Setting Up Samba 4 Active Directory Domain Controller on Ubuntu in VirtualBox

Поділитися
Вставка
  • Опубліковано 2 січ 2025

КОМЕНТАРІ • 97

  • @MrPythonProgramer
    @MrPythonProgramer 2 роки тому +1

    Ver descriptive and helpful for a newbie in this. Thank you for the time spent

  • @schwaulen
    @schwaulen 4 роки тому +2

    Dude, thanks a lot for this video, I'm getting thrown into the deep end with this stuff and this really helps.

  • @Augerz
    @Augerz 4 роки тому +1

    Well, when i have set up the bridge network card i had no internet on my Linux so i couldn't install anything.. I had to change back to NAT.

  • @sureshprince7240
    @sureshprince7240 3 роки тому

    I'm not able to join Windows 10 to Samba Active Directory. Please help to this issue. Samba Active Directory to Windows 10 client system are both communication. But not able to join.

  • @johnWick-ti5ly
    @johnWick-ti5ly 4 роки тому

    What is the version of Samba have you installed and on which distribution ? Is it necessary the server distribution that have to be used for the configuration ?

  • @lordviator
    @lordviator 6 років тому +2

    Good video, thanks.
    I too was trying to work through their guide, except on 18.04 LTS. Comparing to you helped me figure what was normal, and where my problem was at. I hadn't correctly disabled resolvconf, so resolv.conf changed after reboot.
    One thing to share with you, is when I got stuck with the krb5.conf file, I used 'updatedb' followed by 'locate krb5.conf' to quickly figure out where it was hiding.

    • @RocketCityTech
      @RocketCityTech  6 років тому

      Great comment, thanks for watching.

    • @elixsa69
      @elixsa69 5 років тому

      awesome, you clearly stated what your issue was and how you fixed it, will help me when I set mine up

  • @PE4Doers
    @PE4Doers 5 років тому +1

    Not to be critical, really, but maybe the Linux command 'find' may have helped locate the brb5.conf file. Besides that however, I really learned a LOT from this video and I look forward to watching many more that you upload (I subscribed).

    • @RocketCityTech
      @RocketCityTech  5 років тому

      Not sure why I didn't use it, would have been way easier. Thanks for watching!

    • @PE4Doers
      @PE4Doers 5 років тому +1

      @@RocketCityTech Believe me I know how it goes when the camera is running. I forgot how 'pwd' worked the first time I did something in a Unix-variant in one of my videos. BTW, I am seeing you video right now for the 3rd time - great work - Thanks for making it.

  • @handykaprasetya264
    @handykaprasetya264 4 роки тому +1

    Thankyou for the tutorial.
    But i face the problem.
    When execute samba-tool domain provision --interactive
    The command line is running normal except
    "Unable to determine the DomainSID, can not enforce uniqueness constraint on local domainSIDs.
    Help me please, thanks bro.

    • @JulioLeonFandinho
      @JulioLeonFandinho 3 роки тому

      same problem here, anybody has a solution or something?

  • @dungeonseeker3087
    @dungeonseeker3087 5 років тому +1

    Tried this today on Ubuntu Server 18.04 (the installation instructions are now updated) and it worked a charm. Had a few small issues but nothing I couldn't work around using Google (18.04 server uses a different default network manager). Will test if my main rig can join my domain tomorrow. Thanks.

    • @RocketCityTech
      @RocketCityTech  5 років тому

      Awesome, glad to hear and thanks for sharing!!

    • @johnWick-ti5ly
      @johnWick-ti5ly 4 роки тому

      Can you help me do it. I'm trying but i am facing some issues.

  • @nbarrager
    @nbarrager 2 роки тому +1

    I name my servers after random shit to keep things obscure to outside eyes. My "organization" is a communal hose with three roommates and I'm the only admin there will ever be. The roommates know how to access Jellyfin and the NAS, but if someone I don't know gets on the network for whatever reason and decide they want to mess with my stuff, they won't know what they're looking at based on hostnames.

  • @zincfive
    @zincfive 4 роки тому

    Thanks so much for this video. I've been using Samba4 for a number of years in our small domain, and these tips help. I can confirm that the basic functions of samba AD work fine, and I've been able to install samba ad on ubuntu 18.04 successfully as well, which have a few differences from ubuntu 16.04, and should carry forward to 20.04.

