linux:samba4
Különbségek
A kiválasztott változat és az aktuális verzió közötti különbségek a következők.
| Előző változat mindkét oldalonElőző változatKövetkező változat | Előző változat | ||
| linux:samba4 [2025/09/07 19:39] – riba.zoltan | linux:samba4 [2025/09/13 05:05] (aktuális) – riba.zoltan | ||
|---|---|---|---|
| Sor 77: | Sor 77: | ||
| # rpm --import / | # rpm --import / | ||
| - | < | + | </code> |
| Létre kell hozni a samba csomagokat tartalmazó repo fájlt | Létre kell hozni a samba csomagokat tartalmazó repo fájlt | ||
| Sor 130: | Sor 130: | ||
| < | < | ||
| - | # samba-tool domain provision --use-rfc2307 --domain=ADOMAIN --realm=ADOMAIN.LAN | + | # samba-tool domain provision --use-rfc2307 --domain=ADOMAIN --realm=ADOMAIN.LAN |
| INFO 2025-09-06 13: | INFO 2025-09-06 13: | ||
| Sor 168: | Sor 168: | ||
| === Ellenőrzések === | === Ellenőrzések === | ||
| - | Névfeloldáso | + | Konfiguráció érvényessége |
| + | |||
| + | < | ||
| + | # samba-tool testparm | ||
| + | INFO 2025-09-07 21: | ||
| + | INFO 2025-09-07 21: | ||
| + | Press enter to see a dump of your service definitions | ||
| + | |||
| + | # Global parameters | ||
| + | [global] | ||
| + | dns forwarder = 8.8.8.8 | ||
| + | netbios name = DC1 | ||
| + | realm = ADOMAIN.LAN | ||
| + | server role = active directory domain controller | ||
| + | workgroup = ADOMAIN | ||
| + | idmap_ldb: | ||
| + | |||
| + | [sysvol] | ||
| + | path = / | ||
| + | read only = No | ||
| + | |||
| + | [netlogon] | ||
| + | path = / | ||
| + | read only = No | ||
| + | |||
| + | </ | ||
| + | |||
| + | Névfeloldás működése | ||
| < | < | ||
| Sor 186: | Sor 213: | ||
| Aliases: | Aliases: | ||
| - | _ldap._tcp.adomain.lan has SRV record 0 100 389 dc1.adomain.lan.adomain.lan. | + | _ldap._tcp.adomain.lan has SRV record 0 100 389 dc1.adomain.lan. |
| </ | </ | ||
| Sor 197: | Sor 224: | ||
| </ | </ | ||
| - | Kerberos | + | Kerberos |
| < | < | ||
| Sor 249: | Sor 276: | ||
| A tartományba léptetett Windows kliensek a tartományvezérlőt használják időszinkronként. Ennek beállításához szükséges a chrony konfigurációjának módosítása. | A tartományba léptetett Windows kliensek a tartományvezérlőt használják időszinkronként. Ennek beállításához szükséges a chrony konfigurációjának módosítása. | ||
| + | |||
| + | Eredeti konfiguráció (felesleges üres sorok és a kommentezett tartalom nélkül) | ||
| < | < | ||
| + | # cat / | ||
| + | pool 2.almalinux.pool.ntp.org iburst | ||
| + | sourcedir / | ||
| + | driftfile / | ||
| + | makestep 1.0 3 | ||
| + | rtcsync | ||
| + | keyfile / | ||
| + | ntsdumpdir / | ||
| + | leapsectz right/UTC | ||
| + | logdir / | ||
| + | </ | ||
| + | Módosított konfiguráció (engedélyezett kliens tartomány és samba aláíró socket könyvtár megadással) | ||
| + | |||
| + | < | ||
| + | pool 2.almalinux.pool.ntp.org iburst | ||
| + | sourcedir / | ||
| + | driftfile / | ||
| + | makestep 1.0 3 | ||
| + | rtcsync | ||
| + | keyfile / | ||
| + | ntsdumpdir / | ||
| + | leapsectz right/UTC | ||
| + | logdir / | ||
| + | |||
| + | allow 192.168.110.0/ | ||
| + | ntpsigndsocket / | ||
| </ | </ | ||
| + | Zárt hálózaton a *pool* és a *server* sorokat törölni kell és be kell állítani a helyi forrást | ||
| + | |||
| + | < | ||
| + | sourcedir / | ||
| + | driftfile / | ||
| + | makestep 1.0 3 | ||
| + | rtcsync | ||
| + | keyfile / | ||
| + | ntsdumpdir / | ||
| + | leapsectz right/UTC | ||
