smb.conf
Код: Выделить всё
[global]
dos charset = cp866
unix charset = koi8-r
display charset = cp1251
workgroup = DOMAIN1.LOCAL
realm = DOMAIN1.LOCAL
server string = Samba Server %v
security = ADS
password server = domain1.local
log file = /var/log/samba/log.%m
max log size = 50
load printers = no
show add printer wizard = no
printing = bsd
printcap name = /dev/null
disable spoolss = yes
os level = 0
idmap uid = 10000-20000
idmap gid = 10000-20000
template homedir = /fs/private_user_data/%U
template shell = /bin/csh
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = Yes
admin users = "@DOMAIN1\Domain Admins"
hosts allow = 192.168.114.0/255.255.255.0, 10.96.7.0/255.255.255.0, 192.168.0.0/255.255.255.0, 127.
case sensitive = No
wins proxy = Yes
wins support = Yes
[Share]
comment = SHARE
path = /fs/SHARE
admin users = @DOMAIN1\it
read only = No
create mask = 0775
directory mask = 0775
map readonly = no
locking = No
volume = SHARE
delete readonly = Yes
wbinfo --all-domains :
DOMAIN1
DOMAIN2
nslookup разрешает как по имени, так и по IP,
nsswitch.conf
Код: Выделить всё
group: files winbind
group_compat: nis
hosts: files dns
networks: files
passwd: files winbind
passwd_compat: nis
shells: files
services: compat
services_compat: nis
protocols: files
rpc: files
Код: Выделить всё
[libdefaults]
ticket_lifetime = 36000
default_realm = DOMAIN1.LOCAL
dns_lookup_realm = false
dns_lookup_kdc = false
kdc_req_checksum_type = 2
checksum_type = 2
ccache_type = 1
forwardable = true
proxiable = true
[realms]
DOMAIN1.LOCAL = {
kdc = 192.168.114.231
admin_server = 192.168.114.231
default_domain = 192.168.114.231
}
[domain_realm]
.DOMAIN1.LOCAL = DOMAIN1.LOCAL
[pam]
debug = false
ticket_lifetime = 24h
renew_lifetime = 24h
forwardable = true
krb4_convert = false
[login]
krb4_convert = false
krb4_get_tickets = false
[logging]
default = FILE:/var/log/kerberos/krb5libs.log
kdc = FILE:/var/log/kerberos/krb5kdc.log
admin_server = FILE:/var/log/kerberos/kadmind.log
Код: Выделить всё
search domain1.local
domain domain1.local
nameserver 192.168.114.231
Код: Выделить всё
[2013/06/04 12:23:09.331318, 1] libsmb/clikrb5.c:789(ads_krb5_mk_req)
ads_krb5_mk_req: smb_krb5_get_credentials failed for ldap/dc03.domain2.ru@DOMAIN2.RU (Cannot contact any KDC for requested realm)
[2013/06/04 12:23:09.331391, 0] libads/sasl.c:823(ads_sasl_spnego_bind)
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Cannot contact any KDC for requested realm
Как настроить Самбу - чтобы она давала доступ пользователям DOMAIN2.ru к своим ресурсам ??
Согласно man_smb : достаточно ли в smb.conf в секции [global] добавить параметр "allow trusted domains = yes", а также изменить значение idmap uid ?