| 1 | # Install samba-dc and provision master into LXC container
|
| 2 | apt-get install samba-dc
|
| 3 |
|
| 4 | rm -rf /etc/samba/smb.conf
|
| 5 | samba-tool domain provision --domain DEV --realm=dev.srt.basealt.ru --site infra --dns-backend=SAMBA_INTERNAL --server-role=dc --function-level=2016 --use-rfc2307 --backend-store=mdb --option="ad dc functional level = 2016"
|
| 6 | sed -i '/\[global\]/a \\tad dc functional level = 2016' /etc/samba/smb.conf
|
| 7 |
|
| 8 | systemctl enable samba.service
|
| 9 | systemctl start samba.service
|
| 10 |
|
| 11 | # Install bind dns
|
| 12 | apt-get install bind
|
| 13 | control bind-chroot disabled
|
| 14 | sed -i '/options {/a \\ttkey-gssapi-keytab "/var/lib/samba/bind-dns/dns.keytab";' /etc/bind/options.conf
|
| 15 | sed -i '/options {/a \\tminimal-responses yes;' /etc/bind/options.conf
|
| 16 | sed -i -E 's/^([ \t]*)(listen-on\s+\{.*\};)$/\1\/\/\2/g' /etc/bind/options.conf
|
| 17 | sed -i -E 's/^([ \t]*)(listen-on-v6\s+\{.*\};)$/\1\/\/\2/g' /etc/bind/options.conf
|
| 18 | sed -i -E 's/^([ \t]*)\/\/(forwarders\s+\{).*(\};)$/\1\2 10.64.224.3; 10.64.0.16; 10.64.0.17; \3/g' /etc/bind/options.conf
|
| 19 | sed -i -E 's/^([ \t]*)\/\/(allow-query\s+\{).*(\};)$/\1\2 any; \3/g' /etc/bind/options.conf
|
| 20 | sed -i -E 's/^([ \t]*)\/\/(allow-recursion\s+\{).*(\};)$/\1\2 any; \3/g' /etc/bind/options.conf
|
| 21 | echo 'include "/var/lib/samba/bind-dns/named.conf";' >> /etc/bind/named.conf
|
| 22 | sed -i -E '/\[global\]/a \\tserver services = -dns' /etc/samba/smb.conf
|
| 23 |
|
| 24 | systemctl stop samba
|
| 25 | systemctl start bind
|
| 26 | systemctl start samba
|
| 27 |
|
| 28 | # Domain auth in DC
|
| 29 | apt-get install task-auth-ad-winbind gpupdate alterator-roles-common
|
| 30 | sed -i -E 's/^[ #]?(dns_lookup_realm)\s+=\s+[a-zA-Z]+$/ \1 = false/' /etc/krb5.conf
|
| 31 | sed -i -E 's/^[ #]+(default_realm)\s+=\s+[a-zA-Z.-]+$/ \1 = DEV.SRT.BASEALT.RU/' /etc/krb5.conf
|
| 32 |
|
| 33 | /etc/samba/smb.conf:
|
| 34 | [Global]
|
| 35 | ## Local domain auth
|
| 36 | kerberos method = dedicated keytab
|
| 37 | dedicated keytab file = /etc/krb5.keytab
|
| 38 | template shell = /bin/bash
|
| 39 | template homedir = /home/%D/%U
|
| 40 | wins support = no
|
| 41 | winbind use default domain = yes
|
| 42 | winbind enum users = no
|
| 43 | winbind enum groups = no
|
| 44 | winbind refresh tickets = yes
|
| 45 | winbind offline logon = yes
|
| 46 |
|
| 47 | /etc/nsswitch.conf:
|
| 48 | passwd: files winbind systemd
|
| 49 | shadow: tcb files winbind
|
| 50 | group: files [SUCCESS=merge] winbind systemd role
|
| 51 |
|
| 52 | control system-auth winbind
|
| 53 | control sudowheel enabled
|
| 54 | net ads keytab create
|
| 55 | roleadd 'domain users' users
|
| 56 | roleadd 'domain admins' localadmins
|
| 57 | systemctl restart samba.service
|
| 58 | gpupdate-setup enable --local-policy ad-domain-controller
|