<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.kitsnet.us/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2603%3A7000%3A9800%3A4742%3A69A9%3A3976%3A3F81%3A221B</id>
	<title>KitsNet - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.kitsnet.us/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2603%3A7000%3A9800%3A4742%3A69A9%3A3976%3A3F81%3A221B"/>
	<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/wiki/Special:Contributions/2603:7000:9800:4742:69A9:3976:3F81:221B"/>
	<updated>2026-10-07T19:51:45Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Linux:Samba_AD_Factory&amp;diff=85</id>
		<title>Linux:Samba AD Factory</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Linux:Samba_AD_Factory&amp;diff=85"/>
		<updated>2021-05-16T17:20:39Z</updated>

		<summary type="html">&lt;p&gt;2603:7000:9800:4742:69A9:3976:3F81:221B: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;To use [https://www.samba.org/ Samba] as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD &amp;quot;Factory&amp;quot;, where [https://www.samba.org/samba/download/ source kits] will be downloaded and built into binaries under the &amp;lt;code&amp;gt;/usr/local/samba&amp;lt;/code&amp;gt; directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the &#039;&#039;knada.lan.kitsnet.us&#039;&#039; domain. &amp;lt;blockquote&amp;gt;&#039;&#039;There is still an issue with serving time from the DCs. The answer will be found by going through https://wiki.samba.org/index.php/Time_Synchronisation&#039;&#039; &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Build CentOS 8 / Rocky Linux 8 Base System for Factory ==&lt;br /&gt;
The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]&amp;lt;/ref&amp;gt; with 1.5&amp;amp;nbsp;GB RAM, 4 vCPU and two disks:&lt;br /&gt;
&lt;br /&gt;
* T0 disk0 10&amp;amp;nbsp;GB (V0uv&#039;&#039;###&#039;&#039; /tmp 1024&amp;amp;nbsp;MB, /swap 512&amp;amp;nbsp;MB, /boot 1&amp;amp;nbsp;GB, and the rest for root)&lt;br /&gt;
* T3 disk1 16&amp;amp;nbsp;GB (V3uv&#039;&#039;###&#039;&#039; /var 3&amp;amp;nbsp;GB, /usr/local 13&amp;amp;nbsp;GB)&lt;br /&gt;
&lt;br /&gt;
The system will have a DHCP reservation as &amp;lt;code&amp;gt;&amp;lt;&#039;&#039;new-guest&#039;&#039;&amp;gt;.lan.kitsnet.us&amp;lt;/code&amp;gt;. When running the Anaconda installer, add to &amp;lt;u&amp;gt;Software Selection&amp;lt;/u&amp;gt;,  &amp;lt;u&amp;gt;Additional software for Selected Environment&amp;lt;/u&amp;gt;:  &#039;&#039;Development Tools&#039;&#039; .&lt;br /&gt;
== Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC ==&lt;br /&gt;
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt; with 1.5&amp;amp;nbsp;GB RAM, 2 vCPU and two disks:&lt;br /&gt;
&lt;br /&gt;
* T0 disk0 14&amp;amp;nbsp;GB (V0uv&#039;&#039;###&#039;&#039; /tmp 512&amp;amp;nbsp;MB, /swap 3&amp;amp;nbsp;GB, /boot 1&amp;amp;nbsp;GB, root 7&amp;amp;nbsp;GB)&lt;br /&gt;
* T3 disk1 4&amp;amp;nbsp;GB (V3uv&#039;&#039;###&#039;&#039; /var 2&amp;amp;nbsp;GB)&lt;br /&gt;
&lt;br /&gt;
Since these system will be domain-joined, it is important that they have a DHCP reservation as &amp;lt;code&amp;gt;&amp;lt;&#039;&#039;new-guest&#039;&#039;&amp;gt;.&#039;&#039;&#039;knada&#039;&#039;&#039;.lan.kitsnet.us&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
=== Environment Customization ===&lt;br /&gt;
&lt;br /&gt;
==== path ====&lt;br /&gt;
&lt;br /&gt;
* add &amp;lt;code&amp;gt;/usr/local/samba/bin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; to: &lt;br /&gt;
