Blaise18 | Bonjour,
Tout d'abord, merci de vos réponses !
J'ai eu d'autres priorités ces derniers temps, mais me revoilà En ce qui concerne Ubuntu, le serveur est déjà en production et je n'ai pas la possibilité de changer d'OS.
Le domaine et LDAP (+ Gosa pour la gestion de l'annuaire) sont installés. Par contre je galère avec smbldap-tools.
J'ai suivi le guide que bardiel m'a conseillé, mais j'ai un problème à l'étape "Installation et configuration de smbldap-tools"
Lorsque je tape net getlocalsid j’obtiens les erreurs suivantes :
[2012/01/26 11:02:38, 0] passdb/secrets.c:914(fetch_ldap_pw)
fetch_ldap_pw: neither ldap secret retrieved!
[2012/01/26 11:02:38, 0] lib/smbldap.c:1046(smbldap_connect_system)
ldap_connect_system: Failed to retrieve password from secrets.tdb
[2012/01/26 11:02:39, 0] passdb/secrets.c:914(fetch_ldap_pw)
fetch_ldap_pw: neither ldap secret retrieved!
[2012/01/26 11:02:39, 0] lib/smbldap.c:1046(smbldap_connect_system)
ldap_connect_system: Failed to retrieve password from secrets.tdb
[2012/01/26 11:02:40, 0] passdb/secrets.c:914(fetch_ldap_pw)
fetch_ldap_pw: neither ldap secret retrieved!
[2012/01/26 11:02:40, 0] lib/smbldap.c:1046(smbldap_connect_system)
ldap_connect_system: Failed to retrieve password from secrets.tdb
[2012/01/26 11:02:41, 0] passdb/secrets.c:914(fetch_ldap_pw)
fetch_ldap_pw: neither ldap secret retrieved!
[2012/01/26 11:02:41, 0] lib/smbldap.c:1046(smbldap_connect_system)
ldap_connect_system: Failed to retrieve password from secrets.tdb
^C |
Je vous laisse mes fichiers de config.
/etc/ldap/slapd.conf :
Code :
- include /etc/ldap/schema/core.schema
- include /etc/ldap/schema/cosine.schema
- include /etc/ldap/schema/inetorgperson.schema
- include /etc/ldap/schema/nis.schema
- include /etc/ldap/schema/samba3.schema
- include /etc/ldap/schema/gosystem.schema
- include /etc/ldap/schema/gofon.schema
- include /etc/ldap/schema/goto.schema
- include /etc/ldap/schema/goto-mime.schema
- # Note: before 2.6.5 this file was named gosa+samba3.schema
- include /etc/ldap/schema/gosa-samba3.schema
- include /etc/ldap/schema/gofax.schema
- include /etc/ldap/schema/goserver.schema
- #schemacheck on
- password-hash {CRYPT}
- pidfile /var/run/slapd/slapd.pid
- argsfile /var/run/slapd/slapd.args
- loglevel 256
- modulepath /usr/lib/ldap
- moduleload back_bdb
- moduleload back_monitor
- backend bdb
- database monitor
- access to dn.subtree=cn=Monitor
- by * read
- access to dn.subtree=""
- by dn.regex="cn=admin,dc=domaine,dc=com" read
- database bdb
- cachesize 10000
- #checkpoint 512 720
- mode 0600
- suffix "dc=domaine,dc=com"
- rootdn "cn=admin,dc=domaine,dc=com"
- rootpw {SSHA}5PuANMbVhvCuo0lcnFmfHPTrkON5zXTo
- index uid,mail eq
- index gosaMailAlternateAddress eq
- index gosaMailForwardingAddress eq
- index cn,sn,givenName,ou pres,eq,sub
- index objectClass pres,eq
- index uidNumber,gidNumber,memberuid eq
- index gosaSubtreeACL,gosaObject,gosaUser pres,eq
- index sambaSID eq,sub
- index sambaPrimaryGroupSID eq
- index sambaDomainName eq
- directory "/var/lib/ldap"
- lastmod off
- access to attrs=userPassword,sambaPwdLastSet,sambaPwdMustChange,sambaPwdCanChange,shadowMax,shadowExpire
