$ samba-tool domain join testing.com.ar DC -Uadministrator --realm=TESTING.COM.AR Finding a writeable DC for domain 'testing.com.ar' Found DC firewall.testing.com.ar Password for [TESTING\administrator]: ******** workgroup is TESTING realm is testing.com.ar checking sAMAccountName Adding CN=SAMBA_SERVER,OU=Domain Controllers,DC=testing,DC=com,DC=ar Adding CN=SAMBA_SERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=testing,DC=com,DC=ar Adding CN=NTDS Settings,CN=SAMBA_SERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=testing,DC=com,DC=ar Adding SPNs to CN=SAMBA_SERVER,OU=Domain Controllers,DC=testing,DC=com,DC=ar Setting account password for SAMBA_SERVER$ Enabling account Calling bare provision No IPv6 address will be assigned xattr_tdb_removexattr() failed to get vfs_handle->data! Provision OK for domain DN DC=testing,DC=com,DC=ar Starting replication Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[402/1550] linked_values[0/0] Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[804/1550] linked_values[0/0] Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[1206/1550] linked_values[0/0] Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[1550/1550] linked_values[0/0] Analyze and apply schema objects Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[402/1615] linked_values[0/0] Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[804/1615] linked_values[0/0] Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1206/1615] linked_values[0/0] Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1608/1615] linked_values[0/0] Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1615/1615] linked_values[28/0] Replicating critical objects from the base DN of the domain Partition[DC=testing,DC=com,DC=ar] objects[97/97] linked_values[23/0] Partition[DC=testing,DC=com,DC=ar] objects[351/254] linked_values[26/0] Done with always replicated NC (base, config, schema) Replicating DC=DomainDnsZones,DC=testing,DC=com,DC=ar Partition[DC=DomainDnsZones,DC=testing,DC=com,DC=ar] objects[45/45] linked_values[0/0] Replicating DC=ForestDnsZones,DC=testing,DC=com,DC=ar Partition[DC=ForestDnsZones,DC=testing,DC=com,DC=ar] objects[18/18] linked_values[0/0] Partition[DC=ForestDnsZones,DC=testing,DC=com,DC=ar] objects[36/18] linked_values[0/0] Committing SAM database Sending DsReplicateUpdateRefs for all the replicated partitions Setting isSynchronized and dsServiceName Setting up secrets database Joined domain TESTING (SID S-1-5-21-2909717633-1614928470-4196413475) as a DC
$ samba-tool fsmo seize --force --role=all Will not attempt transfer, seizing... FSMO transfer of 'rid' role successful Will not attempt transfer, seizing... FSMO transfer of 'pdc' role successful Will not attempt transfer, seizing... FSMO transfer of 'naming' role successful Will not attempt transfer, seizing... FSMO transfer of 'infrastructure' role successful Will not attempt transfer, seizing... FSMO transfer of 'schema' role successful
Join_a_domain_as_a_DC
ReplyDeleteOS_Requirements
ReplyDeletePara debuguear errores de kinit (por ejemplo, "kinit: Preauthentication failed while getting initial credentials"):
ReplyDelete$ env KRB5_TRACE=/tmp/krb5.trace.log kinit administrator
Uf! El problema fue (quizá) relojes desincronizados y uso de password viejo!
Delete$ samba-tool domain join testing.com.ar DC -Uadministrator --realm=TESTING.COM.AR
ReplyDeleteFinding a writeable DC for domain 'testing.com.ar'
Found DC firewall.testing.com.ar
Password for [TESTING\administrator]: ********
workgroup is TESTING
realm is testing.com.ar
checking sAMAccountName
Adding CN=SAMBA_SERVER,OU=Domain Controllers,DC=testing,DC=com,DC=ar
Adding CN=SAMBA_SERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=testing,DC=com,DC=ar
Adding CN=NTDS Settings,CN=SAMBA_SERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=testing,DC=com,DC=ar
Adding SPNs to CN=SAMBA_SERVER,OU=Domain Controllers,DC=testing,DC=com,DC=ar
Setting account password for SAMBA_SERVER$
Enabling account
Calling bare provision
No IPv6 address will be assigned
xattr_tdb_removexattr() failed to get vfs_handle->data!
Provision OK for domain DN DC=testing,DC=com,DC=ar
Starting replication
Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[402/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[804/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[1206/1550] linked_values[0/0]
Schema-DN[CN=Schema,CN=Configuration,DC=testing,DC=com,DC=ar] objects[1550/1550] linked_values[0/0]
Analyze and apply schema objects
Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[402/1615] linked_values[0/0]
Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[804/1615] linked_values[0/0]
Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1206/1615] linked_values[0/0]
Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1608/1615] linked_values[0/0]
Partition[CN=Configuration,DC=testing,DC=com,DC=ar] objects[1615/1615] linked_values[28/0]
Replicating critical objects from the base DN of the domain
Partition[DC=testing,DC=com,DC=ar] objects[97/97] linked_values[23/0]
Partition[DC=testing,DC=com,DC=ar] objects[351/254] linked_values[26/0]
Done with always replicated NC (base, config, schema)
Replicating DC=DomainDnsZones,DC=testing,DC=com,DC=ar
Partition[DC=DomainDnsZones,DC=testing,DC=com,DC=ar] objects[45/45] linked_values[0/0]
Replicating DC=ForestDnsZones,DC=testing,DC=com,DC=ar
Partition[DC=ForestDnsZones,DC=testing,DC=com,DC=ar] objects[18/18] linked_values[0/0]
Partition[DC=ForestDnsZones,DC=testing,DC=com,DC=ar] objects[36/18] linked_values[0/0]
Committing SAM database
Sending DsReplicateUpdateRefs for all the replicated partitions
Setting isSynchronized and dsServiceName
Setting up secrets database
Joined domain TESTING (SID S-1-5-21-2909717633-1614928470-4196413475) as a DC
$ samba-tool fsmo seize --force --role=all
ReplyDeleteWill not attempt transfer, seizing...
FSMO transfer of 'rid' role successful
Will not attempt transfer, seizing...
FSMO transfer of 'pdc' role successful
Will not attempt transfer, seizing...
FSMO transfer of 'naming' role successful
Will not attempt transfer, seizing...
FSMO transfer of 'infrastructure' role successful
Will not attempt transfer, seizing...
FSMO transfer of 'schema' role successful
FIREWALL: https://wiki.samba.org/index.php/Samba_port_usage
ReplyDelete