слуш, какая-то фигня, у всех работает, а у тебя нет... давай по шагам с конфигами, как ты подключаешь
1.Устанавливаю пакеты samba smbfs winbind libpam-mount
2.Создаю папку /home/LAN
3.Редактирую файл /etc/hosts
127.0.0.1 dd.lan.local localhost dd
192.168.0.200 dc.lan.local
192.168.0.201 dc1.lan.local
192.168.0.1 gateway.lan.local
4.Редактирую /etc/default/ntpdate
NTPDATE_USE_NTP_CONF=yes
NTPSERVERS="dc.lan.local"
NTPOPTIONS=""
5.Редактирую /etc/default/rcS
TMPTIME=0
SULOGIN=no
DELAYLOGIN=no
UTC=no
VERBOSE=no
FSCKFIX=no
6.Создаю скрипт /etc/network/if-up.d/winbr
#!/bin/sh
/etc/init.d/winbind restart
7.Присваиваю ему права запуска chmod +x /etc/network/if-up.d/winbr
8.Редактирую /etc/samba/smb.conf
[global]
unix charset = UTF-8
dos charset = CP866
display charset = UTF-8
workgroup = LAN
server string = %h server (Samba, Ubuntu)
wins support = no
dns proxy = no
log file = /var/log/samba/log.%m
max log size = 1000
syslog = 0
panic action = /usr/share/samba/panic-action %d
security = ads
password server = 192.168.0.200 192.168.0.201
realm = LAN.LOCAL
encrypt passwords = true
passdb backend = tdbsam
obey pam restrictions = yes
invalid users = root
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\sUNIX\spassword:* %n\n *Retype\snew\sUNIX\spassword:* %n\n *passwd:*password\supdated\ssuccessfully* .
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
idmap uid = 10000-20000
idmap gid = 10000-20000
template shell = /bin/bash
winbind enum groups = yes
winbind enum users = yes
template homedir = /home/%D/%U
client use spnego = yes
winbind use default domain = yes
winbind refresh tickets = yes
restrict anonymous = 2
domain master = no
local master = no
preferred master = no
os level = 0
9.Даю команду на синхр времени /etc/network/if-up.d/ntpdate
10.Даю команду на перечитку конфигурации /etc/init.d/winbind stop && /etc/init.d/samba restart && /etc/init.d/winbind start
11.Ввожу машину в домен
root@dd:~# net ads join -U ivanov_ii@LAN.LOCAL
ivanov_ii@LAN.LOCAL's password:
Using short domain name -- LAN
Joined 'DD' to realm 'LAN.LOCAL'
root@dd:~#
12.Редактирую /etc/pam.d/common-account
account sufficient pam_winbind.so
account required pam_unix.so
13.Редактирую /etc/pam.d/common-auth
auth required pam_mount.so
auth optional pam_group.so
auth sufficient pam_unix.so nullok_secure use_first_pass
auth sufficient pam_winbind.so use_first_pass krb5_auth krb5_ccache_type=FILE debug
auth required pam_deny.so
14.Редактирую /etc/pam.d/common-password
password sufficient pam_unix.so nullok obscure md5
password sufficient pam_winbind.so
15.Редактирую /etc/pam.d/common-session
session required pam_winbind.so
session required pam_unix.so
session required pam_mkhomedir.so umask=0022 skel=/etc/skel
session optional pam_foreground.so
16.Редактирую /etc/pam.d/gdm
#%PAM-1.0
auth requisite pam_nologin.so
auth required pam_env.so
@include common-auth
@include common-account
session required pam_limits.so
@include common-session
#session required pam_mount.so use_first_pass
@include common-pammount
session required pam_mkhomedir.so umask=0022 skel=/etc/skel
@include common-password
17.Редактирую /etc/pam.d/sudo
#%PAM-1.0
auth sufficient pam_winbind.so
auth sufficient pam_unix.so use_first_pass
auth required pam_deny.so
@include common-account
18.Редактирую файл /etc/nsswitch.conf
passwd: compat winbind
group: compat winbind
shadow: compat
hosts: files dns
networks: files dns
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: files winbind
19.Редактирую /etc/security/group.conf
*;*;*;Wk0900-2200;adm,audio,scanner,lpadmin
*;*;usysop;Al0000-2400;adm,audio,scanner,cdrom,floppy,plugdev,admin,dip,video,netdev,lpadmin,powerdev
*;*;ivanov_ii@lan.local;Al0000-10080;adm,audio,scanner,cdrom,floppy,plugdev,admin,dip,video,netdev,lpadmin,powerdev
20.Редактирую /etc/security/pam_mount.conf
debug 0
mkmountpoint 1
fsckloop /dev/loop7
options_allow nosuid,nodev,loop,encryption,fsck
options_require nosuid,nodev
lsof /usr/bin/lsof %(MNTPT)
fsck /sbin/fsck -p %(FSCKTARGET)
losetup /sbin/losetup -p0 "%(before=\"-e\" CIPHER)" "%(before=\"-k\" KEYBITS)" %(FSCKLOOP) %(VOLUME)
unlosetup /sbin/losetup -d %(FSCKLOOP)
cifsmount /bin/mount -t cifs //%(SERVER)/%(VOLUME) %(MNTPT) -o "user=%(USER),uid=%(USERUID),gid=%(USERGID)%(before=\",\" OPTIONS)"
smbmount /usr/bin/smbmount //%(SERVER)/%(VOLUME) %(MNTPT) -o "username=%(USER),uid=%(USERUID),gid=%(USERGID)%(before=\",\" OPTIONS)"
ncpmount /usr/bin/ncpmount %(SERVER)/%(USER) %(MNTPT) -o "pass-fd=0,volume=%(VOLUME)%(before=\",\" OPTIONS)"
smbumount /usr/bin/smbumount %(MNTPT)
ncpumount /usr/bin/ncpumount %(MNTPT)
fusemount /sbin/mount.fuse %(VOLUME) %(MNTPT) "%(before=\"-o\" OPTIONS)"
fuseumount /usr/bin/fusermount -u %(MNTPT)
umount /bin/umount %(MNTPT)
lclmount /bin/mount -p0 -t %(FSTYPE) %(VOLUME) %(MNTPT) "%(before=\"-o\" OPTIONS)"
cryptmount /bin/mount -t crypt "%(before=\"-o\" OPTIONS)" %(VOLUME) %(MNTPT)
nfsmount /bin/mount %(SERVER):%(VOLUME) %(MNTPT) "%(before=\"-o\" OPTIONS)"
mntagain /bin/mount --bind %(PREVMNTPT) %(MNTPT)
mntcheck /bin/mount # For BSDs (don't have /etc/mtab)
pmvarrun /usr/sbin/pmvarrun -u %(USER) -o %(OPERATION)
volume * cifs gateway setup /media/gateway/G/Setup uid=&,gid='domain users',dir_mode=0751,domain=LAN,iocharset=utf8,codepage=866 - -
volume * cifs gateway documents /media/gateway/G/Документы uid=&,gid='domain users',dir_mode=0751,domain=LAN,iocharset=utf8,codepage=866 - -
volume * cifs gateway other /media/gateway/G/Разное uid=&,gid='domain users',dir_mode=0751,domain=LAN,iocharset=utf8,codepage=866 - -
21.Перезагружаю компьютер