HP ProLiant DL380G5-WSS 3.7.0 HP StorageWorks HP Scalable NAS File Serving Sof - Page 415

Changes for ADS level security, Other windbind information

Page 415 highlights

Changes for ADS level security Set these parameters: • Workgroup = [short Domain Name] • security = ads • password server = [IP of the KDC, then other DCs] • realm = [WINDOWS DOMAIN] See the Samba Official HOWTO for more information about using net ads join to join Samba to the domain using ADS level security. Use net ads testjoin to test the join after the join has completed successfully. NOTE: All VHOSTs need to be kept active and running even if they are not serving any virtual servers. This is necessary to keep the member computer account secrets up-to-date with the Windows domain. This is done by default as long as the VHOST is not disabled. If a node is down for a prolonged time, Samba will need to be rejoined to the domain. Access should be tested on nodes that have been down for a period of time to be sure Samba is properly joined to the domain in case of a failover that causes Virtual Servers to be migrated to another node. Other windbind information HP Scalable NAS currently does not provide custom service monitors to monitor winbind daemons. Once configured, winbind can be started manually. See the Samba Official HOWTO for more information about winbind models and configuration variables. Either the RID model or the LDAP idmap backend needs to be used to assure that UIDs and GIDs are consistent across all cluster nodes. For more information about setting up winbind and the available winbind and idmap parameters, see the Samba Official HOWTO and use the man smb.conf command. Be sure to specify values for the following: • uid= [10000-20000] • gid=[10000-20000] There are no default ranges. These ranges must be outside the UIDs and GIDs assigned in other name services. HP Scalable NAS File Serving Software administration guide 415

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

Changes for ADS level security
Set these parameters:
Workgroup = [short Domain Name]
security = ads
password server = [IP of the KDC, then other DCs]
realm = [WINDOWS DOMAIN]
See the Samba Official HOWTO for more information about using
net ads join
to join Samba to the domain using ADS level security.
Use
net ads testjoin
to test the join after the join has completed successfully.
NOTE:
All VHOSTs need to be kept active and running even if they are not serving any
virtual servers. This is necessary to keep the member computer account secrets
up-to-date with the Windows domain. This is done by default as long as the VHOST
is not disabled. If a node is down for a prolonged time, Samba will need to be
rejoined to the domain. Access should be tested on nodes that have been down for
a period of time to be sure Samba is properly joined to the domain in case of a
failover that causes Virtual Servers to be migrated to another node.
Other windbind information
HP Scalable NAS currently does not provide custom service monitors to monitor
winbind daemons. Once configured, winbind can be started manually. See the
Samba Official HOWTO for more information about winbind models and
configuration variables.
Either the RID model or the LDAP idmap backend needs to be used to assure that
UIDs and GIDs are consistent across all cluster nodes.
For more information about setting up winbind and the available winbind and idmap
parameters, see the Samba Official HOWTO and use the
man smb.conf
command.
Be sure to specify values for the following:
uid= [10000-20000]
gid=[10000-20000]
There are no default ranges. These ranges must be outside the UIDs and GIDs assigned
in other name services.
HP Scalable NAS File Serving Software administration guide
415