Samba as an Active Directory Domain Controller - 夜莺博客

Samba as an Active Directory Domain Controller

Windows Active Directory stopped being a Windows-only service a long time ago. Samba 4 and later implement the AD domain controller role natively — Kerberos KDC, LDAP, DNS, SMB and replication — inside a single daemon, which means a Linux shop can run a real AD forest without a single Windows Server licence. This guide covers provisioning a new forest or domain, the DNS and Kerberos plumbing that must be right before anything else works, joining clients, and the health checks that reveal a silently broken deployment.

Why run Samba AD rather than FreeIPA or plain LDAP

Samba AD   real AD schema and protocols; Windows clients join natively
           GPOs, DNS-integrated zones, trusts with AD
FreeIPA    Linux-centric identity: Kerberos + LDAP + CA + sudo + HBAC
           excellent for Linux fleets, not an AD replacement for Windows
For a mixed fleet, pick per need: Samba AD for Windows integration,
FreeIPA for Linux automation — see the FreeIPA walkthrough for contrast.

Being honest about scope matters: Samba AD handles the identity plane well, but administrative tooling is thinner than Microsoft's — expect to script more and to use RSAT from a Windows workstation for GPO authoring.

Prepare the host

# static IP, correct FQDN, no conflicting services
hostnamectl set-hostname dc1.example.lan
# /etc/hosts must map the FQDN to the primary IP (not 127.0.1.1)
ip -4 addr show
apt install samba krb5-user winbind libnss-winbind libpam-winbind
apt install dnsutils smbclient ldb-tools
Critical: /etc/resolv.conf must point at the DC's own IP, and the DC must be
the only DNS server for the domain. Pointing at an external resolver breaks
AD DNS lookups for _ldap._tcp and SRV records.

Provision the domain

# remove the distro's default smb.conf, the provisioner writes its own
mv /etc/samba/smb.conf /etc/samba/smb.conf.dist

samba-tool domain provision --use-rfc2307 --interactive
#   Realm:            EXAMPLE.LAN
#   Domain:           EXAMPLE
#   Server Role:      dc
#   DNS backend:      SAMBA_INTERNAL
#   DNS forwarder IP: 10.10.1.1
#   Administrator password: 
# install the provisioned Kerberos config as the system default
cp /var/lib/samba/private/krb5.conf /etc/krb5.conf
systemctl disable --now smbd nmbd winbind
systemctl unmask samba-ad-dc
systemctl enable --now samba-ad-dc

The --use-rfc2307 flag adds POSIX attributes (uidNumber/gidNumber) to the AD schema, which is what lets the same directory serve Linux logins via SSSD as well as Windows logins.

Verify DNS and Kerberos before going further

samba-tool domain level show
host -t A dc1.example.lan
host -t SRV _ldap._tcp.example.lan
host -t SRV _kerberos._udp.example.lan
kinit administrator@EXAMPLE.LAN
klist
samba-tool domain info 127.0.0.1

If kinit fails, the cause is nearly always the realm casing in /etc/krb5.conf or a missing SRV record because DNS still answers from somewhere else. Fix DNS first; Kerberos problems are usually DNS problems.

Create users, groups and join clients

samba-tool user create alice 'Str0ng!Pass'
samba-tool user setexpiry alice --days=365
samba-tool group addmembers "Domain Admins" alice
samba-tool user list | head

# join a Linux client via SSSD (recommended over winbind for Linux)
realm discover example.lan
realm join --user=Administrator example.lan

# join from Windows: set DNS to the DC, then
#   netdom join /domain:example.lan /userd:Administrator /passwordd:*

Replication health

samba-tool drs showrepl              ! per-partition replication status
samba-tool drs kcc -U Administrator  ! trigger knowledge consistency check
samba-tool fsmo show                 ! who holds the FSMO roles
samba-tool dbcheck --cross-ncs       ! database consistency
samba-tool domain backup online --targetdir=/srv/backup-$(date +%F) \
        --server=dc1.example.lan

samba-tool dbcheck --fix resolves the most common integrity issues after an unclean shutdown; run it before bringing a second DC online so you do not replicate corruption.

Adding a second DC

# on dc2, after provisioning it as a member server first
samba-tool domain join example.lan DC -UAdministrator --realm=EXAMPLE.LAN
# then enable samba-ad-dc, fix DNS to point at both DCs, and check replication
samba-tool drs showrepl

Two DCs on the same site is the minimum for availability. Put the second one on a different host and confirm showrepl reports zero failures in both directions — a one-way replication failure is easy to miss and only becomes visible when you fail a DC.

Pitfalls

Pointing clients at external DNS      SRV lookups fail, joins fail
Running smbd + samba-ad-dc together   the classic "why does this break" cause
Time skew > 5 minutes                 Kerberos refuses to authenticate
PFS/encryption mismatch with old SMB  adjust server min protocol in smb.conf
No sysvol replication over rsync      use samba-tool or the native DRS path
Backups without sysvol                restore yields a broken domain

Time synchronisation is non-negotiable in an AD forest: point the PDC emulator at a reliable external source and let everything else follow the domain hierarchy. The DNS side is worth reviewing in detail via systemd-resolved troubleshooting; for Linux-only identity automation, FreeIPA is the better fit, and for web SSO use Keycloak in front of either.

FAQ

Q: Is Samba AD production-ready? Yes — it is widely deployed, including at sites with many thousands of users. Test your specific GPO requirements first, since GPO coverage is the weakest area.
Q: Can it trust a Microsoft AD forest? Yes, both directions, via samba-tool domain trust.
Q: What about Group Policy Preferences (drive maps, registry)? Supported for the common cases; validate before migrating a heavily-GPO-dependent estate.

原文链接:https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Active_Directory_Domain_Controller