| (33 intermediate revisions by 3 users not shown) | |||
| Line 1: | Line 1: | ||
To use [https://www.samba.org/ Samba] as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD "Factory", where [https://www.samba.org/samba/download/ source kits] will be downloaded and built into binaries under the <code>/usr/local/samba</code> directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the ''knada.lan.kitsnet.us'' domain. | To use [https://www.samba.org/ Samba] as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD "Factory", where [https://www.samba.org/samba/download/ source kits] will be downloaded and built into binaries under the <code>/usr/local/samba</code> directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the ''knada.lan.kitsnet.us'' domain. <blockquote>''There is still an issue with serving time from the DCs. The answer will be found by going through https://wiki.samba.org/index.php/Time_Synchronisation'' </blockquote> | ||
== Build CentOS 8 / Rocky Linux 8 Base System for Factory == | == Build CentOS 8 / Rocky Linux 8 Base System for Factory == | ||
The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest<ref name=":0">[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]</ref> with 1.5 GB RAM, 4 vCPU and two disks: | The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic [[KVM:guests|Linux Virtual Server Guest]]<ref name=":0">[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]</ref> with 1.5 GB RAM, 4 vCPU and two disks: | ||
* T0 disk0 10 GB (V0uv''###'' /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root) | * T0 disk0 10 GB (V0uv''###'' /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root) | ||
* T3 disk1 16 GB (V3uv''###'' /var 3 GB, /usr/local 13 GB) | * T3 disk1 16 GB (V3uv''###'' /var 3 GB, /usr/local 13 GB) | ||
The system will have a DHCP reservation as <code><''new-guest''>.lan.kitsnet.us</code>. When running the Anaconda installer, add to <u>Software Selection</u>, <u>Additional software for Selected Environment</u>: ''Development Tools'' . | |||
== Build Rocky Linux 9 Base System for Factory == | |||
The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic [[KVM:guests|Linux Virtual Server Guest]]<ref name=":0" /> with 2.0 GB RAM, 4 vCPU and two disks: | |||
* T0 disk0 8 GB (V0uv''###'' /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root) | |||
* T3 disk1 16 GB (V3uv''###'' /var 3 GB, /usr/local 8 GB) | |||
The system will have a DHCP reservation as <code><''new-guest''>.lan.kitsnet.us</code>. When running the Anaconda installer, add to <u>Software Selection</u>, <u>Additional software for Selected Environment</u>: ''Development Tools'' . | The system will have a DHCP reservation as <code><''new-guest''>.lan.kitsnet.us</code>. When running the Anaconda installer, add to <u>Software Selection</u>, <u>Additional software for Selected Environment</u>: ''Development Tools'' . | ||
== Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC == | == Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC == | ||
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest<ref name=":0" /> with 1.5 GB RAM, 2 vCPU and two disks: | The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic [[KVM:guests|Linux Virtual Server Guest]]<ref name=":0" /> with 1.5 GB RAM, 2 vCPU and two disks: | ||
* T0 disk0 14 GB (V0uv''###'' /tmp 512 MB, /swap 3 GB, /boot 1 GB, root 7 GB) | * T0 disk0 14 GB (V0uv''###'' /tmp 512 MB, /swap 3 GB, /boot 1 GB, root 7 GB) | ||
| Line 16: | Line 23: | ||
Since these system will be domain-joined, it is important that they have a DHCP reservation as <code><''new-guest''>.'''knada'''.lan.kitsnet.us</code>. | Since these system will be domain-joined, it is important that they have a DHCP reservation as <code><''new-guest''>.'''knada'''.lan.kitsnet.us</code>. | ||
=== | === Environment Customization === | ||
==== path ==== | ==== path ==== | ||
* add <code>/usr/local/samba/bin</code> and <code>/usr/local/samba/sbin</code> to: | * add <code>/usr/local/samba/bin</code> and <code>/usr/local/samba/sbin</code> to: | ||
