2016-07-24

Dear Mr xxxx

Thank you for choosing HSBC Premier Singapore!

I just want to advise that your new accounts have been opened with the following details:

1)  PREMIER RELATIONSHIP MANAGER

I have copied herewith your dedicated Premier Relationship Manager, who will be managing your portfolio and relationship in the long term.  I would like to check if you would be available on (Date and time) to take a quick call for me to formally make the introductions. 


2)  ACCOUNT DETAILS

xxxx - Multicurrency Savings account.  This account number can carry several currencies but what I have opened for you is in SGD, AUD, JPY, NZD and USD.  Later on, should you decide to open other currencies we can just easily add.  The great thing about this account is that you just remember one account number for "sub-accounts" in different currencies.  Also when you remit funds in, you just need to quote this account number.  So when you will remit USD, just quote this account number and it will automatically flow into the USD sub-account. This account does not come with a chequebook, debit nor ATM.

xxxx - SGD Premier Current account. This account may come with a debit card and a chequebook. if you requested for these, kindly expect the chequebook, card, PIN, to be sent to you via DHL separately.  If you have not requested for the account tools upon account opening, you may request for it anytime.

The Current accounts are mainly for transactional use as it may come with an ATM or debit card. The Multicurrency Savings account are more for investment as it gives your flexibility to convert your money to other currencies without the hassle of remembering too many account numbers.

Generally, clients are given 3 months to fund the account with at least USD150,000 or its foreign currency equivalent. Should you not reach this balance after 6 months, a service fee of $50.00 shall be automatically debited from your account. If you are a maintaining Premier client in other HSBC countries, you need not worry about the HSBC Singapore maintaining balances.

3)  REMITTANCE DETAILS:

For the initial funding and in the future just in case you will need to make remittances into your HSBC Singapore account, please find remittance details for your reference:

Beneficiary Bank: HSBC SINGAPORE
Beneficiary Name: complete account title
Beneficiary Account number: xxx-xxxxxx-xxx
Swift Code: HSBCSGS2
Bank Code: 9548
Bank Address: 6 Claymore Hill #03-01 Claymore Plaza, Singapore 229571

Kindly advise me when you have given the instruction to remit as it is important I monitor from my end the exact amount remitted.  There may be intermediary bank charges (for USD it is between USD10 to USD35).  Charges are waived for incoming remittances for Premier customers.

4) CARD ACTIVATION

I have issued you an ATM/Debit card & PIN, and Telephone banking ID. You will need to activate the card by following the instruction on the letter that comes with the card. You need to use this to create your internet banking access. Cards and PIN will arrive separately. Should eyou ned assistance to activate your cards, kindly sign attached form and send it back to us.

5)  INTERNET BANKING AND SECURITY DEVICE

Once your ATM card is activated,  you may already register for internet banking at www.hsbc.com.sg.  The registration button is below the log in buttons.  You will need your activated debit/ATM Card number and PIN on hand to register.  The system will walk you through the process and is pretty straightforward.  Once successfully registered, please drop me an email so can have the security device sent to you. It is important for you to inform us after you have successfully registered, failing to do so would result to the Security Device being sent to your correspondence address via normal mail (which you may need to self collect from your nearest post office).

Should you wish to see your other HSBC accounts, this can easily be linked by just adding countries.  Global View function will allow you to view balances in both countries.  Global Transfers will allow you to make transfers (local regulatory restrictions may apply); and transfers via internet banking are free from Premier customers making transfers between self-named accounts.

6) TELEPHONE BANKING PIN

For access to Telephone banking, you will need to get the PIN by calling the Premier hotline +65 62278889 and providing them the Telephone Banking ID.  Once Premier hotline verifies you, they will be sending you the Telephone banking PIN to the mobile number you registered with us during account opening.

7)  FAX INSTRUCTIONS OR SECURED MESSAGE VIA INTERNET BANKING

For security purposes, we do not accept email instructions.  We can take fax instructions (coupled with callback phone verification) or secured message via internet banking.  Whenever we will be discussing account details, I will be encrypting the email or I will do a phone verification if we happen to be speaking to each other.  These security measures are put in place for your protection.

