
ããã«ã¡ã¯HabrïŒ
Petyaã©ã³ãµã ãŠã§ã¢06/27/2017ã®æŽ»ååŸãç§ã¯SMB1ïŒå¥åCIFSïŒããªãã«ããSMBãããã³ã«ã®ãæ°ãããããŒãžã§ã³ã§ã®äœæ¥æ¹æ³ãããããªãçç£èšåãšãããã¯ãŒã¯MFPãåãåããŸããã
ãå€ããããã€ã¹ããããŒã¿ãåä¿¡ããæ¹æ³ã¯ïŒ å®è·µã瀺ããŠããããã«ãWindowsãåããå¥ã®ããã·ã³ãã¯éžæè¢ã§ã¯ãããŸãããæ»æäžã«ããã¡ã€ã³ããã·ã³ããšã¯å¥ã«ããã¡ã€ã³ã«å«ãŸããŠããªããã·ã³ã被害ãåããŸããã
ç«ã®äžã«ã¯ãCentOS 7ã«åºã¥ããSAMBAãã¡ã€ã«ãµãŒããŒãã€ã³ã¹ããŒã«ããã³æ§æããããã®æ®µéçãªæé ããããŸãã
-å¿åã¢ã¯ã»ã¹
-èªèšŒãšæ¿èª
-Active Directoryãšã®çµ±å
CentOS 7ãã€ã³ã¹ããŒã«ãã
ãµãŒããŒã¯VMware ESXiãå®è¡ããŠãããããCentOS 7 1611ãVMã«ã€ã³ã¹ããŒã«ãã1 CPUã1GB RAMã3GB HDDãå²ãåœãŠãŸããã
LVMã䜿çšãããSWAPããŒãã£ã·ã§ã³ãäœæãããããŒãããŒãã£ã·ã§ã³ã«500MBãå²ãåœãŠããã®ä»ãã¹ãŠããã¡ã€ã«ã·ã¹ãã ã®ã«ãŒãã«å²ãåœãŠãŸãã ãã¡ã€ã«ã·ã¹ãã ãšããŠext4ã䜿çšããŸãã

ã€ã³ã¹ããŒã«ããã»ã¹ã«ã€ããŠã¯èª¬æããŸããããããè¡ã£ãããšããªãå Žåã§ããé£ããã¯ãããŸãããæåããŸãã ç§ã¯ããªãããã§ã«ãã¹ãŠãã€ã³ã¹ããŒã«ãããšä»®å®ããŸãããããŠããªãã¯å
ã«é²ãããšãã§ããŸãã
LinuxãåããŠäœ¿çšããå Žåã¯ãæ§æã䜿çšããŠå
ã®ãã¡ã€ã«ã®ã³ããŒãäœæãã
cpã³ãã³ãã䜿çšã
ãŸã ã
cp /etc/somefile.conf /etc/somefile.conf.bak
DHCPçµç±ã§IPã¢ãã¬ã¹ãååŸãã
äœããã®çç±ã§ãããã¯ãŒã¯ã«DHCPãµãŒããŒããªãå Žåã¯ããããäžããå¿
èŠããããŸãã DHCPãªãã§å€æ°ã®VMãæäœããã®ã¯äŸ¿å©ã§ã¯ãããŸããã
æŽæ°ã匷å¶ããããIPã¢ãã¬ã¹ãååŸããã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸã
dhclient
IPã¢ãã¬ã¹ã衚瀺
ifconfig nmcli device show
ã€ã
CentOS 7ã¯YUMããã±ãŒãžãããŒãžã£ãŒã䜿çšããŸãã ã€ã ããŒãã·ãŒãã¯
ãã¡ãã§ãã
ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ããããã·ãµãŒããŒãä»ããŠæ§æãããŠããå Žåã¯ããããã·ã¢ãã¬ã¹ã
/etc/yum.confæ§æ
ãã¡ã€ã«ã«è¿œå ããviãšãã£ã¿ãŒãŸãã¯æ¬¡ã®ã³ãã³ãã䜿çšã
ãŸã echo proxy=http://your.proxy:8888 >> /etc/yum.conf
ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠãããã·ãµãŒããŒã«ã¢ã¯ã»ã¹ããå Žåã¯ã次ã®ãã©ã¡ãŒã¿ãŒãè¿œå ããŸãã
