2016-06-27

apt-get install acl attr autoconf bison build-essential \
  debhelper dnsutils docbook-xml docbook-xsl flex gdb krb5-user \
  libacl1-dev libaio-dev libattr1-dev libblkid-dev libbsd-dev \
  libcap-dev libcups2-dev libgnutls28-dev libjson-perl \
  libldap2-dev libncurses5-dev libpam0g-dev libparse-yapp-perl \
  libpopt-dev libreadline-dev perl perl-modules pkg-config \
  python-all-dev python-dev python-dnspython python-crypto \
  xsltproc zlib1g-dev libjansson-dev libgpgme11-dev libarchive-dev




 sambaの内蔵DNSを使用する際にavahi-daemonが稼働しているとDNS周りが動作しない。
 色々検索したところ、avahi-daemonを削除してあげれば良いと判明。

root@raspberrypi1:/etc/init.d# samba_dnsupdate --verbose --all-names
IPs: ['192.168.0.20']
force update: A raspberrypi1.yamatomura.local 192.168.0.20
force update: A yamatomura.local 192.168.0.20
force update: SRV _ldap._tcp.yamatomura.local raspberrypi1.yamatomura.local 389
---snip---
27 DNS updates and 0 DNS deletes needed
Traceback (most recent call last):
  File "/opt/samba/sbin/samba_dnsupdate", line 631, in
    get_credentials(lp)
  File "/opt/samba/sbin/samba_dnsupdate", line 123, in get_credentials
    raise e
RuntimeError: kinit for RASPBERRYPI1$@YAMATOMURA.LOCAL failed (Cannot contact any KDC for requested realm)

https://lists.samba.org/archive/samba/2013-September/175547.html


---
Hi there,

a few days ago I tried to install a print spooler with samba4 and in the
installation process the "avahi-daemon" was installed.

This daemon prevented the samba4 internal dns from working fully....

The solution: "apt-get --purge remove avahi-daemon"

Now everything is working like beast ;-)

Best regards
Tom
---

 なお、正常に動作しても"TSIG error with server: tsig verify failure Failed nsupdate: 2"が出力され続けるが、これは問題無い様子



root@raspberrypi2:/opt/samba/var# samba_dnsupdate --verbose
IPs: ['192.168.0.21']
Looking for DNS entry A raspberrypi2.highspec.org 192.168.0.21 as raspberrypi2.highspec.org.
Looking for DNS entry NS highspec.org raspberrypi2.highspec.org as highspec.org.
Looking for DNS entry NS _msdcs.highspec.org raspberrypi2.highspec.org as _msdcs.highspec.org.
Looking for DNS entry A highspec.org 192.168.0.21 as highspec.org.
Looking for DNS entry SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.dc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88 as _kerberos._udp.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.dc._msdcs.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464 as _kpasswd._tcp.highspec.org.
Checking 0 100 464 raspberrypi2.highspec.org. against SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464
Looking for DNS entry SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464 as _kpasswd._udp.highspec.org.
Checking 0 100 464 raspberrypi2.highspec.org. against SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464
Looking for DNS entry CNAME 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org raspberrypi2.highspec.org as 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org.
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.pdc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry A gc._msdcs.highspec.org 192.168.0.21 as gc._msdcs.highspec.org.
Looking for DNS entry SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268 as _gc._tcp.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268 as _ldap._tcp.gc._msdcs.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268 as _gc._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268 as _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry A DomainDnsZones.highspec.org 192.168.0.21 as DomainDnsZones.highspec.org.
Looking for DNS entry SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.DomainDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry A ForestDnsZones.highspec.org 192.168.0.21 as ForestDnsZones.highspec.org.
Looking for DNS entry SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.ForestDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
No DNS updates needed
root@raspberrypi2:/opt/samba/var# samba_dnsupdate --verbose --all-name
IPs: ['192.168.0.21']
force update: A raspberrypi2.highspec.org 192.168.0.21
force update: NS highspec.org raspberrypi2.highspec.org
force update: NS _msdcs.highspec.org raspberrypi2.highspec.org
force update: A highspec.org 192.168.0.21
force update: SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464
force update: SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464
force update: CNAME 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org raspberrypi2.highspec.org
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
force update: SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: A gc._msdcs.highspec.org 192.168.0.21
force update: SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
force update: A DomainDnsZones.highspec.org 192.168.0.21
force update: SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: A ForestDnsZones.highspec.org 192.168.0.21
force update: SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
29 DNS updates and 0 DNS deletes needed
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
update(nsupdate): A raspberrypi2.highspec.org 192.168.0.21
Calling nsupdate for A raspberrypi2.highspec.org 192.168.0.21 (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
raspberrypi2.highspec.org. 900 IN A 192.168.0.21

; TSIG error with server: tsig verify failure
Failed nsupdate: 2
update(nsupdate): NS highspec.org raspberrypi2.highspec.org
Calling nsupdate for NS highspec.org raspberrypi2.highspec.org (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
highspec.org. 900 IN NS raspberrypi2.highspec.org.