8) SERVICE GUIDE

9) LATEST UPDATES 
Always connected to global opportunities.





Thank you and please do not hesitate to email me should you have questions on above.

Best Regards,



AVP, Relationship Manager

The HSBC Bank (Singapore) Limited

Premier International Centre
6 Claymore Hill #03-01 Claymore Plaza Singapore 229571

● Phone (65) xxxx  ● Mobile (65) xxxx  ● Fax (65) xxxx ● Email: xxxx
________________________________________________________________________________________
You can also contact your HSBC Premier Service Manager if you need any assistance with your banking needs


HSBC Premier Website and Personal Internet Banking access:  http://www.hsbcpremier.com.sg/
24-hour HSBC Premier Hotline: 1800-227 8889 or 6227 8889 (if you are calling from overseas)
________________________________________________________________________________________
Every expat has an extraordinary story to tell. What's your view on life abroad? Take the Expat Explorer survey: http://
 
From 9 May 2016, our FAST Bank description will be HSBC Bank (Singapore) Ltd. To avoid rejected funds transfers to your personal bank account, please remind the remitting party to select the appropriate information. Visit www.hsbc.com.sg/retailbank for more details


Our new website highlights our enhanced PIC proposition "At HSBC Premier International, we speak one language. Yours.", and features the benefits and service offerings provided by PIC to existing and prospective clients.



2016-06-27

apt-get install acl attr autoconf bison build-essential \
  debhelper dnsutils docbook-xml docbook-xsl flex gdb krb5-user \
  libacl1-dev libaio-dev libattr1-dev libblkid-dev libbsd-dev \
  libcap-dev libcups2-dev libgnutls28-dev libjson-perl \
  libldap2-dev libncurses5-dev libpam0g-dev libparse-yapp-perl \
  libpopt-dev libreadline-dev perl perl-modules pkg-config \
  python-all-dev python-dev python-dnspython python-crypto \
  xsltproc zlib1g-dev libjansson-dev libgpgme11-dev libarchive-dev




 sambaの内蔵DNSを使用する際にavahi-daemonが稼働しているとDNS周りが動作しない。
 色々検索したところ、avahi-daemonを削除してあげれば良いと判明。

root@raspberrypi1:/etc/init.d# samba_dnsupdate --verbose --all-names
IPs: ['192.168.0.20']
force update: A raspberrypi1.yamatomura.local 192.168.0.20
force update: A yamatomura.local 192.168.0.20
force update: SRV _ldap._tcp.yamatomura.local raspberrypi1.yamatomura.local 389
---snip---
27 DNS updates and 0 DNS deletes needed
Traceback (most recent call last):
  File "/opt/samba/sbin/samba_dnsupdate", line 631, in
    get_credentials(lp)
  File "/opt/samba/sbin/samba_dnsupdate", line 123, in get_credentials
    raise e
RuntimeError: kinit for RASPBERRYPI1$@YAMATOMURA.LOCAL failed (Cannot contact any KDC for requested realm)

https://lists.samba.org/archive/samba/2013-September/175547.html


---
Hi there,

a few days ago I tried to install a print spooler with samba4 and in the
installation process the "avahi-daemon" was installed.

This daemon prevented the samba4 internal dns from working fully....

The solution: "apt-get --purge remove avahi-daemon"

Now everything is working like beast ;-)

Best regards
Tom
---

 なお、正常に動作しても"TSIG error with server: tsig verify failure Failed nsupdate: 2"が出力され続けるが、これは問題無い様子