proxy_username = yum-user
proxy_password = qwerty
VMã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããŠãã¹ããµãŒããŒãšå¯Ÿè©±ãã
VMware ESXiã®å Žåãopen-vm-toolsãã€ã³ã¹ããŒã«ããå¿
èŠããããŸã
yum install open-vm-tools
Hyper-Vã®å Žåãhyperv-daemons
yum install hyperv-daemons
ã¢ããããŒããã€ã³ã¹ããŒã«ãã
å©çšå¯èœãªãã¹ãŠã®ã¢ããããŒããã€ã³ã¹ããŒã«ããããšãéåžžã«éèŠã§ãã
yum update
çå€äžã®åžä»€å®
éåžžã®ãšãã£ã¿ãŒãªãã§ãã¡ã€ã«ãç·šéããããšã¯ããŸã䟿å©ã§ã¯ãããŸãããmcããã³mceditã䜿çšããããšããå§ãããŸãã
yum install mc
ãããã¯ãŒã¯èšå®
nmtuiãŠãŒãã£ãªãã£ã䜿çšããŠãéçIPã¢ãã¬ã¹ãšãã¹ã
åãæ§æã§ããŸã

ã³ãã³ãããã³ããã§ããããã¯ãŒã¯ã¢ããã¿ãŒã®ãªã¹ãã次ã®ã³ãã³ãã§ååŸã§ããŸãã
nmcli device status
éçIPããã³ã²ãŒããŠã§ã€ã¯ã次ã®ã³ãã³ãã«ãã£ãŠèšå®ãããŸãããens192ãã¯ãããã¯ãŒã¯ã¢ããã¿ãŒã®ååã§ãã
nmcli connection modify âens192â ipv4.addresses â192.168.1.100/24 192.168.1.1â
FQDNãæ§æãã
å®å
šä¿®é£Ÿãã¹ãåã
ls01.fqdn.comãšããã³ãã³ããå®è¡ããŸã
hostnamectl set-hostname ls01.fqdn.com
ããŒã ãµãŒãã¹ãåèµ·åããŸã
systemctl restart systemd-hostnamed
次ã®ã³ãã³ãã§çµæã確èªã§ããŸã
hostnamectl status hostname hostname -s hostname -f
ipv6
ipv6ã䜿çšããªãå Žåã¯ãç¡å¹ã«ããã®ãè«ççã§ããããè¡ãã«ã¯ã2ã€ã®ãã©ã¡ãŒã¿ãŒã
/etc/sysctl.confãã¡ã€ã«ã«è¿œå ãã次ã®ã³ãã³ããå®è¡ãããã
mceditãšãã£ã¿ãŒã䜿çšããŸã
echo net.ipv6.conf.all.disable_ipv6 = 1 >> /etc/sysctl.conf echo net.ipv6.conf.default.disable_ipv6 = 1 >> /etc/sysctl.conf
ãããã¯ãŒã¯ãµãŒãã¹ãåèµ·åãã
service network restart
ã»ãªããã¯ã¹
ãã®æ®µéã§ãSELINUXãµãŒãã¹ãç¡å¹ã«ããå¿
èŠããããŸããã³ãã³ãã䜿çšããŠãSELINUXãµãŒãã¹ã®ã¹ããŒã¿ã¹ã確èªã§ããŸãã
sestatus
/ etc / selinux / config ãã¡ã€ã«ã®SELINUXå€ã
SELINUX = disabledã«å€æŽãããµãŒããŒãåèµ·åããŸãã
reboot
èšäºã®æåŸã§SELINUXã«æ»ããŸãã
ãµã³ã
èšçœ®
yum install samba