| + | logdir / | ||
| + | |||
| + | allow 192.168.110.0/ | ||
| + | ntpsigndsocket / | ||
| + | local stratum 10 | ||
| + | </ | ||
| + | |||
| + | Újra kell indítani a szolgáltatást | ||
| + | |||
| + | < | ||
| + | # systemctl restart chronyd | ||
| + | </ | ||
| + | |||
| + | Ellenőrizni kell, hogy a status oldalon megjelenik az ' | ||
| + | |||
| + | Engedélyezni kell a tűzfalon az NTP szolgáltatást | ||
| + | |||
| + | < | ||
| + | # firewall-cmd --permanent --add-service=ntp | ||
| + | success | ||
| + | |||
| + | # firewall-cmd --add-service=ntp | ||
| + | success | ||
| + | </ | ||
| ===== Általános műveletek ===== | ===== Általános műveletek ===== | ||
| Sor 409: | Sor 498: | ||
| ===== Különleges műveletek ===== | ===== Különleges műveletek ===== | ||
| + | |||
| + | ==== LDAP szerkesztő használata ==== | ||
| + | |||
| + | Telepítés | ||
| + | |||
| + | < | ||
| + | # dnf install ldapvi | ||
| + | </ | ||
| + | |||
| + | Használat (jelszó megadása nélkül) | ||
| + | |||
| + | < | ||
| + | EDITOR=mcedit ldapvi -h ldaps:// | ||
| + | </ | ||
| + | |||
| + | Használat (jelszó megadásával) | ||
| + | |||
| + | < | ||
| + | EDITOR=mcedit ldapvi -h ldaps:// | ||
| + | </ | ||
| ==== Tanúsítványok ellenőrzése ==== | ==== Tanúsítványok ellenőrzése ==== | ||
| Sor 437: | Sor 546: | ||
| Alapértelmezetten a Samba/AD környezetben nem olvashatók a felhasználók jelszavai. Az alábbi módszer elérhetővé teszi a felhasználók jelszavait különböző formátumokban. | Alapértelmezetten a Samba/AD környezetben nem olvashatók a felhasználók jelszavai. Az alábbi módszer elérhetővé teszi a felhasználók jelszavait különböző formátumokban. | ||
| + | |||
| + | Az eredeti leírás itt érhető el [[https:// | ||
| Telepítsük a rng-tools csomagot | Telepítsük a rng-tools csomagot | ||
| Sor 555: | Sor 666: | ||
| # echo -n MTIzNDU2Nzg= | base64 -d | # echo -n MTIzNDU2Nzg= | base64 -d | ||
| 12345678 | 12345678 | ||
| + | </ | ||
| + | |||
| + | ===== Linux kliens beléptetése a tartományba ===== | ||
| + | |||
| + | Minimal telepítés után be kell állítani a hálózatot, | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # Generated by NetworkManager | ||
| + | nameserver 192.168.110.11 | ||
| + | </ | ||
| + | |||
| + | ==== Kerberos + LADP (realmd) ==== | ||
| + | |||
| + | Telepíteni kell az alábbi csomagokat | ||
| + | |||
| + | < | ||
| + | # dnf install adcli oddjob oddjob-mkhomedir realmd sssd | ||
| + | </ | ||
| + | |||
| + | Listázni kell a domain adatokat | ||
| + | |||
| + | < | ||
| + | # realm discover ADOMAIN.LAN | ||
| + | adomain.lan | ||
| + | type: kerberos | ||
| + | realm-name: ADOMAIN.LAN | ||
| + | domain-name: | ||
| + | configured: kerberos-member | ||
| + | server-software: | ||
| + | client-software: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | login-formats: | ||
| + | login-policy: | ||
| + | </ | ||
| + | |||
| + | Csatlakozni kell a tartományhoz | ||
| + | |||
| + | < | ||
| + | # realm join ADOMAIN.LAN -U Administrator --client-software=sssd | ||
| + | Password for Administrator@ADOMAIN.LAN: | ||
| + | Warning: Your password will expire in 179 days on Sat Mar 7 12:43:03 2026 | ||
| + | </ | ||
| + | |||
| + | Állítsuk be az SSSD-t mint hitelesítési forrást | ||
| + | |||
| + | < | ||
| + | # authselect select sssd --force | ||
| + | Backup stored at / | ||
| + | Profile " | ||
| + | The following nsswitch maps are overwritten by the profile: | ||