    • @RocketCityTech
      @RocketCityTech  3 роки тому +1

      Very awesome to hear. Gotta love using RSAT toolkit connected to a Linux server! Thanks for watching!

    • @zincfive
      @zincfive 3 роки тому

      @@RocketCityTech Yes, I manage a couple dozen win10 clients. You get all the important security and deployment parts of AD for smaller workgroups. We deploy software, files, printers and security from any admin logon. Great learning tool for AD, we've had a couple of interns manage it, helped them in their careers.

    • @RocketCityTech
      @RocketCityTech  3 роки тому +1

      @@zincfive Indeed, if someone can deploy AD this way and be successful in managing it, they are probably exercising parts of their brains they never knew they had.

  • @DanielDshajani
    @DanielDshajani 3 роки тому

    Hey, is there a tutorial on making a samba file server and joining it to an AD to make roaming user profiles. Thats a high requested Feature in our enviroment. Thx

  • @EF1298
    @EF1298 5 років тому

    1:19:37 i type host -t SRV _ldap._tcp.CURSO.TEC and it output: connection timed out; no servers could be reached. any help shall be appreciated.

    • @EF1298
      @EF1298 5 років тому

      i use bind for dns

    • @RocketCityTech
      @RocketCityTech  5 років тому +1

      Make sure you have also used curso.tec in other steps where I have used ad.testcompany.com Instead of ad.testcompany.com you will just use curso.tec without the ad.
      Good luck, thanks for watching!

    • @EF1298
      @EF1298 5 років тому

      @@RocketCityTech I love u

  • @mr.administrator8809
    @mr.administrator8809 5 років тому +1

    This Video worked, but only until you restart your Server. After that, kerberos and ldap were not reachable. Whats the Problem an do you have a Solution for that Problem?

    • @RocketCityTech
      @RocketCityTech  5 років тому

      Sorry for delayed response. Hmm, interesting, not sure what is going on there but it could just be that you need a startup script to run on boot to get the services running. If I remember correctly, Samba has bootup scripts on their website for different Linux distros, you may want to check there. Thanks for watching.

  • @will936
    @will936 4 роки тому

    Hi, I'm looking to set a DC up on a Raspberry Pi 4, running Ubuntu Server 20.10 or using Raspberry Pi OS (Debian). Would that version of Ubuntu work or no?

    • @RocketCityTech
      @RocketCityTech  3 роки тому

      Did you get this setup going? That would be awesome. Thanks for watching!

    • @will936
      @will936 3 роки тому

      @@RocketCityTech Yes! I use it as my main (and only) DC in my home network. It’s great! I can use it like a standard windows server - it’s my file server, print server, of course AD, and also I was looking to host Plex on it. I did have to use the desktop version of Ubuntu on the raspi because i couldn’t figure out how to get the Static IP to work and also i had loads of DNS issues. No issues now tho - haven’t really had to do much as it just works. I usually reboot the server like once a month! Got a 1tb hard drive and a 2tb hard drive connected and use it as my personal cloud too - remote access to the files. Thanks so much for this tutorial - i would be completely lost without it.

  • @nealtomlinson2673
    @nealtomlinson2673 4 роки тому

    Great video, enabled me to progress past various points where I had got stuck. Have you made any other videos to explain how to add/maintian users to complete this subject?

    • @RocketCityTech
      @RocketCityTech  4 роки тому

      Hello! It's possible the video I made describing the RSAT toolkit may be what you're looking for. Thanks for watching!

  • @mauriciomorales3704
    @mauriciomorales3704 4 роки тому

    Really helped out with my first linux DC test deployment! Thanks!

    • @RocketCityTech
      @RocketCityTech  4 роки тому

      Glad to hear and good luck, thanks for watching!

  • @jelmer4019
    @jelmer4019 5 років тому

    I have a question, i want both internet connection and connection between my Ubuntu server and Windows 10 workstation. How can i set up two network adapters in virtual box and Ubuntu so i can achieve this?

    • @jelmer4019
      @jelmer4019 5 років тому

      The workstation is installed virtual box

    • @elninodelcsgop8399
      @elninodelcsgop8399 5 років тому

      @@jelmer4019 Set an internal network + NAT

  • @christhomas2389
    @christhomas2389 6 років тому

    Would you be willing to share your configuration files as an example? I'm trying to troubleshoot and isolate what's wrong with my configuration.