èªåçã«éå§ãããµãŒãã¹ãè¿œå ãã
chkconfig smb on
ãµãŒãã¹ã®éå§ãšã¹ããŒã¿ã¹ã®ç¢ºèª
service smb start smbstatus
ãã¡ã€ã¢ãŠã©ãŒã«D
ããã©ã«ãã§ã¯ãCentOS 7ã¯firewallDãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŸãããµãŒãã¹ã®ã¹ããŒã¿ã¹ã¯æ¬¡ã®ã³ãã³ãã§ç¢ºèªã§ããŸã
firewall-cmd --state
ã«ãŒã«ãšãµãŒãã¹ã®ãªã¹ãã«ã€ããŠã¯ã
firewall-cmd --list-all firewall-cmd --list-services

ãµãŒãã¹ã®ãªã¹ãã«æ³šæããŠãã ãããipv6ãããã³ã«ãç¡å¹ã«ããå Žåãdhcpv6-clientã§ãåãããšãè¡ãã®ãè«ççã§ã
firewall-cmd -âpermanent -âremove-service=dhcpv6-client
SAMBAã®ã«ãŒã«ãäœæããŠåèµ·åãã
firewall-cmd --permanent --add-service=samba firewall-cmd --reload
å¿åã·ã§ã¢
ãªãœãŒã¹/ samba /ã²ã¹ãçšã®ãã©ã«ããŒãäœæããŸã
mkdir /samba mkdir /samba/guest
ææè
ãå€æŽããæš©å©ãå²ãåœãŠãŸã
chown nobody:nobody /samba/guest chmod 777 /samba/guest
SAMBAæ§æãã¡ã€ã«
/etc/samba/smb.confã®ç·šé
mcedit /etc/samba/smb.conf
å
ã®ãã¡ã€ã«ã®å
容ã次ã®ããã«å€æŽããŸã
[ã°ããŒãã«]
ã¯ãŒã¯ã°ã«ãŒã= WORKGROUP
ã»ãã¥ãªãã£=ãŠãŒã¶ãŒ
ã²ã¹ããžã®ããã=æªããŠãŒã¶ãŒ
æå°ãããã³ã«= NT1
[ã²ã¹ã]
ãã¹= /ãµã³ã/ã²ã¹ã
ã²ã¹ãOK =ã¯ã
æžã蟌ã¿å¯èœ=ã¯ã
念ã®ããããããã³ã«
SMB = NT1ã®æå°ããŒãžã§ã³ã瀺ããŸããã SMB2ãŸãã¯SMB3ãæå®ãããšãWindows XP以åã®ã¯ã©ã€ã¢ã³ãã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
ãã©ã¡ãŒã¿ã®ç¢ºèªãšãµãŒãã¹ã®åèµ·å
testparm service smb restart smbstatus
ããã§ãšãããããŸããããªãã¯ã€ãã·ãšãŒã·ã§ã³ã®æåã®ã¬ãã«ã«éããŸããã å¿åã¢ã¯ã»ã¹ãåããå
±æãªãœãŒã¹ãæ§æãããŠãããããé·æéã«ããã£ãŠç¢ºå®ã«æ©èœããŸãã ãã ããããã«ããã€ãã®èšå®ãè¡ãããšãã§ããŸããåŒ
ããã©ã«ãã§ã¯ããã°ãã¡ã€ã«ã¯
/ var / log / sambaãã©ã«ããŒã«ãããŸãã 詳现ãã°ãååŸããå¿
èŠãããå Žåã¯ã[global]ã»ã¯ã·ã§ã³ã§ãã©ã¡ãŒã¿ãŒlog level = 2ãŸãã¯3ãè¿œå ããå¿
èŠããããŸããããã©ã«ãå€ã¯1ã§ãå€0ã¯ãã®ã³ã°ãç¡å¹ã«ããŸãã
[ã°ããŒãã«]
ãã°ã¬ãã«= 2
