{"id":715,"date":"2020-03-15T03:04:56","date_gmt":"2020-03-14T18:04:56","guid":{"rendered":"https:\/\/wp.study3.biz\/?p=715"},"modified":"2020-03-15T03:05:31","modified_gmt":"2020-03-14T18:05:31","slug":"debian-gnu-linux-bullseye-sid-samba4-11-5-active-directory-domain%e3%81%ae%e6%a7%8b%e7%af%89%e3%81%a8%e5%8b%95%e4%bd%9c%e7%a2%ba%e8%aa%8d","status":"publish","type":"post","link":"https:\/\/wp.study3.biz\/?p=715","title":{"rendered":"Debian GNU\/Linux bullseye\/sid Samba4.11.5 Active Directory Domain\u306e\u69cb\u7bc9\u3068\u52d5\u4f5c\u78ba\u8a8d"},"content":{"rendered":"<p>root@debian:~# samba-tool domain provision\u3000\u3000\u2192Active Directory Domain\u306e\u69cb\u7bc9<br \/>\nRealm: TEST.JP<br \/>\nDomain [TEST]:<br \/>\nServer Role (dc, member, standalone) [dc]:<br \/>\nDNS backend (SAMBA_INTERNAL, BIND9_FLATFILE, BIND9_DLZ, NONE) [SAMBA_INTERNAL]:<br \/>\nDNS forwarder IP address (write &#8216;none&#8217; to disable forwarding) [192.168.1.146]:<br \/>\nAdministrator password:<br \/>\nRetype password:<br \/>\nLooking up IPv4 addresses<br \/>\nLooking up IPv6 addresses<br \/>\nNo IPv6 address will be assigned<br \/>\nSetting up share.ldb<br \/>\nSetting up secrets.ldb<br \/>\nSetting up the registry<br \/>\nSetting up the privileges database<br \/>\nSetting up idmap db<br \/>\nSetting up SAM db<br \/>\nSetting up sam.ldb partitions and settings<br \/>\nSetting up sam.ldb rootDSE<br \/>\nPre-loading the Samba 4 and AD schema<br \/>\nUnable to determine the DomainSID, can not enforce uniqueness constraint on local domainSIDs<\/p>\n<p>Adding DomainDN: DC=test,DC=jp<br \/>\nAdding configuration container<br \/>\nSetting up sam.ldb schema<br \/>\nSetting up sam.ldb configuration data<br \/>\nSetting up display specifiers<br \/>\nModifying display specifiers and extended rights<br \/>\nAdding users container<br \/>\nModifying users container<br \/>\nAdding computers container<br \/>\nModifying computers container<br \/>\nSetting up sam.ldb data<br \/>\nSetting up well known security principals<br \/>\nSetting up sam.ldb users and groups<br \/>\nSetting up self join<br \/>\nRepacking database from v1 to v2 format (first record CN=ms-WMI-MergeablePolicyTemplate,CN=Schema,CN=Configuration,DC=test,DC=jp)<br \/>\nRepack: re-packed 10000 records so far<br \/>\nRepacking database from v1 to v2 format (first record CN=mSMQMigratedUser-Display,CN=40E,CN=DisplaySpecifiers,CN=Configuration,DC=test,DC=jp)<br \/>\nRepacking database from v1 to v2 format (first record CN=6bcd5688-8314-11d6-977b-00c04f613221,CN=Operations,CN=DomainUpdates,CN=System,DC=test,DC=jp)<br \/>\nAdding DNS accounts<br \/>\nCreating CN=MicrosoftDNS,CN=System,DC=test,DC=jp<br \/>\nCreating DomainDnsZones and ForestDnsZones partitions<br \/>\nPopulating DomainDnsZones and ForestDnsZones partitions<br \/>\nRepacking database from v1 to v2 format (first record DC=c.root-servers.net,DC=RootDNSServers,CN=MicrosoftDNS,DC=DomainDnsZones,DC=test,DC=jp)<br \/>\nRepacking database from v1 to v2 format (first record DC=ForestDnsZones,DC=test,DC=jp)<br \/>\nSetting up sam.ldb rootDSE marking as synchronized<br \/>\nFixing provision GUIDs<br \/>\nA Kerberos configuration suitable for Samba AD has been generated at \/var\/lib\/samba\/private\/krb5.conf<br \/>\nMerge the contents of this file with your system krb5.conf or replace it with this one. Do not create a symlink!<br \/>\nOnce the above files are installed, your Samba AD server will be ready to use<br \/>\nServer Role: active directory domain controller<br \/>\nHostname: debian<br \/>\nNetBIOS Domain: TEST<br \/>\nDNS Domain: test.jp<br \/>\nDOMAIN SID: S-1-5-21-4146388153-4193096593-3140523898<\/p>\n<p>root@debian:~# cat \/etc\/os-release<br \/>\nPRETTY_NAME=&#8221;Debian GNU\/Linux bullseye\/sid&#8221;<br \/>\nNAME=&#8221;Debian GNU\/Linux&#8221;<br \/>\nID=debian<br \/>\nHOME_URL=&#8221;https:\/\/www.debian.org\/&#8221;<br \/>\nSUPPORT_URL=&#8221;https:\/\/www.debian.org\/support&#8221;<br \/>\nBUG_REPORT_URL=&#8221;https:\/\/bugs.debian.org\/&#8221;<br \/>\nroot@debian:~# samba -V<br \/>\nVersion 4.11.5-Debian<br \/>\nroot@debian:~# samba -i -M single\u3000\u3000\u00a0\u00a0\u00a0\u00a0 \u2192 Active Directory Domain\u306e\u8d77\u52d5<br \/>\nsamba version 4.11.5-Debian started.