...ããŒããããã¯èµ·ãã£ãã ãã¹ãŠãéåžžã«åçŽã§ããããšã倿ããŸããããäž»ã«ã€ã³ã¿ãŒãããäžã®æ
å ±ãæ€çŽ¢ããã®ã«ããªãã®æéãè²»ãããªããã°ãªããŸããã§ããïŒãã¡ãã䟿å©ã§ãïŒã ãããã£ãŠãç§ã¯èªåã®å®è£
çµéšã«åºã¥ããŠãã®ã¬ã€ããæžãããšã«ããŸããã äž»ãªããšã¯ããã¹ãŠã1ãæã§çµã¿ç«ãŠãããããšã§ãïŒããããbind9èšå®ãé€ããŸãããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãïŒã
ã ããææŠã Ubuntu 12.04ãæèŒãããµãŒããŒããããŸãã 圌ã¯ãªãå¿
èŠããããŸãïŒ
- Active DirectoryãåããPDC Windowsãã¡ã€ã³ã
- RadiusãµãŒããŒã§ã®æ¿èªã䌎ãVPNãµãŒããŒïŒããšãã°ãPPTPãšããŸãããMS-CHAP v2ããã³MPPE-128ã匷å¶çã«ãµããŒãããŸãïŒã
- ããã«å¿ããŠ-FreeradiusãµãŒããŒã«ãã£ãŠã
- ADãŠãŒã¶ãŒãééçã«ãã°ã€ã³ããã¿ãŒããã«ãµãŒããŒã
éããã
Samba4ã眮ã
Samba4 / HOWTOãæ³šææ·±ãèªã¿ãŸããã ã€ã³ã¹ããŒã«ã®éå§æã«ãSamba4 -4.0.0rc2ã®æ¬¡ã®ããŒãžã§ã³ãå©çšå¯èœã§ããã ä»ãç§ãç¥ãéã-4.0.0rc3ã RC2ã䜿çšããŠèª¬æããŸãã
HOWTOã®æç€ºã«åŸã£ãŠãã¹ãŠãè¡ããŸãããããã€ãã®ãã¥ã¢ã³ã¹ãå¿ããªãã§ãã ããã
- çµå±ã®ãšãããLinuxã³ã³ãã¥ãŒã¿ãŒã§ADãŠãŒã¶ãŒãèªèšŒããå¿
èŠããããŸããïŒ æ¬¡ã«ãã·ã¹ãã ã«libpam0g-devããã±ãŒãžãã€ã³ã¹ããŒã«ããããšãå¿ããªãã§ãã ããïŒ sudo apt-get install libpam0g-dev ïŒã ãããã®ã©ã€ãã©ãªããªããšãPambaã¯samba4ã§ãµããŒããããŸããïŒå¿
èŠãªpam_winbind.soã©ã€ãã©ãªãå«ã/ usr / local / samba / lib / security /ãã£ã¬ã¯ããªã¯ãã«ãããããããžã§ã¯ãã«ã¯ååšããŸããïŒã
- ïŒåŒ·ãïŒïŒ ./configureã®ä»£ããã«./configure.developerã䜿çšããããšããå§ãããŸãã
次ã«ã
WiKi Samba4 HOWTOã®èª¬æã«
åŸã£ãŠãã ãã ã ãã«ããããsamba4ã¯ããã£ã¬ã¯ããª
/ usr / local / samba /ã«é
眮ãããŸãã ç¹°ãè¿ããŸããããã¹ãŠã®samba4ãã€ããªã¯
/ usr / local / samba / bin /ãã£ã¬ã¯ããªã«ãã ããµãŒãã¹ã¯
/ usr / local / samba / sbin /ãã£ã¬ã¯ããªã«ããããã絶察ãã¹ã䜿çšããŠã¢ã¯ã»ã¹ããããä¿®æ£ããå¿
èŠãããããšã«æ³šæããŠãã ããPATH倿°ããŸãã¯-ç§ãè¡ã£ãããã«ãsamba4ãsamba3ãªãã®ãã·ã³ã«çœ®ããå Žå-ãã¹ãŠã®ãã¡ã€ã«ã®ã·ã³ããªãã¯ãªã³ã¯ããã£ã¬ã¯ããª
