User Tools

Site Tools


настройка_сети_для_использования_kerberos

This is an old revision of the document!


Настройка сети для использования KERBEROS

Настройка DNS сервера

FreeBSD

[server:~] # cat /etc/rc.conf
...
named_enable="YES"
...

[server:~] # cat /etc/namedb/named.conf 
options {
        directory       "/etc/namedb";
        pid-file        "/var/run/named/pid";
};

zone "." {
        type hint;
        file "named.root";
};

zone "corpX.un" {
        type master;
        file "master/corpX.un";
};

zone "X.168.192.IN-ADDR.ARPA" {
        type master;
        file "master/corpX.rev";
};

Ubuntu

root@server:~# apt-get install bind9

root@server:~# cat /etc/bind/named.conf.local
zone "corpX.un" {
        type master;
        file "/var/cache/bind/corpX.un";
};

zone "X.168.192.in-addr.arpa" {
        type master;
        file "/var/cache/bind/corpX.rev";
};

Описание файлов зон

FreeBSD

server# cd /etc/namedb/master/

Ubuntu

server# cd /var/cache/bind/

FreeBSD/Ubuntu

server# cat corpX.un
$TTL    3h
@                   SOA     server root.server  1 1d 12h 1w 3h
                    NS      server
server              A       192.168.X.10
gate                A       192.168.X.1
_kerberos._udp      SRV     01 00 88 server
_kerberos._tcp      SRV     01 00 88 server
_kpasswd._udp       SRV     01 00 464 server
_kerberos-adm._tcp  SRV     01 00 749 server
_kerberos           TXT     CORPX.UN
server# cat corpX.rev 
$TTL    3h
@       SOA     server.corpX.un. root.server.corpX.un.  1 1d 12h 1w 3h
        NS      server.corpX.un.
10      PTR     server.corpX.un.
1       PTR     gate.corpX.un.
server# named-checkconf -z

Запуск сервиса

FreeBSD

[server:~] # /etc/rc.d/named start

Ubuntu

root@server:~# /etc/init.d/bind9 restart

Настройки DNS клиентов

server# cat /etc/resolv.conf
domain corpX.un
nameserver 127.0.0.1

gate# cat /etc/resolv.conf
domain corpX.un
nameserver 192.168.X.10

client1# cat /etc/resolv.conf
domain corpX.un
nameserver 192.168.X.10

Проверки (на gate client1 и server)

# host ya.ru
# host gate.corpX.un
# host server.corpX.un
# host 192.168.X.10
# host 192.168.X.1
# dig TXT _kerberos.corpX.un
# dig SRV _kerberos._tcp.corpX.un

Cинхронизация времени (может потребоваться рестарт служб NIS, NFS и RPCBIND)

FreeBSD

# cp /usr/share/zoneinfo/Europe/Moscow /etc/localtime

# ntpdate time.apple.com

Ubuntu

# cp /usr/share/zoneinfo/Europe/Moscow /etc/localtime

# ntpdate time.apple.com
настройка_сети_для_использования_kerberos.1291715575.txt.gz · Last modified: 2013/05/22 13:50 (external edit)