| + | - passwd | ||
| + | - group | ||
| + | - netgroup | ||
| + | - automount | ||
| + | - services | ||
| + | |||
| + | Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. | ||
| + | </ | ||
| + | |||
| + | Engedélyezzük a home könyvtár létrehozását | ||
| + | |||
| + | < | ||
| + | # authselect enable-feature with-mkhomedir | ||
| + | Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. | ||
| + | |||
| + | - with-mkhomedir is selected, make sure pam_oddjob_mkhomedir module | ||
| + | is present and oddjobd service is enabled and active | ||
| + | - systemctl enable --now oddjobd.service | ||
| + | </ | ||
| + | |||
| + | Engedélyezzük és indítsuk el az oddjobd és az sssd szolgáltatásokat | ||
| + | |||
| + | < | ||
| + | # systemctl enable oddjobd sssd | ||
| + | |||
| + | # systemctl restart oddjobd sssd | ||
| + | </ | ||
| + | |||
| + | Csatlakozás ellőrzése kliens oldalon | ||
| + | |||
| + | < | ||
| + | # realm list | ||
| + | adomain.lan | ||
| + | type: kerberos | ||
| + | realm-name: ADOMAIN.LAN | ||
| + | domain-name: | ||
| + | configured: kerberos-member | ||
| + | server-software: | ||
| + | client-software: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | required-package: | ||
| + | login-formats: | ||
| + | login-policy: | ||
| + | </ | ||
| + | |||
| + | Csatlakozás ellenőrzése szerver oldalon | ||
| + | |||
| + | < | ||
| + | # samba-tool computer list | ||
| + | DC1$ | ||
| + | CLIENT1$ | ||
| + | |||
| + | # samba-tool computer show CLIENT1 | ||
| + | dn: CN=CLIENT1, | ||
| + | objectClass: | ||
| + | objectClass: | ||
| + | objectClass: | ||
| + | objectClass: | ||
| + | objectClass: | ||
| + | cn: CLIENT1 | ||
| + | instanceType: | ||
| + | whenCreated: | ||
| + | whenChanged: | ||
| + | uSNCreated: 4297 | ||
| + | name: CLIENT1 | ||
| + | objectGUID: 32f949fe-6606-474f-bbac-3d58953c5c09 | ||
| + | userAccountControl: | ||
| + | badPwdCount: | ||
| + | codePage: 0 | ||
| + | countryCode: | ||
| + | badPasswordTime: | ||
| + | lastLogoff: 0 | ||
| + | primaryGroupID: | ||
| + | objectSid: S-1-5-21-3005407612-655364726-173448620-1107 | ||
| + | accountExpires: | ||
| + | sAMAccountName: | ||
| + | sAMAccountType: | ||
| + | operatingSystem: | ||
| + | dNSHostName: | ||
| + | servicePrincipalName: | ||
| + | servicePrincipalName: | ||
| + | objectCategory: | ||
| + | isCriticalSystemObject: | ||
| + | msDS-SupportedEncryptionTypes: | ||
| + | pwdLastSet: 134018260773846470 | ||
| + | lastLogonTimestamp: | ||
| + | uSNChanged: 4299 | ||
| + | lastLogon: 134018260778089100 | ||
| + | logonCount: 2 | ||
| + | distinguishedName: | ||
| + | </ | ||
| + | |||
| + | Kliens oldalon a csatlakozás után létrejön a / | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | |||
| + | [sssd] | ||
| + | domains = adomain.lan | ||
| + | config_file_version = 2 | ||
| + | services = nss, pam | ||
| + | |||
| + | [domain/ | ||
| + | default_shell = /bin/bash | ||
| + | krb5_store_password_if_offline = True | ||
| + | cache_credentials = True | ||
| + | krb5_realm = ADOMAIN.LAN | ||
| + | realmd_tags = manages-system joined-with-adcli | ||
| + | id_provider = ad | ||
| + | fallback_homedir = /home/%u@%d | ||
| + | ad_domain = adomain.lan | ||
| + | use_fully_qualified_names = True | ||
| + | ldap_id_mapping = True | ||
| + | access_provider = ad | ||
| + | </ | ||
| + | |||
| + | Végezzük el az ellenőrzéseket | ||
| + | |||