ãåç¥ã®ããã«ããã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãæäŸããããšã¯ãSAMBAæ©èœã®äžéšã«ãããŸããã ãµãŒããŒã«ãã¡ã€ã«ãªãœãŒã¹ãããªãå Žåãå°å·ãµãŒãã¹ãç¡å¹ã«ããã®ãè«ççã§ãã [global]ã»ã¯ã·ã§ã³ã§ã次ã®ãã©ã¡ãŒã¿ãŒãè¿œå ããŸã
[ã°ããŒãã«]
ããªã³ã¿ãŒãããŒããã=ããã
show printer add wizard = no
printcap name = / dev / null
ã¹ããŒã«ãç¡å¹ã«ãã=ã¯ã
SAMBAæ§æã¯
/ etc / sambaãã£ã¬ã¯ããªãŒã«ããããã°ã¯
/ var / log / sambaãã£ã¬ã¯ããªãŒã«ãããŸã
ãã¹ãŠã®ããŒã«ãæå
ã«çœ®ããŠãããã»ãã䟿å©ãªã®ã§ãå¿
èŠãªãã£ã¬ã¯ããªã
/ sambaã«ããŠã³ãããŸã
ãã¹ãŠãããŠã³ãããããã£ã¬ã¯ããªãäœæããŸã
mkdir /samba/smbconf mkdir /samba/smblogs
æ§æãã¡ã€ã«
/ etc / fstabãç·šéããŸã
ãfstabãäœãæ
åœããŠãããç¥ã£ãŠãããšæããŸãã
mcedit /etc/fstab
次ã®è¡ãè¿œå ããŸã
/ etc / samba / samba / smbconf none bind 0 0
/ var / log / samba / samba / smblogs none bind 0 0
åèµ·åããã«ããŠã³ã
mount -a
ãã©ã€ãæ¥ç¶
ã¯ã©ãŒã¿ãªãã§ã·ã¹ãã ãã©ã€ãã«å
±æãªãœãŒã¹ãä¿æããããšã¯é©åãªéžæã§ã¯ãããŸããã ã¯ã©ãŒã¿ã«é¢äžããªãããšã«ããŸãããå¥ã®ãç©çããã£ã¹ã¯ãæ¥ç¶ããæ¹ãç°¡åã§ãã
ããã€ã¹ã®ãªã¹ããååŸããã«ã¯ã
lsblkã³ãã³ãã䜿çšã§ããŸã
lsblk
/ dev / sdbã«ããŒãã£ã·ã§ã³ããŒãã«ãäœæãã
parted /dev/sdb mklabel msdos
ãŸãã¯
parted /dev/sdb mklabel gpt
gptã®è©³çŽ°ã«ã€ããŠã¯ã
ãã¡ããã芧ãã ããããžã£ã³ã«ã®æé«ã®äŒçµ±ã§ãsdbãã£ã¹ã¯å
šäœã«ããŒãã£ã·ã§ã³ãäœæãããã£ã¹ã¯ã®å
é ã§1MiBãã€ã³ãã³ãããããšã«ããŸããã
parted /dev/sdb mkpart primary ext4 1MiB 100%
ext4ãã¡ã€ã«ã·ã¹ãã ãäœæãã
mkfs.ext4 /dev/sdb1
fstabã®ç·šé
mcedit /etc/fstab
å¥ã®è¡ãè¿œå
/ dev / sdb1 / samba / guest ext4 defaults 0 0
åãä»ã
mount âa
çµæã確èªãã
df -h
æš©å©ã®è²æž¡
chmod 777 /samba/guest
ãã£ã¹ã¯ã€ã¡ãŒãžãããŠã³ããã
倧容éã§ååãªãªãœãŒã¹ãµã€ãºxxx mbãå¿
èŠãªãå Žåã¯ããã¡ã€ã«ãããã£ã¹ã¯ã€ã¡ãŒãžãæ¥ç¶ã§ããŸãã
ç»åãä¿åãããã£ã¬ã¯ããªãäœæãã
mkdir /samba/smbimg
100 MBã®ç»åãã¡ã€ã«ãäœæããŸã