**&amp;lt;code&amp;gt;secure_path&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/sudoers&amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/crontab&amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/anacrontab&amp;lt;/code&amp;gt;&lt;br /&gt;
* carefully add &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/usr/local/samba/bin&amp;lt;/code&amp;gt; appropriately (check order) to &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in /etc/csh.login &lt;br /&gt;
* add  &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;pathmunge&amp;lt;/code&amp;gt; in /etc/profile:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;&lt;br /&gt;
if [ &amp;quot;$EUID&amp;quot; = &amp;quot;0&amp;quot; ]; then&lt;br /&gt;
    pathmunge /usr/sbin&lt;br /&gt;
    pathmunge /usr/local/sbin&lt;br /&gt;
    pathmunge /usr/local/samba/sbin&lt;br /&gt;
    pathmunge /usr/local/samba/bin after&lt;br /&gt;
else&lt;br /&gt;
    pathmunge /usr/local/sbin after&lt;br /&gt;
    pathmunge /usr/sbin after&lt;br /&gt;
    pathmunge /usr/local/samba/sbin after&lt;br /&gt;
    pathmunge /usr/local/samba/bin&lt;br /&gt;
fi&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Firewall ====&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# firewall-cmd --set-default-zone=internal&lt;br /&gt;
# firewall-cmd --zone=internal --change-interface ens3 --permanent&lt;br /&gt;
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent&lt;br /&gt;
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent&lt;br /&gt;
# firewall-cmd --reload&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== Port Reference =====&lt;br /&gt;
&lt;br /&gt;
* 88=kerberos &lt;br /&gt;
* 135=epmap &lt;br /&gt;
* 137=netbios-ns &lt;br /&gt;
* 138=netbios-dgm &lt;br /&gt;
* 139=netbios-ssn &lt;br /&gt;
* 389=ldap &lt;br /&gt;
* 445=microsoft-ds &lt;br /&gt;
* 464=kpasswd &lt;br /&gt;
* 636=ldaps &lt;br /&gt;
* 3268=msft-gc &lt;br /&gt;
&lt;br /&gt;
* 3269=msft-gc-ssl&lt;br /&gt;
&lt;br /&gt;
==== Backup ====&lt;br /&gt;
Copy &amp;lt;code&amp;gt;backup_samba-ad-dc&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;/usr/local/sbin/&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# mkdir /var/lib/samba-ad-dc_backup&lt;br /&gt;
# chgrp kitsnet_adm  /var/lib/samba-ad-dc_backup&lt;br /&gt;
# chmod o-rx /var/lib/samba-ad-dc_backup&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== rsyslog ====&lt;br /&gt;
&lt;br /&gt;
* add to end of &amp;lt;code&amp;gt;/etc/rsyslog.conf&amp;lt;/code&amp;gt; the line &amp;lt;code&amp;gt;*.*  @192.168.15.80:514&amp;lt;/code&amp;gt; &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# systemctl restart rsyslog.service&lt;br /&gt;
# systemctl enable rsyslog.service&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setup Server to Build or Run Samba AD DC ==&lt;br /&gt;
Complete the preparations documented in [https://wiki.samba.org/index.php/https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Active_Directory_Domain_Controller Setting up Samba as an Active Directory Domain Controller]&lt;br /&gt;
&lt;br /&gt;
=== Factory Build Server Packages ===&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba Package Dependencies Required to Build Samba] and incorporate the [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba#Manually_maintained_Distribution-specific_Package_lists Manually maintained Distribution-specific Package lists] and the Red Hat Enterprise Linux 8 / CentOS 8 section. It will also be necessary to &amp;lt;code&amp;gt;dnf install dbus-devel python3-markdown&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Samba AD DC Server Packages ===&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# dnf install avahi-libs cups-libs python3-markdown patch pam-devel python3-cryptography python3-dns krb5-workstation libtasn1-tools &lt;br /&gt;
