Linux:Samba AD Factory: Difference between revisions

Line 2: Line 2:


== Build CentOS 8 / Rocky Linux 8 Base System for Factory ==
== Build CentOS 8 / Rocky Linux 8 Base System for Factory ==
Build a basic Linux Virtual Server Guest<ref>[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]</ref> with 1.5&nbsp;GB RAM, 4 vCPU and two disks:
The Factory system is that which will be used to download [https://www.samba.org/samba/download/ Samba source kits] to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest<ref name=":0">[[KVM:guests#Making_a_Guest|KVM:guests#Making_a_Guest]]</ref> with 1.5&nbsp;GB RAM, 4 vCPU and two disks:


* T0 disk0 10&nbsp;GB (V0uv000 /tmp 1024&nbsp;MB, /swap 512&nbsp;MB, /boot 1&nbsp;GB, and the rest for /)
* T0 disk0 10&nbsp;GB (V0uv''###'' /tmp 1024&nbsp;MB, /swap 512&nbsp;MB, /boot 1&nbsp;GB, and the rest for root)
* T3 disk1 16&nbsp;GB (V3uv000 /var 3&nbsp;GB, /usr/local 13&nbsp;GB)
* T3 disk1 16&nbsp;GB (V3uv''###'' /var 3&nbsp;GB, /usr/local 13&nbsp;GB)


When running the Anaconda installer, add to <u>Software Selection</u>,  <u>Additional software for Selected Environment</u>:  ''Development Tools'' .
The system will have a DHCP reservation as <code><''new-guest''>.lan.kitsnet.us</code>. When running the Anaconda installer, add to <u>Software Selection</u>,  <u>Additional software for Selected Environment</u>:  ''Development Tools'' .
== Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC ==
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest<ref name=":0" /> with 1.5&nbsp;GB RAM, 2 vCPU and two disks:
 
* T0 disk0 14&nbsp;GB (V0uv''###'' /tmp 512&nbsp;MB, /swap 3&nbsp;GB, /boot 1&nbsp;GB, root 7&nbsp;GB)
* T3 disk1 4&nbsp;GB (V3uv''###'' /var 2&nbsp;GB)
 
Since these system will be domain-joined, it is important that they have a DHCP reservation as <code><''new-guest''>.'''knada'''.lan.kitsnet.us</code>.
 
=== Guest Environment Customization ===
 
==== path ====
 
* add <code>/usr/local/samba/bin</code> and <code>/usr/local/samba/sbin</code> to:
** <code>secure_path</code> in /etc/sudoers
** <code>PATH</code> in /etc/crontab
** <code>PATH</code> in /etc/anacrontab
* carefully add <code>/usr/local/samba/sbin</code> and <code>/usr/local/samba/bin</code> appropriately (check order) to <code>PATH</code> in /etc/csh.login
* add  <code>/usr/local/samba/sbin</code> to <code>pathmunge</code> in /etc/profile:
<syntaxhighlight lang="sh">
if [ "$EUID" = "0" ]; then
    pathmunge /usr/sbin
    pathmunge /usr/local/sbin
    pathmunge /usr/local/samba/sbin
    pathmunge /usr/local/samba/bin after
else
    pathmunge /usr/local/sbin after
    pathmunge /usr/sbin after
    pathmunge /usr/local/samba/sbin after
    pathmunge /usr/local/samba/bin
fi
</syntaxhighlight>
 
==== Firewall ====
<syntaxhighlight lang="shell-session">
# firewall-cmd --set-default-zone=internal
# firewall-cmd --zone=internal --change-interface ens3 --permanent
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent
# firewall-cmd --reload
</syntaxhighlight>
 
===== Port Reference =====
 
* 88=kerberos
* 135=epmap
* 137=netbios-ns
* 138=netbios-dgm
* 139=netbios-ssn
* 389=ldap
* 445=microsoft-ds
* 464=kpasswd
* 636=ldaps
* 3268=msft-gc
 
