Strumenti Utente

Strumenti Sito


debian:joinad

Questa è una vecchia versione del documento!


con realm

Join ad Active Directory

impostare ip statico e gateway in /etc/network/interface

impostare nome pc

#hostnamectl set-hosntname nomepc.dominio.com

impostare su resolv.conf solo i nameserver

nameserver xx.xx.xx.xx

fermare e disabilitare systemd-resolved

#systemctl disable systemd-resolved
#systemctl stop systemd-resolved

installare

#apt-get install realmd libnss-sss libpam-sss sssd sssd-tools adcli samba-common-bin oddjob oddjob-mkhomedir packagekit

verificare prima del join

#realm discover casa.int
casa.int
type: kerberos
realm-name: CASA.INT
domain-name: casa.int
configured: no
server-software: active-directory
client-software: sssd
required-package: sssd-tools
required-package: sssd
required-package: libnss-sss
required-package: libpam-sss
required-package: adcli
required-package: samba-common-bin

creare /etc/krb5.conf

[libdefaults]
 dns_lookup_realm = false
 ticket_lifetime = 24h
 renew_lifetime = 7d
 forwardable = true
 rdns = false
 default_realm = CASA.INT
 default_ccache_name = KEYRING:persistent:%{uid}

join

realm join -U administrator dominio.it

verificare dopo il join

#realm discover casa.int
casa.int
type: kerberos
realm-name: CASA.INT
domain-name: casa.int
configured: kerberos-member
server-software: active-directory
client-software: sssd
required-package: sssd-tools
required-package: sssd
required-package: libnss-sss
required-package: libpam-sss
required-package: adcli
required-package: samba-common-bin
login-formats: %U@casa.int
login-policy: allow-realm-logins

altri installati

apt-get install acl attr

con net ads

inst con ins dominio

asdad

sdad

debian/joinad.1606927022.txt.gz · Ultima modifica: 2023/04/17 14:25 (modifica esterna)