# dnf install lmdb-devel&lt;br /&gt;
# mkdir /usr/local/samba&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Check Filesystem Support on all Servers ===&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/File_System_Support File System Support] for details KistNet standard is for using xfs, so there is only one option to check for:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# uname -r&lt;br /&gt;
4.18.0-240.22.1.el8_3.x86_64&lt;br /&gt;
# grep -E &amp;quot;CONFIG_EXT4_FS_POSIX_ACL&amp;quot; /boot/config-4.18.0-240.22.1.el8_3.x86_64&lt;br /&gt;
CONFIG_EXT4_FS_POSIX_ACL=y&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;Install the &amp;lt;code&amp;gt;attr&amp;lt;/code&amp;gt; package with &amp;lt;code&amp;gt;dnf install attr&amp;lt;/code&amp;gt;. Next, refer to the [https://wiki.samba.org/index.php/File_System_Support#Testing_your_filesystem Testing your filesystem] section of the documentation for the verification steps&lt;br /&gt;
&lt;br /&gt;
== Download Samba Source to Factory Build Server ==&lt;br /&gt;
&lt;br /&gt;
* Create the base of the Factory source directory structure&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# mkdir /usr/local/SambaAD-Factory&lt;br /&gt;
# chown psmode:kitsnet_adm /usr/local/SambaAD-Factory&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Check https://download.samba.org/pub/samba/stable/ to identify the latest &amp;lt;code&amp;gt;*.tar.gz&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;wget&amp;lt;/code&amp;gt; that file &lt;br /&gt;
* &amp;lt;code&amp;gt;tar -xzvf&amp;lt;/code&amp;gt; the downloaded file with &amp;lt;code&amp;gt;-C /usr/local/SambaAD-Factory&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Build Samba AD DC Factory Distribution ==&lt;br /&gt;
Enter the version-specific directory under &amp;lt;code&amp;gt;/usr/local/SambaAD-Factory&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ ./configure --mandir=/usr/local/samba/man&lt;br /&gt;
$ make uninstall&lt;br /&gt;
$ du /usr/local/samba&lt;br /&gt;
0 /usr/local/samba/etc&lt;br /&gt;
0 /usr/local/samba/var/lib&lt;br /&gt;
0 /usr/local/samba/var/locks&lt;br /&gt;
0 /usr/local/samba/var/cache&lt;br /&gt;
0 /usr/local/samba/var/lock&lt;br /&gt;
0 /usr/local/samba/var/run&lt;br /&gt;
0 /usr/local/samba/var&lt;br /&gt;
0 /usr/local/samba/private&lt;br /&gt;
0 /usr/local/samba/bind-dns&lt;br /&gt;
0 /usr/local/samba/&lt;br /&gt;
$ make -j 8&lt;br /&gt;
$ rm -R /usr/local/samba/*&lt;br /&gt;
$ make -j 8 install&lt;br /&gt;
$ cd ../dist&lt;br /&gt;
$ tar czf samba-4.14.3-factory.tar.gz --owner=root -C /usr/local samba&lt;br /&gt;
$ tar --list --verbose --file samba-4.14.3-factory.tar.gz&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Deploy Samba AD DC Factory Distribution on AD DC ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;&#039;&#039;initial deploy only&#039;&#039;&#039;&#039;&#039;, use: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;on all updates after that, use: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/ --exclude=&amp;quot;samba/bind-dns&amp;quot; --exclude=&amp;quot;samba/etc&amp;quot; --exclude=&amp;quot;samba/private&amp;quot; --exclude=&amp;quot;samba/var&amp;quot;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* check for &amp;lt;code&amp;gt;knada.lan.kitsnet.us&amp;lt;/code&amp;gt; to end of search line in &amp;lt;code&amp;gt;/etc/resolv.conf&amp;lt;/code&amp;gt; &lt;br /&gt;
* test DNS and SRV record resolution per [https://wiki.samba.org/index.php/Linux_and_Unix_DNS_Configuration Linux and Unix DNS Configuration]&lt;br /&gt;
* Verify the server is ready per the steps in [https://wiki.samba.org/index.php/Joining_a_Samba_DC_to_an_Existing_Active_Directory#Installing_Samba Preparing the Host for Joining the Domain]&lt;br /&gt;