; TSIG error with server: tsig verify failure
Failed nsupdate: 2
update(nsupdate): NS _msdcs.highspec.org raspberrypi2.highspec.org
Calling nsupdate for NS _msdcs.highspec.org raspberrypi2.highspec.org (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
_msdcs.highspec.org. 900 IN NS raspberrypi2.highspec.org.

2016-06-26


 設定後、固定IPアドレスを付与する。従来と設定箇所が変わっているので留意が必要。
dhcpcd.confでIPアドレス、DNSを設定する。


/etc/dhcpcd.conf




 に以下を追記。後日active directory冗長化のため、コメント行はdomain name serverを2個登録しているが、active directory冗長化までは一旦自身と外部とをDNSとして設定する。


interface eth0
static ip_address=192.168.0.20/24
static routers=192.168.0.1
static domain_name_servers=192.168.0.1 192.168.0.20
#static domain_name_servers=192.168.0.21 192.168.0.20

static domain_search=yamatomura.local
static domain_name=yamatomura.local









 従来、raspbianを書き込み後、初回起動時はHDMI端子経由でモニタを接続して固定IPアドレスを付与していた。
 jessieからbonjourが標準で動く様で、ssh接続時にIPアドレスで接続先を指定するのではなく、デフォルトホスト名で初回接続できる。


 host name;raspberrypi.local , user name;pi , password;raspberry


 接続後はrootのパスワードを設定、raspi-configで各種設定を行う。


mini:~ doctor_d$ ssh raspberrypi.local -l pi
The authenticity of host 'raspberrypi.local ()' can't be established.
ECDSA key fingerprint is SHA256:
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'raspberrypi.local,' (ECDSA) to the list of known hosts.
pi@raspberrypi.local's password:

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.





 接続後はrootのパスワードを設定、raspi-config等で各種設定を行う。
 設定事項はRaspberry Piで統合認証環境を作ってみる pt.2 ssh経由で初期設定と同一である。b)のfirmware更新のみ、rpi-updateのパッケージが含まれないためapt-get install rpi-updateを用いて手動で追加する。


pi@raspberrypi:~ $ sudo passwd root
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully



pi@raspberrypi:~ $ su
Password:



root@raspberrypi:/home/pi# raspi-config

 以前、debian 7(wheezy)ベースでactive directory構築を記載したが、debian 8 (jessie)がlaunchしたので、これを基にしたものを纏めてみた。


 先ずはSDカードへraspbian jessie-liteを書き込む。raspbianはGUIを含むfullとCLI前提のliteとが存在する。active directoryのみを運用する想定なので、liteを用いる。


mini:~ doctor_d$ diskutil list
/dev/disk0 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *1.0 TB     disk0
   1:                        EFI EFI                     209.7 MB   disk0s1
   2:          Apple_CoreStorage fusion                  999.3 GB   disk0s2
   3:                 Apple_Boot Boot OS X               650.0 MB   disk0s3
/dev/disk1 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *256.1 GB   disk1
   1:                        EFI EFI                     209.7 MB   disk1s1
   2:          Apple_CoreStorage fusion                  255.7 GB   disk1s2
   3:                 Apple_Boot Boot OS X               134.2 MB   disk1s3
/dev/disk2 (internal, virtual):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:                  Apple_HFS SSD                    +1.2 TB     disk2
                                 Logical Volume on disk1s2, disk0s2
                                 0530E9CE-4A72-4F7A-9B43-DFB74A192285
                                 Unencrypted Fusion Drive
/dev/disk3 (external, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:     FDisk_partition_scheme                        *15.9 GB    disk3
   1:             Windows_FAT_32 boot                    58.7 MB    disk3s1
   2:                      Linux                         15.9 GB    disk3s2



mini:~ doctor_d$ diskutil unmountDisk /dev/rdisk3
Unmount of all volumes on disk3 was successful



mini:~ doctor_d$ sudo dd if=~/Downloads/2016-05-27-raspbian-jessie-lite.img of=/dev/rdisk3 bs=1m
Password:
1323+0 records in
1323+0 records out
1387266048 bytes transferred in 279.444055 secs (4964378 bytes/sec)

mini:~ doctor_d$ diskutil unmountDisk /dev/rdisk3
Unmount of all volumes on disk3 was successful

