando o Download "cd /optwget -c http://ftp.samba.org/pub/samba/samba-latest.tar.gz

    echo "Descompactando"tar xzf samba-latest.tar.gz -C /usr/local/src/

    echo "Instalando o Samba 4"cd /usr/local/src/samba*make && make install./configure --enable-debug --enable-selftest

  • 7/22/2019 comandos_samba4

    13/20

    [root@dominio01 bin]# ./samba-tool domain provisionRealm [CCB.ORG.BR]: ccb.org.brDomain [ccb]: ccb

    Server Role (dc, member, standalone) [dc]: dcDNS backend (SAMBA_INTERNAL, BIND9_FLATFILE, BIND9_DLZ, NONE)

    [SAMBA_INTERNAL]:DNS forwarder IP address (write 'none' to disable forwarding)

    [192.168.122.1]:Administrator password:Retype password:Looking up IPv4 addressesLooking up IPv6 addressesNo IPv6 address will be assignedSetting up share.ldbSetting up secrets.ldbSetting up the registrySetting up the privileges databaseSetting up idmap dbSetting up SAM dbSetting up sam.ldb partitions and settingsSetting up sam.ldb rootDSEPre-loading the Samba 4 and AD schemaAdding DomainDN: DC=ccb,DC=org,DC=brAdding configuration container

    Setting up sam.ldb schemaSetting up sam.ldb configuration dataSetting up display specifiersModifying display specifiersAdding users containerModifying users containerAdding computers containerModifying computers containerSetting up sam.ldb dataSetting up well known security principalsSetting up sam.ldb users and groups

    Setting up self joinAdding DNS accountsCreating CN=MicrosoftDNS,CN=System,DC=ccb,DC=org,DC=brCreating DomainDnsZones and ForestDnsZones partitionsPopulating DomainDnsZones and ForestDnsZones partitionsSetting up sam.ldb rootDSE marking as synchronizedFixing provision GUIDsA Kerberos configuration suitable for Samba 4 has been generatedat /usr/local/samba/private/krb5.confOnce the above files are installed, your Samba4 server will be readyto useServer Role: active directory domain controllerHostname: dominio01NetBIOS Domain: CCB

  • 7/22/2019 comandos_samba4

    14/20

    DNS Domain: ccb.org.brDOMAIN SID: S-1-5-21-3703885753-632100921-3966294513

    [root@dominio01 bin]# /usr/local/samba/sbin/samba[root@dominio01 bin]# netstat -lntup|grep sambatcp 0 0 0.0.0.0:135 0.0.0.0:* OUA

    1508/sambatcp 0 0 0.0.0.0:464 0.0.0.0:* OUA1514/sambatcp 0 0 0.0.0.0:53 0.0.0.0:* OUA1520/sambatcp 0 0 0.0.0.0:88 0.0.0.0:* OUA1514/sambatcp 0 0 0.0.0.0:636 0.0.0.0:* OUA1511/sambatcp 0 0 0.0.0.0:1024 0.0.0.0:* OUA1508/sambatcp 0 0 0.0.0.0:3268 0.0.0.0:* OUA1511/sambatcp 0 0 0.0.0.0:3269 0.0.0.0:* OUA1511/sambatcp 0 0 0.0.0.0:389 0.0.0.0:* OUA1511/sambaudp 0 0 192.168.122.202:137 0.0.0.0:*1509/sambaudp 0 0 192.168.122.255:137 0.0.0.0:*1509/samba

    udp 0 0 0.0.0.0:137 0.0.0.0:*1509/sambaudp 0 0 192.168.122.202:138 0.0.0.0:*1509/sambaudp 0 0 192.168.122.255:138 0.0.0.0:*1509/sambaudp 0 0 0.0.0.0:138 0.0.0.0:*1509/sambaudp 0 0 0.0.0.0:53 0.0.0.0:*1520/sambaudp 0 0 192.168.122.202:464 0.0.0.0:*

    1514/sambaudp 0 0 0.0.0.0:464 0.0.0.0:*1514/sambaudp 0 0 192.168.122.202:88 0.0.0.0:*1514/sambaudp 0 0 0.0.0.0:88 0.0.0.0:*1514/sambaudp 0 0 192.168.122.202:389 0.0.0.0:*1512/sambaudp 0 0 0.0.0.0:389 0.0.0.0:*1512/samba

  • 7/22/2019 comandos_samba4

    15/20

    Verificando o dominio

    [root@dominio01 bin]# ./smbclient -L localhost -U%Domain=[CCB] OS=[Unix] Server=[Samba 4.0.9]