  • @queen_of_domination
    @queen_of_domination 5 років тому +1

    Sir, I have a question. First of all, I enjoy your videos. Thank you for posting. I would like to build a Linux network, consisting of Domain Controller, Email Server, Web Server, Backup Server, and OS deployment server (similar to WDS/WADK), SOLELY for the purposes of reverse engineering malware and penetration testing, as I’m preparing to take an exam.
    With a Windows-based DC, I would have to build two DCs for a setup like this. Is that required for a Linux-based setup? Also, what are some considerations that I should have for DMZ setup, as well as remote access?
    Any help shall be appreciated.

  • @kylecurry6841
    @kylecurry6841 5 років тому +1

    I've been running this type of setup for 2+ yrs and haven't had any major issues. Debian Jessie for the ADC, setup on Stretch or Ubuntu 18.04 requires different changes regarding DNS for Forward lookup and root hints.
    Windows 10 and the lastest build varients will not respond to GPO's made for mapped drives, however I'm running Samba 4.2.14, where as Samba 4.9 is now available so I'm curious to see if many adaptations have been added to suit changes on the Windows landscape.

    • @RocketCityTech
      @RocketCityTech  5 років тому

      I believe the drives aren't mapping possibly because of dropped support for SMB 1 in Windows 10 and you can either upgrade the server or enable SMB 1 support in Win 10. Just a thought.

    • @kylecurry6841
      @kylecurry6841 5 років тому

      @@RocketCityTech Hi, yes I'm familiar with that change, however I should have been more specific. If manually mapped, theirs no issues, and I've confirmed the SMB version is above 2.1 between Server and Windows client. The issue is automatically mapping drives via GPO.... When tested against a Win7/Server 08, or Win8/8.2/Server 12 machine, everything works fine..... Initially it worked with Win 10 in earlier builds too till something changed after the Win10 Creators update as I recall

    • @RocketCityTech
      @RocketCityTech  5 років тому

      @@kylecurry6841 Interesting. I'd love to hear if updating the Samba server helps with this issue.

    • @kylecurry6841
      @kylecurry6841 5 років тому

      Along the lines of what you mentioned though, I'm wondering if it is related to the enforcement of higher SMB versions, and if this could need adjusting within the DC, if theirs a parameter to do so. That being said, I may try lowering the SMB version in Win10 just to see if they auto-map again.

    • @RocketCityTech
      @RocketCityTech  5 років тому

      @@kylecurry6841 yeah that's exactly what I would do just to see if it makes any difference at all. If not, there could be issues that are resolved in an updated Samba version.

  • @davehouser1
    @davehouser1 5 років тому

    Does anyone know what the office resource requirements are (CPU / Memory)?

  • @fanaFSF
    @fanaFSF 4 роки тому +1

    I only put into hostnames things which are very unlikely to change. Naming a server win-srv-2016 is bad because at some point it will be upgraded to 2019 so it creates more work and irritates people. Calling a server dc1 is OK because usually a DC stays a DC.

    • @RocketCityTech
      @RocketCityTech  4 роки тому

      I ❤️ this comment. Thanks for watching!

  • @dominic667
    @dominic667 5 років тому

    i cant add my client to the domain. i know theres something wrong with the DNS i just cant figure out what i did wrong..

    • @RocketCityTech
      @RocketCityTech  5 років тому

      Can you ping the server from the client using the server's IP address? If not, there is a bigger issue than DNS. If so, then yep, you have a DNS issue.

    • @dominic667
      @dominic667 5 років тому

      @@RocketCityTech i can ping the ad.testcompany.com i cant ping samba.ad.testcompant.local

  • @enamhaque6684
    @enamhaque6684 4 роки тому

    Thank you sir for this wonderful video. I am interested to configure the print server, is there any tutorial?

    • @RocketCityTech
      @RocketCityTech  4 роки тому

      Hello! Ah, yes the dark secrets of Samba4 print servers and GPO would be a fun video. I can say from experience, it can be a headache! Thanks for watching!

  • @geogmz8277
    @geogmz8277 6 років тому +2

    Holy crap! I can't believe I watched the whole thing.. Anyways thanks for the hard work.

