04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

8.4 Extended Configuration<br />

auth/user/methods must be expanded with winbind using <strong>Univention</strong> Management Console (see<br />

Chapter 5.3.5), e.g., to krb5 ldap unix winbind.<br />

If the winbindd process cannot be found in the process list in <strong>Univention</strong> Management Console, it<br />

must be started there (see Chapter 5.3.9).<br />

On a domaincontroller master/backup<br />

net idmap secret WINDOWSDOMAIN $(cat /etc/ldap.secret)<br />

needs to be called.<br />

On a domain controller slave or a member server<br />

net idmap secret WINDOWSDOMAIN $(cat /etc/machine.secret)<br />

needs to be executed instead.<br />

2. A trust relationship must be created on the Windows PDC (see Chapter 8.4.1.2). Any requirements<br />

for Windows applicable to the Windows domain must be taken into account when choosing the<br />

password for the trust relationship. The NetBIOS name of the Samba domain is required for this.<br />

3. The root user must run the following command on the Samba PDC:<br />

net rpc trustdom establish <br />

The winbind service must then be restarted over <strong>Univention</strong> Management Console.<br />

must be replaced with the NetBIOS name of the Windows domain. The com-<br />

mand requests the input of a password; the password used on the Windows PDC must be entered.<br />

The message Trust to domain established then appears.<br />

Attention:<br />

This command must be run on all Samba log-in servers (domain controller master, backup and<br />

slave).<br />

The command occasionally provokes unjustified error messages such as Could not connect to<br />

server . The following command can be used to check that the trust<br />

relationship has been added correctly:<br />

net rpc trustdom list<br />

The password of emphroot on the Samba PDC or BDC should be used. The command display<br />

should be similar to the following:<br />

Trusted domains list:<br />

S-1-5-21-1275210071-1060284298-839522115<br />

Trusting domains list:<br />

none<br />

The System log in Windows can offer help in problem containment when troubleshooting.<br />

4. The command<br />

net rpc trustdom revoke <br />

can be used to remove the trust relationship with the Windows domain. The trust relationship must<br />

also be removed from the Windows PDC.<br />

193

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!