{"id":123,"date":"2019-01-07T15:18:49","date_gmt":"2019-01-07T14:18:49","guid":{"rendered":"http:\/\/blog.nosland.com\/?p=123"},"modified":"2019-01-07T15:22:04","modified_gmt":"2019-01-07T14:22:04","slug":"mise-sur-le-domaine-poste-linux","status":"publish","type":"post","link":"http:\/\/blog.nosland.com\/?p=123","title":{"rendered":"Mise sur le domaine Poste Linux"},"content":{"rendered":"\n<p>Test\u00e9 sous Debian 8<\/p>\n\n\n\n<h4> V\u00e9rification des DNS&nbsp; <\/h4>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\">\/etc\/resolv.conf&nbsp;: <br>nameserver 192.168.73.100<\/p>\n\n\n\n<p>Le nameserver doit \u00eatre le DNS qui r\u00e9sout votre ActiveDirectory <\/p>\n\n\n\n<h4>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nInstallation de ntpdate pour synchro du poste avec contr\u00f4leur de domaine\n\n\n\n<\/h4>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># Apt-get install ntpdate <br># ntpdate domaincontoler.nosland.com<\/p>\n\n\n\n<p>Il est important que le poste soit bien syncho au niveau du temps avec les contr\u00f4leurs de domaines de l&rsquo;AD. <\/p>\n\n\n\n<h4>Installation de Kerberos et configuration<\/h4>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"> # apt-get install krb5-user<br> # cp -p \/etc\/krb5.conf \/etc\/krb5.conf.orig<br> # vi \/etc\/krb5.con <\/p>\n\n\n\n<p>Ajouter et\/ou modifier le fichier avec les lignes : <\/p>\n\n\n\n<p class=\"has-text-color has-background has-very-dark-gray-color has-light-green-cyan-background-color\"><em>[libdefaults]<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 default_realm = NOSLAND.COM<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 dns_lookup_kdc = false<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ticket_lifetime = 24h<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 renew_lifetime = 7d<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 forwardable = true<\/em><br><em>[realms]<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 NOSLAND.COM = {<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 kdc = dc1.nosland.com<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 kdc = dc2.nosland.com<\/em><br><em>\u00a0               kdc = dc3.nosland.com<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0admin_server = dc1.nosland.com<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 default_domain = nosland.com<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 }<\/em><br><em>[domain_realm]<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 .nosland.com = NOSLAND.COM<\/em><br><em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nosland.com = NOSLAND.COM<\/em><\/p>\n\n\n\n<p>Afin de tester si la configuration est OK&nbsp;: <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># kdestroy<br># klist<br># kinit <a href=\"mailto:username@PARIS8.UP8\">username@NOSLAND.COM<\/a><br># klist<\/p>\n\n\n\n<h4>Configuration samba <\/h4>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># mv \/etc\/samba\/smb.conf \/etc\/samba\/smb.origine<br># vi \/etc\/samba\/smb.conf<\/p>\n\n\n\n<p class=\"has-background has-light-green-cyan-background-color\"><em>[global]<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; workgroup = NOSLAND<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; security = ADS<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; realm = NOSLAND.COM<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; password server = dc1.nosland.com<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; domain logons = no<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; encrypt passwords = yes<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template homedir = \/home\/%D\/%U<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template shell = \/bin\/bash<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; winbind enum groups = yes<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; winbind enum users = yes<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; winbind trusted domains only = no<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; winbind use default domain = yes<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; domain master = no<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; local master = no<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; prefered master = no<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; os level = 0<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; idmap config * : backend = tdb<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; idmap config * : range = 11000-20000<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; idmap config NOSLAND : backend = rid<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; idmap config NOSLAND : range=10000000-19000000<\/em><br><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; idmap config NOSLAND : base_rid = 0<\/em><br><em>&nbsp;&nbsp; dns proxy = no<\/em><br><em>&nbsp;&nbsp; log file = \/var\/log\/samba\/log.