| + | < | ||
| + | # sss_cache -E | ||
| + | |||
| + | # systemctl restart sssd | ||
| + | |||
| + | # getent passwd teszt.elek | ||
| + | |||
| + | # getent passwd ADOMAIN\\teszt.elek | ||
| + | teszt.elek@adomain.lan: | ||
| + | |||
| + | # getent passwd teszt.elek@adomain | ||
| + | teszt.elek@adomain.lan: | ||
| + | |||
| + | # getent passwd teszt.elek@adomain.lan | ||
| + | teszt.elek@adomain.lan: | ||
| + | </ | ||
| + | |||
| + | Módosítsuk a beállításokat az alábbiak szerint | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | |||
| + | [sssd] | ||
| + | domains = adomain.lan | ||
| + | config_file_version = 2 | ||
| + | services = nss, pam | ||
| + | |||
| + | [domain/ | ||
| + | default_shell = /bin/bash | ||
| + | krb5_store_password_if_offline = True | ||
| + | cache_credentials = True | ||
| + | krb5_realm = ADOMAIN.LAN | ||
| + | realmd_tags = manages-system joined-with-adcli | ||
| + | id_provider = ad | ||
| + | fallback_homedir = /home/%u | ||
| + | ad_domain = adomain.lan | ||
| + | use_fully_qualified_names = False | ||
| + | ldap_id_mapping = True | ||
| + | access_provider = ad | ||
| + | </ | ||
| + | |||
| + | Végezzük el az ellenőrzést | ||
| + | |||
| + | < | ||
| + | # getent passwd teszt.elek | ||
| + | teszt.elek: | ||
| + | |||
| + | # su - teszt.elek | ||
| + | Creating home directory for teszt.elek. | ||
| + | |||
| + | $ id teszt.elek | ||
| + | uid=1930201104(teszt.elek) gid=1930200513(domain users) groups=1930200513(domain users) | ||
| + | |||
| + | $ exit | ||
| + | </ | ||
| + | |||
| + | ==== LDAP (sssd-ldap) ==== | ||
| + | |||
| + | DC szerveren érdemes létrehozni egy OU-t, amibe a szervíz hozzáférések kerülnek | ||
| + | |||
| + | < | ||
| + | # samba-tool ou add ' | ||
| + | Added ou " | ||
| + | </ | ||
| + | |||
| + | Létre kell hozni az LDAP lekérésekhez egy felhasználót (jelszó ne járjon le) | ||
| + | |||
| + | < | ||
| + | # samba-tool user add ldapbind ' | ||
| + | User ' | ||
| + | |||
| + | # samba-tool user setexpiry ldapbind --noexpiry | ||
| + | Expiry for user ' | ||
| + | </ | ||
| + | |||
| + | Kliens oldalon telepíteni kell az alábbi csomagokat | ||
| + | |||
| + | < | ||
| + | # dnf install authselect sssd-ldap oddjob-mkhomedir | ||
| + | </ | ||
| + | |||
| + | Be kell állítani az SSSD konfigurációs állományát | ||
| + | |||
| + | < | ||
| + | # cat > / | ||
| + | [sssd] | ||
| + | domains = adomain.lan | ||
| + | config_file_version = 2 | ||
| + | services = nss, pam | ||
| + | |||
| + | [domain/ | ||
| + | id_provider = ldap | ||
| + | auth_provider = ldap | ||
| + | chpass_provider = ldap | ||
| + | access_provider = ldap | ||
| + | |||
| + | ldap_uri = ldaps:// | ||
| + | ldap_search_base = DC=adomain, | ||
| + | ldap_schema = ad | ||
| + | ldap_default_bind_dn = CN=ldapbind, | ||
| + | ldap_default_authtok = 12345678 | ||
| + | |||
| + | ldap_id_mapping = True | ||
| + | ldap_referrals = False | ||
| + | ldap_user_search_base = CN=Users, | ||
| + | ldap_group_search_base = CN=Groups, | ||
| + | |||
| + | # SSL / TLS | ||
| + | ldap_tls_reqcert = never | ||
| + | EOF | ||
| + | </ | ||
| + | |||
| + | Állítsuk be az SSSD-t mint hitelesítési forrást | ||
| + | |||
| + | < | ||
| + | # authselect select sssd --force | ||
| + | Backup stored at / | ||
| + | Profile " | ||
| + | The following nsswitch maps are overwritten by the profile: | ||
| + | - passwd | ||
| + | - group | ||
| + | - netgroup | ||
