{"id":12367,"date":"2019-12-16T02:33:48","date_gmt":"2019-12-15T17:33:48","guid":{"rendered":"https:\/\/wp.study3.biz\/?p=12367"},"modified":"2022-08-10T13:43:42","modified_gmt":"2022-08-10T04:43:42","slug":"freebsd-13-0-current-r349025-samba4-8-12-active-directory-domain-controller%e3%81%ae%e6%a7%8b%e7%af%89%e3%81%a8%e5%8b%95%e4%bd%9c%e7%a2%ba%e8%aa%8d","status":"publish","type":"post","link":"https:\/\/wp.study3.biz\/?p=12367","title":{"rendered":"FreeBSD 13.0-CURRENT r349025  Samba4.8.12 Active Directory Domain Controller\u306e\u69cb\u7bc9\u3068\u52d5\u4f5c\u78ba\u8a8d"},"content":{"rendered":"<p>root@freebsd:~ # samba-tool domain provision<br \/>\nRealm: TEST.JP<br \/>\n Domain [TEST]:<br \/>\n Server Role (dc, member, standalone) [dc]:<br \/>\n DNS backend (SAMBA_INTERNAL, BIND9_FLATFILE, BIND9_DLZ, NONE) [SAMBA_INTERNAL]:<br \/>\n DNS forwarder IP address (write &#8216;none&#8217; to disable forwarding) [192.168.1.165]:<br \/>\nAdministrator password:<br \/>\nRetype password:<br \/>\nLooking up IPv4 addresses<br \/>\nLooking up IPv6 addresses<br \/>\nSetting up share.ldb<br \/>\nSetting up secrets.ldb<br \/>\nSetting up the registry<br \/>\nSetting up the privileges database<br \/>\nSetting up idmap db<br \/>\nSetting up SAM db<br \/>\nSetting up sam.ldb partitions and settings<br \/>\nSetting up sam.ldb rootDSE<br \/>\nPre-loading the Samba 4 and AD schema<br \/>\nUnable to determine the DomainSID, can not enforce uniqueness constraint on local domainSIDs<\/p>\n<p>Adding DomainDN: DC=test,DC=jp<br \/>\nAdding configuration container<br \/>\nSetting up sam.ldb schema<br \/>\nSetting up sam.ldb configuration data<br \/>\nSetting up display specifiers<br \/>\nModifying display specifiers and extended rights<br \/>\nAdding users container<br \/>\nModifying users container<br \/>\nAdding computers container<br \/>\nModifying computers container<br \/>\nSetting up sam.ldb data<br \/>\nSetting up well known security principals<br \/>\nSetting up sam.ldb users and groups<br \/>\nSetting up self join<br \/>\nAdding DNS accounts<br \/>\nCreating CN=MicrosoftDNS,CN=System,DC=test,DC=jp<br \/>\nCreating DomainDnsZones and ForestDnsZones partitions<br \/>\nPopulating DomainDnsZones and ForestDnsZones partitions<br \/>\nSetting up sam.ldb rootDSE marking as synchronized<br \/>\nFixing provision GUIDs<br \/>\nA Kerberos configuration suitable for Samba AD has been generated at \/var\/db\/samba4\/private\/krb5.conf<br \/>\nMerge the contents of this file with your system krb5.conf or replace it with this one. Do not create a symlink!<br \/>\nOnce the above files are installed, your Samba AD server will be ready to use<br \/>\nServer Role:           active directory domain controller<br \/>\nHostname:              freebsd<br \/>\nNetBIOS Domain:        TEST<br \/>\nDNS Domain:            test.jp<br \/>\nDOMAIN SID:            S-1-5-21-1593849174-3160430826-2334651641<br \/>\n<a href=\"http:\/\/wp.study3.biz\/wp-content\/uploads\/2019\/06\/bf096db70a6a4e41a3d0f8c5b23b75b1.txt\">FreeBSD 13.0-CURRENT r349025 Samba4.8.12 Active Directory Domain Controller\u306e\u69cb\u7bc9<\/a><br \/>\nroot@freebsd:~ # kinit administrator<br \/>\nadministrator@TEST.JP&#8217;s Password:<br \/>\nroot@freebsd:~ # klist<br \/>\nCredentials cache: FILE:\/tmp\/krb5cc_0<br \/>\n        Principal: administrator@TEST.JP<\/p>\n<p>  Issued                Expires               Principal<br \/>\nJun 17 19:47:20 2019  Jun 18 05:47:20 2019  krbtgt\/TEST.JP@TEST.JP<br \/>\nroot@freebsd:~ # samba-tool user add chibi<br \/>\nNote: samba-tool user add is deprecated.  Please use samba-tool user create for the same function.<br \/>\nNew Password:<br \/>\nRetype Password:<br \/>\nUser &#8216;chibi&#8217; created successfully<br \/>\nroot@freebsd:~ # wbinfo -u<br \/>\nTEST\\administrator<br \/>\nTEST\\guest<br \/>\nTEST\\krbtgt<br \/>\nTEST\\chibi<br \/>\nroot@freebsd:~ # wbinfo -n chibi<br \/>\nS-1-5-21-1593849174-3160430826-2334651641-1103 SID_USER (1)<br \/>\nroot@freebsd:~ # net ads info<br \/>\nLDAP server: 192.168.1.165<br \/>\nLDAP server name: freebsd.test.jp<br \/>\nRealm: TEST.JP<br \/>\nBind Path: dc=TEST,dc=JP<br \/>\nLDAP port: 389<br \/>\nServer time: Mon, 17 Jun 2019 19:48:09 JST<br \/>\nKDC server: 192.168.1.165<br \/>\nServer time offset: 0<br \/>\nLast machine account password change: Mon, 17 Jun 2019 19:46:18 JST<br \/>\nroot@freebsd:~ # host -4 freebsd<br \/>\nfreebsd.test.jp has address 192.168.1.165<br \/>\nfreebsd.test.jp has IPv6 address 2400:4052:46e0:b700:20c:29ff:fecf:8bce<br \/>\nroot@freebsd:~ # host -t SRV _ldap._tcp.test.jp<br \/>\n_ldap._tcp.test.jp has SRV record 0 100 389 freebsd.test.jp.<br \/>\nroot@freebsd:~ # host -t SRV _kerberos._udp.test.jp<br \/>\n_kerberos._udp.test.jp has SRV record 0 100 88 freebsd.test.jp.<br \/>\nroot@freebsd:~ # host -t A freebsd.test.jp.<br \/>\nfreebsd.test.jp has address 192.168.1.165<br \/>\nroot@freebsd:~ # smbclient -L localhost -U%<br \/>\n<a href=\"http:\/\/wp.study3.biz\/wp-content\/uploads\/2019\/06\/80d2dab602c4da7633f08f5bef73ce05.txt\">FreeBSD 13.0-CURRENT r349025 Samba4.8.12 Active Directory Domain Controller\u306e\u52d5\u4f5c\u78ba\u8a8d<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>root@freebsd:~ # samba-tool domain provision Realm: TEST.JP Domain [TEST]: Server Role (dc, member, standalone &hellip; <a href=\"https:\/\/wp.study3.biz\/?p=12367\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[8,9],"tags":[],"class_list":["post-12367","post","type-post","status-publish","format-standard","hentry","category-freebsd","category-samba4"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/12367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12367"}],"version-history":[{"count":2,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/12367\/revisions"}],"predecessor-version":[{"id":12371,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/12367\/revisions\/12371"}],"wp:attachment":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}