** <code>secure_path</code> in /etc/sudoers | **<code>secure_path</code> in <code>/etc/sudoers</code> | ||
** <code>PATH</code> in /etc/crontab | ** <code>PATH</code> in <code>/etc/crontab</code> | ||
** <code>PATH</code> in /etc/anacrontab | ** <code>PATH</code> in <code>/etc/anacrontab</code> | ||
* carefully add <code>/usr/local/samba/sbin</code> and <code>/usr/local/samba/bin</code> appropriately (check order) to <code>PATH</code> in /etc/csh.login | * carefully add <code>/usr/local/samba/sbin</code> and <code>/usr/local/samba/bin</code> appropriately (check order) to <code>PATH</code> in /etc/csh.login | ||
* add <code>/usr/local/samba/sbin</code> to <code>pathmunge</code> in /etc/profile: | * add <code>/usr/local/samba/sbin</code> to <code>pathmunge</code> in /etc/profile: | ||
| Line 44: | Line 51: | ||
# firewall-cmd --set-default-zone=internal | # firewall-cmd --set-default-zone=internal | ||
# firewall-cmd --zone=internal --change-interface ens3 --permanent | # firewall-cmd --zone=internal --change-interface ens3 --permanent | ||
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent | # firewall-cmd --add-service={dns,ldap,ldaps,kerberos,rsyncd} --permanent | ||
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent | # firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,464/udp,464/tcp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent | ||
# firewall-cmd --reload | # firewall-cmd --reload | ||
</syntaxhighlight> | </syntaxhighlight> | ||
| Line 72: | Line 79: | ||
==== rsyslog ==== | ==== rsyslog ==== | ||
Add to end of <code>/etc/rsyslog.conf</code> the line <code>*.* @192.168.15.80:514</code> <syntaxhighlight lang="shell-session"> | |||
# systemctl restart rsyslog.service | # systemctl restart rsyslog.service | ||
# systemctl enable rsyslog.service | # systemctl enable rsyslog.service | ||
</syntaxhighlight> | </syntaxhighlight> | ||
== Setup Server to Build or Run Samba AD DC == | |||
Complete the preparations documented in [https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Active_Directory_Domain_Controller Setting up Samba as an Active Directory Domain Controller] | |||
=== Factory Build Server Packages === | |||
Refer to [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba Package Dependencies Required to Build Samba] and incorporate the [https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba#Manually_maintained_Distribution-specific_Package_lists Manually maintained Distribution-specific Package lists] and the Red Hat Enterprise Linux 8 / CentOS 8 section. It will also be necessary to <code>dnf install dbus-devel python3-markdown</code> | |||
=== Samba AD DC Server Packages === | |||
<syntaxhighlight lang="shell-session"> | |||
# dnf install avahi-libs cups-libs python3-markdown patch pam-devel python3-cryptography python3-dns krb5-workstation libtasn1-tools python3-tdb tdb-tools | |||
# dnf install lmdb-devel | |||
# mkdir /usr/local/samba | |||
</syntaxhighlight> | |||
===Check Filesystem Support on all Servers=== | |||
Refer to [https://wiki.samba.org/index.php/File_System_Support File System Support] for details KistNet standard is for using xfs, so there is only one option to check for:<syntaxhighlight lang="shell-session"> | |||
# uname -r | |||
4.18.0-240.22.1.el8_3.x86_64 | |||
# grep -E "CONFIG_XFS_POSIX_ACL" /boot/config-4.18.0-240.22.1.el8_3.x86_64 | |||
CONFIG_XFS_POSIX_ACL=y | |||
</syntaxhighlight>Install the <code>attr</code> package with <code>dnf install attr</code>. Next, refer to the [https://wiki.samba.org/index.php/File_System_Support#Testing_your_filesystem Testing your filesystem] section of the documentation for the verification steps | |||
==Download Samba Source to Factory Build Server == | |||
*Create the base of the Factory source directory structure | |||
<syntaxhighlight lang="shell-session"> | |||
# mkdir /usr/local/src/SambaADC-Factory | |||
# chown psmode:kitsnet_adm /usr/local/src/SambaADC-Factory</syntaxhighlight> | |||
*Check https://download.samba.org/pub/samba/stable/ to identify the latest <code>*.tar.gz</code> and <code>wget</code> that file | |||
*<code>tar -xzvf</code> the downloaded file with <code>-C /usr/local/src/SambaADC-Factory</code> | |||
==Build Samba AD DC Factory Distribution== | |||
Enter the version-specific directory under <code>/usr/local/src/SambaADC-Factory</code><syntaxhighlight lang="shell-session"> | |||
$ ./configure --mandir=/usr/local/samba/man | |||
$ make uninstall | |||
