Creating a Windows AD using Samba 4 on Ubuntu 22.04

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 88

  • @MattDaley-j2d
    @MattDaley-j2d ปีที่แล้ว +38

    Warning for people setting this up .... never use something.local as your domain name. ".local" is reserved by the ietf and used by multicast DNS. I learned this the hard way so you don't have to.

    • @annako5240
      @annako5240 ปีที่แล้ว +3

      .lan is great ?

    • @MattDaley-j2d
      @MattDaley-j2d ปีที่แล้ว

      Yes. .LAN is fine.@@annako5240

    • @alexfrench3748
      @alexfrench3748 ปีที่แล้ว +1

      I tend to use .internal, .local and bonjour don't play nice.

    • @BenediktHauer
      @BenediktHauer 7 หลายเดือนก่อน

      In case you didn’t know, the ICANN proposes to use .internal… It was published recently - you can check it out here: itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf

    • @mitsukiyouko
      @mitsukiyouko 6 หลายเดือนก่อน +1

      oof i scrolled down too late RIP

  • @dimram2005
    @dimram2005 ปีที่แล้ว +11

    Great tutorial sir. Works 100%.
    Just for those who have ufw in their system, you need to open ports 53 for DNS and 135 for the Domain Controller

    • @dawnS33ker
      @dawnS33ker 9 หลายเดือนก่อน +2

      I found this out the hard way. I had pihole running in my test VM 😃

  • @dawnS33ker
    @dawnS33ker 9 หลายเดือนก่อน +1

    I have been looking for a video like this for ages. Thank you very much for this.

  • @kosak46
    @kosak46 ปีที่แล้ว +6

    Thank you very very much. It is the first time, when I've launched AD in my Ubuntu server and this is the video that showed me the right way to do that!
    By the way, after I've installed RSAT, the icons didn't apper in the control panel.
    And I cannot create any samba group in WebMin anymore.

  • @colram
    @colram ปีที่แล้ว +1

    you made my night!
    thank you very much for this great description!
    greetings from bavaria

  • @justask6686
    @justask6686 6 หลายเดือนก่อน

    For what it's worth, I just followed this with Ubuntu 24.04 and it worked great.

  • @Mikesco3
    @Mikesco3 ปีที่แล้ว

    Totally worth my subscription!!!
    I would love to see a video setting up a mail server hosted locally with a VPS serving as a proxy / VPN gateway

    • @considerednormal
      @considerednormal  8 หลายเดือนก่อน +1

      Sorry for the late reply. Intriguing idea. Might make it happen

  • @madserge11
    @madserge11 8 หลายเดือนก่อน

    Nathan Fillion doing tech guides, nice!

  • @miladsaeed6508
    @miladsaeed6508 3 หลายเดือนก่อน

    Wonderful appreciate your hardwork!

  • @Pshock13y
    @Pshock13y 20 วันที่ผ่านมา

    I'm using a debian server for samba and a fedora client. everything seems to be working right up until trying to log in with a domain user. The only thing I've come across is `systemctl status sssd` tells me that the backend is offline. But based on everything else that works...it's not. I've tried so many things I'm not sure what else to do to get it to work.

  • @vidhyasagarreddy-in8wh
    @vidhyasagarreddy-in8wh 2 หลายเดือนก่อน

    My RSAT tool is responsible very slowly when click any option it is taking so much time to response I have in multiple devices same issue

  • @Barryleunge
    @Barryleunge ปีที่แล้ว +2

    Please note that RSTAT only installs if system language is ENGLISH

  • @nikolatepavac2539
    @nikolatepavac2539 ปีที่แล้ว

    You have explained every step very clearly. Thanks for making such a useful vedeo!
    Can you maybe create a video where you'll explain how to update sabma to the latest version?

    • @considerednormal
      @considerednormal  8 หลายเดือนก่อน

      That is a possibility for a future video, for sure.

  • @dressyspider
    @dressyspider ปีที่แล้ว +1

    Thank you for creating this amazing tutorial.
    Do you have any plans to create a domain joined file server via Ubuntu or Debian? Specifically, one that can have its shares managed via ACL? That is something I have not been able to find a good tutorial for.

    • @considerednormal
      @considerednormal  ปีที่แล้ว +2

      A nice idea. Currently my VM server is offline, bit the dust about a month after I created this tutorial. But once it is back up I might take a run at this.

  • @jhartlov
    @jhartlov ปีที่แล้ว +2

    This is a really awesome tutorial. Thank you so much for adding this. Can you use this, or similar methodology to join an existing Windows domain?

    • @considerednormal
      @considerednormal  ปีที่แล้ว +2

      I have not tried on Ubuntu. I know Fedora has native joining capability, although I personally have never tried it. Not sure about other distros. I don't have a windows server readily available to test. If I ever manage to get one, I will definitely test this out.

    • @sinon_simp
      @sinon_simp ปีที่แล้ว +1

      ​@@considerednormal You can use windows server evaluation to test that

  • @Sabs761010
    @Sabs761010 3 หลายเดือนก่อน +1

    Hi, does its possible install posfix or other email server using the samba users?