| + | - automount | ||
| + | - services | ||
| + | |||
| + | Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. | ||
| + | </ | ||
| + | |||
| + | Engedélyezzük a home könyvtár létrehozását | ||
| + | |||
| + | < | ||
| + | # authselect enable-feature with-mkhomedir | ||
| + | Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. | ||
| + | |||
| + | - with-mkhomedir is selected, make sure pam_oddjob_mkhomedir module | ||
| + | is present and oddjobd service is enabled and active | ||
| + | - systemctl enable --now oddjobd.service | ||
| + | </ | ||
| + | |||
| + | Engedélyezzük és indítsuk el az oddjobd és az sssd szolgáltatásokat | ||
| + | |||
| + | < | ||
| + | # systemctl enable oddjobd sssd | ||
| + | |||
| + | # systemctl restart oddjobd sssd | ||
| + | </ | ||
| + | |||
| + | Tesztelni kell a beállításokat | ||
| + | |||
| + | < | ||
| + | # id teszt.elek | ||
| + | uid=1930201104(teszt.elek) gid=1930200513(Domain Users) groups=1930200513(Domain Users) | ||
| + | |||
| + | # id teszt.elek@adomain | ||
| + | uid=1930201104(teszt.elek) gid=1930200513(Domain Users) groups=1930200513(Domain Users) | ||
| + | |||
| + | [root@client1 sssd]# id teszt.elek@adomain.lan | ||
| + | uid=1930201104(teszt.elek) gid=1930200513(Domain Users) groups=1930200513(Domain Users) | ||
| + | </ | ||
| + | |||
| + | Új csoport létrehozása a DC szerveren | ||
| + | |||
| + | < | ||
| + | # samba-tool group add logread --description ' | ||
| + | Added group logread | ||
| + | </ | ||
| + | |||
| + | Felhasználó hozzáadása a csoporthoz | ||
| + | |||
| + | < | ||
| + | # samba-tool group addmembers logread teszt.elek | ||
| + | Added members to group logread | ||
| + | </ | ||
| + | |||
| + | Ellenőrzés a kliens oldalon | ||
| + | |||
| + | < | ||
| + | # sss_cache -E | ||
| + | |||
| + | # id teszt.elek | ||
| + | uid=1930201104(teszt.elek) gid=1930200513(Domain Users) groups=1930200513(Domain Users), | ||
| + | |||
| + | # getent group logread | ||
| + | logread: | ||
| + | |||
| + | # getent group ' | ||
| + | Domain Users: | ||
| + | </ | ||
| + | |||
| + | ===== Új tartományvezérlő hozzáadása ===== | ||
| + | |||
| + | Az új tartományvezérlő telepítése és beállítása a provision műveletig megegyezik. | ||
| + | |||
| + | ==== Beállítások mindkét gépen ==== | ||
| + | |||
| + | A replikációs környezet mindkét gépét fel kell venni a /etc/hosts állományba | ||
| + | |||
| + | < | ||
| + | # cat /etc/hosts | ||
| + | 127.0.0.1 | ||
| + | ::1 | ||
| + | |||
| + | 192.168.110.11 dc1.adomain.lan dc1 | ||
| + | 192.168.110.12 dc2.adomain.lan dc2 | ||
| + | </ | ||
| + | |||
| + | Mindkét gépen működnie kell az időszinkron szolgáltatásnak | ||
| + | |||
| + | < | ||
| + | # timedatectl | ||
| + | Local time: Tue 2025-09-09 20:55:34 CEST | ||
| + | | ||
| + | RTC time: n/a | ||
| + | Time zone: Europe/ | ||
| + | System clock synchronized: | ||
| + | NTP service: active | ||
| + | RTC in local TZ: no | ||
| + | </ | ||
| + | |||
| + | Midkét gépnek azonos nyelvi környezettel kell rendelkeznie | ||
| + | |||
| + | < | ||
| + | # localectl | ||
| + | System Locale: LANG=en_US.UTF-8 | ||
| + | VC Keymap: (unset) | ||
| + | X11 Layout: (unset) | ||
| + | </ | ||
| + | |||
| + | ==== Beállítások a replikán ==== | ||
| + | |||
| + | Az elsődleges névszerver a forrás gépre mutasson | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # Generated by NetworkManager | ||