$ du /usr/local/samba | |||
0 /usr/local/samba/etc | |||
0 /usr/local/samba/var/lib | |||
0 /usr/local/samba/var/locks | |||
0 /usr/local/samba/var/cache | |||
0 /usr/local/samba/var/lock | |||
0 /usr/local/samba/var/run | |||
0 /usr/local/samba/var | |||
0 /usr/local/samba/private | |||
0 /usr/local/samba/bind-dns | |||
0 /usr/local/samba/ | |||
$ make -j 8 | |||
$ rm -R /usr/local/samba/* | |||
$ make -j 8 install | |||
$ cd ../dist | |||
$ tar czf samba-4.14.3-factory.tar.gz --owner=root -C /usr/local samba | |||
$ tar --list --verbose --file samba-4.14.3-factory.tar.gz | |||
</syntaxhighlight> | |||
==Deploy Samba AD DC Factory Distribution on AD DC== | |||
On '''''initial deploy only''''', use: <syntaxhighlight lang="shell-session"> | |||
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/ | |||
</syntaxhighlight>It is then necessary to enable write access to <code>/usr/local/samba/var</code> by logrotate. Add to the end of <code>/lib/systemd/system/logrotate.service</code> <syntaxhighlight lang="text"> | |||
# | |||
# Default hardening prevents access to entirety of the /usr filesystem. Since | |||
# we load Samba under /usr/local/samba, this would mean that the var | |||
# subdirectory would be read-only by default. | |||
# | |||
ReadWritePaths=/usr/local/samba/var | |||
</syntaxhighlight>On all updates after initial deployment, use: <syntaxhighlight lang="shell-session"> | |||
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/ --exclude="samba/bind-dns" --exclude="samba/etc" --exclude="samba/private" --exclude="samba/var" | |||
</syntaxhighlight> | |||
*check for <code>knada.lan.kitsnet.us</code> to end of search line in <code>/etc/resolv.conf</code> | |||
*test DNS and SRV record resolution per [https://wiki.samba.org/index.php/Linux_and_Unix_DNS_Configuration Linux and Unix DNS Configuration] | |||
*Verify the server is ready per the steps in [https://wiki.samba.org/index.php/Joining_a_Samba_DC_to_an_Existing_Active_Directory#Installing_Samba Preparing the Host for Joining the Domain] | |||
*copy <code>/usr/local/samba/share/setup/krb5.conf</code> to <code>/etc/krb5.conf</code> and modify to: | |||
<syntaxhighlight> | |||
[libdefaults] | |||
default_realm = KNADA.LAN.KITSNET.US | |||
dns_lookup_realm = false | |||
dns_lookup_kdc = true | |||
[realms] | |||
KNADA.LAN.KITSNET.US = { | |||
default_domain = knada.lan.kitsnet.us | |||
} | |||
#[domain_realm] | |||
# ${HOSTNAME} = KNADA.LAN.KITSNET.US</syntaxhighlight> | |||
*Initialize Kerberos with | |||
<syntaxhighlight lang="shell-session"> | |||
# kinit administrator | |||
# klist</syntaxhighlight> | |||
*copy in <code>/etc/logrotate.d/samba-ad-dc</code> | |||
=Join to Active Directory as a Domain Controller= | |||
<syntaxhighlight lang="shell-session"> | |||
# script join-kitsnet.log | |||
# samba-tool domain join knada.lan.kitsnet.us DC -U"KNADA\administrator" --option='idmap_ldb:use rfc2307 = yes' | |||
</syntaxhighlight> | |||
If log output directs it, <code>cp /usr/local/samba/private/krb5.conf /etc/</code> <blockquote> | |||
Information about ID mapping is available at https://wiki.samba.org/index.php/Identity_Mapping_Back_Ends and https://wiki.samba.org/index.php/Idmap_config_ad. It appears from walker's smb.conf that we have: <code>idmap_ldb:use rfc2307 = yes</code></blockquote> | |||
Add to <code>/usr/local/samba/etc/smb.conf</code> in the <code>[global]</code> section: <syntaxhighlight> | |||
dns forwarder = 192.168.15.1 | |||
time server = yes | |||
</syntaxhighlight>Then: <syntaxhighlight lang="shell-session"> | |||
# sudo smbcontrol all reload-config | |||
# sudo samba | |||
</syntaxhighlight>The last command will trigger samba startup. Until this is done, <code>samba-tool drs showrepl</code> will show cryptic, scary error messages. | |||
To trigger RID block creation on the new Domain Controller <code>sudo samba-tool user create <''new-user''> --given-name "Silly" --surname "Person"</code> | |||
==Managing Samba Service on the AD DC== | |||
Refer to [https://wiki.samba.org/index.php/Managing_the_Samba_AD_DC_Service_Using_Systemd Managing the Samba AD DC Service Using Systemd] for how to add Samba to <code>systemctl</code>. Current KitsNet version of <code>/etc/systemd/system/samba-ad-dc.service</code> is:<syntaxhighlight lang="text"> | |||