* copy &amp;lt;code&amp;gt;/usr/local/samba/share/setup/krb5.conf&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;/etc/krb5.conf&amp;lt;/code&amp;gt; and modify to: &lt;br /&gt;
&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
[libdefaults]&lt;br /&gt;
    default_realm = KNADA.LAN.KITSNET.US&lt;br /&gt;
    dns_lookup_realm = false&lt;br /&gt;
    dns_lookup_kdc = true&lt;br /&gt;
    dns_lookup_kdc = true&lt;br /&gt;
&lt;br /&gt;
[realms]&lt;br /&gt;
KNADA.LAN.KITSNET.US = {&lt;br /&gt;
    default_domain = knada.lan.kitsnet.us&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
#[domain_realm]&lt;br /&gt;
#   ${HOSTNAME} = KNADA.LAN.KITSNET.US&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Initialize Kerberos with&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# kinit administrator&lt;br /&gt;
# klist&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Join to Active Directory as a Domain Controller=&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# script join-kitsnet.log&lt;br /&gt;
# samba-tool domain join knada.lan.kitsnet.us DC -k yes --option=&#039;idmap_ldb:use rfc2307 = yes&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
If log output directs it, &amp;lt;code&amp;gt;cp /usr/local/samba/private/krb5.conf /etc/&amp;lt;/code&amp;gt; &amp;lt;blockquote&amp;gt;&lt;br /&gt;
Information about ID mapping is available at https://wiki.samba.org/index.php/Identity_Mapping_Back_Ends and https://wiki.samba.org/index.php/Idmap_config_ad. It appears from walker&#039;s smb.conf that we have: &amp;lt;code&amp;gt;idmap_ldb:use rfc2307 = yes&amp;lt;/code&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
Add to &amp;lt;code&amp;gt;/usr/local/samba/etc/smb.conf&amp;lt;/code&amp;gt; in the &amp;lt;code&amp;gt;[global]&amp;lt;/code&amp;gt; section: &amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
dns forwarder = 192.168.15.1&lt;br /&gt;
time server = yes&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;Then: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# sudo smbcontrol all reload-config&lt;br /&gt;
# sudo samba&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The last command will trigger samba startup. Until this is done, &amp;lt;code&amp;gt;samba-tool drs showrepl&amp;lt;/code&amp;gt; will show cryptic, scary error messages.&lt;br /&gt;
&lt;br /&gt;
To trigger RID block creation on the new Domain Controller &amp;lt;code&amp;gt;sudo samba-tool user create &amp;lt;&#039;&#039;new-user&#039;&#039;&amp;gt; --given-name &amp;quot;Silly&amp;quot; --surname &amp;quot;Person&amp;quot;&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Managing Samba Service on the AD DC ==&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/Managing_the_Samba_AD_DC_Service_Using_Systemd Managing the Samba AD DC Service Using Systemd] for how to add Samba to &amp;lt;code&amp;gt;systemctl&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Transferring FSMO Roles ==&lt;br /&gt;
See [https://wiki.samba.org/index.php/Transferring_and_Seizing_FSMO_Roles Transferring and Seizing FSMO Roles] for background on FSMO roles and management. Note that when transferring &amp;lt;code&amp;gt;domaindns&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;forestdns&amp;lt;/code&amp;gt; roles, add &amp;lt;code&amp;gt;-U administrator&amp;lt;/code&amp;gt; to end of the command:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# samba-tool fsmo transfer --role=forestdns -U administrator&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Advertise AD DC as DNS Server ==&lt;br /&gt;
On &amp;lt;code&amp;gt;radix.kitsnet.us&amp;lt;/code&amp;gt; update the file &amp;lt;code&amp;gt;/etc/config/dhcp&amp;lt;/code&amp;gt; in the &amp;lt;code&amp;gt;config dnsmasq&amp;lt;/code&amp;gt; section to add a line for the new DC:&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