    • @considerednormal
      @considerednormal  3 หลายเดือนก่อน +1

      @@Sabs761010 samba and postfix/exim are independent apps from samba, so they should be able to be configured to work.

  • @O_Jiisan
    @O_Jiisan ปีที่แล้ว +2

    Thank you for this great tutorial. 2 question tho. If I added a user, how to assign a location (on the server?) for the home dir? And how to also have shares? Or should another samba server be built seperate for shares?

    • @considerednormal
      @considerednormal  5 หลายเดือนก่อน +1

      @@O_Jiisan when I have a chance I will look into this and post a video for it

  • @jegant8216
    @jegant8216 2 หลายเดือนก่อน

    Thanks for this video, this helped me a lot to set up my servers. when joining second ubuntu machine to samba server, it is not getting the domain admin privileges, it is keep on coming back with guest user privilege. Is there any setting should be made on the smb.conf file to join the administrator as root?

    • @considerednormal
      @considerednormal  2 หลายเดือนก่อน

      @@jegant8216 unfortunately I have not looked into permissions further. Do you have a windows machine (or vm)? You might be able to set it with the domain tools.

  • @coderrquitsreality_
    @coderrquitsreality_ ปีที่แล้ว +1

    I cannot get past the domain provisioning. It keeps telling me invalid DNS backend

    • @considerednormal
      @considerednormal  ปีที่แล้ว

      You might wanna take a look at the following documentation to help fix it. wiki.samba.org/index.php/Changing_the_DNS_Back_End_of_a_Samba_AD_DC

    • @coderrquitsreality_
      @coderrquitsreality_ ปีที่แล้ว +1

      @@considerednormal I got past that part now, however I ran into another issue. the DC and kerberos is not being found when host -t is run.

  • @JasonEreso
    @JasonEreso หลายเดือนก่อน

    My current setup is
    Router>MainSwitch>Ubuntu Server
    / |
    / |
    / v
    PC PC
    The when I tried to ping the server in any PC in switch 1 and 2 it says unreachable. How can I fix this?

  • @mokox9061
    @mokox9061 5 หลายเดือนก่อน

    amazing, i have tried. and this works.

  • @josecabrera5632
    @josecabrera5632 2 หลายเดือนก่อน

    Can a dual boot Linux/Windows machine be added into the same AD controller FOR BOTH Windows and Linux?

    • @considerednormal
      @considerednormal  2 หลายเดือนก่อน

      @@josecabrera5632 short answer, yes. As the login is unique for each os and not purely based on hardware, you should be able to have both attached. As long as the hostnames are different there should be no issue.

  • @theniceboss_yt1214
    @theniceboss_yt1214 10 หลายเดือนก่อน

    Great Tutorial Thank you man

  • @philmennenoh5946
    @philmennenoh5946 ปีที่แล้ว

    Thank you for your time.

  • @accessdenied5998
    @accessdenied5998 5 หลายเดือนก่อน

    I'm stucked at the administrator login after adding the computer to the dns

  • @nomad3846
    @nomad3846 ปีที่แล้ว

    Upon searching multiple tutorial in creating ad this is the best and easiest, i hope you can make also tutorial on how to make a file server or activate the file server after creating the ad, i tried but there seems an error.

    • @considerednormal
      @considerednormal  ปีที่แล้ว

      Thank you for the kind words and thank you for the idea. That might be my next video

  • @annefunclub4100
    @annefunclub4100 4 หลายเดือนก่อน

    I follow this tutorial and I have successfully setup the AD DC. One question, I want to use an external DNS server (an another IP on the same Network, rpi - pihole), so all users on the domain uses the rpi IP as DNS Server. So not the AD DC DNS IP. Any solution? I am trying to add a forwarder from DNS RSAT Tools from windows, but thos feature not supported tells me a error message.

    • @considerednormal
      @considerednormal  4 หลายเดือนก่อน +1

      @@annefunclub4100 not sure how to make it automatic. But you could in the interim, manually set the DNS for devices.

  • @TheTF01
    @TheTF01 11 หลายเดือนก่อน

    Would you be able to configure a read only domain controller similarly?

    • @considerednormal
      @considerednormal  11 หลายเดือนก่อน

      Sadly I do not have an answer for this.

    • @TheTF01
      @TheTF01 11 หลายเดือนก่อน

      @@considerednormal I appreciate the quick response. This video blew my mind how straightforward it was! I would love to be able to setup small Linux boxes as rodc machines in remote offices. Guess I’ll have to wait for someone smarter than I to test it on Linux.
      Is this an actual Microsoft ADDC or an ldap from another company?

  • @denisgreshnyakov8551
    @denisgreshnyakov8551 ปีที่แล้ว

    thank you for this video! this video really helped me!

  • @marcospaulo-xl3ey
    @marcospaulo-xl3ey 3 หลายเดือนก่อน

    Can i still use samba to share files between my windows computers?