<br \/>\nCopyright Andrew Tridgell and the Samba Team 1992-2019<br \/>\nbinary_smbd_main: samba: using &#8216;single&#8217; process model<br \/>\nAttempting to autogenerate TLS self-signed keys for https for hostname &#8216;DEBIAN.test.jp&#8217;<br \/>\nTLS self-signed keys generated OK<\/p>\n<p>root@debian:~# kinit administrator\u3000\u3000\u00a0\u00a0 \u2192Active Directory Domain\u306e\u52d5\u4f5c\u78ba\u8a8d<br \/>\nPassword for administrator@TEST.JP:<br \/>\nWarning: Your password will expire in 41 days on 2020\u5e7404\u670804\u65e5 07\u664232\u520632\u79d2<br \/>\nroot@debian:~# samba-tool user add chibi<br \/>\nNote: samba-tool user add is deprecated. Please use samba-tool user create for the same function.<br \/>\nNew Password:<br \/>\nRetype Password:<br \/>\nUser &#8216;chibi&#8217; created successfully<br \/>\nroot@debian:~# wbinfo -u<br \/>\nTEST\\administrator<br \/>\nTEST\\guest<br \/>\nTEST\\krbtgt<br \/>\nTEST\\chibi<br \/>\nroot@debian:~# wbinfo -n administrator<br \/>\nS-1-5-21-4146388153-4193096593-3140523898-500 SID_USER (1)<br \/>\nroot@debian:~# wbinfo -n chibi<br \/>\nS-1-5-21-4146388153-4193096593-3140523898-1103 SID_USER (1)<br \/>\nroot@debian:~# net ads info<br \/>\nLDAP server: 192.168.1.146<br \/>\nLDAP server name: debian.test.jp<br \/>\nRealm: TEST.JP<br \/>\nBind Path: dc=TEST,dc=JP<br \/>\nLDAP port: 389<br \/>\nServer time: \u571f, 22 2\u6708 2020 07:39:27 JST<br \/>\nKDC server: 192.168.1.146<br \/>\nServer time offset: 0<br \/>\nLast machine account password change: \u571f, 22 2\u6708 2020 07:32:32 JST<br \/>\nroot@debian:~# host -4 debian<br \/>\ndebian.test.jp has address 192.168.1.146<br \/>\nroot@debian:~# host -t SRV _ldap._tcp.test.jp<br \/>\n_ldap._tcp.test.jp has SRV record 0 100 389 debian.test.jp.<br \/>\nroot@debian:~# host -t SRV _kerberos._udp.test.jp<br \/>\n_kerberos._udp.test.jp has SRV record 0 100 88 debian.test.jp.<br \/>\nroot@debian:~# host -t A debian.test.jp<br \/>\ndebian.test.jp has address 192.168.1.146<br \/>\nroot@debian:~# smbclient -L localhost -U%<\/p>\n<p>Sharename Type Comment<br \/>\n&#8212;&#8212;&#8212; &#8212;- &#8212;&#8212;-<br \/>\nsysvol Disk<br \/>\nnetlogon Disk<br \/>\nIPC$ IPC IPC Service (Samba 4.11.5-Debian)<br \/>\nSMB1 disabled &#8212; no workgroup available<br \/>\nroot@debian:~# smbclient \/\/localhost\/netlogon -Uadministrator<br \/>\nEnter TEST\\administrator&#8217;s password:<br \/>\nTry &#8220;help&#8221; to get a list of possible commands.<br \/>\nsmb: \\&gt; ls<br \/>\n. D 0 Sat Feb 22 07:32:29 2020<br \/>\n.. D 0 Sat Feb 22 07:32:31 2020<\/p>\n<p>38958432 blocks of size 1024. 31915828 blocks available<br \/>\nsmb: \\&gt; exit<br \/>\nroot@debian:~# smbclient \/\/localhost\/sysvol -Uadministrator<br \/>\nEnter TEST\\administrator&#8217;s password:<br \/>\nTry &#8220;help&#8221; to get a list of possible commands.<br \/>\nsmb: \\&gt; ls<br \/>\n. D 0 Sat Feb 22 07:32:32 2020<br \/>\n.. D 0 Sat Feb 22 07:38:02 2020<br \/>\ntest.jp D 0 Sat Feb 22 07:32:31 2020<\/p>\n<p>38958432 blocks of size 1024. 31915828 blocks available<br \/>\nsmb: \\&gt; exit<br \/>\nroot@debian:~# net ads lookup<\/p>\n<p><a href=\"https:\/\/wp.study3.biz\/wp-content\/uploads\/2020\/02\/Debian-GNU-Linux-bullseye-sid-samba4.11.5-Acitive-Directory-Domein\u306e\u52d5\u4f5c\u78ba\u8a8d-1.txt\">Debian GNU Linux bullseye sid samba4.11.5 Acitive Directory Domein\u306e\u52d5\u4f5c\u78ba\u8a8d<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>root@debian:~# samba-tool domain provision\u3000\u3000\u2192Active Directory Domain\u306e\u69cb\u7bc9 Realm: TEST.JP Domain [TEST]: Server R &hellip; <a href=\"https:\/\/wp.study3.biz\/?p=715\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13,9],"tags":[],"class_list":["post-715","post","type-post","status-publish","format-standard","hentry","category-debian","category-samba4"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=715"}],"version-history":[{"count":5,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/715\/revisions"}],"predecessor-version":[{"id":730,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=\/wp\/v2\/posts\/715\/revisions\/730"}],"wp:attachment":[{"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.study3.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}