04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8 Services for Windows<br />

1. The <strong>Univention</strong> Configuration Registry variable windows/wins-support must be set to yes using<br />

<strong>Univention</strong> Management Console on the Samba server which should offer WINS from this point<br />

onwards<br />

2. The Samba service must be restarted<br />

3. Existing systems must be configured to the address of the new WINS server using, for<br />

example, a DNS alias record (see Chapter 4.5.9.2), a DHCP-NetBIOS policy (see Chap-<br />

ter 4.5.11.5) or for Samba servers by configuring the <strong>Univention</strong> Configuration Registry variable<br />

windows/wins-server.<br />

8.4.3 NETLOGON share<br />

The NETLOGON share serves the purpose of providing system policies and logon scripts in Windows<br />

domains. Under <strong>UCS</strong>, the directory /var/lib/samba/netlogon is set up as the Samba share NETL-<br />

OGON.<br />

The NETLOGON share must be available on all Samba domain controllers and contain the same contents.<br />

To provide this guarantee,changes are only made on the DC master (even when Samba is not installed on<br />

the DC master) and synchronised (as standard hourly) encrypted with the help of the programs rsync und<br />

ssh to all DC backup and DC slave systems on which Samba is installed The synchronisation intervals<br />

can be changed on the individual servers in the /etc/cron.d/univention-samba file.<br />

8.4.3.1 Logon Scripts<br />

Logon scripts are executed on Windows computers after successful login of a user. They permit a variety<br />

of changes to be made in the user’s environment before he can work within the system. The logon script<br />

can be found in the scripts directory of the Samba share NETLOGON. Chapter 8.4.5 explains how other<br />

login scripts on Samba level and on user level can be defined. Scripts have to be saved in a format which<br />

can be executed by Windows, such as bat and cmd.<br />

Under Windows, the<br />

net user / domain<br />

command is used for checking if a logon script is assigned to the user stated in username and if so, which<br />

script this is.<br />

The <strong>Univention</strong> Configuration Registry variable samba/logonscript can be used for defining a global<br />

logon script. If this variable is set on a Samba server, then all users logging into this Samba server have<br />

the specified logon script assigned.<br />

8.4.3.2 System policies<br />

Samba supports the use of so-called system policies which are created and edited under Windows by the<br />

tool poledit.exe. System policies allow a large number of presettings to be made concerning users and<br />

clients. For example: Users can be restricted to execute only a small number of predefined programs.<br />

196

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!