        list server &#039;/knada.lan.kitsnet.us/192.168.15.84&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>2603:7000:9800:4742:69A9:3976:3F81:221B</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Linux:Samba_AD_Factory&amp;diff=84</id>
		<title>Linux:Samba AD Factory</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Linux:Samba_AD_Factory&amp;diff=84"/>
		<updated>2021-05-16T17:20:09Z</updated>

		<summary type="html">&lt;p&gt;2603:7000:9800:4742:69A9:3976:3F81:221B: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;To use [https://www.samba.org/ Samba] as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD &amp;quot;Factory&amp;quot;, where [https://www.samba.org/samba/download/ source kits] will be downloaded and built into binaries under the &amp;lt;code&amp;gt;/usr/local/samba&amp;lt;/code&amp;gt; directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the &#039;&#039;knada.lan.kitsnet.us&#039;&#039; domain. &amp;lt;blockquote&amp;gt;There is still an issue with serving time from the DCs. The answer will be found by going through https://wiki.samba.org/index.php/Time_Synchronisation &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Build CentOS 8 / Rocky Linux 8 Base System for Factory ==&lt;br /&gt;
The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]&amp;lt;/ref&amp;gt; with 1.5&amp;amp;nbsp;GB RAM, 4 vCPU and two disks:&lt;br /&gt;
&lt;br /&gt;
* T0 disk0 10&amp;amp;nbsp;GB (V0uv&#039;&#039;###&#039;&#039; /tmp 1024&amp;amp;nbsp;MB, /swap 512&amp;amp;nbsp;MB, /boot 1&amp;amp;nbsp;GB, and the rest for root)&lt;br /&gt;
* T3 disk1 16&amp;amp;nbsp;GB (V3uv&#039;&#039;###&#039;&#039; /var 3&amp;amp;nbsp;GB, /usr/local 13&amp;amp;nbsp;GB)&lt;br /&gt;
&lt;br /&gt;
The system will have a DHCP reservation as &amp;lt;code&amp;gt;&amp;lt;&#039;&#039;new-guest&#039;&#039;&amp;gt;.lan.kitsnet.us&amp;lt;/code&amp;gt;. When running the Anaconda installer, add to &amp;lt;u&amp;gt;Software Selection&amp;lt;/u&amp;gt;,  &amp;lt;u&amp;gt;Additional software for Selected Environment&amp;lt;/u&amp;gt;:  &#039;&#039;Development Tools&#039;&#039; .&lt;br /&gt;
== Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC ==&lt;br /&gt;
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt; with 1.5&amp;amp;nbsp;GB RAM, 2 vCPU and two disks:&lt;br /&gt;
&lt;br /&gt;
* T0 disk0 14&amp;amp;nbsp;GB (V0uv&#039;&#039;###&#039;&#039; /tmp 512&amp;amp;nbsp;MB, /swap 3&amp;amp;nbsp;GB, /boot 1&amp;amp;nbsp;GB, root 7&amp;amp;nbsp;GB)&lt;br /&gt;
* T3 disk1 4&amp;amp;nbsp;GB (V3uv&#039;&#039;###&#039;&#039; /var 2&amp;amp;nbsp;GB)&lt;br /&gt;
&lt;br /&gt;
Since these system will be domain-joined, it is important that they have a DHCP reservation as &amp;lt;code&amp;gt;&amp;lt;&#039;&#039;new-guest&#039;&#039;&amp;gt;.&#039;&#039;&#039;knada&#039;&#039;&#039;.lan.kitsnet.us&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
=== Environment Customization ===&lt;br /&gt;
&lt;br /&gt;
==== path ====&lt;br /&gt;
&lt;br /&gt;
* add &amp;lt;code&amp;gt;/usr/local/samba/bin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; to: &lt;br /&gt;
**&amp;lt;code&amp;gt;secure_path&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/sudoers&amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/crontab&amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;/etc/anacrontab&amp;lt;/code&amp;gt;&lt;br /&gt;
* carefully add &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/usr/local/samba/bin&amp;lt;/code&amp;gt; appropriately (check order) to &amp;lt;code&amp;gt;PATH&amp;lt;/code&amp;gt; in /etc/csh.login &lt;br /&gt;