dd if=/dev/zero of=/samba/smbimg/100M.img bs=100 count=1M
ddã³ãã³ãã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãããã€ã¡ãŒãžã®ããããŒãžã§ã³ã§ã¯ãããŒãã£ã·ã§ã³ããŒãã«ãäœæãããext4ãã¡ã€ã«ã·ã¹ãã ãäœæããã ãã«ããŸããã
mkfs.ext4 /samba/smbimg/100M.img
fstabã®ç·šé
mcedit /etc/fstab
ã€ã¡ãŒãžãããŠã³ãããããã®æ§æ
/samba/smbimg/100M.img / samba / guest ext4 defaults 0 0
åãä»ã
mount -a
çµæã確èªãã
df -h
æš©å©ã®è²æž¡
chmod 777 /samba/guest
RAMãã£ã¹ã¯æ¥ç¶
倧éã®ãªãœãŒã¹ãå¿
èŠãšããªãäžæçãªãªãœãŒã¹ã®å ŽåãRAMãã£ã¹ã¯ãæé©ãªãªãã·ã§ã³ã§ãããéåžžã«è¿
éãã€ç°¡åã«æ§æã§ããäœæ¥é床ã¯é©ãã¹ããã®ã§ããããã«æããŸãã
fstabã®ç·šé
mcedit /etc/fstab
RAMãã£ã¹ã¯ã®æ§æ
none / samba / guest tmpfsããã©ã«ãããµã€ãº= 100M 0 0
åãä»ã
mount -a
çµæã確èªãã
df -h
å€ããã¡ã€ã«ãåé€ãã
ããã¡ã€ã«ãŠã©ãã·ã¥ãã®å ŽåããªãœãŒã¹ãäœããã®æ¹æ³ã§è§£æŸããå¿
èŠããããŸããããã«ã¯ãcrontabã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã䜿çšã§ããŸã
課é¡ãèŠã
crontab âl
ã¿ã¹ã¯ç·šé
crontab âe
èšå®äŸïŒ
ã·ã§ã«= / bin / bash
PATH = / sbinïŒ/ binïŒ/ usr / sbinïŒ/ usr / bin
MAILTO =ââ
ããŒã = /
ïŒ1æéããšã«ãã¡ã€ã«ãšãã£ã¬ã¯ããªãåé€
* 0-23 * * * rm âR /ãµã³ã/ã²ã¹ã/ *
ïŒ1æ¥ããå€ããã¡ã€ã«ã®ã¿ãåé€ããã³ãã³ãã10åããšã«å®è¡ããŸã
0-59 / 10 * * * * find / samba / guest / * -type f -mtime +1 -exec rm âf {} \;
ïŒ50åããå€ããã¡ã€ã«ãåé€ãã10åããšã«ã³ãã³ããå®è¡ããŸã
0-59 / 10 * * * * find / samba / guest / * -type f -mmin +50 -exec rm -f {} \;
viãçµäº
<ESC> :wq
crontabãµãŒãã¹ã®ãã°ã¯ããã¡ã€ã«
/ var / log / cronã«ãããŸãIPã¢ãã¬ã¹ã«ããSAMBAãžã®ã¢ã¯ã»ã¹ã®å¶é
ãã¹ãŠã®SAMBAãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããå¿
èŠãããå Žåã¯ãã°ããŒãã«ã»ã¯ã·ã§ã³ã«ã¢ã¯ã»ã¹ãªã¹ããè¿œå ããç¹å®ã®ãªãœãŒã¹ã®ã¿ã«å¶éããå¿
èŠãããå Žåã¯ããã®ãªãœãŒã¹ã®ã»ã¯ã·ã§ã³ã«è¿œå ããŸãã
äŸïŒ