* 3269=msft-gc-ssl
 
==== Backup ====
Copy <code>backup_samba-ad-dc</code> to <code>/usr/local/sbin/</code><syntaxhighlight lang="shell-session">
# mkdir /var/lib/samba-ad-dc_backup
# chgrp kitsnet_adm  /var/lib/samba-ad-dc_backup
# chmod o-rx /var/lib/samba-ad-dc_backup
</syntaxhighlight>
 
==== rsyslog ====
 
* add to end of <code>/etc/rsyslog.conf</code> <code>*.*  @192.168.15.80:514</code> <syntaxhighlight lang="shell-session">
# systemctl restart rsyslog.service
# systemctl enable rsyslog.service
</syntaxhighlight>

Revision as of 17:53, 15 May 2021

To use Samba as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD "Factory", where source kits will be downloaded and built into binaries under the /usr/local/samba directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the knada.lan.kitsnet.us domain.

1 Build CentOS 8 / Rocky Linux 8 Base System for Factory[edit | edit source]

The Factory system is that which will be used to download Samba source kits to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 4 vCPU and two disks:

  • T0 disk0 10 GB (V0uv### /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root)
  • T3 disk1 16 GB (V3uv### /var 3 GB, /usr/local 13 GB)

The system will have a DHCP reservation as <new-guest>.lan.kitsnet.us. When running the Anaconda installer, add to Software Selection, Additional software for Selected Environment: Development Tools .

2 Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC[edit | edit source]

The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 2 vCPU and two disks:

  • T0 disk0 14 GB (V0uv### /tmp 512 MB, /swap 3 GB, /boot 1 GB, root 7 GB)
  • T3 disk1 4 GB (V3uv### /var 2 GB)

Since these system will be domain-joined, it is important that they have a DHCP reservation as <new-guest>.knada.lan.kitsnet.us.

2.1 Guest Environment Customization[edit | edit source]

2.1.1 path[edit | edit source]

  • add /usr/local/samba/bin and /usr/local/samba/sbin to:
    • secure_path in /etc/sudoers
    • PATH in /etc/crontab
    • PATH in /etc/anacrontab
  • carefully add /usr/local/samba/sbin and /usr/local/samba/bin appropriately (check order) to PATH in /etc/csh.login
  • add /usr/local/samba/sbin to pathmunge in /etc/profile:
if [ "$EUID" = "0" ]; then
    pathmunge /usr/sbin
    pathmunge /usr/local/sbin
    pathmunge /usr/local/samba/sbin
    pathmunge /usr/local/samba/bin after
else
    pathmunge /usr/local/sbin after
    pathmunge /usr/sbin after
    pathmunge /usr/local/samba/sbin after
    pathmunge /usr/local/samba/bin
fi

2.1.2 Firewall[edit | edit source]

# firewall-cmd --set-default-zone=internal
# firewall-cmd --zone=internal --change-interface ens3 --permanent
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent
# firewall-cmd --reload
2.1.2.1 Port Reference[edit | edit source]
  • 88=kerberos
  • 135=epmap
  • 137=netbios-ns
  • 138=netbios-dgm
  • 139=netbios-ssn
  • 389=ldap
  • 445=microsoft-ds
  • 464=kpasswd
  • 636=ldaps
  • 3268=msft-gc
  • 3269=msft-gc-ssl

2.1.3 Backup[edit | edit source]

Copy backup_samba-ad-dc to /usr/local/sbin/

# mkdir /var/lib/samba-ad-dc_backup
# chgrp kitsnet_adm  /var/lib/samba-ad-dc_backup
# chmod o-rx /var/lib/samba-ad-dc_backup

2.1.4 rsyslog[edit | edit source]

  • add to end of /etc/rsyslog.conf *.* @192.168.15.80:514
    # systemctl restart rsyslog.service
    # systemctl enable rsyslog.service