blacksun2lelu 发表于 2010-03-18 10:13:15

samba加域出现的问题

本帖最后由 blacksun2lelu 于 2010-03-18 10:19 编辑

我的实验环境是这样

安装了的软件包有
krb5-workstation-1.2.7-19
pam_krb5-1.70-1
krb5-devel-1.2.7-19
krb5-libs-1.2.7-19

samba-common-3.0.28-0.el5.8
samba-client-3.0.28-0.el5.8
samba-3.0.28-0.el5.8

有人说需要samba-swat-3.0.28-0.el5.8但是fedora8里面没有的。

pdc+dns(win2003):

dns1.test.com
ip 192.168.13.13

linux(Fedora 8):

linux(计算机名)
ip 192.168.13.135



linux的配置如下


先配置的nsswitch.conf:

/etc/nsswitch.conf
passwd:     files winbind
shadow:     files winbind
group:      files winbind


krb5.conf配置如下:

/etc/krb5.conf

default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log


default_realm = TEST.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
forwardable = yes


EXAMPLE.COM = {
  kdc = kerberos.example.com:88
  admin_server = kerberos.example.com:749
  default_domain = example.com
}

TEST.COM = {
  kdc = 192.168.13.13:88
  kdc = 192.168.13.13
}


.example.com = EXAMPLE.COM
example.com = EXAMPLE.COM

.test.com = TEST.COM
test.com = TEST.COM

pam = {
   debug = false
   ticket_lifetime = 36000
   renew_lifetime = 36000
   forwardable = true
   krb4_convert = false
}



samba配置文件如下:

/etc/samba/smb.conf
   workgroup = TEST
   password server = 192.168.13.13
   realm = TEST.COM
   security = ads
   idmap uid = 16777216-33554431
   idmap gid = 16777216-33554431
   template shell = /bin/bash
   winbind use default domain = true
   winbind offline logon = true
template homedir = /home/%U
   winbind separator = /
   winbind enum users = Yes
   winbind enum groups = Yes


(红色代表添加的信息)

linux这台机器的DNS已经设置成域的IP,也能正常解析。

我在最后用加域的时候使用的命令
net ads join -U administrator@TEST.COM

出现了如下问题:

using short domain bane -- TEST
DNS update failed!
Joined 'LINUX' to realm 'TEST.COM'

我的LINUX版本是Fedora 8,在域控制器上也出现了LINUX这台计算机,但是DNS里面始终没有linux.test.com这条记录。
我已经求助了很久,还望各位能帮忙解决下,谢谢了!

blacksun2lelu 发表于 2010-03-18 10:39:18

哎,看的人多,解决的人少,来个BOSS就好了。

walters 发表于 2010-03-18 13:39:52

Windows 2000 Domain Controller ?
What does it say on windows 2000 server ?

blacksun2lelu 发表于 2010-03-18 14:34:19

楼上的还要给咱罐点洋墨水,用中文好吗?

Please speak Chinese?


ok ?

laohuanggua 发表于 2010-03-31 12:49:09

尝试用net rpc join -S 域控主机名 -U administrator
呢?
页: [1]
查看完整版本: samba加域出现的问题