Centos7 with Samba and AD support, Windbind
How to configure a samba server on RHEL 7/ CentoOS7 to work with samba and windbind for AD authentication.
First we need to enrol the server as an AD client within the domain and this is done by configuring the Kerberos and Samba services.
Requirements
We first start by installing the following packages
yum install samba samba-client samba-common samba-winbind samba-winbind-clients krb5- workstation
DNS
- Edit the file /etc/resolv.conf so that the fully qualified domain name (FQDN) of the DNS servers is specified
- The hostname of the Red Hat Enterprise Linux 6 system should be set to the FQDN so edit the file /etc/sysconfig/network and set the hostname to use the FQDN
HOSTNAME=rhel-srv11.cloud.lab.eng.bos.redhat.com - Optional, Install the oddjob-mkhomedir package to ensure that user home directories are created
with the proper SELinux file and directory contexts.
yum install oddjobmkhomedir.x86_64
NTP
Ntp needs to be configured otherwise you can have weird behaviours when connecting to AD.
Kerberos
we configure Kerberos to use the AD Kerberos realm.
# Open the Kerberos client configuration file.
vim /etc/krb5.conf
# Configure the `[logging]` and `[libdefaults]` sections
[logging]
default = FILE:/var/log/krb5libs.log
[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = true
dns_lookup_kdc = true
ticket_lifetime = 24h
renew_lifetime = 7d
rdns = false
forwardable = yes
After this is done, we can double check the configuration by obtain Kerberos credentials for a domain user.
# Clear out any existing tickets
kdestroy
klist
# Obtain a new Kerberos ticket:
kinit user1@EXAMPLE.COM
# Verify a new Kerberos ticket was granted:
klist
Samba
After configuring kerberos, we need to configure the Samba server to connect to the AD server.
# Open the Samba configuration file.
vi /etc/samba/smb.conf
# Set the AD domain information in the `[global]` section.
[global]
workgroup = EXAMPLE
client signing = yes
client use spnego = yes
kerberos method = secrets and keytab
log file = /var/log/samba/%m.log
password server = AD.EXAMPLE.COM
realm = EXAMPLE.COM
security = ads
# Add the machine to the domain using the `net` command.
net ads join -k
This should create a new keytab file, /etc/krb5.keytab and we can list the keys for the system and check that the host principal is there using klist -k
sudo authconfig --enablewinbindauth --enablemkhomedir --update
sudo etckeeper vcs status
On branch master
Changes not staged for commit:
(use "git add <file>..." to update what will be committed)
(use "git checkout -- <file>..." to discard changes in working directory)
modified: pam.d/fingerprint-auth-ac
modified: pam.d/password-auth-ac
modified: pam.d/smartcard-auth-ac
modified: pam.d/system-auth-ac
modified: sysconfig/authconfig
Sources: