Univention Corporate Server. Extended Windows integration documentation



Similar documents
Univention Corporate Server. Operation of a Samba domain based on Windows NT domain services

ITCertMaster. Safe, simple and fast. 100% Pass guarantee! IT Certification Guaranteed, The Easy Way!

Active Directory Restoration

PASS4TEST 専 門 IT 認 証 試 験 問 題 集 提 供 者

Searching for accepting?

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

How to install Small Business Server 2003 in an existing Active

Microsoft Virtual Labs. Active Directory New User Interface

Managing and Maintaining Windows Server 2008 Active Directory Servers

Outline SSS Configuring and Troubleshooting Windows Server 2008 Active Directory

Outline SSC Configuring and Troubleshooting Windows Server 2008 Active Directory

R4: Configuring Windows Server 2008 Active Directory

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Active Directory Installation on Windows Server 2012

6436: Designing a Windows Server 2008 Active Directory Infrastructure and Services (5 Days)

ILTA HAND 6B. Upgrading and Deploying. Windows Server In the Legal Environment

Active Directory Monitoring With PATROL

Managing and Maintaining Windows Server 2008 Active Directory Servers

Deploying Windows Server 2008

NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course Outline: 6436 _ Designing a Windows Server 2008 Active Directory Infrastructure and Services Learning Method: Instructor-led Classroom Learning

Designing a Windows Server 2008 Active Directory Infrastructure and Services

COMPLETE COMPUTING, INC.

How To Configure An Active Directory Domain Services

ExecuTrain Course Outline Configuring & Troubleshooting Windows Server 2008 Active Directory Domain Services MOC 6425C 5 Days

Univention Corporate Server. Extended domain services documentation

Course: Configuring and Troubleshooting Windows Server 2008 Active Direct-ory Domain Services

Configuring and Troubleshooting Windows 2008 Active Directory Domain Services

M6425a Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Microsoft Active Directory (AD) Service Log Configuration Guide

Course 6432A: Managing and Maintaining Windows Server 2008 Active Directory Servers

Configuring Windows Server 2008 Active Directory

RSA Authentication Manager 7.1 Microsoft Active Directory Integration Guide

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425

Course Syllabus. Managing and Maintaining Windows Server 2008 Active Directory Servers. Key Data. Audience. Prerequisites. At Course Completion

Windows Server 2008 Active Directory Configuration (Exam )

Updating Your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008

6425C - Windows Server 2008 R2 Active Directory Domain Services

Managing and Maintaining a Windows Server 2003 Network Environment

Installing Active Directory

Video Administration Backup and Restore Procedures

Avatier Identity Management Suite

Build Your Knowledge!

Create a printer preference in the Default Domain Policy that sets a default printer as laser5.nutex.com and designate the policy as Enforced.

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services

Samba's AD DC: Samba 4.2 and Beyond. Presented by Andrew Bartlett of Catalyst //

MOC 6436A: Designing Active Directory Infrastructure and Services in Windows Server 2008

6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Deploying Windows Server 2008 Course 6418C; 3 days, Instructor-led

The Best Active Directory Courses For Windows Server 2008

Applying Filters. List Only User Accounts

Implementing Microsoft Azure Infrastructure Solutions

PassTest. Bessere Qualität, bessere Dienstleistungen!

Microsoft. Jump Start. M11: Implementing Active Directory Domain Services

Preliminary Course Syllabus

MS 6419 Configuring, Managing and Maintaining Windows Server 2008-based Servers

How to monitor AD security with MOM

Migrating Active Directory to Windows Server 2012 R2

INUVIKA OVD VIRTUAL DESKTOP ENTERPRISE

6.1.2 Installing AD DS 7:45

Course 6425C: Five days

SETTING UP ACTIVE DIRECTORY (AD) ON WINDOWS 2008 FOR EROOM

Installation of MicroSoft Active Directory

This article was previously published under Q SUMMARY

9. Which is the command used to remove active directory from a domain controller? Answer: Dcpromo /forceremoval

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Introduction to Auditing Active Directory

Active Directory Infrastructure Design Document

Active Directory Services with Windows Server MOC 10969

How To Deploy Lync 2010 Client Using SCCM 2012 R2

SolarWinds Migrating SolarWinds NPM Technical Reference

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Installation Guide

This guide provides information to show how to create and manage Riva Dynamic Distribution List policies.

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

This module explains how to configure and troubleshoot DNS, including DNS replication and caching.

ITTEST QUESTION & ANSWER. Guías de estudio precisos, Alta tasa de paso!

Course Syllabus. Deploying Microsoft Windows Server Key Data. Audience. At Course Completion

Updating your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008

Computer Visions Course Outline

Course Outline. Course 6419 : Configuring, Managing and Maintaining Windows Server 2008-based Servers. Duration: 5 Days

Metastorm BPM Interwoven Integration. Process Mapping solutions. Metastorm BPM Interwoven Integration. Introduction. The solution

Active Directory Services with Windows Server

Deploying Personal Virtual Desktops by Using RemoteApp and Desktop Connection Step-by-Step Guide

Updating your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008 (MS6416)

Course: Fundamentals of Microsoft Server 2008 Active Directory

Configure Single Sign on Between Domino and WPS

NetIQ Advanced Authentication Framework. FIDO U2F Authentication Provider Installation Guide. Version 5.1.0

Microsoft. Official Course. Introduction to Active Directory Domain Services. Module 2