[Unit] | |||
Description=Samba Active Directory Domain Controller | |||
After=network.target network-online.target remote-fs.target nss-lookup.target | |||
[Service] | |||
Type=forking | |||
ExecStart=/usr/local/samba/sbin/samba -D | |||
PIDFile=/usr/local/samba/var/run/samba.pid | |||
ExecReload=/bin/kill -HUP $MAINPID | |||
[Install] | |||
WantedBy=multi-user.target | |||
[root@frangelico ~]# cat /etc/systemd/system/samba-ad-dc.service | |||
[Unit] | |||
Description=Samba Active Directory Domain Controller | |||
After=network.target network-online.target remote-fs.target nss-lookup.target | |||
[Service] | |||
Type=forking | |||
ExecStart=/usr/local/samba/sbin/samba -D | |||
PIDFile=/usr/local/samba/var/run/samba.pid | |||
ExecReload=/bin/kill -HUP $MAINPID | |||
[Install] | |||
WantedBy=multi-user.target | |||
</syntaxhighlight> | |||
==Transferring FSMO Roles== | |||
See [https://wiki.samba.org/index.php/Transferring_and_Seizing_FSMO_Roles Transferring and Seizing FSMO Roles] for background on FSMO roles and management. FSMO transfer commands are issued on the DC that will be the new owner of the role. Note that when transferring <code>domaindns</code> and <code>forestdns</code> roles, add <code>-U administrator</code> to end of the command:<syntaxhighlight lang="shell-session"> | |||
# samba-tool fsmo transfer --role=forestdns -U administrator | |||
</syntaxhighlight> | |||
==Advertise AD DC as DNS Server== | |||
On <code>radix.kitsnet.us</code> update the file <code>/etc/config/dhcp</code> in the <code>config dnsmasq</code> section to add a line for the new DC:<syntaxhighlight> | |||
list server '/knada.lan.kitsnet.us/192.168.15.84' | |||
</syntaxhighlight> | |||
==Updating AD DC Software from Factory== | |||
The underlying process for updating KitsNet AD DCs is based on the standard [https://wiki.samba.org/index.php/Upgrading_a_Samba_AD_DC#Updating_Multiple_Samba_Domain_Controllers Updating Multiple Samba Domain Controllers] process after the [[#Download_Samba_Source_to_Factory_Build_Server|updated Samba sources have been downloaded]] and the [[#Build_Samba_AD_DC_Factory_Distribution|new Factory AD DC distribution has been built]] on the factory build server. The entire update procedure should be executed on the AD DC as root. It is preferred to execute the procedure on the secondary AD DC first. Use <code>samba-tool fsmo show</code> to verify which DC currently holds the FSMO roles. | |||
===Download Distribution from Factory Build Server=== | |||
<syntaxhighlight lang="shell-session"> | |||
# sftp psmode@hendrick | |||
psmode@hendrick's password: | |||
Connected to psmode@hendrick. | |||
sftp> cd /usr/local/src/SambaADC-Factory/dist | |||
sftp> ls -al | |||
drwxr-xr-x 2 psmode kitsnet_adm 111 Jun 18 16:21 . | |||
drwxrwxr-x 7 psmode kitsnet_adm 234 Jun 18 16:08 .. | |||
-rw-r--r-- 1 psmode kitsnet_adm 24519210 Apr 22 15:25 samba-4.14.2-factory.tar.gz | |||
-rw-r--r-- 1 root root 24517648 Apr 26 15:36 samba-4.14.3-factory.tar.gz | |||
-rw-r--r-- 1 psmode kitsnet_adm 24525015 Jun 18 16:21 samba-4.14.5-factory.tar.gz | |||
sftp> get samba-4.14.5-factory.tar.gz | |||
Fetching /usr/local/src/SambaADC-Factory/dist/samba-4.14.5-factory.tar.gz to samba-4.14.5-factory.tar.gz | |||
/usr/local/src/SambaADC-Factory/dist/samba-4.14.5-factory.tar.gz 100% 23MB 245.7MB/s 00:00 | |||
sftp> quit | |||
</syntaxhighlight> | |||
===Check DC Status=== | |||
<syntaxhighlight lang="shell-session"> | |||
# samba-tool fsmo show | |||
SchemaMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
InfrastructureMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
RidAllocationMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
PdcEmulationMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
DomainNamingMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
DomainDnsZonesMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
ForestDnsZonesMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
# samba-tool drs showrepl | |||
Default-First-Site-Name\GOSLING | |||
DSA Options: 0x00000001 | |||
DSA object GUID: c8e62aed-ebc9-4c0e-a7de-97e8813b39fd | |||
DSA invocationId: 490eea9b-1892-4768-bb96-f21fc9a5cd7e | |||
==== INBOUND NEIGHBORS ==== | |||
CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful | |||
0 consecutive failure(s). | |||
Last success @ Sun Jun 20 12:17:47 2021 EDT | |||
CN=Schema,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful | |||
0 consecutive failure(s). | |||
Last success @ Sun Jun 20 12:17:47 2021 EDT | |||
DC=ForestDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful | |||
0 consecutive failure(s). | |||
Last success @ Sun Jun 20 12:17:47 2021 EDT | |||
DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful | |||
0 consecutive failure(s). | |||
Last success @ Sun Jun 20 12:17:47 2021 EDT | |||
DC=DomainDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful | |||
0 consecutive failure(s). | |||
Last success @ Sun Jun 20 12:17:47 2021 EDT | |||
==== OUTBOUND NEIGHBORS ==== | |||
CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ NTTIME(0) was successful | |||
0 consecutive failure(s). | |||
Last success @ NTTIME(0) | |||
CN=Schema,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ NTTIME(0) was successful | |||
0 consecutive failure(s). | |||
Last success @ NTTIME(0) | |||
DC=ForestDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ NTTIME(0) was successful | |||
0 consecutive failure(s). | |||
Last success @ NTTIME(0) | |||
DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ NTTIME(0) was successful | |||
0 consecutive failure(s). | |||
Last success @ NTTIME(0) | |||
DC=DomainDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
Default-First-Site-Name\CAMUS via RPC | |||
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88 | |||
Last attempt @ NTTIME(0) was successful | |||
0 consecutive failure(s). | |||
Last success @ NTTIME(0) | |||
==== KCC CONNECTION OBJECTS ==== | |||
Connection -- | |||
Connection name: 3567b8f0-df97-4b2c-8bfe-0b6aa3df4118 | |||
Enabled : TRUE | |||
Server DNS name : camus.knada.lan.kitsnet.us | |||
Server DN name : CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us | |||
TransportType: RPC | |||
options: 0x00000001 | |||
Warning: No NC replicated for Connection! | |||
# samba-tool dbcheck --cross-ncs | |||
Checking 3634 objects | |||
Checked 3634 objects (0 errors) | |||
</syntaxhighlight>Verify Last Backup | |||
Shutdown Samba Processes | |||
---- | ---- | ||
<references /> | |||
Latest revision as of 17:28, 22 March 2025
To use Samba as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD "Factory", where source kits will be downloaded and built into binaries under the /usr/local/samba directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the knada.lan.kitsnet.us domain.
There is still an issue with serving time from the DCs. The answer will be found by going through https://wiki.samba.org/index.php/Time_Synchronisation
1 Build CentOS 8 / Rocky Linux 8 Base System for Factory[edit | edit source]
The Factory system is that which will be used to download Samba source kits to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 4 vCPU and two disks:
- T0 disk0 10 GB (V0uv### /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root)
- T3 disk1 16 GB (V3uv### /var 3 GB, /usr/local 13 GB)
The system will have a DHCP reservation as <new-guest>.lan.kitsnet.us. When running the Anaconda installer, add to Software Selection, Additional software for Selected Environment: Development Tools .
2 Build Rocky Linux 9 Base System for Factory[edit | edit source]
The Factory system is that which will be used to download Samba source kits to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest[1] with 2.0 GB RAM, 4 vCPU and two disks:
- T0 disk0 8 GB (V0uv### /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root)
- T3 disk1 16 GB (V3uv### /var 3 GB, /usr/local 8 GB)
The system will have a DHCP reservation as <new-guest>.lan.kitsnet.us. When running the Anaconda installer, add to Software Selection, Additional software for Selected Environment: Development Tools .
3 Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC[edit | edit source]
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 2 vCPU and two disks:
- T0 disk0 14 GB (V0uv### /tmp 512 MB, /swap 3 GB, /boot 1 GB, root 7 GB)
- T3 disk1 4 GB (V3uv### /var 2 GB)
Since these system will be domain-joined, it is important that they have a DHCP reservation as <new-guest>.knada.lan.kitsnet.us.