root@raspberrypi2:/opt/samba/var# samba_dnsupdate --verbose
IPs: ['192.168.0.21']
Looking for DNS entry A raspberrypi2.highspec.org 192.168.0.21 as raspberrypi2.highspec.org.
Looking for DNS entry NS highspec.org raspberrypi2.highspec.org as highspec.org.
Looking for DNS entry NS _msdcs.highspec.org raspberrypi2.highspec.org as _msdcs.highspec.org.
Looking for DNS entry A highspec.org 192.168.0.21 as highspec.org.
Looking for DNS entry SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.dc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88 as _kerberos._udp.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.dc._msdcs.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464 as _kpasswd._tcp.highspec.org.
Checking 0 100 464 raspberrypi2.highspec.org. against SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464
Looking for DNS entry SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464 as _kpasswd._udp.highspec.org.
Checking 0 100 464 raspberrypi2.highspec.org. against SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464
Looking for DNS entry CNAME 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org raspberrypi2.highspec.org as 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org.
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88 as _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org.
Checking 0 100 88 raspberrypi2.highspec.org. against SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
Looking for DNS entry SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.pdc._msdcs.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry A gc._msdcs.highspec.org 192.168.0.21 as gc._msdcs.highspec.org.
Looking for DNS entry SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268 as _gc._tcp.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268 as _ldap._tcp.gc._msdcs.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268 as _gc._tcp.Default-First-Site-Name._sites.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268 as _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org.
Checking 0 100 3268 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
Looking for DNS entry A DomainDnsZones.highspec.org 192.168.0.21 as DomainDnsZones.highspec.org.
Looking for DNS entry SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.DomainDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry A ForestDnsZones.highspec.org 192.168.0.21 as ForestDnsZones.highspec.org.
Looking for DNS entry SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.ForestDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
Looking for DNS entry SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389 as _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org.
Checking 0 100 389 raspberrypi2.highspec.org. against SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
No DNS updates needed
root@raspberrypi2:/opt/samba/var# samba_dnsupdate --verbose --all-name
IPs: ['192.168.0.21']
force update: A raspberrypi2.highspec.org 192.168.0.21
force update: NS highspec.org raspberrypi2.highspec.org
force update: NS _msdcs.highspec.org raspberrypi2.highspec.org
force update: A highspec.org 192.168.0.21
force update: SRV _ldap._tcp.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.62640a65-1803-482b-b2c2-4827919a2c2d.domains._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _kerberos._tcp.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._udp.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._tcp.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kpasswd._tcp.highspec.org raspberrypi2.highspec.org 464
force update: SRV _kpasswd._udp.highspec.org raspberrypi2.highspec.org 464
force update: CNAME 987e75b2-95b8-4ee6-a5ca-52f5b30af856._msdcs.highspec.org raspberrypi2.highspec.org
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 88
force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.highspec.org raspberrypi2.highspec.org 88
force update: SRV _ldap._tcp.pdc._msdcs.highspec.org raspberrypi2.highspec.org 389
force update: A gc._msdcs.highspec.org 192.168.0.21
force update: SRV _gc._tcp.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _ldap._tcp.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _gc._tcp.Default-First-Site-Name._sites.highspec.org raspberrypi2.highspec.org 3268
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.highspec.org raspberrypi2.highspec.org 3268
force update: A DomainDnsZones.highspec.org 192.168.0.21
force update: SRV _ldap._tcp.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: A ForestDnsZones.highspec.org 192.168.0.21
force update: SRV _ldap._tcp.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
force update: SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.highspec.org raspberrypi2.highspec.org 389
29 DNS updates and 0 DNS deletes needed
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
update(nsupdate): A raspberrypi2.highspec.org 192.168.0.21
Calling nsupdate for A raspberrypi2.highspec.org 192.168.0.21 (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
raspberrypi2.highspec.org. 900 IN A 192.168.0.21

; TSIG error with server: tsig verify failure
Failed nsupdate: 2
update(nsupdate): NS highspec.org raspberrypi2.highspec.org
Calling nsupdate for NS highspec.org raspberrypi2.highspec.org (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
highspec.org. 900 IN NS raspberrypi2.highspec.org.

; TSIG error with server: tsig verify failure
Failed nsupdate: 2
update(nsupdate): NS _msdcs.highspec.org raspberrypi2.highspec.org
Calling nsupdate for NS _msdcs.highspec.org raspberrypi2.highspec.org (add)
Successfully obtained Kerberos ticket to DNS/raspberrypi1.highspec.org as RASPBERRYPI2$
Outgoing update query:
;; ->>HEADER<<- id:="" nbsp="" noerror="" opcode:="" p="" status:="" update="">;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
_msdcs.highspec.org. 900 IN NS raspberrypi2.highspec.org.

