一 摘要
在企業中為了對所有服務器的帳號和密碼進行統一的管理,可以采用windows活動目錄的解決方案;對於windows服務器,直接將服務器加入域即可;對於Linux服務器,如果要將Linux服務器加入域,還需要其他的軟件的協助,本文介紹通過Samba和Winbind的協助將Linux加入活動目錄,實現帳號和密碼統一管理。[root@localhost cdrom]# yum -y install samba samba-client samba-common samba-winbind samba-winbind-clients
[root@linux01 ~]# service smb stop
關閉 SMB 服務: [確定]
[root@linux01 ~]# service smb start
啟動 SMB 服務: [確定]
[root@linux01 ~]# chkconfig smb on
[root@linux01 ~]# netstat -tunlnp | grep smb
tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN 3556/smbd
tcp 0 0 0.0.0.0:139 0.0.0.0:* LISTEN 3556/smbd
tcp 0 0 :::445 :::* LISTEN 3556/smbd
tcp 0 0 :::139 :::* LISTEN 3556/smbd
[root@linux01 ~]# service winbind start
啟動 Winbind 服務: [確定]
[root@linux01 ~]# chkconfig winbind on
[root@linux01 ~]# cat /etc/resolv.conf
search vinda.cn
nameserver 192.168.10.1
[root@linux01 ~]# cat /etc/sysconfig/network
NETWORKING=yes
[root@linux01 ~]# yum -y install krb5-workstation krb5-libs pam_krb5
[root@linux01 ~]# rpm -qa | grep krb5
pam_krb5-2.3.11-9.el6.x86_64
sssd-krb5-common-1.12.4-47.el6.x86_64
krb5-libs-1.10.3-42.el6.x86_64
sssd-krb5-1.12.4-47.el6.x86_64
root@linux01 ~]# yum install -y oddjob-mkhomedir
root@linux01 ~]# setup
root@linux01 ~]# system-config-authentication
[root@linux01 ~]# net ads join -U administrator
Enter administrator's password:
Using short domain name -- VINDA
Joined 'LINUX01' to dns domain 'vinda.cn'
[root@linux01 ~]# wbinfo –u
VINDA\administrator
VINDA\guest
VINDA\krbtgt
VINDA\sccmadmin
VINDA\sccm_sql_services
VINDA\test01
VINDA\test02
[root@linux01 ~]# wbinfo -g
VINDA\winrmremotewmiusers__
VINDA\domain computers
VINDA\domain controllers
VINDA\schema admins
VINDA\enterprise admins
VINDA\cert publishers
…