Samba file server with AD authentication

Prerequities
Fedora 8 with base

vim /etc/selinux/config
"SELINUX=disabled"

vim /etc/hosts
"192.168.123.228 test-ad.contoso.com test-ad"

yum install ntp
ntpdate

yum install samba
yum install samba-common
yum install samba-client
yum install samba-swat

chkconfig smb on
service smb start
service nmb start
chkconfig nmb on

cp /etc/samba/smb.conf /etc/samba/smb.conf.original

vi /etc/xinetd.d/swat
"only_from = 127.0.0.1 192.168.123.0/24"
"disable = no"

service xinetd start
chkconfig xinetd on

connecting the samba server to the AD

setup -> Authentication configuration
(only check following options)
-Use Winbind
-use MD5 passwords
-Use Shadow Passwords
-Local authorization is sufficient

-> next ->

-Security Model = ads
-Domain = CONTOSO.COM
-Domain Controllers = test-ad.contoso.com
-ADS Realm = CONTOSO.COM
-Template Shell = /sbin/nologin

-> next -> yes ->

Domain Administrator = Administrator
Password =

-> Ok -> Ok -> Quit

("wbinfo -u" command returns domain user list if the ad join is successful)


####################################################

vim /etc/nsswitch.conf

passwd: compat winbind
shadow: compat
group: compat winbind

###################################################

init 6 (restart the server)

####################################################

iptables rules for samba share access

iptables -A INPUT -m multiport -p TCP -s 192.168.123.0/24 --destination-ports

631,139,445 -j ACCEPT
iptables -A INPUT -m multiport -p UDP -s 192.168.123.0/24 --destination-ports

631,137,138 -j ACCEPT

iptables rules for SWAT access on port 901

iptables -A INPUT -p TCP -s 192.168.123.0/24 --destination-port 901 -j ACCEPT

####################################################

use http://samba-server-IP:901 to configure shares

[global]
workgroup = CONTOSO
realm = CONTOSO.COM
server string = Samba Server Version %v
security = ADS
password server = test-ad.contoso.com
passdb backend = tdbsam
log file = /var/log/samba/log.%m
max log size = 50
socket options = TCP_NODELAY SO_RCVBUF=16384 SO_SNDBUF=16384
preferred master = No
dns proxy = No
ldap ssl = no
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
template shell = /sbin/nologin
winbind enum users = Yes
winbind enum groups = Yes
cups options = raw
[administrator]
path = /home/administrator
valid users = contoso\administrator
admin users = contoso\administrator
read only = No

####################################################
create samba directories on samba server

mkdir /home/administrator
chmod 777 /home/administrator
chmod a+s /home/administrator

####################################################
Please note that in my examples I've made following assumptions
192.168.123.0/24 is my LAN ip block
contoso.com is my AD domain
192.168.123.228 is my AD's IP
test-ad.contoso.com is my AD machine name

Change the Volume Licensing product key of win xp sp1 and later versions

Use the Activation Wizard

Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.

If you have only a few volume licensing product keys to change, you can use the Activation Wizard.

Note Microsoft recommends that you run System Restore to create a new restore point before you follow these steps. For information about how to create a restore point by using System Restore, see the "To Create a Restore Point" help topic in Help and Support.

1 - Click Start, and then click Run.
2 - In the Open box, type regedit, and then click OK.
3 - In the left pane, locate and then click the following registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\Current Version\WPAEvents

4 - In the right pane, right-click OOBETimer, and then click Modify.
5 - Change at least one digit of this value to deactivate Windows.
6 - Click Start, and then click Run.
7 - In the Open box, type the following command, and then click OK.

%systemroot%\system32\oobe\msoobe.exe /a

8 - Click Yes, I want to telephone a customer service representative to activate Windows, and then click Next.
9 - Click Change Product key.
10 - Type the new product key in the New key boxes, and then click Update.

If you are returned to the previous window, click Remind me later, and then restart the computer.

11 - Repeat steps 6 and 7 to verify that Windows is activated. You receive the following message:

Windows is already activated. Click OK to exit.

12 - Click OK.
13 - Install Windows XP SP1 or a later version of Windows XP.

If you cannot restart Windows after you install Windows XP SP1 or a later version of Windows XP, press F8 when you restart the computer, select Last Known Good Configuration, and then repeat this procedure.

Hi Friends,,,