[ã°ããŒãã«]
ãã¹ãèš±å¯= 192.168.1.100ã192.168.1.101
ãã¹ãæåŠ= ALL
[ã²ã¹ã]
hosts allow = 192.168.0.0/255.255.0.0
ãã¹ãdeny = 10. 10.1.1.1ãé€ã
ãŠãŒã¶ãŒèªèšŒãšæ¿èª
IPã¢ãã¬ã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããããšã¯åžžã«äŸ¿å©ãŸãã¯å¯èœãšã¯éããªãããããã°ã€ã³ãšãã¹ã¯ãŒãã䜿çšã§ããŸãã
ãŸããã·ã¹ãã ã«ããŒã«ã«ãŠãŒã¶ãŒãäœæããå¿
èŠããããŸã
adduser user1
ãŠãŒã¶ãŒãSAMBAãªãœãŒã¹ã®ã¿ã䜿çšããå Žåãã·ã¹ãã ã®ãã¹ã¯ãŒããèšå®ããå¿
èŠã¯ãããŸããã ã·ã¹ãã ãšSAMBAã®ãã¹ã¯ãŒãã¯ç°ãªããã¡ã€ã«ã«ä¿åãããç°ãªãå ŽåããããŸãã
次ã«ãã·ã¹ãã ãŠãŒã¶ãŒãsambaãŠãŒã¶ãŒã«è¿œå ãããã¹ã¯ãŒããèšå®ããå¿
èŠããããŸã
smbpasswd -a user1
ããã©ã«ãã§ã¯ããã¹ã¯ãŒãã®ä¿åã«tdbãã¡ã€ã«ã䜿çšãããŸããããã¯ã/ var / lib / samba / private /ãã£ã¬ã¯ããªã«ãããŸã
ã°ããŒãã«ãªpassdbããã¯ãšã³ããã©ã¡ãŒã¿ã䜿çšããŠããã¡ã€ã«ã®å Žæã®ãã£ã¬ã¯ããªãå€æŽã§ããŸãã
[ã°ããŒãã«]
passdb backend = tdbsamïŒ/etc/samba/smbpassdb.tdb
ãå»æ¢ããããããã¹ããã¡ã€ã«ã眮ãæããããã«tdbãã¡ã€ã«ãäœæãããŸãããããã¹ããã¡ã€ã«ã䜿çšãã
å Žåã¯ãã°ããŒãã«ã»ã¯ã·ã§ã³ã§
passdb backend = smbpasswdãã©ã¡ãŒã¿ãŒã䜿çšããŸã
passdb backend = smbpasswdïŒ/ etc / samba / smbpasswd
次ã«ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®ãŠãŒã¶ãŒãšã°ã«ãŒãã®ãªã¹ããæå®ããŸã
[ã²ã¹ã]
ãã¹= /ãµã³ã/ã²ã¹ã
æžã蟌ã¿å¯èœ=ããã
èªã¿åããªã¹ã= user1ã@ group2
æžã蟌ã¿ãªã¹ã= user2ãuser3
Active Directoryçµ±å
LDAPãããŠãŒã¶ãŒã«é¢ããæ
å ±ãååŸããããšãã§ããŸããããã®ãªãã·ã§ã³ã¯ç§ã«ã¯èå³ããªããããã«ADã«ã¢ã¯ã»ã¹ããŸãã ãã€ã¯ããœããããã®è©³çŽ°ãªæé ã¯
ãã¡ãã§ãã
æå»åæã¯ADã«ãšã£ãŠéåžžã«éèŠãªã®ã§ãããããå§ãã䟡å€ããããŸããé©åãªãµãŒãã¹ãã€ã³ã¹ããŒã«ãã
yum install ntp
ãã¡ã€ã³ã³ã³ãããŒã©ãŒãšããŠæ©èœãããµãŒããŒã®/etc/ntp.confãã¡ã€ã«ãæ§æã«è¿œå ããŸã
mcedit /etc/ntp.conf
äŸïŒ
ãµãŒããŒ192.168.1.10
ãµãŒããŒ192.168.1.20
ãµãŒããŒsomeserver.contoso.com
èªåéå§ã«ntpãµãŒãã¹ãè¿œå ããŸã