* add  &amp;lt;code&amp;gt;/usr/local/samba/sbin&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;pathmunge&amp;lt;/code&amp;gt; in /etc/profile:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;&lt;br /&gt;
if [ &amp;quot;$EUID&amp;quot; = &amp;quot;0&amp;quot; ]; then&lt;br /&gt;
    pathmunge /usr/sbin&lt;br /&gt;
    pathmunge /usr/local/sbin&lt;br /&gt;
    pathmunge /usr/local/samba/sbin&lt;br /&gt;
    pathmunge /usr/local/samba/bin after&lt;br /&gt;
else&lt;br /&gt;
    pathmunge /usr/local/sbin after&lt;br /&gt;
    pathmunge /usr/sbin after&lt;br /&gt;
    pathmunge /usr/local/samba/sbin after&lt;br /&gt;
    pathmunge /usr/local/samba/bin&lt;br /&gt;
fi&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Firewall ====&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# firewall-cmd --set-default-zone=internal&lt;br /&gt;
# firewall-cmd --zone=internal --change-interface ens3 --permanent&lt;br /&gt;
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent&lt;br /&gt;
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent&lt;br /&gt;
# firewall-cmd --reload&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== Port Reference =====&lt;br /&gt;
&lt;br /&gt;
* 88=kerberos &lt;br /&gt;
* 135=epmap &lt;br /&gt;
* 137=netbios-ns &lt;br /&gt;
* 138=netbios-dgm &lt;br /&gt;
* 139=netbios-ssn &lt;br /&gt;
* 389=ldap &lt;br /&gt;
* 445=microsoft-ds &lt;br /&gt;
* 464=kpasswd &lt;br /&gt;
* 636=ldaps &lt;br /&gt;
* 3268=msft-gc &lt;br /&gt;
&lt;br /&gt;
* 3269=msft-gc-ssl&lt;br /&gt;
&lt;br /&gt;
==== Backup ====&lt;br /&gt;
Copy &amp;lt;code&amp;gt;backup_samba-ad-dc&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;/usr/local/sbin/&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# mkdir /var/lib/samba-ad-dc_backup&lt;br /&gt;
# chgrp kitsnet_adm  /var/lib/samba-ad-dc_backup&lt;br /&gt;
# chmod o-rx /var/lib/samba-ad-dc_backup&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== rsyslog ====&lt;br /&gt;
&lt;br /&gt;
* add to end of &amp;lt;code&amp;gt;/etc/rsyslog.conf&amp;lt;/code&amp;gt; the line &amp;lt;code&amp;gt;*.*  @192.168.15.80:514&amp;lt;/code&amp;gt; &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# systemctl restart rsyslog.service&lt;br /&gt;
# systemctl enable rsyslog.service&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setup Server to Build or Run Samba AD DC ==&lt;br /&gt;
Complete the preparations documented in [https://wiki.samba.org/index.php/https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Active_Directory_Domain_Controller Setting up Samba as an Active Directory Domain Controller]&lt;br /&gt;
&lt;br /&gt;
=== Factory Build Server Packages ===&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba Package Dependencies Required to Build Samba] and incorporate the [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba#Manually_maintained_Distribution-specific_Package_lists Manually maintained Distribution-specific Package lists] and the Red Hat Enterprise Linux 8 / CentOS 8 section. It will also be necessary to &amp;lt;code&amp;gt;dnf install dbus-devel python3-markdown&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Samba AD DC Server Packages ===&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# dnf install avahi-libs cups-libs python3-markdown patch pam-devel python3-cryptography python3-dns krb5-workstation libtasn1-tools &lt;br /&gt;
# dnf install lmdb-devel&lt;br /&gt;
# mkdir /usr/local/samba&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Check Filesystem Support on all Servers ===&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/File_System_Support File System Support] for details KistNet standard is for using xfs, so there is only one option to check for:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# uname -r&lt;br /&gt;
4.18.0-240.22.1.el8_3.x86_64&lt;br /&gt;