3.1 Environment Customization[edit | edit source]
3.1.1 path[edit | edit source]
- add
/usr/local/samba/binand/usr/local/samba/sbinto:secure_pathin/etc/sudoersPATHin/etc/crontabPATHin/etc/anacrontab
- carefully add
/usr/local/samba/sbinand/usr/local/samba/binappropriately (check order) toPATHin /etc/csh.login - add
/usr/local/samba/sbintopathmungein /etc/profile:
if [ "$EUID" = "0" ]; then
pathmunge /usr/sbin
pathmunge /usr/local/sbin
pathmunge /usr/local/samba/sbin
pathmunge /usr/local/samba/bin after
else
pathmunge /usr/local/sbin after
pathmunge /usr/sbin after
pathmunge /usr/local/samba/sbin after
pathmunge /usr/local/samba/bin
fi
3.1.2 Firewall[edit | edit source]
# firewall-cmd --set-default-zone=internal
# firewall-cmd --zone=internal --change-interface ens3 --permanent
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos,rsyncd} --permanent
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,464/udp,464/tcp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent
# firewall-cmd --reload
3.1.2.1 Port Reference[edit | edit source]
- 88=kerberos
- 135=epmap
- 137=netbios-ns
- 138=netbios-dgm
- 139=netbios-ssn
- 389=ldap
- 445=microsoft-ds
- 464=kpasswd
- 636=ldaps
- 3268=msft-gc
- 3269=msft-gc-ssl
3.1.3 Backup[edit | edit source]
Copy backup_samba-ad-dc to /usr/local/sbin/
# mkdir /var/lib/samba-ad-dc_backup
# chgrp kitsnet_adm /var/lib/samba-ad-dc_backup
# chmod o-rx /var/lib/samba-ad-dc_backup
3.1.4 rsyslog[edit | edit source]
Add to end of /etc/rsyslog.conf the line *.* @192.168.15.80:514
# systemctl restart rsyslog.service
# systemctl enable rsyslog.service
4 Setup Server to Build or Run Samba AD DC[edit | edit source]
Complete the preparations documented in Setting up Samba as an Active Directory Domain Controller
4.1 Factory Build Server Packages[edit | edit source]
Refer to Package Dependencies Required to Build Samba and incorporate the Manually maintained Distribution-specific Package lists and the Red Hat Enterprise Linux 8 / CentOS 8 section. It will also be necessary to dnf install dbus-devel python3-markdown
4.2 Samba AD DC Server Packages[edit | edit source]
# dnf install avahi-libs cups-libs python3-markdown patch pam-devel python3-cryptography python3-dns krb5-workstation libtasn1-tools python3-tdb tdb-tools
# dnf install lmdb-devel
# mkdir /usr/local/samba
4.3 Check Filesystem Support on all Servers[edit | edit source]
Refer to File System Support for details KistNet standard is for using xfs, so there is only one option to check for:
# uname -r
4.18.0-240.22.1.el8_3.x86_64
# grep -E "CONFIG_XFS_POSIX_ACL" /boot/config-4.18.0-240.22.1.el8_3.x86_64
CONFIG_XFS_POSIX_ACL=y
Install the attr package with dnf install attr. Next, refer to the Testing your filesystem section of the documentation for the verification steps
5 Download Samba Source to Factory Build Server[edit | edit source]
- Create the base of the Factory source directory structure
# mkdir /usr/local/src/SambaADC-Factory
# chown psmode:kitsnet_adm /usr/local/src/SambaADC-Factory
- Check https://download.samba.org/pub/samba/stable/ to identify the latest
*.tar.gzandwgetthat file tar -xzvfthe downloaded file with-C /usr/local/src/SambaADC-Factory
6 Build Samba AD DC Factory Distribution[edit | edit source]
Enter the version-specific directory under /usr/local/src/SambaADC-Factory
$ ./configure --mandir=/usr/local/samba/man
$ make uninstall
$ du /usr/local/samba
0 /usr/local/samba/etc
0 /usr/local/samba/var/lib
0 /usr/local/samba/var/locks
0 /usr/local/samba/var/cache
0 /usr/local/samba/var/lock
0 /usr/local/samba/var/run
0 /usr/local/samba/var
0 /usr/local/samba/private
0 /usr/local/samba/bind-dns
0 /usr/local/samba/
$ make -j 8
$ rm -R /usr/local/samba/*
$ make -j 8 install
$ cd ../dist
$ tar czf samba-4.14.3-factory.tar.gz --owner=root -C /usr/local samba
$ tar --list --verbose --file samba-4.14.3-factory.tar.gz
7 Deploy Samba AD DC Factory Distribution on AD DC[edit | edit source]
On initial deploy only, use:
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/
It is then necessary to enable write access to /usr/local/samba/var by logrotate. Add to the end of /lib/systemd/system/logrotate.service