| + | search adomain.lan | ||
| + | nameserver 192.168.110.11 | ||
| + | </ | ||
| + | |||
| + | Csatlakozni kell a meglévő DC-hez | ||
| + | |||
| + | < | ||
| + | # samba-tool domain join adomain.lan DC -U administrator@ADOMAIN.LAN | ||
| + | INFO 2025-09-09 20: | ||
| + | </ | ||
| + | |||
| + | Hasonlítsuk össze a forrás és a cél DC samba konfigurációját | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # Global parameters | ||
| + | [global] | ||
| + | dns forwarder = 8.8.8.8, 8.8.4.4 | ||
| + | netbios name = DC2 | ||
| + | realm = ADOMAIN.LAN | ||
| + | server role = active directory domain controller | ||
| + | workgroup = ADOMAIN | ||
| + | idmap_ldb: | ||
| + | ad dc functional level = 2016 | ||
| + | |||
| + | [sysvol] | ||
| + | path = / | ||
| + | read only = No | ||
| + | |||
| + | [netlogon] | ||
| + | path = / | ||
| + | read only = No | ||
| + | </ | ||
| + | |||
| + | El kell indítani a samba szolgáltatást | ||
| + | |||
| + | < | ||
| + | # systemctl --now enable samba | ||
| + | </ | ||
| + | |||
| + | Ellenőrizni kell a replikációt | ||
| + | |||
| + | < | ||
| + | # host -t SRV _ldap._tcp.adomain.lan | ||
| + | _ldap._tcp.adomain.lan has SRV record 0 100 389 dc1.adomain.lan. | ||
| + | _ldap._tcp.adomain.lan has SRV record 0 100 389 dc2.adomain.lan. | ||
| + | |||
| + | # host -t SRV _kerberos._tcp.adomain.lan | ||
| + | _kerberos._tcp.adomain.lan has SRV record 0 100 88 dc1.adomain.lan. | ||
| + | _kerberos._tcp.adomain.lan has SRV record 0 100 88 dc2.adomain.lan. | ||
| + | </ | ||
| + | |||
| + | Utolsó lépésként módosítsuk a névszerver beállításokat | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # Generated by NetworkManager | ||
| + | search adomain.lan | ||
| + | nameserver 192.168.110.11 | ||
| + | nameserver 192.168.110.12 | ||
| + | </ | ||
| + | |||
| + | ==== Beállítások a forrás gépen ==== | ||
| + | |||
| + | Ellenőrizzük a replikációt | ||
| + | |||
| + | < | ||
| + | # samba-tool drs showrepl | ||
| + | Default-First-Site-Name\DC1 | ||
| + | DSA Options: 0x00000001 | ||
| + | DSA object GUID: 1d002858-83a4-4629-8de8-af0d62cf1cff | ||
| + | DSA invocationId: | ||
| + | |||
| + | ==== INBOUND NEIGHBORS ==== | ||
| + | |||
| + | DC=adomain, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ Tue Sep 9 21:06:01 2025 CEST was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ Tue Sep 9 21:06:01 2025 CEST | ||
| + | |||
| + | DC=DomainDnsZones, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ Tue Sep 9 21:06:01 2025 CEST was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ Tue Sep 9 21:06:01 2025 CEST | ||
| + | |||
| + | DC=ForestDnsZones, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ Tue Sep 9 21:06:01 2025 CEST was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ Tue Sep 9 21:06:01 2025 CEST | ||
| + | |||
| + | CN=Configuration, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ Tue Sep 9 21:06:01 2025 CEST was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ Tue Sep 9 21:06:01 2025 CEST | ||
| + | |||
| + | CN=Schema, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ Tue Sep 9 21:06:01 2025 CEST was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ Tue Sep 9 21:06:01 2025 CEST | ||
| + | |||
| + | ==== OUTBOUND NEIGHBORS ==== | ||
| + | |||
| + | DC=adomain, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ NTTIME(0) was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ NTTIME(0) | ||
