基于Samba的Debian共享文件夹Windows AD用户认证访问问题
Alright, let's get your Debian server's shared folder working with AD user authentication. Since you already have the server joined to DOMAIN.LOCAL, we just need to tweak Samba and related configurations to bridge the gap between the domain and your shared directory.
Step 1: Install Required Packages
First, ensure you have all the tools Samba needs to integrate with AD:
sudo apt update && sudo apt install samba krb5-user
(You can skip winbind since you're already using SSSD for user/group resolution)
Step 2: Configure Kerberos for AD Authentication
Kerberos handles secure authentication with your AD domain controller. Edit /etc/krb5.conf to match your domain setup:
[libdefaults] default_realm = DOMAIN.LOCAL dns_lookup_realm = true dns_lookup_kdc = true [realms] DOMAIN.LOCAL = { kdc = dc01.domain.local # Replace with your DC's FQDN/hostname admin_server = dc01.domain.local } [domain_realm] .domain.local = DOMAIN.LOCAL domain.local = DOMAIN.LOCAL
Save the file once you've made these changes.
Step 3: Update Samba Configuration
Open /etc/samba/smb.conf and replace the global section with settings that align with your AD integration and existing SSSD setup:
[global] workgroup = DOMAIN realm = DOMAIN.LOCAL security = ADS passdb backend = tdbsam # Use SSSD for ID mapping to match your nsswitch setup idmap config * : backend = tdb idmap config DOMAIN : backend = sss idmap config DOMAIN : range = 10000-999999 template homedir = /home/%D/%U template shell = /bin/bash client signing = yes client use spnego = yes kerberos method = secrets and keytab log file = /var/log/samba/log.%m max log size = 1000 logging = file panic action = /usr/share/samba/panic-action %d
Add Your Shared Folder Definition
At the end of smb.conf, add a section for your shared folder (replace /path/to/your/folder with the actual directory path):
[DomainShared] path = /path/to/your/folder valid users = @DOMAIN\\domain-users # Allow all domain users, or specify individual users/groups read only = no browseable = yes create mask = 0775 directory mask = 0775
Step 4: Set Correct Filesystem Permissions
Make sure the shared folder has permissions that let AD users access it:
# Create the folder if it doesn't exist sudo mkdir -p /path/to/your/folder # Set ownership to a domain group (e.g., domain admins) and domain users sudo chown DOMAIN\\domain-admins:DOMAIN\\domain-users /path/to/your/folder sudo chmod 775 /path/to/your/folder
Step 5: Rejoin Samba to the Domain (Establish Trust)
Even though your server is joined via SSSD, we need to ensure Samba has a valid keytab for AD authentication:
sudo net ads join -U administrator@DOMAIN.LOCAL
Enter your AD admin password when prompted. Verify the join was successful with:
sudo net ads testjoin
You should see the message Join is OK.
Step 6: Restart Samba Services
Apply all changes by restarting Samba:
sudo systemctl restart smbd nmbd sudo systemctl enable smbd nmbd
Step 7: Test Access
From a Windows machine in DOMAIN.LOCAL, open File Explorer and navigate to \\your-debian-server-hostname\DomainShared. You should be able to access the folder using your AD credentials (or automatically if you're logged into the domain on the Windows machine).
Troubleshooting Tips
- If access fails, check Samba logs at
/var/log/samba/log.<your-windows-machine-name>for specific errors - Ensure your firewall allows Samba traffic (TCP ports 139, 445; UDP ports 137, 138)
- Double-check that the AD user/group you're using is listed in the
valid usersline of your shared folder config
内容的提问来源于stack exchange,提问作者arturo.mj

