Week 6 - March 10 Some entries here are quotes from samba documentation. Scripting More on Samba Worked on some, failed on others: sudo smbmount //laptopN/installs /mnt/installs username=owner Should work on all: *slightly* different form of the command. Why is there a difference??? sudo mount -t smbfs -o username=owner //laptopN/installs /mnt/installs ro? cifs? ======================================================================= One helpful thing about samba is that it shines a light on domain-controller operations ======================================================================= Brief overview of DC terminology: * Domain Controller o Primary Domain Controller (PDC) (obsolete) o Backup Domain Controller (BDC) (obsolete) o ADS Domain Controller * Domain Member Server = a server (eg of file shares) that obtains authentication via a Domain Controller (typical samba setup) o Active Directory Domain Server o NT4-Style-Domain Domain Server (obsolete) * Standalone Server = needs own password, in addition to logon password. Core feature of windows domains: Single Sign-On, or SSO SSO can be implemented at the server (logon creates a credential, that is checked each time a share is accessed) or at the client (a password entered once is remembered for subsequent accesses). The latter is distinctly risky in most environments, but is probably acceptable in a school environment so long as teachers are aware of it.) SID: Security IDentifier Machine SID: S-1-5-21-726309263-4128913605-1168186429 (typical) Machines and domains have unique SIDs. When you propagate images, as we did virtually with VMware but which many people do "in reality" with image-burning utilities, you really should change the SID of each machine to something unique. Accounts then add a 3-digit (or more) number (Administrator adds 500): S-1-5-21-726309263-4128913605-1168186429-500 Domain membership: creates "machine trust account" that client *machines* use to log in to server. (Why? Why can't we just have client machine send user credentials to DC?) (Answer: because client machine MUST be able to trust the DC. Otherwise someone could plug the client into their own DC, and then log into the client, and gain access to its files.) Machine-Account password is the shared secret used by that client-server pair to encrypt communications and to authenticate. These form the basis for "computer accounts" in AD. See http://support.microsoft.com/kb/150493 One-shot: NETDOM /Domain:MYDOMAIN /user:adminuser /password:apassword MEMBER MYCOMPUTER /JOINDOMAIN Two-step: Administrator: creates machine-trust acct: NETDOM /Domain:MYDOMAIN /user:adminuser /password:apassword MEMBER MYCOMPUTER /ADD Then local computer user: NETDOM /Domain:MYDOMAIN MEMBER MYCOMPUTER /JOINDOMAIN Note: must be run *from* MYCOMPUTER if ForceGuest is in effect. Which it probably is. Maybe only for "Windows Professional"??? ======================================== What can samba do? Samba has two modes: user-level and share-level security share-level: separate authentication for each share mounted This is what you implemented! user-level: SSO. Windows domains use this. Samba implements four choices for user-level security: user domain ADS server Share-level: more or less straightforward, except for some weirdness with the "standard" linux password file /etc/passwd versus the samba password file /etc/samba/private/smbpasswd Machine trust accounts are stored in AD, in windows server. In samba, they are stored as follows: passdb database configured in smb.conf file corresponding unix (/etc/passwd) account $ NetBIOS-name is usually the machine common name, eg "client1". In fact, we're not really using NetBIOS at all. AD is itself an implementation of "LDAP directory protocol" How to get samba server to participate in SSO logon, when the ADDC (Active-Directory Domain Controller, often ADC) is a winbox? What we want is to be a Domain Member Server. See Samba3-HOWTO.pdf: 6.3 Domain Member Server (p 103) creating machine accounts resetting machine accounts (eg for rebuilt machine) http://support.microsoft.com/kb/216393 joining a domain: create machine account log in using it make some settings announcing you're on the domain =========================================== samba: Samba as a Domain Member Server When Samba is operating in security = domain mode, the Samba server has a domain security trust account (a machine account) and causes all authentication requests to be passed through to the domain controllers This method involves addition of the following parameters in the smb.conf file: security = domain workgroup = VIRTUAL1.CS.LUC.EDU In order for this method to work, the Samba server needs to join the MS Windows NT security domain. This is done as follows: 1. On the MS Windows domain controller, using the Server Manager, add a machine account for the Samba server. 