    • @RocketCityTech
      @RocketCityTech  6 років тому

      Haha! My thoughts exactly after making the video.. Congrats on making it through and thanks for watching!

    • @geogmz8277
      @geogmz8277 5 років тому

      @@RocketCityTech Was a good video tho.. 👍

    • @RocketCityTech
      @RocketCityTech  5 років тому

      @@geogmz8277 LOL thanks

  • @nilfarmohamed4778
    @nilfarmohamed4778 4 роки тому

    Hi there. Highly appreciate your content and I tried the same way with the same setup. Only difference is that I used Ubuntu 16.04.07 instead of 16.04.05
    At the final step when I install #apt install krb5-user , it was little different and asked to type kerberos realm and I just skipped and automatically assign a name same as my Local host name.
    Then when I try #kinit Administrator and even if I type the correct password, error message :
    kinit : preauthentication failed while getting initial credentials.
    It would be a great help if you can help me with this

    • @nilfarmohamed4778
      @nilfarmohamed4778 4 роки тому

      Hi there. Problem has been fixed. Thank you 😊

    • @RocketCityTech
      @RocketCityTech  3 роки тому

      Glad you got it going! Have fun and thanks for watching!

  • @emmanuelvincentmensah6221
    @emmanuelvincentmensah6221 5 років тому

    Thank you sir for this wonderful video. My Boss has handed over to me an HPE ProLiant DL380 Gen10 Server to setup a linux Domain Controller to authenticate windows clients and users. I have been reading on samba as a preferred choice. I have seen a couple of videos on setting up samba Active Directory on ubuntu. I had a look on the samba wiki and there seem to be some changes on the ubuntu distribution specific package installation as compared to your video. Can you kindly do another tutorial on setting up the current samba AD on the current stable version of ubuntu server. Thank you.

    • @RocketCityTech
      @RocketCityTech  5 років тому

      I will try to do this soon. Thanks for watching!

  • @susanthabathige5860
    @susanthabathige5860 4 роки тому

    very useful video. Thanks! Subscribed

    • @RocketCityTech
      @RocketCityTech  3 роки тому

      Who knew Samba and Active Directory could be so fun!? Thanks for watching.

  • @AnilBind
    @AnilBind 6 років тому +1

    Thanks allot appreciate ur hard work

  • @bobbysweetmore1688
    @bobbysweetmore1688 4 роки тому

    Hey brother can i pm you need some advice ?

  • @gren8759
    @gren8759 5 років тому +1

    Watching your video, will update when done 🐱‍👓

    • @nilsus8365
      @nilsus8365 4 роки тому

      u done?

    • @JasmineIwanek1
      @JasmineIwanek1 4 роки тому

      @@nilsus8365 Unfortunately youtube got stuck in a loop, and he's now doomed to watch forever.

  • @TheSzczurowa
    @TheSzczurowa 4 роки тому +1

    thank You for Your job. Greetings from Poland!

  • @richardson3627
    @richardson3627 5 років тому +1

    Thanks! Subscribed

  • @basil0607
    @basil0607 5 років тому +1

    Thanks from Russia ) Best fresh video about

  • @justinyoung7755
    @justinyoung7755 3 роки тому

    Naming servers after Starwars characters... every time I've been called out to deal with a ransomware attack it seems that the servers are always named in some wacky "oh look how cheeky I am" way. Most of the time these cats quit once the crap hits the fan and the poor dude that has to come in and untangle the mess has to weed through a bunch of pop culture references to get the company going again. Seems to be a correlation between how poorly set up and how poorly named a domain is lol

  • @IoanEugenStan
    @IoanEugenStan 4 роки тому

    Watched it in 1.5x normal speed.

  • @paraglajding
    @paraglajding 5 років тому +1

    Why Ubuntu??? When you have Debian!

  • @KonuralpBalcik
    @KonuralpBalcik 4 роки тому +1

    free linux free problem test it Redhad :D

  • @charlesbenca5357
    @charlesbenca5357 2 роки тому

    Too many ads

  • @fanaFSF
    @fanaFSF 4 роки тому +1

    find / -name krb5.conf

  • @SaarlaneKretiin
    @SaarlaneKretiin 7 місяців тому

    thanks for wasting 5 hours of my life.