灵易深论坛

 找回密码
 立即注册
搜索
热搜: 活动 交友 discuz
查看: 246|回复: 0

CentOS加入AD域

[复制链接]

101

主题

29

回帖

302

积分

超级版主

积分
302
发表于 2019-9-11 08:29:01 | 显示全部楼层 |阅读模式
首先安装各个依赖包;
yum install sssd realmd oddjob oddjob-mkhomedir adcli samba-common samba-common-tools krb5-workstation openldap-clients policycoreutils-python ntp –y

确保至AD的解析正常,编辑 /etc/resolv.conf 文件;
[root@@testLinux-WH ~]# cat /etc/resolv.conf
search example.com
nameserver 192.168.10.51

确保该账户具有相应权限,加入AD域;
[root@@testLInux-WH ~]# realm join --user=administrator example.com
Password for administrator:

如有报错可以使用命令 journalctl -xe REALMD_OPERATION=r549.7056 加错误代码查看信息报错。确认DNS解析正常,确认时间是否一致;
ntpdate ntpserver

使用 realm list 确认 realm 信息;
[root@@testLinux-WH ~]# realm list
example.com
type: kerberos
realm-name: EXAMPLE.COM
domain-name: example.com
configured: kerberos-member
server-software: active-directory
client-software: sssd
required-package: oddjob
required-package: oddjob-mkhomedir
required-package: sssd
required-package: adcli
required-package: samba-common-tools
login-formats: %U@example.com
login-policy: allow-realm-logins

加域成功后,AD中自动创建了相关记录;

由于CentOS中默认使用完整用户名“administrator@example.com”,需要修改 /etc/sssd/sssd.conf 配置文件来达到使用短用户名的目的;
use_fully_qualified_names = False
fallback_homedir = /home/%u

重启服务使其生效;
systemctl restart sssd

尝试使用测试账户连接;
fei-u031@192.168.0.101's password:
Creating home directory for fei-u031.
Last failed login: Wed Aug 7 15:52:22 CST 2019 from adsvr01.example.com on ssh:notty
There were 4 failed login attempts since the last successful login.
/usr/bin/xauth: file /home/fei-u031/.Xauthority does not exist
[fei-u031@testLinux-WH ~]$ pwd
/home/fei-u031

退出AD域;
realm leave example.com
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|手机版|灵易深论坛 ( 沪ICP备2020036158号-2 )

GMT+8, 2025-6-22 00:23 , Processed in 0.014535 second(s), 21 queries .

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表