You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Samba的Debian共享文件夹Windows AD用户认证访问问题

Alright, let's get your Debian server's shared folder working with AD user authentication. Since you already have the server joined to DOMAIN.LOCAL, we just need to tweak Samba and related configurations to bridge the gap between the domain and your shared directory.

Step 1: Install Required Packages

First, ensure you have all the tools Samba needs to integrate with AD:

sudo apt update && sudo apt install samba krb5-user

(You can skip winbind since you're already using SSSD for user/group resolution)

Step 2: Configure Kerberos for AD Authentication

Kerberos handles secure authentication with your AD domain controller. Edit /etc/krb5.conf to match your domain setup:

[libdefaults]
        default_realm = DOMAIN.LOCAL
        dns_lookup_realm = true
        dns_lookup_kdc = true

[realms]
        DOMAIN.LOCAL = {
                kdc = dc01.domain.local  # Replace with your DC's FQDN/hostname
                admin_server = dc01.domain.local
        }

[domain_realm]
        .domain.local = DOMAIN.LOCAL
        domain.local = DOMAIN.LOCAL

Save the file once you've made these changes.

Step 3: Update Samba Configuration

Open /etc/samba/smb.conf and replace the global section with settings that align with your AD integration and existing SSSD setup:

[global]
        workgroup = DOMAIN
        realm = DOMAIN.LOCAL
        security = ADS
        passdb backend = tdbsam
        # Use SSSD for ID mapping to match your nsswitch setup
        idmap config * : backend = tdb
        idmap config DOMAIN : backend = sss
        idmap config DOMAIN : range = 10000-999999
        template homedir = /home/%D/%U
        template shell = /bin/bash
        client signing = yes
        client use spnego = yes
        kerberos method = secrets and keytab
        log file = /var/log/samba/log.%m
        max log size = 1000
        logging = file
        panic action = /usr/share/samba/panic-action %d

Add Your Shared Folder Definition

At the end of smb.conf, add a section for your shared folder (replace /path/to/your/folder with the actual directory path):

[DomainShared]
        path = /path/to/your/folder
        valid users = @DOMAIN\\domain-users  # Allow all domain users, or specify individual users/groups
        read only = no
        browseable = yes
        create mask = 0775
        directory mask = 0775

Step 4: Set Correct Filesystem Permissions

Make sure the shared folder has permissions that let AD users access it:

# Create the folder if it doesn't exist
sudo mkdir -p /path/to/your/folder

# Set ownership to a domain group (e.g., domain admins) and domain users
sudo chown DOMAIN\\domain-admins:DOMAIN\\domain-users /path/to/your/folder
sudo chmod 775 /path/to/your/folder

Step 5: Rejoin Samba to the Domain (Establish Trust)

Even though your server is joined via SSSD, we need to ensure Samba has a valid keytab for AD authentication:

sudo net ads join -U administrator@DOMAIN.LOCAL

Enter your AD admin password when prompted. Verify the join was successful with:

sudo net ads testjoin

You should see the message Join is OK.

Step 6: Restart Samba Services

Apply all changes by restarting Samba:

sudo systemctl restart smbd nmbd
sudo systemctl enable smbd nmbd

Step 7: Test Access

From a Windows machine in DOMAIN.LOCAL, open File Explorer and navigate to \\your-debian-server-hostname\DomainShared. You should be able to access the folder using your AD credentials (or automatically if you're logged into the domain on the Windows machine).

Troubleshooting Tips

  • If access fails, check Samba logs at /var/log/samba/log.<your-windows-machine-name> for specific errors
  • Ensure your firewall allows Samba traffic (TCP ports 139, 445; UDP ports 137, 138)
  • Double-check that the AD user/group you're using is listed in the valid users line of your shared folder config

内容的提问来源于stack exchange,提问作者arturo.mj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:16:42