Centos7 with Samba and AD support, Windbind

How to configure a samba server on RHEL 7/ CentoOS7 to work with samba and windbind for AD authentication.

First we need to enrol the server as an AD client within the domain and this is done by configuring the Kerberos and Samba services.

Requirements

We first start by installing the following packages

yum install samba samba-client samba-common samba-winbind samba-winbind-clients krb5- workstation

DNS

  • Edit the file /etc/resolv.conf so that the fully qualified domain name (FQDN) of the DNS servers is specified
  • The hostname of the Red Hat Enterprise Linux 6 system should be set to the FQDN so edit the file /etc/sysconfig/network and set the hostname to use the FQDN HOSTNAME=rhel-srv11.cloud.lab.eng.bos.redhat.com
  • Optional, Install the oddjob-mkhomedir package to ensure that user home directories are created with the proper SELinux file and directory contexts. yum install oddjob­mkhomedir.x86_64

NTP

Ntp needs to be configured otherwise you can have weird behaviours when connecting to AD.

Kerberos

we configure Kerberos to use the AD Kerberos realm.

# Open the Kerberos client configuration file.
vim /etc/krb5.conf

# Configure the `[logging]` and `[libdefaults]` sections
[logging]
default = FILE:/var/log/krb5libs.log
[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = true
dns_lookup_kdc = true
ticket_lifetime = 24h
renew_lifetime = 7d
rdns = false
forwardable = yes

After this is done, we can double check the configuration by obtain Kerberos credentials for a domain user.

# Clear out any existing tickets
kdestroy
klist

# Obtain a new Kerberos ticket:
kinit user1@EXAMPLE.COM

# Verify a new Kerberos ticket was granted:
klist

Samba

After configuring kerberos, we need to configure the Samba server to connect to the AD server.

# Open the Samba configuration file.
vi /etc/samba/smb.conf

# Set the AD domain information in the `[global]` section.
[global]
 workgroup = EXAMPLE
 client signing = yes
 client use spnego = yes
 kerberos method = secrets and keytab
 log file = /var/log/samba/%m.log
 password server = AD.EXAMPLE.COM
 realm = EXAMPLE.COM
 security = ads

# Add the machine to the domain using the `net` command.
net ads join -k

This should create a new keytab file, /etc/krb5.keytab and we can list the keys for the system and check that the host principal is there using klist -k

sudo authconfig --enablewinbindauth  --enablemkhomedir --update
sudo etckeeper vcs status
On branch master
Changes not staged for commit:
(use "git add <file>..." to update what will be committed)
(use "git checkout -- <file>..." to discard changes in working directory)

modified:   pam.d/fingerprint-auth-ac
modified:   pam.d/password-auth-ac
modified:   pam.d/smartcard-auth-ac
modified:   pam.d/system-auth-ac
modified:   sysconfig/authconfig

Sources:

​