首先安装各个依赖包;
<code>yum install sssd realmd oddjob oddjob-mkhomedir adcli samba-common samba-common-tools krb5-workstation openldap-clients policycoreutils-python ntp –y</code>
<code></code>
确保至AD的解析正常,编辑 /etc/resolv.conf 文件;
<code>[root@@testLinux-WH ~]# cat /etc/resolv.conf</code>
<code>search example.com</code>
<code>nameserver 192.168.10.51</code>
确保该账户具有相应权限,加入AD域;
<code>[root@@testLInux-WH ~]# realm join --user=administrator example.com</code>
<code>Password for administrator:</code>
如有报错可以使用命令 journalctl -xe REALMD_OPERATION=r549.7056 加错误代码查看信息报错。确认DNS解析正常,确认时间是否一致;
<code>ntpdate ntpserver</code>
使用 realm list 确认 realm 信息;
<code>[root@@testLinux-WH ~]# realm list</code>
<code>example.com</code>
<code>type: kerberos</code>
<code>realm-name: EXAMPLE.COM</code>
<code>domain-name: example.com</code>
<code>configured: kerberos-member</code>
<code>server-software: active-directory</code>
<code>client-software: sssd</code>
<code>required-package: oddjob</code>
<code>required-package: oddjob-mkhomedir</code>
<code>required-package: sssd</code>
<code>required-package: adcli</code>
<code>required-package: samba-common-tools</code>
<code>login-formats: %[email protected]</code>
<code>login-policy: allow-realm-logins</code>
<code>加域成功后,AD中自动创建了相关记录;</code>

<code>由于CentOS中默认使用完整用户名“[email protected]”,需要修改 /etc/sssd/sssd.conf 配置文件来达到使用短用户名的目的;</code>
<code>use_fully_qualified_names = False</code>
<code>fallback_homedir = /home/%u</code>
<code>重启服务使其生效;</code>
<code>systemctl restart sssd</code>
<code>尝试使用测试账户连接;</code>
<code>ssh [email protected]</code>
<code>[email protected]'s password:</code>
<code>Creating home directory for fei-u031.</code>
<code>Last failed login: Wed Aug 7 15:52:22 CST 2019 from adsvr01.example.com on ssh:notty</code>
<code>There were 4 failed login attempts since the last successful login.</code>
<code>/usr/bin/xauth: file /home/fei-u031/.Xauthority does not exist</code>
<code>[fei-u031@testLinux-WH ~]$ pwd</code>
<code>/home/fei-u031</code>
<code>退出AD域;</code>
<code>realm leave example.com</code>