11.4. Using Samba As a Primary Domain Controller
Problem
You want a central login and authentication server on your network; you have either Windows hosts, or a mixed LAN of Windows and Linux hosts. You may also want this server to provide access to network resources, such as file shares and printers. You do not have a Windows domain controller or existing password server, but a mish-mash of peer networking plus sneakernet, or just shared Internet, so you are starting from scratch.
Solution
There are seven steps to building a Samba domain controller:
Install Samba.
Configure /etc/samba/smb.conf.
Create a Samba root user.
Create a group for machine accounts.
Join all Windows NT/200x/XP/Vista computers in the domain to the Samba server.
Create user accounts on both Linux and Samba.
Fire it up and connect clients for testing.
Here is a complete, basic /etc/samba/smb.conf for your new domain controller. Substitute your own workgroup name (which is the name of the primary domain), NetBIOS name, server string, and network IP:
[global] workgroup = bluedomain netbios name = samba1 server string = Samba PDC domain master = yes os level = 64 preferred master = yes domain logons = yes add machine script = /usr/sbin/useradd -s /bin/false -d /dev/null -g machines '%u' passdb backend = tdbsam security = user encrypt passwords = yes log file = /var/log/samba/log log level = 2 max log size = 50 hosts allow = 192.168.1. wins support = yes [netlogon] comment = Network Logon Service path = /var/lib/samba/netlogon/ ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access