# grep -E &amp;quot;CONFIG_EXT4_FS_POSIX_ACL&amp;quot; /boot/config-4.18.0-240.22.1.el8_3.x86_64&lt;br /&gt;
CONFIG_EXT4_FS_POSIX_ACL=y&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;Install the &amp;lt;code&amp;gt;attr&amp;lt;/code&amp;gt; package with &amp;lt;code&amp;gt;dnf install attr&amp;lt;/code&amp;gt;. Next, refer to the [https://wiki.samba.org/index.php/File_System_Support#Testing_your_filesystem Testing your filesystem] section of the documentation for the verification steps&lt;br /&gt;
&lt;br /&gt;
== Download Samba Source to Factory Build Server ==&lt;br /&gt;
&lt;br /&gt;
* Create the base of the Factory source directory structure&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# mkdir /usr/local/SambaAD-Factory&lt;br /&gt;
# chown psmode:kitsnet_adm /usr/local/SambaAD-Factory&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Check https://download.samba.org/pub/samba/stable/ to identify the latest &amp;lt;code&amp;gt;*.tar.gz&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;wget&amp;lt;/code&amp;gt; that file &lt;br /&gt;
* &amp;lt;code&amp;gt;tar -xzvf&amp;lt;/code&amp;gt; the downloaded file with &amp;lt;code&amp;gt;-C /usr/local/SambaAD-Factory&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Build Samba AD DC Factory Distribution ==&lt;br /&gt;
Enter the version-specific directory under &amp;lt;code&amp;gt;/usr/local/SambaAD-Factory&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ ./configure --mandir=/usr/local/samba/man&lt;br /&gt;
$ make uninstall&lt;br /&gt;
$ du /usr/local/samba&lt;br /&gt;
0 /usr/local/samba/etc&lt;br /&gt;
0 /usr/local/samba/var/lib&lt;br /&gt;
0 /usr/local/samba/var/locks&lt;br /&gt;
0 /usr/local/samba/var/cache&lt;br /&gt;
0 /usr/local/samba/var/lock&lt;br /&gt;
0 /usr/local/samba/var/run&lt;br /&gt;
0 /usr/local/samba/var&lt;br /&gt;
0 /usr/local/samba/private&lt;br /&gt;
0 /usr/local/samba/bind-dns&lt;br /&gt;
0 /usr/local/samba/&lt;br /&gt;
$ make -j 8&lt;br /&gt;
$ rm -R /usr/local/samba/*&lt;br /&gt;
$ make -j 8 install&lt;br /&gt;
$ cd ../dist&lt;br /&gt;
$ tar czf samba-4.14.3-factory.tar.gz --owner=root -C /usr/local samba&lt;br /&gt;
$ tar --list --verbose --file samba-4.14.3-factory.tar.gz&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Deploy Samba AD DC Factory Distribution on AD DC ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;&#039;&#039;initial deploy only&#039;&#039;&#039;&#039;&#039;, use: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;on all updates after that, use: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/ --exclude=&amp;quot;samba/bind-dns&amp;quot; --exclude=&amp;quot;samba/etc&amp;quot; --exclude=&amp;quot;samba/private&amp;quot; --exclude=&amp;quot;samba/var&amp;quot;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* check for &amp;lt;code&amp;gt;knada.lan.kitsnet.us&amp;lt;/code&amp;gt; to end of search line in &amp;lt;code&amp;gt;/etc/resolv.conf&amp;lt;/code&amp;gt; &lt;br /&gt;
* test DNS and SRV record resolution per [https://wiki.samba.org/index.php/Linux_and_Unix_DNS_Configuration Linux and Unix DNS Configuration]&lt;br /&gt;
* Verify the server is ready per the steps in [https://wiki.samba.org/index.php/Joining_a_Samba_DC_to_an_Existing_Active_Directory#Installing_Samba Preparing the Host for Joining the Domain]&lt;br /&gt;
* copy &amp;lt;code&amp;gt;/usr/local/samba/share/setup/krb5.conf&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;/etc/krb5.conf&amp;lt;/code&amp;gt; and modify to: &lt;br /&gt;
&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
[libdefaults]&lt;br /&gt;
    default_realm = KNADA.LAN.KITSNET.US&lt;br /&gt;