Click Studios. Passwordstate. Upgrade Instructions to V7 from V5.xx

2003 O/S. when installed (gets installed as a stand alone server) to promoting to D.C. We have to install A.D.

Installing Active Directory on Windows Server 2008 by Daniel Petri - January 8, 2009 Printer Friendly Version

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

Go to Policy/Global Properties/SmartDashboard Customization, click Configure. In Certificates and PKI properties, change host_certs_key_size to 2048

Transcription:

Univention Corporate Server Extended Windows integration documentation

2

Table of Contents 1. Advanced Samba documentation... 4 1.1. Operating Samba 4 as a read-only domain controller... 4 1.2. Uninstallation of a Samba 4 domain controller... 4 2. Advanced Active Directory connector documentation... 7 2.1. Synchronisation of several Active Directory domains with one UCS directory service... 7 Bibliography... 8 3

Chapter 1. Advanced Samba documentation Operating Samba 4 as a read-only domain controller 1.1. Operating Samba 4 as a read-only domain controller Active Directory offers an operating mode called read-only domain controller (RODC) with the following properties: The data are only stored in read-only format; all write changes must be performed on another domain controller. Consequently, replication is only performed in one direction. A comprehensive description can be found in the Microsoft TechNet Library [technet-rodc]. A Samba 4 domain controller can be operated in RODC mode (on a slave domain controller for example). Prior to the installation of univention-samba4, the Univention Configuration Registry variable samba4/role must be set to RODC: ucr set samba4/role=rodc univention-install univention-samba4 univention-run-join-scripts 1.2. Uninstallation of a Samba 4 domain controller The removal of an Samba 4 domain controller (Active Directory-compatible domain controller) is a far-reaching configuration step and should be prepared thoroughly. If the domain should continue to be provide Active Directory-compatible services, the univention-samba4 package must remain installed on the master domain controller or a backup domain controller system. Before uninstalling the packages, the domain controller registration must be removed from the Samba 4 database. This can be done with the helper script purge_s4_computer.py. It must be run on the master domain controller or a backup domain controller system. The query Really remove master from Samba 4? must be answered with Yes and the question Really remove master from UDM as well? must be answered with No. e.g: root@backup:~# /usr/share/univention-samba4/scripts/purge_s4_computer.py --computername=master Really remove master from Samba 4? [y/n]: Yes If you are really sure type YES and hit enter: YES Ok, continuing as requested. [...] Removing CN=MASTER,CN=Computers,$ldap_BASE from SAM database. Really remove master from UDM as well? [y/n]: No Ok, stopping as requested. root@backup:~# 4

Uninstallation of a Samba 4 domain controller The Univention S4 connector must be run on the master domain controller or a backup domain controller in the domain. After Samba 4 was uninstalled, the join script of the S4 connector (97univention-s4-connector) script should be re-executed on the master domain controller or a another backup domain controller. This can be done via the Univention Management Console module Domain join: Figure 1.1. Re-execute S4 connector join script The FSMO (Flexible Single Master Operations) roles should be checked. In case the roles were provided by the removed DC, they must be transferred, for example: root@backup:~# samba-tool fsmo show InfrastructureMasterRole owner: CN=NTDS RidAllocationMasterRole owner: CN=NTDS PdcEmulationMasterRole owner: CN=NTDS DomainNamingMasterRole owner: CN=NTDS SchemaMasterRole owner: CN=NTDS root@backup:~# samba-tool fsmo seize --role=all --force FSMO transfer of 'rid' role successful 5

Uninstallation of a Samba 4 domain controller FSMO transfer of 'pdc' role successful FSMO transfer of 'naming' role successful FSMO transfer of 'infrastructure' role successful FSMO transfer of 'schema' role successful root@backup:~# 6

Synchronisation of several Active Directory domains with one UCS directory service Chapter 2. Advanced Active Directory connector documentation 2.1. Synchronisation of several Active Directory domains with one UCS directory service It is possible to synchronise several separate Active Directory domains with one UCS directory service (e.g. to synchronise with an AD forest). One OU (organisational unit) can be defined in LDAP for each AD domain, under which the objects of the respective domains are synchronised. The configuration of further connector instances is not covered by the UMC module. Several connector instances are started parallel to each other. Each connector instance is operated with a selfcontained configuration base. The prepare-new-instance script is used to create a new instance, e.g.: /usr/share/univention-ad-connector/scripts/prepare-new-instance -a create -c connector2 This script creates an additional init script for the second connector instance (/etc/init.d/univention-ad-connector2), a configuration directory /etc/univention/connector2 with a copy of the mapping settings of the main connector instance (this can be adapted if necessary) and an array of internal runtime directories. The additional connector instances are registered in the Univention Configuration Registry variable connector/listener/additionalbasenames. If SSL is used for the connection encryption, the exported Active Directory certificate must be converted via openssl into the required format, for example: openssl x509 -inform der -outform pem -in infile.cer -out adconnector2.pem The file name of the converted certificate then needs to be stored in Univention Configuration Registry: univention-config-registry set \ connector2/ad/ldap/certificate=/etc/univention/ad-connector2.pem If a UCS synchronisation is performed towards Active Directory, the replication of the listener module must be restarted after a further connector instance is created. To this end, the following command must be run: univention-directory-listener-ctrl resync ad-connector The command line tools which belong to the AD Connector such as univention-adsearch support selecting the connector instance with the parameter -c. 7

Bibliography [technet-rodc] Microsoft. 2011. AD DS: Read-Only Domain Controllers. http://technet.microsoft.com/en-us/library/cc732801%28v=ws.10%29.aspx.