%m<\/em><br><em>&nbsp;&nbsp; max log size = 1000<\/em><br><em>&nbsp;&nbsp; syslog = 0<\/em><br><em>&nbsp;&nbsp; panic action = \/usr\/share\/samba\/panic-action %d<\/em><\/p>\n\n\n\n<h4>Inscription de la machine dans le domaine<\/h4>\n\n\n\n<p>On a besoin d\u2019un lib PAM pour kerberos&nbsp;: <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># apt-get install libpam-krb5<br>#&nbsp;\/etc\/init.d\/winbind stop<br># \/etc\/init.d\/samba restart<br>#&nbsp;\/etc\/init.d\/winbind start<br># net join -S dc -U administrateur&nbsp;&nbsp;&nbsp; <em>{ saisir au prompt le password admin} <\/em><br># net ads testjoin<br># net ads info<br># wbinfo -u<br># wbinfo \u2013g<\/p>\n\n\n\n<p>La commande <em>wbinfo \u2013u<\/em><br> doit renvoyer l\u2019ensemble des utilisateurs Active Directory <\/p>\n\n\n\n<p>La commande<em> wbinfo \u2013g <\/em><br>doit renvoyer l\u2019ensemble des groupes de s\u00e9curit\u00e9s de l\u2019AD. <\/p>\n\n\n\n<h4>Ajout de winbind pour l\u2019authentification&nbsp; <\/h4>\n\n\n\n<p>On a besoin d\u2019un paquet PAM en plus&nbsp;: <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># apt-get install libnss-winbind libpam-winbind <\/p>\n\n\n\n<p>Modification de nsswitch&nbsp;: <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># vi \/etc\/nsswitch.conf <\/p>\n\n\n\n<p class=\"has-background has-light-green-cyan-background-color\"><em>passwd:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; compat winbind<\/em><br><em>group:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; compat winbind<\/em><br><em>shadow:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; compat winbind<\/em><br><em>gshadow:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; files<\/em><br><em>hosts:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; files dns<\/em><br><em>networks:&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;files<\/em><br><em>protocols:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; db files<\/em><br><em>services:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; db files<\/em><br><em>ethers:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; db files<\/em><br><em>rpc:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; db files<\/em><br><em>netgroup:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; nis<\/em><\/p>\n\n\n\n<p>Test de configuration&nbsp;: <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># getent passwd <\/p>\n\n\n\n<p>Doit renvoyer l\u2019ensemble des users locaux (\/etc\/passwd) +\ntous les users AD<\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># getent group<\/p>\n\n\n\n<p>Doit renvoyer l\u2019ensemble des groupes locaux &amp; des groupes AD. <\/p>\n\n\n\n<h4>Modification du syst\u00e8me d\u2019authentification<\/h4>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># pam-auth-update<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"589\" height=\"110\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-8.png\" alt=\"\" class=\"wp-image-124\"\/><figcaption>Tout cocher<\/figcaption><\/figure>\n\n\n\n<p>Ajouter \u00e0 \/etc\/pam.d\/common-session <\/p>\n\n\n\n<p class=\"has-background has-light-green-cyan-background-color\">session optional&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; pam_krb5.so minimum_uid=1000<\/p>\n\n\n\n<p>(permet la cr\u00e9ation du dossier au premier login) <\/p>\n\n\n\n<p>Cr\u00e9er le Dossier \/home\/domaine (\/home\/%U de smb.conf) <\/p>\n\n\n\n<p class=\"has-text-color has-background has-luminous-vivid-amber-color has-very-dark-gray-background-color\"># mkdir \/home\/NOSLAND <br># chmod 777 \/home\/NOSLAND<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Test\u00e9 sous Debian 8 V\u00e9rification des DNS&nbsp; \/etc\/resolv.conf&nbsp;: nameserver 192.168.73.100 Le nameserver doit \u00eatre le DNS qui r\u00e9sout votre ActiveDirectory&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"_links":{"self":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/123"}],"collection":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=123"}],"version-history":[{"count":2,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/123\/revisions"}],"predecessor-version":[{"id":126,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/123\/revisions\/126"}],"wp:attachment":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=123"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}