/ usr / local / samba / bin /ãããã£ã¬ã¯ããª
/ usr / bin /ã«ããã£ã¬ã¯ããª
/ usr / local /ããäœæããsamba / sbin / -ãã£ã¬ã¯ããª
/ usr / sbin /ãž ã
HOWTOã®èª¬æã«åŸã£ãŠãsamba4ã®ããããžã§ãã³ã°ãè¡ããŸãã ãšãããããã®æé ã¯
/ usr / local / samba / etc /ãã£ã¬ã¯ããªã«ã¡ã€ã³ã®sambaæ§æãã¡ã€ã«-smb.confãäœæããŸããããã«ã¯å¿
èŠãªãªãã·ã§ã³ãšãããŒã«ãã远å ãã... sambaãå®è¡ããŸãã ããã¯ç§ã®
/usr/local/samba/etc/smb.confã®ãããªãã®ã§ãïŒ
/ etc / init /ãã£ã¬ã¯ããªã§
samba4ãå®è¡ããã«ã¯ã
次ã®å
容ã®
samba4.confãã¡ã€ã«ãäœæããŸãã
description "SMB/CIFS File and Active Directory Server" author "Jelmer Vernooij <jelmer@ubuntu.com>" start on (local-filesystems and net-device-up) stop on runlevel [!2345] expect fork normal exit 0 pre-start script [ -r /etc/default/samba4 ] && . /etc/default/samba4 install -o root -g root -m 755 -d /var/run/samba install -o root -g root -m 755 -d /var/log/samba end script exec /usr/local/samba/sbin/samba âD
ãµãŒãã¹ã®éå§/åæ¢ã¯æ¬¡ã®ãšããã§ãã
DNSãèšå®ããã«ã¯ã ãŸãŒã³ãå«ãbind9ã¯ãã®ãµãŒããŒã§æ¢ã«å®è¡ãããŠãããç¬èªã®ãã«ãã€ã³DNSãµãŒããŒãæã€samba4ã¯ãæ¢ã«æ§æãããbind9ãšãåéãäœããããšãæã¿ãŸããã§ããããã€ã³ã9ã
ãã以å€ã¯ãã¹ãŠãäžèšã®HOWTOã«å³å¯ã«åŸã£ãŠãããããã€ãã®ã³ã¡ã³ãããããŸãã
- Windows 7ã«ã€ã³ã¹ããŒã«ãããŠããWindowsãªã¢ãŒã管çããŒã«ããã±ãŒãžã«ã¯ã2ã€ã®äžå¿«ãªæ©èœããããŸãïŒãããŸã§ã®ãšãã2ã€ã«æ°ä»ããŸããïŒã
-ãŸãããŠãŒã¶ãŒããããã£ã®ADUCã¹ãããã€ã³ã«ã¯ãããã€ã€ã«ã€ã³ãã¿ãããŸã£ãããããŸããïŒãŸãã¯ãã·ã¢èªã§ã¯ã©ãã§ããïŒïŒããããã£ãŠãä»ã®æ¹æ³ã§ãŠãŒã¶ãŒã®ãªã¢ãŒãã¢ã¯ã»ã¹èšå®ãè¡ãå¿
èŠããããŸãã
-第äºã«ãç¹å¥ã«äœæããããŠãŒã¶ãŒããã¹ãŠã®å¯èœãªã°ã«ãŒãã«å«ãŸããŠããã«ãããããããã°ã«ãŒãããªã·ãŒã®ç®¡çã¯ç®¡çè
ã¢ã«ãŠã³ãã§ã®ã¿å¯èœã§ã... - æ£çŽãªãšãããsamba4ã§ã®ã°ã«ãŒãããªã·ãŒã®å¯èœæ§ãè©³çŽ°ã«ææ¡ãããŸã§ã¯...
