This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
ntlm_авторизация_в_microsoft_ad [2010/08/11 12:16] val |
— (current) | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== NTLM авторизация в Microsoft AD ====== | ||
- | |||
- | ===== Настройка службы winbindd ===== | ||
- | |||
- | <code> | ||
- | gate# cat smb.conf | ||
- | </code><code> | ||
- | [global] | ||
- | workgroup = ADCORPX | ||
- | security = DOMAIN | ||
- | winbind use default domain = Yes | ||
- | |||
- | idmap uid = 20000-40000 | ||
- | idmap gid = 20000-40000 | ||
- | template homedir = /home/%U | ||
- | template shell = /bin/sh | ||
- | winbind enum users = yes | ||
- | winbind enum groups = yes | ||
- | winbind cache time = 36 | ||
- | </code> | ||
- | |||
- | ===== Запуск службы winbindd ===== | ||
- | |||
- | ==== FreeBSD ==== | ||
- | <code> | ||
- | [gate:~] # /usr/local/etc/rc.d/samba restart | ||
- | </code> | ||
- | |||
- | ==== Ubuntu ==== | ||
- | <code> | ||
- | root@gate:~# /etc/init.d/bind9 restart | ||
- | root@gate:~# /etc/init.d/winbind restart | ||
- | </code> | ||
- | |||
- | ==== Проверки ==== | ||
- | <code> | ||
- | gate# ntlm_auth --username=user | ||
- | password: | ||
- | NT_STATUS_OK: Success (0x0) | ||
- | |||
- | gate# wbinfo -u | ||
- | ... | ||
- | |||
- | gate# wbinfo -g | ||
- | ... | ||
- | </code> | ||
- | ===== Настройка библиотеки nsswitch на использование winbind ===== | ||
- | <code> | ||
- | gate# cat /etc/nsswitch.conf | ||
- | … | ||
- | group: files winbind | ||
- | passwd: files winbind | ||
- | shadow: files winbind # for linux only | ||
- | … | ||
- | |||
- | gate# wbinfo -n user | ||
- | gate# wbinfo -S … | ||
- | |||
- | gate# id user | ||
- | |||
- | gate# chown -R user:'domain users' ~user/ | ||
- | gate# chown -R user:'domain users' /var/mail/user | ||
- | </code> | ||