Installation de samba en PDC
Ce document décrit l'installation de samba en contrôleur principal de domaine (PDC) pour les réseaux Microsoft.
Installation :
pdc:~# apt-get install samba
Initialisation du compte root :
pdc:~# smbpasswd -a root
Création des groupes admins et machines :
pdc:~# addgroup --system admins pdc:~# addgroup --system machines
Création des répertoires netlogon et profiles :
pdc:~# mkdir /var/lib/samba/netlogon/ pdc:~# chown root.admins /var/lib/samba/netlogon/ pdc:~# mkdir /var/lib/samba/profiles pdc:~# chown root.admins /var/lib/samba/profiles/ pdc:~# chmod 1757 /var/lib/samba/profiles/
Configuration minimale :
#======================= Global Settings =======================
[global]
## Browsing/Identification ###
workgroup = DEADBEEF
netbios name = pdc
server string = %h server (Samba %v)
wins support = yes
dns proxy = yes
#### Debugging/Accounting ####
log file = /var/log/samba/log.%m
syslog = 0
log level = 2
panic action = /usr/share/samba/panic-action %d
####### Authentication #######
security = user
passdb backend = tdbsam guest
encrypt passwords = true
domain logons = yes
os level = 64
preferred master = yes
domain master = yes
local master = yes
unix password sync = yes
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\sUNIX\spassword:* %n\n *Retype\snew\sUNIX\spassword:* %n\n .
add user script = /usr/sbin/useradd -d /dev/null -g machines -c 'Machine Account' -s /bin/false -M %u
admin users = root
logon home = \\%L\%U\.profile
logon drive = H:
logon path = \\%L\profiles\%U
#======================= Share Definitions =======================
[homes]
comment = Home Directories
browseable = yes
writable = yes
create mask = 0700
directory mask = 0700
[netlogon]
comment = Network Logon Service
path = /var/lib/samba/netlogon
browseable = no
guest ok = yes
writable = no
share modes = no
[profiles]
comment = Network
path = /var/lib/samba/profiles
writable = yes
browseable = no
guest ok = no
directory mask = 0700
create mask = 0600
[print$]
comment = Printer Drivers
path = /var/lib/samba/printers
browseable = yes
read only = yes
guest ok = no
write list = root, @ntadmin
Télécharger le fichier smb.conf