基于LDAP后端搭建Samba 4 Active Directory技术求助
我明白你折腾好几个月,参考了一堆教程文档还是卡在Samba 4 AD和LDAP后端的配置上有多闹心——毕竟把这俩组件揉在一起确实有不少细节坑,尤其是在Ubuntu 16.04 LTS这种稍旧的稳定版本上。我之前帮朋友排查过几乎一模一样的场景,给你梳理几个关键的排查和配置要点:
1. 先确认核心依赖与LDAP Schema导入
首先得确保你的LDAP服务器(两台主主同步的节点)都导入了Samba所需的LDAP Schema,这是最容易忽略的前提:
- 登录LDAP服务器,执行命令导入Samba Schema:
ldapadd -Y EXTERNAL -H ldapi:/// -f /usr/share/samba/setup/samba.schema - 还要确认
nis.schema也已经导入(Ubuntu 16.04的LDAP默认应该有,但保险起见检查一下):ldapsearch -Y EXTERNAL -H ldapi:/// -b cn=schema,cn=config | grep nisSchema - 因为是主主同步,两台LDAP节点都要完成Schema导入,否则会出现数据同步不完整的问题。
2. 调整Samba配置文件(smb.conf)的核心参数
打开/etc/samba/smb.conf,重点检查以下关键配置段(替换成你的实际域名、LDAP服务器IP):
[global] workgroup = YOURDOMAIN realm = YOURDOMAIN.LOCAL netbios name = SAMBADCSERVER server role = active directory domain controller server string = Samba 4 AD DC with LDAP Backend # LDAP后端连接配置 ldap server = ldap://your-ldap-primary-ip,ldap://your-ldap-secondary-ip ldap suffix = dc=yourdomain,dc=local ldap user suffix = ou=Users ldap group suffix = ou=Groups ldap machine suffix = ou=Computers ldap admin dn = cn=samba-bind-user,dc=yourdomain,dc=local # 建议用专门的绑定账号,不要用LDAP root ldap passwd sync = yes # ID映射配置(Windows和Linux账号关联) idmap config * : backend = ldap idmap config * : range = 10000-20000 idmap config * : ldap_url = ldap://your-ldap-primary-ip idmap config * : ldap_base_dn = dc=yourdomain,dc=local idmap config * : ldap_user_object_class = posixAccount idmap config * : ldap_group_object_class = posixGroup # Winbind相关(Windows客户端登录依赖) winbind use default domain = yes winbind enum users = yes winbind enum groups = yes security = user passdb backend = ldapsam:ldap://your-ldap-primary-ip
配置完后用testparm检查语法错误:
testparm
3. 确保LDAP服务器的权限设置允许Samba访问
在LDAP服务器的slapd配置中,要给Samba绑定账号分配足够的权限(以OpenLDAP的olcAccess为例):
olcAccess: {0}to attrs=userPassword,shadowLastChange by dn="cn=samba-bind-user,dc=yourdomain,dc=local" write by anonymous auth by self write by * none olcAccess: {1}to dn.base="" by * read olcAccess: {2}to * by dn="cn=admin,dc=yourdomain,dc=local" write by dn="cn=samba-bind-user,dc=yourdomain,dc=local" write by * read
修改后重启slapd服务:
sudo systemctl restart slapd
4. 关键测试与调试步骤
- 测试LDAP连接有效性:在Samba服务器上执行,确认能正常读取LDAP数据:
输入绑定账号密码后如果能返回用户/组数据,说明LDAP连接没问题。ldapsearch -x -H ldap://your-ldap-primary-ip -b dc=yourdomain,dc=local -D cn=samba-bind-user,dc=yourdomain,dc=local -W - 检查Samba日志:实时查看Samba的LDAP相关错误:
常见错误包括绑定失败、Schema缺失、权限不足,日志里会有明确提示。tail -f /var/log/samba/log.samba - Windows客户端测试:先确保客户端能ping通Samba服务器和LDAP服务器,然后尝试加入域,用LDAP账号登录——如果提示“找不到域控制器”,检查Samba的
realm和workgroup配置是否和Windows客户端的DNS设置匹配。
如果还是卡壳,把testparm的完整输出和Samba日志里的关键错误片段贴出来,这样更容易定位具体问题。
内容的提问来源于stack exchange,提问作者Jens Kuipers
相关产品推荐
相关产品推荐

