You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于OpenLDAP+Samba构建类Active Directory集中认证体系及存储共享的技术问询

基于OpenLDAP+Samba构建类Active Directory集中认证体系及存储共享的技术问询

Hey there! Let's walk through your questions one by one—you're on the right track with aiming for a centralized auth system like AD using OpenLDAP and Samba, plus cross-server shared storage. Here's the breakdown:

1. Will domain users be able to log into the 6 Ubuntu servers?

Absolutely yes, but you'll need to configure each Ubuntu client to authenticate against your Samba/OpenLDAP domain controller. Here's the typical setup flow:

  • First, ensure your Samba DC is properly integrated with OpenLDAP (note: Samba 4 can use its own built-in LDAP backend, but if you're sticking with a standalone OpenLDAP server, you'll need to import Samba-specific schemas into OpenLDAP first to support AD-style attributes).
  • On each Ubuntu client, install the necessary tools to join the domain:
    sudo apt update && sudo apt install sssd-ad sssd-tools realmd adcli
    
  • Join the domain using realmd (replace your-domain.local and admin-user with your actual domain and DC admin account):
    sudo realm join your-domain.local -U admin-user
    
  • Verify the setup works by listing domain users:
    getent passwd domain-user@your-domain.local
    

Once configured, users can log into any Ubuntu client using their domain credentials (either domain-user@your-domain.local or just domain-user if you set up shortname resolution).

2. How to grant root access to domain users?

You have two main centralized options (avoid editing local sudoers on every server if possible):

  • Option 1: Use domain groups in sudoers
    Create a security group in your Samba/OpenLDAP domain (e.g., domain-admins), add users to this group, then on each Ubuntu client add a rule to /etc/sudoers.d/domain-admins:

    %domain-admins@your-domain.local ALL=(ALL) ALL
    

    This lets any member of the domain-admins group run commands as root.

  • Option 2: Centralize sudo rules via LDAP
    Install the sudo-ldap package on all Ubuntu clients, then configure sudo to pull rules directly from your OpenLDAP server. This way you can manage sudo permissions for all servers from a single place—no need to edit files on each client. You'll need to add sudo-specific schemas to OpenLDAP and define sudo rules as LDAP entries.

3. Shared storage access across servers

To let users mount the FreeBSD storage directory regardless of which Ubuntu server they log into, follow these steps (focused on NFS since it's lightweight for Linux/BSD environments; SMB is also an option if you want to leverage Samba domain permissions):

Step 1: Ensure UID/GID consistency

First, make sure all domain users have identical UID and GID values across all servers (Ubuntu and FreeBSD). Configure your OpenLDAP server to assign fixed uidNumber and gidNumber attributes to each user—this avoids permission issues when accessing files on the storage server.

Step 2: Configure FreeBSD storage server for NFS

  • Edit /etc/exports to define the shared directory (replace 192.168.1.0/24 with your server subnet):
    /mnt/storage -alldirs -network 192.168.1.0/24 -maproot=root -mapall=domain-user
    
  • Start and enable the NFS service:
    sudo service nfsd start
    sudo sysrc nfsd_enable="YES"
    

Step 3: Auto-mount storage on Ubuntu clients

Use autofs to automatically mount the storage when a user logs in:

  • Install autofs:
    sudo apt install autofs
    
  • Edit /etc/auto.master and add this line:
    /mnt/shared /etc/auto.shared --timeout=60
    
  • Create /etc/auto.shared with the mount rule (replace storage-server with your FreeBSD server's hostname/IP):
    storage -fstype=nfs,rw,soft storage-server:/mnt/storage
    
  • Restart autofs:
    sudo systemctl restart autofs
    

Now, when a user logs in, they can access the storage at /mnt/shared/storage without manual mounting. Alternatively, you can use pam_mount to mount a user-specific directory automatically when they log in, which is great for home directories.


备注:内容来源于stack exchange,提问作者AAB

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 10:08:10