    dns_lookup_realm = false&lt;br /&gt;
    dns_lookup_kdc = true&lt;br /&gt;
    dns_lookup_kdc = true&lt;br /&gt;
&lt;br /&gt;
[realms]&lt;br /&gt;
KNADA.LAN.KITSNET.US = {&lt;br /&gt;
    default_domain = knada.lan.kitsnet.us&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
#[domain_realm]&lt;br /&gt;
#   ${HOSTNAME} = KNADA.LAN.KITSNET.US&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Initialize Kerberos with&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# kinit administrator&lt;br /&gt;
# klist&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Join to Active Directory as a Domain Controller=&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# script join-kitsnet.log&lt;br /&gt;
# samba-tool domain join knada.lan.kitsnet.us DC -k yes --option=&#039;idmap_ldb:use rfc2307 = yes&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
If log output directs it, &amp;lt;code&amp;gt;cp /usr/local/samba/private/krb5.conf /etc/&amp;lt;/code&amp;gt; &amp;lt;blockquote&amp;gt;&lt;br /&gt;
Information about ID mapping is available at https://wiki.samba.org/index.php/Identity_Mapping_Back_Ends and https://wiki.samba.org/index.php/Idmap_config_ad. It appears from walker&#039;s smb.conf that we have: &amp;lt;code&amp;gt;idmap_ldb:use rfc2307 = yes&amp;lt;/code&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
Add to &amp;lt;code&amp;gt;/usr/local/samba/etc/smb.conf&amp;lt;/code&amp;gt; in the &amp;lt;code&amp;gt;[global]&amp;lt;/code&amp;gt; section: &amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
dns forwarder = 192.168.15.1&lt;br /&gt;
time server = yes&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;Then: &amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# sudo smbcontrol all reload-config&lt;br /&gt;
# sudo samba&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;The last command will trigger samba startup. Until this is done, &amp;lt;code&amp;gt;samba-tool drs showrepl&amp;lt;/code&amp;gt; will show cryptic, scary error messages.&lt;br /&gt;
&lt;br /&gt;
To trigger RID block creation on the new Domain Controller &amp;lt;code&amp;gt;sudo samba-tool user create &amp;lt;&#039;&#039;new-user&#039;&#039;&amp;gt; --given-name &amp;quot;Silly&amp;quot; --surname &amp;quot;Person&amp;quot;&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Managing Samba Service on the AD DC ==&lt;br /&gt;
Refer to [https://wiki.samba.org/index.php/Managing_the_Samba_AD_DC_Service_Using_Systemd Managing the Samba AD DC Service Using Systemd] for how to add Samba to &amp;lt;code&amp;gt;systemctl&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Transferring FSMO Roles ==&lt;br /&gt;
See [https://wiki.samba.org/index.php/Transferring_and_Seizing_FSMO_Roles Transferring and Seizing FSMO Roles] for background on FSMO roles and management. Note that when transferring &amp;lt;code&amp;gt;domaindns&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;forestdns&amp;lt;/code&amp;gt; roles, add &amp;lt;code&amp;gt;-U administrator&amp;lt;/code&amp;gt; to end of the command:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# samba-tool fsmo transfer --role=forestdns -U administrator&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Advertise AD DC as DNS Server ==&lt;br /&gt;
On &amp;lt;code&amp;gt;radix.kitsnet.us&amp;lt;/code&amp;gt; update the file &amp;lt;code&amp;gt;/etc/config/dhcp&amp;lt;/code&amp;gt; in the &amp;lt;code&amp;gt;config dnsmasq&amp;lt;/code&amp;gt; section to add a line for the new DC:&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
        list server &#039;/knada.lan.kitsnet.us/192.168.15.84&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>2603:7000:9800:4742:69A9:3976:3F81:221B</name></author>
	</entry>
</feed>