To use Samba as an Active Directory Domain Controller, Samba must be built from source. While various RPM distros have been made available in the past (and continue to do so today), relying upon these for continued support of these build packages is an operational hazard. Instead, KitsNet has a formalized process to operate a Samba AD "Factory", where source kits will be downloaded and built into binaries under the /usr/local/samba directory tree. The resulting binary tree will be packaged into a tarball and subsequently deployed to the Active Directory Domain Controllers for the knada.lan.kitsnet.us domain.
1 Build CentOS 8 / Rocky Linux 8 Base System for Factory[edit | edit source]
The Factory system is that which will be used to download Samba source kits to build a binary tree and resulting tarball. There will be one of these systems based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 4 vCPU and two disks:
- T0 disk0 10 GB (V0uv### /tmp 1024 MB, /swap 512 MB, /boot 1 GB, and the rest for root)
- T3 disk1 16 GB (V3uv### /var 3 GB, /usr/local 13 GB)
The system will have a DHCP reservation as <new-guest>.lan.kitsnet.us. When running the Anaconda installer, add to Software Selection, Additional software for Selected Environment: Development Tools .
2 Build CentOS 8 / Rocky Linux 8 Base System for Samba AD DC[edit | edit source]
The Samba AD DC systems are those running Samba as Active Directory Domain Controllers for the knada.lan.kitsnet.us domain. There will be at least two of these systems, each based on a basic Linux Virtual Server Guest[1] with 1.5 GB RAM, 2 vCPU and two disks:
- T0 disk0 14 GB (V0uv### /tmp 512 MB, /swap 3 GB, /boot 1 GB, root 7 GB)
- T3 disk1 4 GB (V3uv### /var 2 GB)
Since these system will be domain-joined, it is important that they have a DHCP reservation as <new-guest>.knada.lan.kitsnet.us.
2.1 Guest Environment Customization[edit | edit source]
2.1.1 path[edit | edit source]
- add
/usr/local/samba/binand/usr/local/samba/sbinto:secure_pathin /etc/sudoersPATHin /etc/crontabPATHin /etc/anacrontab
- carefully add
/usr/local/samba/sbinand/usr/local/samba/binappropriately (check order) toPATHin /etc/csh.login - add
/usr/local/samba/sbintopathmungein /etc/profile:
if [ "$EUID" = "0" ]; then
pathmunge /usr/sbin
pathmunge /usr/local/sbin
pathmunge /usr/local/samba/sbin
pathmunge /usr/local/samba/bin after
else
pathmunge /usr/local/sbin after
pathmunge /usr/sbin after
pathmunge /usr/local/samba/sbin after
pathmunge /usr/local/samba/bin
fi
2.1.2 Firewall[edit | edit source]
# firewall-cmd --set-default-zone=internal
# firewall-cmd --zone=internal --change-interface ens3 --permanent
# firewall-cmd --add-service={dns,ldap,ldaps,kerberos} --permanent
# firewall-cmd --add-port={389/udp,135/tcp,135/udp,138/udp,138/tcp,137/tcp,137/udp,139/udp,139/tcp,445/tcp,445/udp,3268/udp,3268/tcp,3269/tcp,3269/udp,49152/tcp,49153/tcp,49154/tcp} --permanent
# firewall-cmd --reload
2.1.2.1 Port Reference[edit | edit source]
- 88=kerberos
- 135=epmap
- 137=netbios-ns
- 138=netbios-dgm
- 139=netbios-ssn
- 389=ldap
- 445=microsoft-ds
- 464=kpasswd
- 636=ldaps
- 3268=msft-gc
- 3269=msft-gc-ssl
2.1.3 Backup[edit | edit source]
Copy backup_samba-ad-dc to /usr/local/sbin/
# mkdir /var/lib/samba-ad-dc_backup
# chgrp kitsnet_adm /var/lib/samba-ad-dc_backup
# chmod o-rx /var/lib/samba-ad-dc_backup
2.1.4 rsyslog[edit | edit source]
- add to end of
/etc/rsyslog.confthe line*.* @192.168.15.80:514# systemctl restart rsyslog.service # systemctl enable rsyslog.service
3 Setup Server to Build or Run Samba AD DC[edit | edit source]
Complete the preparations documented in Setting up Samba as an Active Directory Domain Controller
3.1 Factory Build Server Packages[edit | edit source]
Refer to Package Dependencies Required to Build Samba and incorporate the Manually maintained Distribution-specific Package lists and the Red Hat Enterprise Linux 8 / CentOS 8 section. It will also be necessary to dnf install dbus-devel python3-markdown
3.2 Samba AD DC Server Packages[edit | edit source]
# dnf install avahi-libs cups-libs python3-markdown patch pam-devel python3-cryptography python3-dns krb5-workstation libtasn1-tools
# dnf install lmdb-devel
# mkdir /usr/local/samba
3.3 Check Filesystem Support on all Servers[edit | edit source]
Refer to File System Support for details KistNet standard is for using xfs, so there is only one option to check for:
# uname -r
4.18.0-240.22.1.el8_3.x86_64
# grep -E "CONFIG_EXT4_FS_POSIX_ACL" /boot/config-4.18.0-240.22.1.el8_3.x86_64
CONFIG_EXT4_FS_POSIX_ACL=y
Install the attr package with dnf install attr. Next, refer to the Testing your filesystem section of the documentation for the verification steps
4 Download Samba Source to Factory Build Server[edit | edit source]
- Create the base of the Factory source directory structure
# mkdir /usr/local/SambaAD-Factory
# chown psmode:kitsnet_adm /usr/local/SambaAD-Factory
- Check https://download.samba.org/pub/samba/stable/ to identify the latest
*.tar.gzandwgetthat file tar -xzvfthe downloaded file with-C /usr/local/SambaAD-Factory
5 Build Samba AD DC Factory Distribution[edit | edit source]
Enter the version-specific directory under /usr/local/SambaAD-Factory
$ ./configure --mandir=/usr/local/samba/man
$ make uninstall
$ du /usr/local/samba
0 /usr/local/samba/etc
0 /usr/local/samba/var/lib
0 /usr/local/samba/var/locks
0 /usr/local/samba/var/cache
0 /usr/local/samba/var/lock
0 /usr/local/samba/var/run
0 /usr/local/samba/var
0 /usr/local/samba/private
0 /usr/local/samba/bind-dns
0 /usr/local/samba/
$ make -j 8
$ rm -R /usr/local/samba/*
$ make -j 8 install
$ cd ../dist
$ tar czf samba-4.14.2-factory.tar.gz --owner=root -C /usr/local samba
$ tar --list --verbose --file samba-4.14.2-factory.tar.gz
6 Deploy Samba AD DC Factory Distribution on AD DC[edit | edit source]
asdf