天天看点

CentOS加入AD域

首先安装各个依赖包;

<code>yum install sssd realmd oddjob oddjob-mkhomedir adcli samba-common samba-common-tools krb5-workstation openldap-clients policycoreutils-python ntp –y</code>

<code></code>

确保至AD的解析正常,编辑 /etc/resolv.conf 文件;

<code>[root@@testLinux-WH ~]# cat /etc/resolv.conf</code>

<code>search example.com</code>

<code>nameserver 192.168.10.51</code>

确保该账户具有相应权限,加入AD域;

<code>[root@@testLInux-WH ~]# realm join --user=administrator example.com</code>

<code>Password for administrator:</code>

如有报错可以使用命令 journalctl -xe REALMD_OPERATION=r549.7056 加错误代码查看信息报错。确认DNS解析正常,确认时间是否一致;

<code>ntpdate ntpserver</code>

使用 realm list 确认 realm 信息;

<code>[root@@testLinux-WH ~]# realm list</code>

<code>example.com</code>

<code>type: kerberos</code>

<code>realm-name: EXAMPLE.COM</code>

<code>domain-name: example.com</code>

<code>configured: kerberos-member</code>

<code>server-software: active-directory</code>

<code>client-software: sssd</code>

<code>required-package: oddjob</code>

<code>required-package: oddjob-mkhomedir</code>

<code>required-package: sssd</code>

<code>required-package: adcli</code>

<code>required-package: samba-common-tools</code>

<code>login-formats: %[email protected]</code>

<code>login-policy: allow-realm-logins</code>

<code>加域成功后,AD中自动创建了相关记录;</code>

CentOS加入AD域

<code>由于CentOS中默认使用完整用户名“[email protected]”,需要修改 /etc/sssd/sssd.conf 配置文件来达到使用短用户名的目的;</code>

<code>use_fully_qualified_names = False</code>

<code>fallback_homedir = /home/%u</code>

<code>重启服务使其生效;</code>

<code>systemctl restart sssd</code>

<code>尝试使用测试账户连接;</code>

<code>ssh [email protected]</code>

<code>[email protected]'s password:</code>

<code>Creating home directory for fei-u031.</code>

<code>Last failed login: Wed Aug 7 15:52:22 CST 2019 from adsvr01.example.com on ssh:notty</code>

<code>There were 4 failed login attempts since the last successful login.</code>

<code>/usr/bin/xauth: file /home/fei-u031/.Xauthority does not exist</code>

<code>[fei-u031@testLinux-WH ~]$ pwd</code>

<code>/home/fei-u031</code>

<code>退出AD域;</code>

<code>realm leave example.com</code>

继续阅读