2016-04-30

 samba wikiのJoining a Samba DC to an Existing Active Directoryをそのまま。

 2台目のrapberrypiでsambaをmake。

 事前に、1台目の/etc/krb5.confを2台目にコピーしておく。

 ドメインへ参加する。

root@raspberrypi1:/opt/samba/etc# samba-tool domain join yamatomura.local DC -U administrator --realm=YAMATOMURA.LOCAL
Finding a writeable DC for domain 'yamatomura.local'
Found DC raspberrypi2.yamatomura.local
Password for [WORKGROUP\administrator]:
Password for [WORKGROUP\administrator]:
Password for [WORKGROUP\administrator]:
workgroup is YAMATOMURA
realm is yamatomura.local
checking sAMAccountName
Deleted CN=RID Set,CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Deleted CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Deleted CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Deleted CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Adding CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding SPNs to CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Setting account password for RASPBERRYPI1$
Enabling account
Calling bare provision
Looking up IPv4 addresses
Looking up IPv6 addresses
No IPv6 address will be assigned
Setting up secrets.ldb
Setting up the registry
Setting up the privileges database
Setting up idmap db
Setting up SAM db
Setting up sam.ldb partitions and settings
Setting up sam.ldb rootDSE
Pre-loading the Samba 4 and AD schema
A Kerberos configuration suitable for Samba 4 has been generated at /opt/samba/private/krb5.conf
Provision OK for domain DN DC=yamatomura,DC=local
Starting replication
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[402/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[804/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[1206/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[1550/1550] linked_values[0/0]
Analyze and apply schema objects
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[402/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[804/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1206/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1608/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1617/1617] linked_values[28/0]
Replicating critical objects from the base DN of the domain
Partition[DC=yamatomura,DC=local] objects[97/97] linked_values[24/0]
Partition[DC=yamatomura,DC=local] objects[367/270] linked_values[24/0]
Done with always replicated NC (base, config, schema)
Replicating DC=DomainDnsZones,DC=yamatomura,DC=local
Partition[DC=DomainDnsZones,DC=yamatomura,DC=local] objects[74/74] linked_values[0/0]
Replicating DC=ForestDnsZones,DC=yamatomura,DC=local
Partition[DC=ForestDnsZones,DC=yamatomura,DC=local] objects[19/19] linked_values[0/0]
Committing SAM database
Sending DsReplicaUpdateRefs for all the replicated partitions
Setting isSynchronized and dsServiceName
Setting up secrets database
Joined domain YAMATOMURA (SID S-1-5-21-1103419775-2087469381-2721633249) as a DC


 Verifying and Creating a DC DNS Recordを参照して2台目をDNSへ登録する。説明ではsamba 4.6以降では本手順は不要となっているのだが、4.6.7で必要だった。

root@raspberrypi1:/opt/samba/etc# ldbsearch -H /opt/samba/private/sam.ldb '(invocationId=*)' --cross-ncs objectguid
# record 1
dn: CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
objectGUID: 47a81dec-2a7f-48a9-9312-08006115a3fa

# record 2
dn: CN=NTDS Settings,CN=RASPBERRYPI2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
objectGUID: b5d3d0e3-4c3e-4253-adb1-6ab126adbb01

# returned 2 records
# 2 entries
# 0 referrals
root@raspberrypi1:/opt/samba/etc# host -t CNAME 47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.loccal.
47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.loccal has no CNAME record
root@raspberrypi1:/opt/samba/etc# samba-tool dns add raspberrypi2 _msdcs.yamatomura.local 47a81dec-2a7f-48a9-9312-08006115a3fa CNAME raspberrypi1.yamatomura.local -Uadministrator
Password for [YAMATOMURA\administrator]:
Record added successfully
root@raspberrypi1:/opt/samba/etc# host -t CNAME 47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.local.
47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.local is an alias for raspberrypi1.yamatomura.local.
root@raspberrypi1:/opt/samba/etc#



 smb.confのdns forwarderを設定する。domainに参加したsambaで当該を設定しないとドメイン参加したコンピュータから名前解決がNGになる。


 /etc/dhcpcd.confのdomain_name_serversを設定する。


送信側の設定

xinetd.dをapt-getする。

apt-get install xinetd

rsyncの起動設定と起動を行う。

root@raspberrypi2:/etc# echo "rsync --daemon --config /etc/rsyncd.conf">>/etc/rc.local

#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will "exit 0" on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.