2016-06-26


 設定後、固定IPアドレスを付与する。従来と設定箇所が変わっているので留意が必要。
dhcpcd.confでIPアドレス、DNSを設定する。


/etc/dhcpcd.conf




 に以下を追記。後日active directory冗長化のため、コメント行はdomain name serverを2個登録しているが、active directory冗長化までは一旦自身と外部とをDNSとして設定する。


interface eth0
static ip_address=192.168.0.20/24
static routers=192.168.0.1
static domain_name_servers=192.168.0.1 192.168.0.20
#static domain_name_servers=192.168.0.21 192.168.0.20

static domain_search=yamatomura.local
static domain_name=yamatomura.local









 従来、raspbianを書き込み後、初回起動時はHDMI端子経由でモニタを接続して固定IPアドレスを付与していた。
 jessieからbonjourが標準で動く様で、ssh接続時にIPアドレスで接続先を指定するのではなく、デフォルトホスト名で初回接続できる。


 host name;raspberrypi.local , user name;pi , password;raspberry


 接続後はrootのパスワードを設定、raspi-configで各種設定を行う。


mini:~ doctor_d$ ssh raspberrypi.local -l pi
The authenticity of host 'raspberrypi.local ()' can't be established.
ECDSA key fingerprint is SHA256:
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'raspberrypi.local,' (ECDSA) to the list of known hosts.
pi@raspberrypi.local's password:

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.





 接続後はrootのパスワードを設定、raspi-config等で各種設定を行う。
 設定事項はRaspberry Piで統合認証環境を作ってみる pt.2 ssh経由で初期設定と同一である。b)のfirmware更新のみ、rpi-updateのパッケージが含まれないためapt-get install rpi-updateを用いて手動で追加する。


pi@raspberrypi:~ $ sudo passwd root
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully



pi@raspberrypi:~ $ su
Password:



root@raspberrypi:/home/pi# raspi-config

 以前、debian 7(wheezy)ベースでactive directory構築を記載したが、debian 8 (jessie)がlaunchしたので、これを基にしたものを纏めてみた。


 先ずはSDカードへraspbian jessie-liteを書き込む。raspbianはGUIを含むfullとCLI前提のliteとが存在する。active directoryのみを運用する想定なので、liteを用いる。


mini:~ doctor_d$ diskutil list
/dev/disk0 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *1.0 TB     disk0
   1:                        EFI EFI                     209.7 MB   disk0s1
   2:          Apple_CoreStorage fusion                  999.3 GB   disk0s2
   3:                 Apple_Boot Boot OS X               650.0 MB   disk0s3
/dev/disk1 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *256.1 GB   disk1
   1:                        EFI EFI                     209.7 MB   disk1s1
   2:          Apple_CoreStorage fusion                  255.7 GB   disk1s2
   3:                 Apple_Boot Boot OS X               134.2 MB   disk1s3
/dev/disk2 (internal, virtual):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:                  Apple_HFS SSD                    +1.2 TB     disk2
                                 Logical Volume on disk1s2, disk0s2
                                 0530E9CE-4A72-4F7A-9B43-DFB74A192285
                                 Unencrypted Fusion Drive
/dev/disk3 (external, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:     FDisk_partition_scheme                        *15.9 GB    disk3
   1:             Windows_FAT_32 boot                    58.7 MB    disk3s1
   2:                      Linux                         15.9 GB    disk3s2



mini:~ doctor_d$ diskutil unmountDisk /dev/rdisk3
Unmount of all volumes on disk3 was successful



mini:~ doctor_d$ sudo dd if=~/Downloads/2016-05-27-raspbian-jessie-lite.img of=/dev/rdisk3 bs=1m
Password:
1323+0 records in
1323+0 records out
1387266048 bytes transferred in 279.444055 secs (4964378 bytes/sec)

mini:~ doctor_d$ diskutil unmountDisk /dev/rdisk3
Unmount of all volumes on disk3 was successful