    Sharename Type Comment

    --------- ---- -------netlogon Disksysvol DiskIPC$ IPC IPC Service (Samba 4.0.9)

    Domain=[CCB] OS=[Unix] Server=[Samba 4.0.9]

    Server Comment--------- -------

    Workgroup Master--------- -------

    Colocando as coisas no seu devido lugar

    #!/bin/bash# Comandos do Samba 4 no path do sistema# Copyright 2013 Jose Carlos Rocha ## This program is free software; you can redistribute it and/or modify

    # it under the terms of the GNU General Public License as published by# the Free Software Foundation; either version 2 of the License, or# (at your option) any later version.## This program is distributed in the hope that it will be useful,# but WITHOUT ANY WARRANTY; without even the implied warranty of# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the# GNU General Public License for more details.## You should have received a copy of the GNU General Public License# along with this program; if not, write to the Free Software# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,# MA 02110-1301, USA.

    #

    # Colocando os comandos do Samba 4 no path do sistemaexport PATH="/usr/local/samba/bin:/usr/local/samba/sbin:${PATH}"

    [root@dominio01 ~]# source /etc/profile.d/samba4.sh[root@dominio01 ~]# samba -VVersion 4.0.9

    Script para iniciar o samba 4[root@dominio01 init.d]# cat samba4

  • 7/22/2019 comandos_samba4

    16/20

    #!/bin/bash## samba4 This shell script takes care of starting and stopping# samba4 daemons.## chkconfig: - 58 74# description: Samba 4.0 will be the next version of the Samba suite

    # and incorporates all the technology found in both the Samba4 alpha# series and the stable 3.x series. The primary additional features# over Samba 3.6 are support for the Active Directory logon protocols# used by Windows 2000 and above.

    ### BEGIN INIT INFO# Provides: samba4# Required-Start: $network $local_fs $remote_fs# Required-Stop: $network $local_fs $remote_fs# Should-Start: $syslog $named# Should-Stop: $syslog $named# Short-Description: start and stop samba4# Description: Samba 4.0 will be the next version of the Samba suite

    # and incorporates all the technology found in both the Samba4 alpha# series and the stable 3.x series. The primary additional features# over Samba 3.6 are support for the Active Directory logon protocols# used by Windows 2000 and above.### END INIT INFO

    # Source function library.. /etc/init.d/functions

    # Source networking configuration.. /etc/sysconfig/network

    prog=sambaprog_dir=/usr/local/samba/sbin/lockfile=/var/lock/subsys/$prog

    start() {[ "$NETWORKING" = "no" ] && exit 1

    # [ -x /usr/sbin/ntpd ] || exit 5

    # Start daemons.echo -n $"Starting samba4: "

    daemon $prog_dir/$prog -DRETVAL=$?echo

    [ $RETVAL -eq 0 ] && touch $lockfilereturn $RETVAL

    }

    stop() {[ "$EUID" != "0" ] && exit 4

    echo -n $"Shutting down samba4: "killproc $prog_dir/$progRETVAL=$?

    echo[ $RETVAL -eq 0 ] && rm -f $lockfilereturn $RETVAL

    }

  • 7/22/2019 comandos_samba4

    17/20

    # See how we were called.case "$1" instart)

    start;;

    stop)stop;;

    status)status $prog;;

    restart)stopstart;;

    reload)echo "Not implemented yet."exit 3

    ;;*)

    echo $"Usage: $0 {start|stop|status|restart|reload}"exit 2

    esac

    Pos criao do Script[root@dominio01 init.d]# chmod 755 samba4[root@dominio01 init.d]# chkconfig --add samba4[root@dominio01 init.d]# chkconfig samba4 on[root@dominio01 init.d]# service samba4 status

    samba (pid 1520 1519 1518 1517 1516 1515 1514 1512 1511 1510 1509 1508 15071506) est em execuo...

    Testando DNS

    [root@dominio01 init.d]# host -t SRV _ldap._tcp.ccb.org.br_ldap._tcp.ccb.org.br has SRV record 0 100 389 dominio01.ccb.org.br.[root@dominio01 init.d]# host -t SRV _kerberos._udp.ccb.org.br_kerberos._udp.ccb.org.br has SRV record 0 100 88 dominio01.ccb.org.br.

    Verificando o Kerberos

    [root@dominio01 init.d]# rpm -qa |grep krb5krb5-devel-1.10.3-10.el6_4.4.i686krb5-libs-1.10.3-10.el6_4.4.i686krb5-workstation-1.10.3-10.el6_4.4.i686

    Configurando o KerberosApenas os itens em negrito devem ser alterados.