| + | |||
| + | DC=DomainDnsZones, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ NTTIME(0) was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ NTTIME(0) | ||
| + | |||
| + | DC=ForestDnsZones, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ NTTIME(0) was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ NTTIME(0) | ||
| + | |||
| + | CN=Configuration, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ NTTIME(0) was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ NTTIME(0) | ||
| + | |||
| + | CN=Schema, | ||
| + | Default-First-Site-Name\DC2 via RPC | ||
| + | DSA object GUID: 45997a6c-ae6d-4350-affc-b42b182fd457 | ||
| + | Last attempt @ NTTIME(0) was successful | ||
| + | 0 consecutive failure(s). | ||
| + | Last success @ NTTIME(0) | ||
| + | |||
| + | ==== KCC CONNECTION OBJECTS ==== | ||
| + | |||
| + | Connection -- | ||
| + | Connection name: 73416208-dc03-4633-9d5b-4bbe13aba35c | ||
| + | Enabled | ||
| + | Server DNS name : dc2.adomain.lan | ||
| + | Server DN name : CN=NTDS Settings, | ||
| + | TransportType: | ||
| + | options: 0x00000001 | ||
| + | Warning: No NC replicated for Connection! | ||
| + | </ | ||
| + | |||
| + | Végezzük el az adatbázisok ellenőrzését | ||
| + | |||
| + | < | ||
| + | # samba-tool dbcheck --cross-ncs | ||
| + | Checking 3863 objects | ||
| + | WARNING: target DN is deleted for msDS-NC-Replica-Locations in object CN=536ea47c-3ac9-47b5-a87c-7eb4c03be986, | ||
| + | Target GUID points at deleted DN ' | ||
| + | Not removing | ||
| + | WARNING: target DN is deleted for msDS-NC-Replica-Locations in object CN=c508580e-94dd-48fe-b75c-2d860812cd11, | ||
| + | Target GUID points at deleted DN ' | ||
| + | Not removing | ||
| + | NOTE: old (due to rename or delete) DN string component for lastKnownParent in object CN=NTDS Settings\0ADEL: | ||
| + | Not fixing old string component | ||
| + | Checked 3863 objects (2 errors) | ||
| + | Please use ' | ||
| + | </ | ||
| + | |||
| + | Hiba esetén javítsuk és ellenőrizzük újra | ||
| + | |||
| + | < | ||
| + | # samba-tool dbcheck --cross-ncs --fix | ||
| + | Checking 3863 objects | ||
| + | WARNING: target DN is deleted for msDS-NC-Replica-Locations in object CN=536ea47c-3ac9-47b5-a87c-7eb4c03be986, | ||
| + | Target GUID points at deleted DN ' | ||
| + | Remove stale DN link? [y/ | ||
| + | Removed deleted DN on attribute msDS-NC-Replica-Locations | ||
| + | WARNING: target DN is deleted for msDS-NC-Replica-Locations in object CN=c508580e-94dd-48fe-b75c-2d860812cd11, | ||
| + | Target GUID points at deleted DN ' | ||
| + | Remove stale DN link? [y/ | ||
| + | Removed deleted DN on attribute msDS-NC-Replica-Locations | ||
| + | NOTE: old (due to rename or delete) DN string component for lastKnownParent in object CN=NTDS Settings\0ADEL: | ||
| + | Change DN to < | ||
| + | Fixed old DN string on attribute lastKnownParent | ||
| + | Checked 3863 objects (2 errors) | ||
| + | |||
| + | # samba-tool dbcheck --cross-ncs | ||
| + | Checking 3863 objects | ||
| + | Checked 3863 objects (0 errors) | ||
| + | </ | ||
| + | |||
| + | Állítsuk be a névszervereket | ||
| + | |||
| + | < | ||
| + | # cat / | ||
| + | # Generated by NetworkManager | ||
| + | search adomain.lan | ||
| + | nameserver 192.168.110.12 | ||
| + | nameserver 192.168.110.11 | ||
| </ | </ | ||
linux/samba4.1757273955.txt.gz · Utolsó módosítás: szerkesztette: riba.zoltan