ãããã£ãŠãsamba4ãã€ã³ã¹ããŒã«ãããå®è¡ãããŠããŸãã Linuxã§ã®ADãŠãŒã¶ãŒèªèšŒã®çªã§ã
Winbindã»ããã¢ãã
Wiki Samba4 / Winbindã®ããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ããŠãããã«æžãããŠããALL-ALL-ALLãå®è¡ããŸãã /etc/nsswitch.confã«å€æŽãå ããåŸãã·ã¹ãã ãåèµ·åããããšãå¿ããªãã§ãã ãããäžè¬çã«ã¯ãåèµ·åãå¿
èŠã§ãã /etc/pam.d/å
ã®ãã¡ã€ã«ã«æ³šæããŠãã ãããééããå ŽåããµãŒããŒãããã©ãã¯ããã¯ã¹ãã«å€ããã®ã§ã sshãŸãã¯ã³ã³ãœãŒã«ããã¢ã¯ã»ã¹ããããšã¯ã§ããŸãã...ãšã©ãŒãªãã§ãã¹ãŠãå®è¡ããå Žå-ããã§ãActive DirectoryãŠãŒã¶ãŒã¢ã«ãŠã³ãã§LinuxãµãŒããŒã«ãã°ã€ã³ã§ããŸãïŒ
ãã ããå¿
èŠãªã¢ã¯ã·ã§ã³ãäžèŠ§è¡šç€ºãããã¹ãŠã®ïŒåäœããŠããïŒïŒèšå®ãã¡ã€ã«ãäžèŠ§è¡šç€ºããŠããã¹ãŠã1ãæã«åãŸãããã«ããŸãã
ã ããã
ã©ã€ãã©ãª
libnss_winbind.soã䜿çšå¯èœã«ããŸã ã
/etc/nsswitch.confãç·šéããŸãã
ïŒ/etc/nsswitch.conf
passwd: compat winbind group: compat winbind shadow: compat hosts: files dns networks: files protocols: db files services: db files ethers: db files rpc: db files netgroup: nis
ãã®ç·šéåŸãããã«åèµ·åããŠãã ããïŒ
winbindã®ãã¹ãã ã¯ããã·ã¹ãã ã«ãã®ãããªããã»ã¹ããªãããšã«æ¥ããããããªãã§ãã ãã-sambaããŒã¢ã³ããã¹ãŠã®æ©èœãå®è¡ããããã«ãªããŸããã
Winbindã®å¯çšæ§ïŒ
$ /usr/local/samba/bin/wbinfo -p Ping to winbindd succeeded
Winbindã¯ãã¡ã€ã³ãŠãŒã¶ãŒã®ãªã¹ããè¿ããŸãã
$ /usr/local/samba/bin/wbinfo -u ... <_>\Administrator ...
getent passwdã¯ãLinuxãšãã¡ã€ã³ã®äž¡æ¹ã®ãã¹ãŠã®ãŠãŒã¶ãŒã®ãªã¹ããæäŸããŸãã
$ getent passwd root:x:0:0⊠... <_>\Administrator:x:0:100::/home/MATWS/Administrator:/bin/false ...
idã³ãã³ãã¯ããã¡ã€ã³ãŠãŒã¶ãŒã«é¢ããæ
å ±ãè¿ããŸãã
$ id Administrator uid=0(root) gid=100(users) groupes=0(root),100(users),3000004(Group Policy Creator Owners),3000008(Domain Admins)
samba4ã®ã調éãæ®µéã§äœæããã管çè
ãã¡ã€ã³ãŠãŒã¶ãŒã¯ãuid = 0ã§ããããã®åŸã®ãã¹ãŠã®çµæã«æ³šæããŠãã ããã
ãã ã®ã»ããã¢ãã
ãŸãã
pam_winbind.soã©ã€ãã©ãªã
å©çšå¯èœã«ããŸã ïŒ
/etc/pam.d/ãã£ã¬ã¯ããªãŒã§ä»¥äžã®ãã¡ã€ã«ãæ§æããŸãã
/etc/pam.d/common-auth
/etc/pam.d/common-account ïŒ
/etc/pam.d/common-session ïŒ
ããã§ããã¡ã€ã³ãŠãŒã¶ãŒãšããŠLinuxã³ã³ãã¥ãŒã¿ãŒã«ãã°ã€ã³ã§ããããã«ãªããŸããã
ããªãŒååŸ
次ã®ã¹ãããã§ã¯ãfreeradiusãµãŒããŒãã€ã³ã¹ããŒã«ããŠæ§æããpptpdãActive DirectoryããŒã¿ãšMS-CHAP v2ããã³MPPE-128ãããã³ã«ã䜿çšããŠfreeradiusãšé£åããããã«æ§æããŸãã ãŸããsamba3ã䜿çšããŠMS-CHAP v2ãå®è£