2016-04-30

 samba wikiのJoining a Samba DC to an Existing Active Directoryをそのまま。

 2台目のrapberrypiでsambaをmake。

 事前に、1台目の/etc/krb5.confを2台目にコピーしておく。

 ドメインへ参加する。

root@raspberrypi1:/opt/samba/etc# samba-tool domain join yamatomura.local DC -U administrator --realm=YAMATOMURA.LOCAL
Finding a writeable DC for domain 'yamatomura.local'
Found DC raspberrypi2.yamatomura.local
Password for [WORKGROUP\administrator]:
Password for [WORKGROUP\administrator]:
Password for [WORKGROUP\administrator]:
workgroup is YAMATOMURA
realm is yamatomura.local
checking sAMAccountName
Deleted CN=RID Set,CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Deleted CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Deleted CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Deleted CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Adding CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
Adding SPNs to CN=RASPBERRYPI1,OU=Domain Controllers,DC=yamatomura,DC=local
Setting account password for RASPBERRYPI1$
Enabling account
Calling bare provision
Looking up IPv4 addresses
Looking up IPv6 addresses
No IPv6 address will be assigned
Setting up secrets.ldb
Setting up the registry
Setting up the privileges database
Setting up idmap db
Setting up SAM db
Setting up sam.ldb partitions and settings
Setting up sam.ldb rootDSE
Pre-loading the Samba 4 and AD schema
A Kerberos configuration suitable for Samba 4 has been generated at /opt/samba/private/krb5.conf
Provision OK for domain DN DC=yamatomura,DC=local
Starting replication
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[402/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[804/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[1206/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=yamatomura,DC=local] objects[1550/1550] linked_values[0/0]
Analyze and apply schema objects
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[402/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[804/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1206/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1608/1617] linked_values[0/0]
Partition[CN=Configuration,DC=yamatomura,DC=local] objects[1617/1617] linked_values[28/0]
Replicating critical objects from the base DN of the domain
Partition[DC=yamatomura,DC=local] objects[97/97] linked_values[24/0]
Partition[DC=yamatomura,DC=local] objects[367/270] linked_values[24/0]
Done with always replicated NC (base, config, schema)
Replicating DC=DomainDnsZones,DC=yamatomura,DC=local
Partition[DC=DomainDnsZones,DC=yamatomura,DC=local] objects[74/74] linked_values[0/0]
Replicating DC=ForestDnsZones,DC=yamatomura,DC=local
Partition[DC=ForestDnsZones,DC=yamatomura,DC=local] objects[19/19] linked_values[0/0]
Committing SAM database
Sending DsReplicaUpdateRefs for all the replicated partitions
Setting isSynchronized and dsServiceName
Setting up secrets database
Joined domain YAMATOMURA (SID S-1-5-21-1103419775-2087469381-2721633249) as a DC


 Verifying and Creating a DC DNS Recordを参照して2台目をDNSへ登録する。説明ではsamba 4.6以降では本手順は不要となっているのだが、4.6.7で必要だった。

root@raspberrypi1:/opt/samba/etc# ldbsearch -H /opt/samba/private/sam.ldb '(invocationId=*)' --cross-ncs objectguid
# record 1
dn: CN=NTDS Settings,CN=RASPBERRYPI1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
objectGUID: 47a81dec-2a7f-48a9-9312-08006115a3fa

# record 2
dn: CN=NTDS Settings,CN=RASPBERRYPI2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=yamatomura,DC=local
objectGUID: b5d3d0e3-4c3e-4253-adb1-6ab126adbb01

# returned 2 records
# 2 entries
# 0 referrals
root@raspberrypi1:/opt/samba/etc# host -t CNAME 47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.loccal.
47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.loccal has no CNAME record
root@raspberrypi1:/opt/samba/etc# samba-tool dns add raspberrypi2 _msdcs.yamatomura.local 47a81dec-2a7f-48a9-9312-08006115a3fa CNAME raspberrypi1.yamatomura.local -Uadministrator
Password for [YAMATOMURA\administrator]:
Record added successfully
root@raspberrypi1:/opt/samba/etc# host -t CNAME 47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.local.
47a81dec-2a7f-48a9-9312-08006115a3fa._msdcs.yamatomura.local is an alias for raspberrypi1.yamatomura.local.
root@raspberrypi1:/opt/samba/etc#



 smb.confのdns forwarderを設定する。domainに参加したsambaで当該を設定しないとドメイン参加したコンピュータから名前解決がNGになる。


 /etc/dhcpcd.confのdomain_name_serversを設定する。


送信側の設定

xinetd.dをapt-getする。

apt-get install xinetd

rsyncの起動設定と起動を行う。

root@raspberrypi2:/etc# echo "rsync --daemon --config /etc/rsyncd.conf">>/etc/rc.local

#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will "exit 0" on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.

