This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
docpublic:systemes:samba4dc [2015/05/10 20:28] procacci@tem-tsp.eu [Kerberos] |
docpublic:systemes:samba4dc [2015/06/06 14:46] (current) procacci@tem-tsp.eu [Samba 4 DC] |
||
---|---|---|---|
Line 4: | Line 4: | ||
* https:// | * https:// | ||
+ | pourquoi debian vs centos MIT/ | ||
+ | |||
+ | * https:// | ||
+ | * http:// | ||
+ | * http:// | ||
+ | * https:// | ||
==== samba 4 ldap ==== | ==== samba 4 ldap ==== | ||
Line 16: | Line 22: | ||
* https:// | * https:// | ||
+ | * http:// | ||
+ | * https:// | ||
+ | * http:// | ||
+ | * https:// | ||
+ | * https:// | ||
==== packages samba ==== | ==== packages samba ==== | ||
Line 337: | Line 348: | ||
renew until 11/05/2015 14:34:58 | renew until 11/05/2015 14:34:58 | ||
</ | </ | ||
+ | |||
+ | |||
+ | ===== KRB change password ===== | ||
+ | |||
+ | http:// | ||
+ | |||
+ | ==== kerberos ticket debug ==== | ||
+ | |||
+ | < | ||
+ | |||
+ | root@debie:/ | ||
+ | [4230] 1432418201.868726: | ||
+ | [4230] 1432418201.869645: | ||
+ | [4230] 1432418201.879583: | ||
+ | [4230] 1432418201.889971: | ||
+ | [4230] 1432418201.925713: | ||
+ | [4230] 1432418201.929666: | ||
+ | [4230] 1432418201.929725: | ||
+ | [4230] 1432418201.929818: | ||
+ | [4230] 1432418201.929848: | ||
+ | Password for Administrator@DOM.4BO.FR: | ||
+ | [4230] 1432418225.405906: | ||
+ | [4230] 1432418225.406093: | ||
+ | [4230] 1432418225.406171: | ||
+ | [4230] 1432418225.406189: | ||
+ | [4230] 1432418225.406246: | ||
+ | [4230] 1432418225.418784: | ||
+ | [4230] 1432418225.428392: | ||
+ | [4230] 1432418225.511409: | ||
+ | [4230] 1432418225.515178: | ||
+ | [4230] 1432418225.515236: | ||
+ | [4230] 1432418225.515265: | ||
+ | [4230] 1432418225.515360: | ||
+ | [4230] 1432418225.515400: | ||
+ | [4230] 1432418225.515453: | ||
+ | [4230] 1432418225.515728: | ||
+ | [4230] 1432418225.515747: | ||
+ | [4230] 1432418225.515912: | ||
+ | [4230] 1432418225.515966: | ||
+ | [4230] 1432418225.515986: | ||
+ | [4230] 1432418225.516145: | ||
+ | [4230] 1432418225.516190: | ||
+ | [4230] 1432418225.516209: | ||
+ | Warning: Your password will expire in 41 days on sam. 04 juil. 2015 23:03:44 CEST | ||
+ | </ | ||
+ | |||
+ | |||
+ | < | ||
+ | root@debie: | ||
+ | kpasswd: Cannot find KDC for requested realm getting initial ticket | ||
+ | root@debie: | ||
+ | klist: Credentials cache file '/ | ||
+ | root@debie: | ||
+ | New Password: | ||
+ | INFO: Current debug levels: | ||
+ | all: 10 | ||
+ | tdb: 10 | ||
+ | .... | ||
+ | ldb: 10 | ||
+ | Processing section " | ||
+ | Processing section " | ||
+ | pm_process() returned Yes | ||
+ | Security token SIDs (1): | ||
+ | SID[ 0]: S-1-5-18 | ||
+ | | ||
+ | Privilege[ | ||
+ | Privilege[ | ||
+ | ... | ||
+ | Privilege[ 24]: SeEnableDelegationPrivilege | ||
+ | | ||
+ | lpcfg_servicenumber: | ||
+ | schema_fsmo_init: | ||
+ | schema_fsmo_init: | ||
+ | ldb: | ||
+ | Sorting rpmd with attid exception 3 rDN=CN DN=CN=Administrator, | ||
+ | Changed password OK | ||
+ | </ | ||
+ | |||
+ | retirer l' | ||
+ | |||
+ | http:// | ||
+ | |||
+ | < | ||
+ | root@debie: | ||
+ | Processing section " | ||
+ | Processing section " | ||
+ | pm_process() returned Yes | ||
+ | Expiry for user ' | ||
+ | </ | ||
+ | |||
==== ntpd ==== | ==== ntpd ==== | ||
Line 372: | Line 473: | ||
</ | </ | ||
+ | ===== windows client Password change ===== | ||
+ | juste apres integrer un poste client W7 dans le domaine, le changement de password user de domain via CTRL+ALT+SUPP echoue | ||
+ | |||
+ | cf log serveur | ||
+ | |||
+ | < | ||
+ | [2015/05/25 12: | ||
+ | kpasswdd: Password change rejected, password changes may not be permitted on this account, or the minimum password age may not have elapsed. | ||
+ | </ | ||
+ | |||
+ | apparement il faut attendre 24H minimum avant de pouvoir le changer d' | ||
+ | |||
+ | < | ||
+ | root@debie: | ||
+ | Processing section " | ||
+ | Processing section " | ||
+ | pm_process() returned Yes | ||
+ | Password informations for domain ' | ||
+ | |||
+ | Password complexity: on | ||
+ | Store plaintext passwords: off | ||
+ | Password history length: 24 | ||
+ | Minimum password length: 7 | ||
+ | Minimum password age (days): 1 | ||
+ | Maximum password age (days): 42 | ||
+ | </ | ||
+ | |||
+ | cf http:// | ||
+ | |||
+ | History lengh 24 -> 2 | ||
+ | |||
+ | < | ||
+ | root@debie:/ | ||
+ | Password history length: 24 | ||
+ | |||
+ | |||
+ | root@debie:/ | ||
+ | Processing section " | ||
+ | Processing section " | ||
+ | pm_process() returned Yes | ||
+ | Password history length changed! | ||
+ | All changes applied successfully! | ||
+ | root@debie:/ | ||
+ | Processing section " | ||
+ | Processing section " | ||
+ | pm_process() returned Yes | ||
+ | Password informations for domain ' | ||
+ | |||
+ | Password complexity: on | ||
+ | Store plaintext passwords: off | ||
+ | Password history length: 2 | ||
+ | Minimum password length: 7 | ||
+ | Minimum password age (days): 1 | ||
+ | Maximum password age (days): 42 | ||
+ | |||
+ | </ | ||
==== domain user ==== | ==== domain user ==== | ||
Line 447: | Line 604: | ||
# 3 referrals | # 3 referrals | ||
</ | </ | ||
+ | |||
+ | ===== Remote Server Administration Tools RSAT ===== | ||
+ | |||
+ | ref | ||
+ | * https:// | ||
+ | * http:// | ||
+ | * https:// | ||
+ | * | ||
+ |