ããå¿
èŠããããããã«ã¯ãŒã«ãªããšã«ãsamba4ãšradius-serverãç°ãªããã·ã³ã«åé¢ããå¿
èŠããããšã¯æããªãã§ãã ããïŒ
ãã®ãããããã§ã
WiKi Samba4 / HOWTO / Virtual_Private_Networkãåºçºç¹ãšããŠäœ¿çšããŸãã ããããæåéãã§ã¯ãããŸããã éããã
freeradiusãã€ã³ã¹ããŒã«ããŸãã
sudo apt-get install freeradius freeradius-common freeradius-krb5 freeradius-ldap freeradius-utils radiusclient1
åè¿°ã®WiKiã®èšäºãšæ¯èŒããŠãradiusclient1ããã±ãŒãžã®ã€ã³ã¹ããŒã«ãããã«è¿œå ãããããšã«æ³šæããŠãã ãããããã¯ãpptpdãradiusãã©ã°ã€ã³ã§åäœããããã«å¿
èŠã§ãã
freeradiusã®æ§æã ãã®
/etc/freeradius/radiusd.confããããŸãïŒ
prefix = /usr exec_prefix = /usr sysconfdir = /etc localstatedir = /var sbindir = ${exec_prefix}/sbin logdir = /var/log/freeradius raddbdir = /etc/freeradius radacctdir = ${logdir}/radacct confdir = ${raddbdir} run_dir = ${localstatedir}/run/freeradius db_dir = ${raddbdir} libdir = /usr/lib/freeradius pidfile = ${run_dir}/freeradius.pid max_request_time = 30 cleanup_delay = 5 max_requests = 1024 listen { type = auth ipaddr = <ip_address_>
次ã«ã
/ etc / freeradius / clients.confã«æ¬¡ã®ããã«èšè¿°ããŸãã
client localhost { ipaddr = 127.0.0.1 netmask = 32 secret = samba4
EAP-TTLSããã³PEAPãå¿
èŠãšããå
éšãã³ãã«ã®å¯èœæ§ãåé€ããŸãã
sudo rm -rf /etc/freeradius/sites-enabled/inner-tunnel
ããã§ã
ããã©ã«ãã®ãã£ã¬ã¯ããªã¯
/ etc / freeradius / sites-enabled /ãã£ã¬ã¯ããªã«æ®ããç·šéããŠããŸãïŒ
authorize { preprocess auth_log chap mschap
/ etc / freeradius / modules /ãã£ã¬ã¯ããªã«ç§»åããå¿
èŠãªã¢ãžã¥ãŒã«ãç·šéããŸãã
ãã¡ã€ã«
/ etc / freeradius / modules / ldap ïŒãã¹ãŠã®cnãšdcãããªãã®ãã®ã«çœ®ãæããŸãïŒïŒ
ldap { server = "localhost" identity = "cn=VPN,cn=users,dc=example,dc=com"
/ etc / freeradius / modules / mschapã®ç·šéïŒ
mschap { use_mppe = yes ( mppe-128) require_encryption = yes require_strong = yes with_ntdomain_hack = no
ããäžåºŠãntlm_auth = "/ usr / local / samba / bin / ntlm_auth3 parameter ..."ã«æ³šç®ããŸããSamba4ã¯samba3ãšãåéãã§ãããMS-CHAP v2ããµããŒãããªãntlm_authãã€ããªã®ä»ã«ãããããã¹ãŠãã©ãã°ããntlm_auth3ãã€ããªããããŸããïŒ
PPTPD
ãããŠæåŸã«pptpdã pptpdèªäœã¯ãã§ã«ã€ã³ã¹ããŒã«ããã³èšå®ãããŠããããšãçè§£ãããŠããŸãïŒ