# Print the IP address
_IP=$(hostname -I) || true
if [ "$_IP" ]; then
  printf "My IP address is %s\n" "$_IP"
fi


rsync --daemon --config /etc/rsyncd.conf

exit 0

/etc/rc.local (END)


root@raspberrypi2:/etc# rsync --daemon --config /etc/rsyncd.conf


[SysVol]
path = /opt/samba/var/locks/sysvol/
comment = Samba Sysvol Share
uid = root
gid = root
read only = yes
auth users = sysvol-replication
secrets file = /opt/samba/etc/rsyncd.secret
/etc/rsyncd.conf (END)


パスワードファイルを作成する。

root@raspberrypi2:/opt/samba/etc# pico /opt/samba/etc/rsyncd.secret

sysvol-replication:pa$$w0rd

root@raspberrypi2:/opt/samba/etc# chmod 600 rsyncd.secret

権限を変更しないとrsyncに失敗する。


受信側の設定

まずはパスワードファイルを設定する。
root@raspberrypi1:/opt/samba/etc# pico rsync-client.secret

pa$$w0rd

permissionを変更しておく。
root@raspberrypi1:/opt/samba/etc# chmod 600 rsync-client.secret 



最初にdry runをして正常に動作するか確認すること。本システムはraspberrypi2をFSMOというか送信側にしている。

root@raspberrypi1:/opt/samba/etc# rsync --dry-run -XAavz --delete-after --password-file=/opt/samba/etc/rsync-client.secret rsync://sysvol-replication@raspberrypi2/SysVol/ /opt/samba/var/locks/sysvol/
receiving file list ... done
./
yamatomura.local/
yamatomura.local/Policies/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/USER/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/GPT.INI
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/MACHINE/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/USER/
yamatomura.local/scripts/

sent 59 bytes  received 588 bytes  99.54 bytes/sec
total size is 40  speedup is 0.06 (DRY RUN)

正常にrsyncするのを確認後cronに登録する。

echo "*/5 * * * * root rsync -XAavz --delete-after --password-file=/opt/samba/etc/rsync-client.secret rsync://sysvol-replication@raspberrypi2/SysVol/ /opt/samba/var/locks/sysvol/">/etc/cron.d/sysvol-replication

同期後、権限の設定変更を行う部分を上記の設定に追記する。

echo "1-59/5 * * * * root /opt/samba/bin/samba-tool ntacl sysvolreset">>/etc/cron.d/sysvol-replication

2016-04-26

  GNU nano 2.2.6                           File: /root/.bashrc                                                           

# ~/.bashrc: executed by bash(1) for non-login shells.

# Note: PS1 and umask are already set in /etc/profile. You should not
# need this unless you want different defaults for root.
# PS1='${debian_chroot:+($debian_chroot)}\h:\w\$ '
# umask 022

# You may uncomment the following lines if you want `ls' to be colorized:
# export LS_OPTIONS='--color=auto'
# eval "`dircolors`"
# alias ls='ls $LS_OPTIONS'
# alias ll='ls $LS_OPTIONS -l'
# alias l='ls $LS_OPTIONS -lA'
#
# Some more alias to avoid making mistakes:
# alias rm='rm -i'
# alias cp='cp -i'
# alias mv='mv -i'

export PATH=/opt/samba/bin/:/opt/samba/sbin/:$PATH

2015-10-18

Dear TOSHIKA-SAN,

I am sorry to learn that your accounts have been rendered inactive. I know that this is important to you.

I have today forwarded a reactivation request to our processing team.

Your accounts will be reactivated within 2-3 business days upon receipt of request. I regret any inconvenience that this procedure has caused you.

Please note that an account becomes 'dormant' if no withdrawals are made over a period of 12 months or more and becomes “unclaimed” after 24 months or more. Please ensure that you make a withdrawal within the timeframe indicated to avoid any account deactivation in the future.

HSBC is also in the process of updating our customer details on file. We may need you to supply us with the following information below so this can be updated on your account.

- Permanent Residence and Postal Address
- Time At Address (Address Since)
- Mobile, Home, Business Phone Numbers
- Occupation, Job Title and Employer’s name
Please feel free to send us a secure email using your device logon confirming the above information.

We thank you for using HSBC Personal Internet Banking to access your account online.

自己紹介

自分の写真
東京都, Japan
憂鬱な凍死家です。こちらではmixiとは異なり固めの話題中心です。

Total Page View

Categories

Powered by Blogger.

Popular Posts

Blog Archive