Portál AbcLinuxu, 3. prosince 2025 21:14
smb.conf:
workgroup = DOMENA
password server = 172.28.3.30
security = domain
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
template shell = /bin/false
winbind use default domain = true
winbind offline logon = false
winbind enum users = yes
winbind enum groups = yes
obey pam restrictions = yes
wins server = 172.28.3.30 # ip AD domeny
krb5.conf
[libdefaults]
default_realm = firma.cz
dns_lookup_realm = true
dns_lookup_kdc = true
ticket_lifetime = 24h
forwardable = yes
[realms]
EXAMPLE.COM = {
kdc = kerberos.example.com:88
admin_server = kerberos.example.com:749
default_domain = example.com
}
myworkgrp = {
kdc = 172.28.3.30:88
admin_server = 172.28.3.30:88
}
firma.cz = {
}
[domain_realm]
.example.com = EXAMPLE.COM
example.com = EXAMPLE.COM
firma.cz = firma.cz
.firma.cz = firma.cz
[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
Neco z toho se nastavilo automaticky, kdyz jsem v nastaveni overovani vybral "Use Winbind Authentication",
ale musel jsem jeste delat nejake rucni upravy. Snad to pomuze.
security = domain ??? Pre Active directory by nemal byt nahodou security = ADS ?
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.