    [root@dominio01 etc]# vim /etc/krb5.conf

    [logging]default = FILE:/var/log/krb5libs.logkdc = FILE:/var/log/krb5kdc.log

  • 7/22/2019 comandos_samba4

    18/20

    admin_server = FILE:/var/log/kadmind.log

    [libdefaults]default_realm = CCB.ORG.BRdns_lookup_realm = falsedns_lookup_kdc = true

    ticket_lifetime = 24hrenew_lifetime = 7dforwardable = true

    [realms]EXAMPLE.COM = {kdc = kerberos.example.comadmin_server = kerberos.example.com}

    [domain_realm].example.com = EXAMPLE.COMexample.com = EXAMPLE.COM

    Testando a autenticao

    [root@dominio01 etc]# kinit [email protected] for [email protected]:Warning: Your password will expire in 41 days on Fri Oct 25 15:43:08 2013

    Verificando as credenciais

    [root@dominio01 etc]# klistTicket cache: FILE:/tmp/krb5cc_0Default principal: [email protected]

    Valid starting Expires Service principal09/13/13 15:18:33 09/14/13 01:18:33 krbtgt/[email protected]

    renew until 09/20/13 15:18:29

    Time Server ( NTP )

    Instalando o servidor e o cliente

    [root@dominio01 etc]# yum -y install ntp ntpdateLoaded plugins: fastestmirrorLoading mirror speeds from cached hostfile* base: mirror.globo.com* extras: mirror.globo.com* updates: mirror.globo.com

    Setting up Install ProcessResolving Dependencies--> Running transaction check---> Package ntp.i686 0:4.2.4p8-3.el6.centos will be installed---> Package ntpdate.i686 0:4.2.4p8-3.el6.centos will be installed--> Finished Dependency Resolution

    Dependencies Resolved

    ============================================================================================================================================================Package Arch Version Repository

    Size============================================================================================================================================================Installing:

  • 7/22/2019 comandos_samba4

    19/20

    ntp i686 4.2.4p8-3.el6.centos base436 kntpdate i686 4.2.4p8-3.el6.centos base

    57 k

    Transaction Summary============================================================================================================================================================Install 2 Package(s)

    Total download size: 493 kInstalled size: 1.2 M

    Downloading Packages:(1/2): ntp-4.2.4p8-3.el6.centos.i686.rpm| 436 kB 00:00(2/2): ntpdate-4.2.4p8-3.el6.centos.i686.rpm| 57 kB 00:00------------------------------------------------------------------------------------------------------------------------------------------------------------Total 1.0 MB/s| 493 kB 00:00Running rpm_check_debugRunning Transaction TestTransaction Test SucceededRunning Transaction

    Installing : ntpdate-4.2.4p8-3.el6.centos.i6861/2

    Installing : ntp-4.2.4p8-3.el6.centos.i6862/2

    Verifying : ntpdate-4.2.4p8-3.el6.centos.i6861/2

    Verifying : ntp-4.2.4p8-3.el6.centos.i6862/2

    Installed:ntp.i686 0:4.2.4p8-3.el6.centos ntpdate.i686 0:4.2.4p8-3.el6.centos

    Complete!

    Configurando o servidor de Horas ( TimeServer )

    Edite o arquivo /etc/ntp.conf, e execute as alteraes como mostradoabaixo.

    # Use public servers from the pool.ntp.org project.# Please consider joining the pool (http://www.pool.ntp.org/join.html ).

    # Linhas comentadas# server 0.centos.pool.ntp.org# server 1.centos.pool.ntp.org# server 2.centos.pool.ntp.org

    # Linhas adicionadasserver a.ntp.brserver b.ntp.brserver c.ntp.br

    Integrao TimeServer com Samba4

    No final do arquivo ntp.conf incluir as linhas abaixo.

    # INTEGRACAO COM O SAMBA4ntpsigndsocket /usr/local/samba/var/lib/ntpsignd/restrict default mssntp

    Colocando pra funcionar

    [root@dominio01 etc]# ntpdate -b a.ntp.br13 Sep 12:30:03 ntpdate[1756]: step time server 200.160.0.8 offset

    -10798.714789 sec[root@dominio01 etc]# service ntpd startIniciando o ntpd: [ OK ]

    http://www.pool.ntp.org/join.htmlhttp://www.pool.ntp.org/join.html
  • 7/22/2019 comandos_samba4

    20/20

    [root@dominio01 etc]# chkconfig ntpd on