ntlm_аутентификация_в_microsoft_ad

This is an old revision of the document!


NTLM аутентификация в Microsoft AD

Настройка службы winbindd

FreeBSD

[gate:~] # /usr/local/etc/rc.d/samba stop

[gate:~] # cat /etc/rc.conf
…
nmbd_enable="NO"
smbd_enable="NO"
winbindd_enable="YES"
…

[gate:~] # cd /usr/local/etc/

Ubuntu (8.04)

root@gate:~# /etc/init.d/samba stop

Ubuntu (10.04)

root@gate:~# stop nmbd
root@gate:~# stop smbd

Ubuntu

root@gate:~# apt-get install winbind

root@gate:~# cd /etc/samba

FreeBSD/Ubuntu

gate# cat smb.conf 
[global]
        workgroup = CORPX
        security = DOMAIN
        winbind use default domain = Yes

Регистрация службы winbindd в домене

gate# net rpc join -U Administrator
Administrators's password: 
Joined domain CORPX

Запуск службы winbindd

FreeBSD

[gate:~] # /usr/local/etc/rc.d/samba start

Ubuntu

root@gate:~# /etc/init.d/bind9 restart

root@gate:~# /etc/init.d/winbind restart

Проверки

gate# ntlm_auth --username=user
password: 
NT_STATUS_OK: Success (0x0)

Настройка библиотеки pam на использование winbind

FreeBSD

[gate:~] # cat /etc/pam.d/sshd
...
auth       sufficient      /usr/local/lib/pam_winbind.so
auth       required        pam_unix.so             no_warn try_first_pass

Ubuntu

root@gate:~# apt-get install libpam-modules

root@gate:~# more /etc/pam.d/sshd
...
auth       sufficient  pam_winbind.so
# Standard Un*x authentication.
...
ntlm_аутентификация_в_microsoft_ad.1284541978.txt.gz · Last modified: 2013/05/22 13:50 (external edit)