#
# Default hardening prevents access to entirety of the /usr filesystem. Since
# we load Samba under /usr/local/samba, this would mean that the var
# subdirectory would be read-only by default.
#
ReadWritePaths=/usr/local/samba/var
On all updates after initial deployment, use:
$ sudo tar xvf samba-4.14.3-factory.tar.gz -C /usr/local/ --exclude="samba/bind-dns" --exclude="samba/etc" --exclude="samba/private" --exclude="samba/var"
- check for
knada.lan.kitsnet.usto end of search line in/etc/resolv.conf - test DNS and SRV record resolution per Linux and Unix DNS Configuration
- Verify the server is ready per the steps in Preparing the Host for Joining the Domain
- copy
/usr/local/samba/share/setup/krb5.confto/etc/krb5.confand modify to:
[libdefaults]
default_realm = KNADA.LAN.KITSNET.US
dns_lookup_realm = false
dns_lookup_kdc = true
[realms]
KNADA.LAN.KITSNET.US = {
default_domain = knada.lan.kitsnet.us
}
#[domain_realm]
# ${HOSTNAME} = KNADA.LAN.KITSNET.US- Initialize Kerberos with
# kinit administrator
# klist
- copy in
/etc/logrotate.d/samba-ad-dc
8 Join to Active Directory as a Domain Controller[edit | edit source]
# script join-kitsnet.log
# samba-tool domain join knada.lan.kitsnet.us DC -U"KNADA\administrator" --option='idmap_ldb:use rfc2307 = yes'
If log output directs it, cp /usr/local/samba/private/krb5.conf /etc/
Information about ID mapping is available at https://wiki.samba.org/index.php/Identity_Mapping_Back_Ends and https://wiki.samba.org/index.php/Idmap_config_ad. It appears from walker's smb.conf that we have:
idmap_ldb:use rfc2307 = yes
Add to /usr/local/samba/etc/smb.conf in the [global] section:
dns forwarder = 192.168.15.1
time server = yesThen:
# sudo smbcontrol all reload-config
# sudo samba
The last command will trigger samba startup. Until this is done, samba-tool drs showrepl will show cryptic, scary error messages.
To trigger RID block creation on the new Domain Controller sudo samba-tool user create <new-user> --given-name "Silly" --surname "Person"
8.1 Managing Samba Service on the AD DC[edit | edit source]
Refer to Managing the Samba AD DC Service Using Systemd for how to add Samba to systemctl. Current KitsNet version of /etc/systemd/system/samba-ad-dc.service is:
[Unit]
Description=Samba Active Directory Domain Controller
After=network.target network-online.target remote-fs.target nss-lookup.target
[Service]
Type=forking
ExecStart=/usr/local/samba/sbin/samba -D
PIDFile=/usr/local/samba/var/run/samba.pid
ExecReload=/bin/kill -HUP $MAINPID
[Install]
WantedBy=multi-user.target
[root@frangelico ~]# cat /etc/systemd/system/samba-ad-dc.service
[Unit]
Description=Samba Active Directory Domain Controller
After=network.target network-online.target remote-fs.target nss-lookup.target
[Service]
Type=forking
ExecStart=/usr/local/samba/sbin/samba -D
PIDFile=/usr/local/samba/var/run/samba.pid
ExecReload=/bin/kill -HUP $MAINPID
[Install]
WantedBy=multi-user.target
8.2 Transferring FSMO Roles[edit | edit source]
See Transferring and Seizing FSMO Roles for background on FSMO roles and management. FSMO transfer commands are issued on the DC that will be the new owner of the role. Note that when transferring domaindns and forestdns roles, add -U administrator to end of the command:
# samba-tool fsmo transfer --role=forestdns -U administrator
8.3 Advertise AD DC as DNS Server[edit | edit source]
On radix.kitsnet.us update the file /etc/config/dhcp in the config dnsmasq section to add a line for the new DC:
list server '/knada.lan.kitsnet.us/192.168.15.84'8.4 Updating AD DC Software from Factory[edit | edit source]
The underlying process for updating KitsNet AD DCs is based on the standard Updating Multiple Samba Domain Controllers process after the updated Samba sources have been downloaded and the new Factory AD DC distribution has been built on the factory build server. The entire update procedure should be executed on the AD DC as root. It is preferred to execute the procedure on the secondary AD DC first. Use samba-tool fsmo show to verify which DC currently holds the FSMO roles.