    • @considerednormal
      @considerednormal  3 หลายเดือนก่อน +1

      @@marcospaulo-xl3ey the functionality of sharing files vis samba should not be affected, although the setup for this was not part of the tutorial.

  • @common_man4857
    @common_man4857 ปีที่แล้ว

    AD Users groups working, but Group policy not working.

  • @attackdemon-h4x
    @attackdemon-h4x ปีที่แล้ว

    sorry sir... when i unlink resolv.conf and touch resolv.conf .. apt update is failure
    and when i disable systemd-resolv apt update is failure too
    why ? please help me

    • @considerednormal
      @considerednormal  ปีที่แล้ว

      What are the contents of your resolv.conf?

    • @apex_byte
      @apex_byte 7 หลายเดือนก่อน

      @@considerednormal I have the same issue and follow the tutorial as is . . the only different is I am on a 192.168.1.0/24 subnet

  • @meilleur102
    @meilleur102 7 หลายเดือนก่อน

    any way to encrypt the DNS with this solution?

  • @LMLecho
    @LMLecho 8 หลายเดือนก่อน

    so I domain join and it worked but its not resolving names like windows based one was

    • @considerednormal
      @considerednormal  8 หลายเดือนก่อน

      Sadly with most proprietary paid software. The open source replacements are limited compared to the counterpart they replace. You need to compare your needs to what each offers and choose the right solution that suits your needs.

  • @ilyakul2200
    @ilyakul2200 ปีที่แล้ว +1

    Thanks you, men! 😀

  • @jcspaziano
    @jcspaziano 8 หลายเดือนก่อน

    Excellent Tutorial!! Thank you!

  • @tokoiaoben3842
    @tokoiaoben3842 ปีที่แล้ว

    I have pfsense in my LAN acting as a DNS server. Do I still need to set my samba AD as the DNS for Windows LAN clients that will the domain?

    • @considerednormal
      @considerednormal  ปีที่แล้ว +1

      Yes you should, because it keeps records of all the machines by name automatically they get added to the DNS when you join the domain.

    • @danielchristie6546
      @danielchristie6546 7 หลายเดือนก่อน

      make your ad domains recursive resolver your pfsense firewall

  • @gendisayuningtyas1343
    @gendisayuningtyas1343 ปีที่แล้ว

    Hi nice work sir.. i try after failed before, but how to make replicate this AD ?

  • @annefunclub4100
    @annefunclub4100 4 หลายเดือนก่อน

    Roaming profiles will works with this method?

    • @considerednormal
      @considerednormal  4 หลายเดือนก่อน +1

      @@annefunclub4100 haven't tested this. When I lost my server I lost my DC. Will revamp it and hopefully do another video on advanced features.

  • @Gelimarr
    @Gelimarr 11 หลายเดือนก่อน

    If I follow this, would this also work in Fedora instead of Ubuntu? I already know to use dnf instead of apt EDIT : nvm, you are also showing Fedora at the end ;)

  • @Gameplayernumber1
    @Gameplayernumber1 หลายเดือนก่อน

    Does anyone know if this works on BSD? :)

    • @considerednormal
      @considerednormal  หลายเดือนก่อน

      The installation procedure might be a bit different but I do not see a reason why the config portion wouldn't work.

  • @giannicarafone2677
    @giannicarafone2677 ปีที่แล้ว

    Grazie, tutorial eccezionale.

  • @husseinameen7210
    @husseinameen7210 ปีที่แล้ว

    can i use commands of ubuntu on mint?

    • @considerednormal
      @considerednormal  ปีที่แล้ว

      If I am not mistaken Mint is an Ubuntu based flavour, so the commands should work out of the box.

    • @considerednormal
      @considerednormal  ปีที่แล้ว

      If you are using the LMDE version, which is Debian based, the commands should still run as well, as Ubuntu is based on Debian.

  • @ปิยะวัฒน์ขนานขาว
    @ปิยะวัฒน์ขนานขาว 12 วันที่ผ่านมา

    Thank Work 100%

  • @monsterhuntfreak2011
    @monsterhuntfreak2011 ปีที่แล้ว

    thank you so much for this :)

  • @ericespino7361
    @ericespino7361 2 ปีที่แล้ว

    Great video. Can't accss the link, it asks for user/password.

    • @considerednormal
      @considerednormal  2 ปีที่แล้ว

      Sorry about that, try again, it should be fixed.

  • @bokdcutie
    @bokdcutie 8 หลายเดือนก่อน

    Will windows 11 work ?

    • @considerednormal
      @considerednormal  8 หลายเดือนก่อน

      It should. I did not test it personally, but it should work much the same way in regards to joining the domain. But I cannot speak on the part of controlling the policies and such with windows tools as I did not investigate what tools are available for Win11

  • @medaey
    @medaey ปีที่แล้ว

    Greating

  • @rajulinux-9587
    @rajulinux-9587 2 หลายเดือนก่อน

    Support ubuntu 24.04