2. On the UNIX/Linux system execute: sudo net rpc join -U ADMINISTRATOR%PASSWORD where the last thing is the account name and actual password separated by %. "Use of this mode of authentication requires there to be a standard UNIX account for each user in order to assign a UID once the account has been authenticated by the Windows domain controller. This account can be blocked to prevent logons by clients other than MS Windows through means such as setting an invalid shell in the /etc/passwd entry. The best way to allocate an invalid shell to a user account is to set the shell to the file /bin/false." What does this mean? Workaround: make sure user FRED can only mount /homes/FRED. All files on the samba server will be owned by GUEST, but each user will only see their own so there's no conflict. Better workaround: "Winbind: Use of Domain Accounts" =============================================================== AD domains: One option is to join as an NT4-style domain member, as above. This works fine, unless your AD security policy prevents it. Joining as a native AD member: Use Kerberos. Kerberos zone is a "realm" realm = YOUR.KERBEROS.REALM security = ADS Kerberos does need some config; see Samba3-HOWTO.pdf, p 108, "Configure /etc/krb5.conf" Basically, a REALM is just a "label" for your kerberos server. net ads join -U Administrator%password or kinit Administrator@your.kerberos.REALM net ads join "organizational_unit" Need version of samba with kerberos support compiled in. In other words, install kerberos and then do a clean reinstall of samba. Older modes: security = server Would pretend to be acting as security=user, but would send the received password on to the designated password server. You can specify that encryption be used. However, you have to be very careful in specifying the "NetBIOS" name of the password server, because otherwise this server can be faked. ============================================================================ Roaming profiles: NETLOGON share: NET SHARE command to list all shares, from the server side mount -t cifs -o username=XXXX,ro //server1/netlogon /mnt/netlogon ============================================================================ Actually *being* an ADDC? Samba has limited support for that, at this time (Samba 3.x) *not* supporting: machine policy group policy objects AD logon scripts use of AD management tools (eg AD Users & Computers) ============================================================================ Dynamic DNS is an integral part of Active Directory, due in part to the fact that domain controllers register their SRV resource records in DNS so that other computers in the Domain (or Forest) can find them. Dynamic DNS is *not* needed so the server can update domain-member IP addresses, if the DHCP server is somewhere else. As clients contact the server, their DNS entries get updated at that time. Because of the machine trust account, client identity is NOT in any way dependent on IP address. Here are some facts about DNS records kept by domain controllers Some of these are for NT4-style PDC/BDC _ldap._tcp.pdc._msdcs.Domain This provides the address of the Windows NT PDC for the domain. _ldap._tcp.pdc._msdcs.DomainTree Resolves the addresses of global catalog servers in the domain. _ldap._tcp.site.sites.writable._msdcs.Domain Provides list of domain controllers based on sites. _ldap._tcp.writable._msdcs.Domain Enumerates list of domain controllers that have the writable copies of the Active Directory data store. _ldap._tcp.GUID.domains._msdcs.DomainTree Entry used by MS Windows clients to locate machines using the global unique identifier. _ldap._tcp.Site.gc._msdcs.DomainTree Used by Microsoft Windows clients to locate the site configuration-dependent global catalog server. ============= Some ADDC records: * _ldap._tcp.pdc._msdcs.VIRTUAL1.CS.LUC.EDU * _ldap.gc._msdcs.VIRTUAL1.CS.LUC.EDU * _ldap.default-first-site-name._sites.gc._msdcs.VIRTUAL1.CS.LUC.EDU * _ldap.