- by dn="cn=admin,dc=domaine,dc=com" write
- by dn="uid=samba,ou=DSA,dc=domaine,dc=com" write
- by anonymous auth
- by self write
- by * none
- access to attrs=goImapPassword
- by dn="cn=admin,dc=domaine,dc=com" write
- by * none
- access to attrs=goKrbPassword
- by dn="cn=admin,dc=domaine,dc=com" write
- by * none
- access to attrs=goFaxPassword
- by dn="cn=admin,dc=domaine,dc=com" write
- by * none
- access to attrs=gotoLastUser
- by * write
- access to attrs=sambaLmPassword,sambaNtPassword
- by dn="cn=admin,dc=domaine,dc=com" write
- by dn="uid=samba,ou=DSA,dc=domaine,dc=com" write
- by anonymous auth
- by self write
- by * none
- access to dn.regex="ou=incoming,dc=domaine,dc=com"
- by dn="cn=terminal-admin,dc=domaine,dc=com" write
- by dn="cn=admin,dc=domaine,dc=com" write
- access to dn.sub="ou=incoming,dc=domaine,dc=com"
- by dn.regex="cn=terminal-admin,dc=domaine,dc=com" write
- by dn="cn=admin,dc=domaine,dc=com" write
- access to dn="ou=(people|groups|computers),dc=domaine,dc=com"
- by dn="cn=admin,dc=domaine,dc=com" write
- by dn="uid=samba,ou=DSA,dc=domaine,dc=com" write
- by * read
- access to *
- by dn="cn=admin,dc=domaine,dc=com" =wrscx
- by * read
- by anonymous auth
|
/etc/samba/smb.conf :
Code :
- [global]
- workgroup = domaine
- server string = %h server (Samba, Ubuntu)
- dns proxy = no
- log file = /var/log/samba/log.%m
- max log size = 1000
- syslog = 0
- panic action = /usr/share/samba/panic-action %d
- security = user
- encrypt passwords = true
- passdb backend = ldapsam:ldap://127.0.0.1/
- obey pam restrictions = yes
- unix password sync = yes
- passwd program = /usr/bin/passwd %u
- passwd chat = *Enter\snew\s*\spassword:* %n\n *Retype\snew\s*\spassword:* %n\n *password\supdated\ssuccessfully* .
- pam password change = yes
- map to guest = bad user
- logon path =
- logon home =
- add user script = /usr/sbin/smbldap-useradd -m "%u"
- delete user script = /usr/sbin/smbldap-userdel "%u"
- add machine script = /usr/sbin/smbldap-useradd -w "%u"
- add group script = /usr/sbin/smbldap-groupadd -p "%g"
- socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
- usershare allow guests = yes
- ldap passwd sync = Yes
- ldap admin dn = "cn=admin"
- ldap suffix = dc=domaine,dc=com
- ldap group suffix = ou=Group
- ldap user suffix = ou=People
- ldap machine suffix = ou=Computers
- ldap delete dn = Yes
- add user to group script = /usr/sbin/smbldap-groupmod -m "%u" "%g"
- delete user from group script = /usr/sbin/smbldap-groupmod -x "%u" "%g"
- set primary group script = /usr/sbin/smbldap-usermod -g "%g" "%u"
- case sensitive = No
- default case = lower
- preserve case = yes
- short preserve case = Yes
- socket options = TCP_NODELAY
- ldap ssl = off
- [printers]
- comment = All Printers
- browseable = no
- path = /var/spool/samba
- printable = yes
- guest ok = no
- read only = yes
- create mask = 0700
- [print$]
- comment = Printer Drivers
- path = /var/lib/samba/printers
- browseable = yes
- read only = yes
- guest ok = no
- [samba]
- path = /Samba
- browseable = yes
- writable = yes
- valid users = %S
|
Merci pour votre aide. ---------------
http://blaisephoto.fr | La MX Revolution disséquée
|