8.4.1 Download Distribution from Factory Build Server[edit | edit source]
# sftp psmode@hendrick
psmode@hendrick's password:
Connected to psmode@hendrick.
sftp> cd /usr/local/src/SambaADC-Factory/dist
sftp> ls -al
drwxr-xr-x 2 psmode kitsnet_adm 111 Jun 18 16:21 .
drwxrwxr-x 7 psmode kitsnet_adm 234 Jun 18 16:08 ..
-rw-r--r-- 1 psmode kitsnet_adm 24519210 Apr 22 15:25 samba-4.14.2-factory.tar.gz
-rw-r--r-- 1 root root 24517648 Apr 26 15:36 samba-4.14.3-factory.tar.gz
-rw-r--r-- 1 psmode kitsnet_adm 24525015 Jun 18 16:21 samba-4.14.5-factory.tar.gz
sftp> get samba-4.14.5-factory.tar.gz
Fetching /usr/local/src/SambaADC-Factory/dist/samba-4.14.5-factory.tar.gz to samba-4.14.5-factory.tar.gz
/usr/local/src/SambaADC-Factory/dist/samba-4.14.5-factory.tar.gz 100% 23MB 245.7MB/s 00:00
sftp> quit
8.4.2 Check DC Status[edit | edit source]
# samba-tool fsmo show
SchemaMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
InfrastructureMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
RidAllocationMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
PdcEmulationMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
DomainNamingMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
DomainDnsZonesMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
ForestDnsZonesMasterRole owner: CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
# samba-tool drs showrepl
Default-First-Site-Name\GOSLING
DSA Options: 0x00000001
DSA object GUID: c8e62aed-ebc9-4c0e-a7de-97e8813b39fd
DSA invocationId: 490eea9b-1892-4768-bb96-f21fc9a5cd7e
==== INBOUND NEIGHBORS ====
CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful
0 consecutive failure(s).
Last success @ Sun Jun 20 12:17:47 2021 EDT
CN=Schema,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful
0 consecutive failure(s).
Last success @ Sun Jun 20 12:17:47 2021 EDT
DC=ForestDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful
0 consecutive failure(s).
Last success @ Sun Jun 20 12:17:47 2021 EDT
DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful
0 consecutive failure(s).
Last success @ Sun Jun 20 12:17:47 2021 EDT
DC=DomainDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ Sun Jun 20 12:17:47 2021 EDT was successful
0 consecutive failure(s).
Last success @ Sun Jun 20 12:17:47 2021 EDT
==== OUTBOUND NEIGHBORS ====
CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ NTTIME(0) was successful
0 consecutive failure(s).
Last success @ NTTIME(0)
CN=Schema,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ NTTIME(0) was successful
0 consecutive failure(s).
Last success @ NTTIME(0)
DC=ForestDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ NTTIME(0) was successful
0 consecutive failure(s).
Last success @ NTTIME(0)
DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ NTTIME(0) was successful
0 consecutive failure(s).
Last success @ NTTIME(0)
DC=DomainDnsZones,DC=knada,DC=lan,DC=kitsnet,DC=us
Default-First-Site-Name\CAMUS via RPC
DSA object GUID: 601275d3-2cb1-46f8-ae41-8c44756f4a88
Last attempt @ NTTIME(0) was successful
0 consecutive failure(s).
Last success @ NTTIME(0)
==== KCC CONNECTION OBJECTS ====
Connection --
Connection name: 3567b8f0-df97-4b2c-8bfe-0b6aa3df4118
Enabled : TRUE
Server DNS name : camus.knada.lan.kitsnet.us
Server DN name : CN=NTDS Settings,CN=CAMUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=knada,DC=lan,DC=kitsnet,DC=us
TransportType: RPC
options: 0x00000001
Warning: No NC replicated for Connection!
# samba-tool dbcheck --cross-ncs
Checking 3634 objects
Checked 3634 objects (0 errors)
Verify Last Backup
Shutdown Samba Processes