{SecID}.domains._msdcs.VIRTUAL1.CS.LUC.EDU * _ldap._tcp.dc._msdcs.VIRTUAL1.CS.LUC.EDU * _kerberos._tcp.dc._msdcs.VIRTUAL1.CS.LUC.EDU * _ldap.default-first-site-name._sites.dc._msdcs.VIRTUAL1.CS.LUC.EDU * _kerberos.default-first-site-name._sites.dc._msdcs.VIRTUAL1.CS.LUC.EDU * SecID._msdcs.VIRTUAL1.CS.LUC.EDU A few examples, using the "dig" utility of linux root# dig @server1 -t any _ldap._tcp.dc._msdcs.virtual1.cs.luc.edu (answer from another command) ; > DiG 9.2.2 > @frodo -t any _ldap._tcp.dc._msdcs.quenya.org ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 3072 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 2 ;; QUESTION SECTION: ;_ldap._tcp.dc._msdcs.quenya.org. IN ANY ;; ANSWER SECTION: _ldap._tcp.dc._msdcs.quenya.org. 600 IN SRV 0 100 389 frodo.quenya.org. _ldap._tcp.dc._msdcs.quenya.org. 600 IN SRV 0 100 389 noldor.quenya.org. ;; ADDITIONAL SECTION: frodo.quenya.org. 3600 IN A 10.1.1.16 noldor.quenya.org. 1200 IN A 10.1.1.17 ;; Query time: 0 msec ;; SERVER: frodo#53(10.1.1.16) ;; WHEN: Wed Oct 7 14:39:31 2004 ;; MSG SIZE rcvd: 171 =============================================================================== [edit] Some XP notes from www.microsoft.com/germany/technet/prodtechnol/winxppro/reskit/c16621675.mspx The built-in Everyone group includes Authenticated Users and Guests, but it no longer includes members of the Anonymous group. this means that anonymous access (eg to a printer) will generally fail, unless you explicity add permission for the Anonymous group. In Windows NT 4.0 and Windows 2000, all resources such as files and folders that are created by a member of the Administrators group belong to the group as a whole. In Windows XP Professional, these resources by default belong to the individual who creates them. So Administrator is not the same any more as Administrators. To protect users who do not password-protect their accounts, Windows XP Professional accounts without passwords can be used only to log on at the physical computer console and not remotely over the network. ============================================================================= 1. Use dig on ubunto to query the server1 dns system: dig @server1 -t any _ldap._tcp.dc._msdcs.virtual1.cs.luc.edu Also try: * _ldap._tcp.pdc._msdcs.virtual1.cs.luc.edu * _ldap.gc._msdcs.virtual1.cs.luc.edu * _ldap.default-first-site-name._sites.gc._msdcs.virtual1.cs.luc.edu * _ldap.{SecID}.domains._msdcs.virtual1.cs.luc.edu * _ldap._tcp.dc._msdcs.virtual1.cs.luc.edu * _kerberos._tcp.dc._msdcs.virtual1.cs.luc.edu * _ldap.default-first-site-name._sites.dc._msdcs.virtual1.cs.luc.edu * _kerberos.default-first-site-name._sites.dc._msdcs.virtual1.cs.luc.edu * SecID._msdcs.virtual1.cs.luc.edu 2. Add vmtools: (a) choose to mount virtual drive in Summary (b) within the program, copy, unzip, run using sudo. 3. Mount the NETLOGON share from server1.virtual1.cs.luc.edu 4. Install and run AD Explorer, and run it from your windows server. (You *can* use the server in native mode if you really want) 5. install something else on ubuntu? Nah. apt: advanced packaging tool: no more .tar.gz, ./configure, make apt-get http://www.debian.org/doc/manuals/apt-howto/ apt-cache search ubuntu: comes with samba installed! but not smbfs sudo apt-get install smbfs ;; done by pld ============================================================================= Midterm takehome (due Wednesday, March 26): You are *expected* to use google and the microsoft knowledge base extensively in finding answers. 1. How can you enable access to network resources with no password? Normally Windows blocks network access unless a password is required. This is very frustrating with things such as printers. 2. How do you set the style of the login screen? * domain-style logon, with a box * list-all-users logon 3. Is it possible (by registry manipulation or other means) to enable fast-user switching (where you can choose Log Off User => Switch User) on a domain machine? 4.(a) How can you see *all* accounts on a machine? (b). What are your options if you've lost the administrative-account password? (c). Where is the Security Accounts Manager database? What do you have to do to look at it? What is the Local Security Authority? 5. Suppose you create an account TEMPUSER create a file C:\tempuser.text readable only by TEMPUSER,\ delete the account TEMPUSER create a new account TEMPUSER Why can't the new account read the file? 6. For domain *members*, where is the Machine Account password stored? 7. How do you disable that annoying requirement on the Windows Server 2003 logon screen that you provide a *reason* for the last shutdown? ================================================================================