{"id":260,"date":"2011-10-18T20:31:21","date_gmt":"2011-10-18T18:31:21","guid":{"rendered":"http:\/\/diablo.craem.net\/wordpress\/?p=260"},"modified":"2011-10-18T20:31:21","modified_gmt":"2011-10-18T18:31:21","slug":"squid-active-directory-parte-2","status":"publish","type":"post","link":"https:\/\/diablo.craem.net\/?p=260","title":{"rendered":"Squid + Active Directory ::parte 2::"},"content":{"rendered":"<p>Ahora, en este segundo paso, configuraremos el cliente kerberos en nuesto <em>linux<\/em>, para ello editaremos el fichero <em>\/etc\/krb5.conf<\/em>. Previamente lo copiamos&#8230;<br \/>\n<code><br \/>\n# cp \/etc\/krb5.conf \/etc\/krb5_old.conf<br \/>\n<\/code><br \/>\nPartiendo de los siguientes datos:<br \/>\n<strong><br \/>\nservidor AD       : 192.168.2.1<br \/>\ndominio           : midominio.local<br \/>\nNombre Servidor AD: miservidor<br \/>\n<\/strong><br \/>\nBorramos todo el contenido y lo dejamos tal que:<br \/>\n<code><br \/>\n[libdefaults]<br \/>\n       default_realm = MIDOMINIO.LOCAL<br \/>\n       clockskew = 300<br \/>\n[realms]<br \/>\n       MIDOMINIO.LOCAL = {<br \/>\n       kdc             = 192.168.2.1<br \/>\n       default_domain  = midominio.local<br \/>\n       admin_server    = 192.168.2.1<br \/>\n}<br \/>\nmidominio.local = {<br \/>\n        kdc            = 192.168.2.1<br \/>\n        default_domain = midominio.local<br \/>\n        admin_server   = 192.168.2.1<br \/>\n}<br \/>\nmidominio = {<br \/>\n        kdc            = 192.168.2.1<br \/>\n        default_domain = midominio<br \/>\n        admin_server   = midominio.local<br \/>\n}<br \/>\n[logging]<br \/>\n        kdc = FILE:\/var\/log\/krb5\/krb5kdc.log<br \/>\n        admin_server = FILE:\/var\/log\/krb5\/kadmind.log<br \/>\n        default = SYSLOG:NOTICE:DAEMON<br \/>\n[domain_realm]<br \/>\n        .midominio       = midominio<br \/>\n        .midominio.local = MIDOMINIO.LOCAL<br \/>\n[appdefaults]<br \/>\npam = {<br \/>\n        ticket_lifetime    = 1d<br \/>\n        renew_lifetime     = 1d<br \/>\n        forwardable        = true<br \/>\n        proxiable          = false<br \/>\n        retain_after_close = false<br \/>\n        minimum_uid        = 0<br \/>\n        try_first_pass     = true<br \/>\n}<br \/>\n<\/code><br \/>\nUna vez editado este fichero, vamos a crear el ticket kerberos, para ello, tecleamos:<br \/>\n<code><br \/>\nkinit administrador<br \/>\n<\/code><br \/>\nSi todo va bien, nos pedir\u00e1 el password de administrador; no deber\u00e1 de mostrar nada. Si no ha ido bien, deberemos repasar los pasos anteriores.<br \/>\nAhora toca configurar <em><strong>samba<\/strong><\/em>, para ello copiaremos y editaremos el fichero <em>\/etc\/samba\/smb.conf<\/em><br \/>\n<code><br \/>\n# cp \/etc\/samba\/smb.conf \/etc\/samba\/smb_old.conf<br \/>\n<\/code><br \/>\nBorramos el contenido y lo dejamos tal que:<br \/>\n<code><br \/>\n[global]<br \/>\n    security              = ADS<br \/>\n    netbios name          = superTUXsErver<br \/>\n    realm                 = MIDOMINIO.LOCAL<br \/>\n    password server       = miservidor_ad.midominio.local<br \/>\n    workgroup             = MIDOMINIO<br \/>\n    log level             = 1<br \/>\n    syslog                = 0<br \/>\n    idmap uid             = 10000-29999<br \/>\n    idmap gid             = 10000-29999<br \/>\n    winbind separator     = +<br \/>\n    winbind enum users    = yes<br \/>\n    winbind enum groups   = yes<br \/>\n    winbind use default domain = yes<br \/>\n    template homedir      = \/home\/%D\/%U<br \/>\n    template shell        = \/bin\/bash<br \/>\n    client use spnego     = yes<br \/>\n    domain master         = no<br \/>\n    server string         = Super TUX Client AD<br \/>\n    encrypt passwords     = yes<br \/>\n[homes]<br \/>\n    comment         = Home Directories<br \/>\n    valid users     = %S<br \/>\n    browseable      = No<br \/>\n    read only       = No<br \/>\n    inherit acls    = Yes<br \/>\n[profiles]<br \/>\n    comment              = Network Profiles Service<br \/>\n    path                 = %H<br \/>\n    read only            = No<br \/>\n    store dos attributes = Yes<br \/>\n    create mask          = 0600<br \/>\n    directory mask       = 0700<br \/>\n<\/code><br \/>\nUna vez editado, reiniciamos samba:<br \/>\n<code><br \/>\n#\/etc\/init.d\/samba restart<br \/>\n<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ahora, en este segundo paso, configuraremos el cliente kerberos en nuesto linux, para ello editaremos el fichero \/etc\/krb5.conf. Previamente lo copiamos&#8230; # cp \/etc\/krb5.conf \/etc\/krb5_old.conf Partiendo de los siguientes datos: servidor AD : 192.168.2.1 dominio : midominio.local Nombre Servidor AD: miservidor Borramos todo el contenido y lo dejamos tal que: [libdefaults] default_realm = MIDOMINIO.LOCAL clockskew [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[16,58,97,102,166,177],"class_list":["post-260","post","type-post","status-publish","format-standard","hentry","category-varios","tag-active-directory","tag-debian","tag-kerberos","tag-linux-2","tag-samba","tag-squid"],"_links":{"self":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts\/260","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=260"}],"version-history":[{"count":0,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts\/260\/revisions"}],"wp:attachment":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}