chkconfig ntpd on
ãµãŒãã¹ãéå§ãã
service ntpd start
æå»ã®åæã確èªãã
ntpq âp
ãŠã£ã³ãã€ã³ã
ADãããŠãŒã¶ãŒã«é¢ããæ
å ±ãååŸããã«ã¯ã
samba-winbindããã±ãŒãžãã€ã³ã¹ããŒã«ããå¿
èŠããã
ãŸã yum install samba-winbind
èªåéå§ã«ãµãŒãã¹ãè¿œå
chkconfig winbind on
ãµãŒãã¹ãéå§ãã
service winbind start
ADã§ã®ãã¹ãã®è¿œå
ãã®æ瀺ã®æåã«ããã¹ãå
ls01.fqdn.comãèšå®ããããšãæãåºãããŠãã ããã å®å
šãªãã¡ã€ã³åã
fqdn.comã§ãããšæ³å®ããçããã¡ã€ã³åã
fqdn_comãšãã
å¿
èŠãªãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãæ§æãã¡ã€ã«ã«å
¥åããã«ã¯ã
authconfig-tuiãŠãŒãã£ãªãã£ãŒã䜿çšãããWinbindã䜿çšããã§ãã¯ããã¯ã¹ãéžæããŠã次ã®ãŠã£ã³ããŠã«é²ã¿ãŸãã

ADSã»ãã¥ãªãã£ã¢ãã«ãéžæãããã¡ã€ã³åãæå®ããŸãã [ãã¡ã€ã³ã³ã³ãããŒã©ãŒ]ãã£ãŒã«ãã§ã*ããæå®ããŸããããã¯ã䜿çšå¯èœãªãã¡ã€ã³ã³ã³ãããŒã©ãŒãèªåçã«æ€çŽ¢ããããã«å¿
èŠã§ãã 次ã«ã[OK]ãã¯ãªãã¯ããŠãŠãŒãã£ãªãã£ãéããŸãã

ãã¹ããADã«è¿œå ããã«ã¯ãã³ãã³ã
net ads join âUïŒ
usernameïŒ
ã䜿çšããŸãããŠãŒã¶ãŒã¯ãã¡ã€ã³ã«PCã¢ã«ãŠã³ããäœæããæš©éãæã£ãŠããå¿
èŠããããŸã
net ads join âU youruser

ãã·ã³ããã¡ã€ã³ã«è¿œå ãããŠããªãå ŽåãFQDNãã¹ãåã
/ etc / hostsãã¡ã€ã«ã«è¿œå
ããŸã ã
ãã¹ãŠãæ°å確èªãããããã¯ãŒã¯ã®ã»ããã¢ãã段éã§äžå®å
šãªãã¹ãåãæå®ãããšãã«ãhostsãã¡ã€ã«ã«å€æŽãå ããŸããã
ãã¡ã€ã³ãããã¹ããåé€ããã«ã¯ã
net ads leave âUïŒ
usernameïŒ
ã³ãã³ãã䜿çšããŸã
authconfig-tuiã¯äœãããŸããïŒ
ãã®ãŠãŒãã£ãªãã£ã¯ãADã«æ¥ç¶ããããã®ãã©ã¡ãŒã¿ãŒã次ã®ãã¡ã€ã«ã«è¿œå ããŸãããã©ã¡ãŒã¿ãŒã¯å€ããããŸãããå¿
èŠã«å¿ããŠããã¹ãŠãæã§æã€ããšãã§ããŸãã
/etc/krb5.conf[libdefaults]
Default_realm = FQDN.COM
[ã¬ã«ã ]
FQDN.COM = {
kdc = *
}
/etc/nsswitch.confpasswdïŒãã¡ã€ã«sss winbind
ã·ã£ããŠïŒãã¡ã€ã«sss winbind
ã°ã«ãŒãïŒãã¡ã€ã«sss winbind
/etc/samba/smb.conf[ã°ããŒãã«]
ã¯ãŒã¯ã°ã«ãŒã= FQDN_COM
ãã¹ã¯ãŒããµãŒããŒ= *
ã¬ã«ã = FQDN.COM
ã»ãã¥ãªãã£=åºå
idmap config *ïŒç¯å²= 16777216-33554431