/etc/pptpd.confãã¡ã€ã«ãç·šéããå¿
èŠã¯ãã
ãŸããïŒïŒ
/ etc / ppp / pptpd-optionsãç·šéïŒ
ãã¡ã€ã«
/etc/radiusclien/radiusclient.conf ïŒç§ã®æèŠã§ã¯ãauthserverãšacctserverãä¿®æ£ããªãéããç§ã¯ããã«è§ŠããŸããã§ããïŒïŒ
ãã¡ã€ã«
/ etc / radiusclien / server ïŒ
éåžžã«éèŠãªãã€ã³ã-ãã¡ã€ã«
/etc/radiusclient/dictionary.microsoftãäœæããŸãã ç§ã¯åœŒã®ããã¹ããåŒçšããŸããããªããªã
ããã§å®å
šã«å
¥æã§ã
ãŸã ïŒ
ãããŠããã¡ã€ã«ã®æåŸã«
/ etc / radiusclient /èŸæžã®è¡ã远å ããŸã
/etc/radiusclient/dictionary.microsoftãå«ããŠã次ã®ãã®ãååŸããŸãã
ãã¹ãŠãããã§ãã Samba4ã¯ãã§ã«å®è¡äžã§ããfreeradiusãµãŒããŒãšpptpdããŒã¢ã³ãåèµ·åããå¿
èŠããããŸãã
ADUCã¹ãããã€ã³ã«[ãã€ã€ã«ã€ã³]ã¿ãããªããšããåé¡ã解決ãã
ããããã ç¹å®ã®ãŠãŒã¶ãŒã®VPNã¢ã¯ã»ã¹ãæå¹/ç¡å¹ã«ããæ¹æ³ã«ã€ããŠã Windowsãªã¢ãŒã管çããŒã«ããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãããïŒ ãã®ãããWindows 7ã®[ãã€ã€ã«ã€ã³]ã¿ãã§WiKiããŒãžã«è¡šç€ºãããADUCã¹ãããã€ã³ã®ç»åã¯è¡šç€ºãããŸããã ãããŠã次ã®ãããªãã®ã衚瀺ãããŸãïŒ

ãããŠããã€ã€ã«ã€ã³ã¿ããŸãã¯ãã®ãã·ã¢ã®å¯Ÿå¿ããçä¿¡ã³ãŒã«ã¯ã©ãã«ãããŸããïŒ ããã§ãŠãŒã¶ãŒæš©éã管çããæ¹æ³ã¯ïŒ å¿é
ããå¿
èŠã¯ãããŸããã ç§ãã¡ã¯å°é£ãæããŠããŸãããïŒ ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ããšãããLDAPãµãŒããŒã§ããããããã®ãããªãµãŒããŒã管çããããã®ããŒã«ïŒããšãã°ã
LdapAdmin ïŒãé
眮ãããããé§åããŸãã
ãŸããsamba4ãµãŒããŒãžã®æ¥ç¶ãæ§æããŸãããµãŒããŒã¢ãã¬ã¹ãç»é²ãã[ãã§ããDN]ãã¿ã³ãã¯ãªãã¯ããæäžäœã¬ãã«ã®ããŒã¹ã§ããã©ãžãªããã¯ã¹[GSS-API]ãéžæããŸãããŠãŒã¶ãŒâ管çè
ãšããŠããã®ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããæ¥ç¶ããŸãã ãã¡ã€ã³ã®å±éäžã«ç©ã¿éããããã«ã¿ãã°å
šäœã衚瀺ãããŸãã å¿
èŠãªãŠãŒã¶ãŒãéžæããç·šéã¢ãŒãã«å
¥ããŸãã msNPAllowDialin屿§ãèŠã€ããŠãTRUEãŸãã¯FALSEãå
¥åããŸãïŒå¿
é -倧æåã§ïŒïŒïŒ

ä¿åããŸãã ãã®ãŠãŒã¶ãŒã¯ãVPNçµç±ã§ã®ãã°ã€ã³ãèš±å¯ïŒãŸãã¯çŠæ¢ïŒãããŸãã
ãŸãšã
ç§ã®æèŠã§ã¯ãæçš¿ã®æåã«èšå®ããããã¹ãŠã®ã¿ã¹ã¯ã¯è§£æ±ºãããŸããã ãœãªã¥ãŒã·ã§ã³ã«è²»ãããæéïŒçŽ2é±éåïŒã¯ãäž»ã«ã€ã³ã¿ãŒãããäžã®ããã¥ã¡ã³ãã®èª¿æ»ããã®ãããªãœãªã¥ãŒã·ã§ã³ã®çµéšãåãåã£ãæ
å ±ãšãµãŒããŒã§èªåã®ç®ã§èŠãçŸå®ãšã®æ¯èŒãsamba4ã®ã³ã³ãã€ã«ãšåã³ã³ãã€ã«ãããã³ç·šéãç·šéãšæ§æã®ç·šéãç¹°ãè¿ããŸã...ããããçµæã¯ç§ãæºè¶³ãããŸãããçµæã¯ãWindows Server 2008 R2ãActive Directoryããããã¯ãŒã¯ããªã·ãŒãšã¢ã¯ã»ã¹ãµãŒãã¹ããªã¢ãŒããã¹ã¯ããããµãŒãã¹ã«ã»ãŒå®å
šã«çœ®ãæãããã®ã§ã OVAã¯æžããŠããªãïŒã