# Print the IP address
_IP=$(hostname -I) || true
if [ "$_IP" ]; then
  printf "My IP address is %s\n" "$_IP"
fi


rsync --daemon --config /etc/rsyncd.conf

exit 0

/etc/rc.local (END)


root@raspberrypi2:/etc# rsync --daemon --config /etc/rsyncd.conf


[SysVol]
path = /opt/samba/var/locks/sysvol/
comment = Samba Sysvol Share
uid = root
gid = root
read only = yes
auth users = sysvol-replication
secrets file = /opt/samba/etc/rsyncd.secret
/etc/rsyncd.conf (END)


パスワードファイルを作成する。

root@raspberrypi2:/opt/samba/etc# pico /opt/samba/etc/rsyncd.secret

sysvol-replication:pa$$w0rd

root@raspberrypi2:/opt/samba/etc# chmod 600 rsyncd.secret

権限を変更しないとrsyncに失敗する。


受信側の設定

まずはパスワードファイルを設定する。
root@raspberrypi1:/opt/samba/etc# pico rsync-client.secret

pa$$w0rd

permissionを変更しておく。
root@raspberrypi1:/opt/samba/etc# chmod 600 rsync-client.secret 



最初にdry runをして正常に動作するか確認すること。本システムはraspberrypi2をFSMOというか送信側にしている。

root@raspberrypi1:/opt/samba/etc# rsync --dry-run -XAavz --delete-after --password-file=/opt/samba/etc/rsync-client.secret rsync://sysvol-replication@raspberrypi2/SysVol/ /opt/samba/var/locks/sysvol/
receiving file list ... done
./
yamatomura.local/
yamatomura.local/Policies/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/
yamatomura.local/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/USER/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/GPT.INI
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/MACHINE/
yamatomura.local/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}/USER/
yamatomura.local/scripts/

sent 59 bytes  received 588 bytes  99.54 bytes/sec
total size is 40  speedup is 0.06 (DRY RUN)

正常にrsyncするのを確認後cronに登録する。

echo "*/5 * * * * root rsync -XAavz --delete-after --password-file=/opt/samba/etc/rsync-client.secret rsync://sysvol-replication@raspberrypi2/SysVol/ /opt/samba/var/locks/sysvol/">/etc/cron.d/sysvol-replication

同期後、権限の設定変更を行う部分を上記の設定に追記する。

echo "1-59/5 * * * * root /opt/samba/bin/samba-tool ntacl sysvolreset">>/etc/cron.d/sysvol-replication

2016-04-26

  GNU nano 2.2.6                           File: /root/.bashrc                                                           

# ~/.bashrc: executed by bash(1) for non-login shells.

# Note: PS1 and umask are already set in /etc/profile. You should not
# need this unless you want different defaults for root.
# PS1='${debian_chroot:+($debian_chroot)}\h:\w\$ '
# umask 022

# You may uncomment the following lines if you want `ls' to be colorized:
# export LS_OPTIONS='--color=auto'
# eval "`dircolors`"
# alias ls='ls $LS_OPTIONS'
# alias ll='ls $LS_OPTIONS -l'
# alias l='ls $LS_OPTIONS -lA'
#
# Some more alias to avoid making mistakes:
# alias rm='rm -i'
# alias cp='cp -i'
# alias mv='mv -i'

export PATH=/opt/samba/bin/:/opt/samba/sbin/:$PATH

自己紹介

自分の写真
東京都, Japan
憂鬱な凍死家です。こちらではmixiとは異なり固めの話題中心です。

Total Page View

Categories

Powered by Blogger.

Popular Posts

Blog Archive