ãã³ãã¬ãŒãã·ã§ã«= / sbin / nologin
Kerberosã¡ãœãã=ã·ãŒã¯ã¬ããã®ã¿
winbindã¯ããã©ã«ãã®ãã¡ã€ã³= falseã䜿çšããŸã
winbind pffline logon = false
ãã®ãŠãŒãã£ãªãã£ã¯ãMicrosoftã®æ瀺ãŸãã¯ä»ã®æ瀺ã«æžãããŠãããããããªãå°ãªããã©ã¡ãŒã¿ãŒãå°å
¥ããŠããããšã«æ°ã¥ãããããããŸãããããã®ããã«æ©èœããå Žåããªãããã§ã¯ãªãã®ã§ããïŒMicrosoftã®ããã¥ã¢ã«ããã次ã®ãã©ã¡ãŒã¿ãŒãæ§æã«è¿œå ããŸã
[ã°ããŒãã«]
ãã¡ã€ã³ãã¹ã¿ãŒ=ããã
ããŒã«ã«ãã¹ã¿ãŒ=ããã
åªå
ãã¹ã¿ãŒ=ããã
OSã¬ãã«= 0
ãã¡ã€ã³ãã°ãªã³=ããã
ãªãœãŒã¹èš±å¯ã®èšå®äŸãšããŠãæ確ã«ããããã«ã1ã€ã®ãã©ã«ããŒã«ç°ãªãæš©éãæã€ãªãœãŒã¹ãã»ããã¢ããããããšããå§ãããŸã
[ãã¡ã€ã³ãŠãŒã¶ãŒã¯èªã¿åãå°çš]
ãã¹= /ãµã³ã/ã²ã¹ã
èªã¿åããªã¹ã=ã@fqdn_com \ãã¡ã€ã³ãŠãŒã¶ãŒã
匷å¶äœæã¢ãŒã= 777
ãã£ã¬ã¯ããªãã¹ã¯= 777
[æžã蟌ã¿å¯èœãªãã¡ã€ã³ãŠãŒã¶ãŒ]
ãã¹= /ãµã³ã/ã²ã¹ã
èªã¿åããªã¹ã=ã@fqdn_com \ãã¡ã€ã³ãŠãŒã¶ãŒã
æžã蟌ã¿ãªã¹ã= "@fqdn_com \ãã¡ã€ã³ãŠãŒã¶ãŒ"
匷å¶äœæã¢ãŒã= 777
ãã£ã¬ã¯ããªãã¹ã¯= 777
SambaãµãŒãã¹ã®åèµ·å
service smb restart
確èªãã
smbstatus
ã¹ã¯ãªãŒã³ã·ã§ããã¯ãå
±æãã©ã«ããŒã®ããããã«ãããã¡ã€ã³ãŠãŒã¶ãŒã瀺ããŠããŸã
çµãã䟿å©ãªãªã³ã¯ã®ãªã¹ãïŒ
ãŠã€ã«ã¹ãšã€ã³ãã©ã¹ãã©ã¯ãã£ãšã®æŠãããŸãã¯SMB v1ã®ç¡å¹åSambaCryã®é倧ãªè匱æ§ïŒä¿è·ããæ¹æ³Linuxã·ã¹ãã ã§SambaCryã®è匱æ§ïŒCVE-2017-7494ïŒãä¿®æ£ããæ¹æ³ã€ã ãããŒãã·ãŒãddã³ãã³ããšããã«é¢é£ãããã¹ãŠSamba 2nd Editionã䜿çšããADããŒã¹ã«UbuntuããŒã¹ã®SambaãµãŒããŒãå«ããLinux / Windowsã¯ã©ã€ã¢ã³ãã§ãã¡ã€ã«å
±æãèš±å¯ããããã®Sambaã®ã»ããã¢ãããšFirewallDããã³SELinuxã®æ§æSELinux-ã·ã¹ãã ã®æäœã®èª¬æãšæ©èœã ããŒã1SELinux-ã·ã¹ãã ã®æäœã®èª¬æãšæ©èœã ããŒã2PSSELINUXã«æ»ããSAMBAãµãŒããŒãä»»æã®ãã£ã¬ã¯ããªãžã®ã¢ã¯ã»ã¹ãæäŸã§ããããã«ããã«ã¯ã次ã®ã³ãã³ããå®è¡ããå¿
èŠããããŸãã
setsebool -P samba_export_all_ro=1 setsebool -P samba_export_all_rw=1
æ®å¿µãªãããSELINUXãæå¹ãªç¶æ
ã§åäœããããã«winbindãæ§æããããšã¯ã§ããŸããã§ãããæ¹æ³ãæããŠããã ããã°ãæè¬ããŸãã