Linuxã§ç¨¼åããã¦ããApacheã«ã¦èªè¨¼ãå¿ è¦ãªWebãµã¼ãã¹ã«ãWindowsãã¡ã¤ã³(Active Directory)ã®èªè¨¼æ å ±ã使ã£ã¦ãã·ã³ã°ã«ãµã¤ã³ãªã³ãå®ç¾ãããã¾ã§ã®æé ãåå¿é²ã¨ãã¦æ®ãã¦ããã¾ãã
ä»åããã©ã¦ã¶ã¯ãIEã¨Firefoxã«ã¦åä½ç¢ºèªãè¡ãã¾ããã
Windowsãã¡ã¤ã³ãã°ãªã³ããã¦ããã¯ã©ã¤ã¢ã³ããããä¸è¨2種é¡ã®ãã©ã¦ã¶ã使ãã¨ãNTLMèªè¨¼â»ãå©ç¨ãã¦ããWebãµã¼ãã¹ã«ã¯ãèªè¨¼æ¸ã¿ã®ãã¡ã¤ã³ãã°ãªã³ã®æ å ±ãå©ç¨ãããã¨ãã§ããã¦ã¼ã¶åããã¹ã¯ã¼ããå ¥åããå¿ è¦ã®ç¡ãã·ã³ã°ã«ãµã¤ã³ãªã³ç°å¢ãå®ç¾ã§ãã¾ãã
â»NTLM認証(NT LAN Manager authentication)とは - IT用語辞典 e-Words
åæ
ä»åå©ç¨ããæ§æã¯ä»¥ä¸ã®ãããªæãã
- Webãµã¼ã
- CentOS 5
- Apache 2.2 + mod_auth_ntlm_winbind
- Winbind(Samba)
- (以ä¸ãä»åã®ä¾ã§ã¯ãweb.hoge.co.jp)
- çµ±åWindowsãã¡ã¤ã³ãµã¼ã(ãã¡ã¤ã³ã³ã³ããã¼ã©)
- Windows Server 2003
- (以ä¸ãä»åã®ä¾ã§ã¯ãdomain.hoge.co.jp)
- ã¯ã©ã¤ã¢ã³ã
- Windows XP + IE8/IE6/Firefox3
Webãµã¼ãã¯ãä»åCentOS 5ã使ã£ãåæã§æ¸ãã¦ãã¾ãããä»ã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ã§ããèªã¿æ¿ãã¦ããããã°åé¡ãªãã¯ãã§ãã
å°ãèªè¨¼ã®æµãã¨ãã¦ã¯ãä¸å³ã®éãã§ããã
ãã©ã¦ã¶ --> Apache(mod_auth_ntlm_winbind) --> winbindd --> ãã¡ã¤ã³ã³ã³ããã¼ã©
ã¨ãªãã¾ãã
Winbind(Samba)ã®è¨å®
ã¾ããSambaãåããã¦ãWebãµã¼ãããã¡ã¤ã³ã«åå ãããã¨ããã¾ã§ã
# yum install samba
ã¾ããSambaãã¤ã³ã¹ãã¼ã«ãã¾ãã
/etc/samba/smb.conf
Sambaã®è¨å®ãã¡ã¤ã«ãç·¨éã
# vi /etc/samba/smb.conf
[global] security = ads workgroup = DOMAIN realm = DOMAIN.HOGE.CO.JP password server = domain.hoge.co.jp encrypt passwords = true idmap uid = 10000-20000 idmap gid = 10000-20000 winbind use default domain = yes
ä»åãè¨å®ãã¡ã¤ã«(smb.conf)ã«ã¯ãä¸è¨æ²è¼åã®ã¿ãè¨è¿°ãã¾ããã
ã¡ãªã¿ã«ããã¡ã¤ã³åã¯ä»®ã«"DOMAIN"ã¨ãã¦ãã¾ãã
realmã¯FQDNãæå®ãpassword serverã¯ãIPã¢ãã¬ã¹ã§ãOKã¿ããã§ãã
/etc/nsswitch.conf
次ã«ãnsswitch.confãç·¨éã
# vi /etc/nsswitch.conf
passwd: files winbind shadow: files winbind group: files winbind
passwdãshadowãgroupã®é
ç®ãä¸è¨ã®ããã«æ¸ãæãã¾ãã
/etc/krb5.conf
次ã«ãkrb5.confãç·¨éã
# vi /etc/krb5.conf
[logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] default_realm = DOMAIN.HOGE.CO.JP dns_lookup_realm = false dns_lookup_kdc = false ticket_lifetime = 24h forwardable = yes [realms] DOMAIN.HOGE.CO.JP = { kdc = domain.hoge.co.jp admin_server = domain.hoge.co.jp default_domain = domain.hoge.co.jp } [domain_realm] .domain.hoge.co.jp = DOMAIN.HOGE.CO.JP domain.hoge.co.jp = DOMAIN.HOGE.CO.JP [appdefaults] pam = { debug = false ticket_lifetime = 36000 renew_lifetime = 36000 forwardable = true krb4_convert = false }
ä»åã¯ãkrb5.confã¯ä¸è¨ã®è¨è¿°ã®ã¿ã¨ãã¾ããã
主ã«ããã¡ã¤ã³ããã¡ã¤ã³ã³ã³ããã¼ã©ã®ãµã¼ãã«é¢ããè¨è¿°ãæ¸ãæãã¾ãã
/etc/hosts
次ã«ã/etc/hostsãç·¨éã
xxx.xxx.xxx.xxx web.hoge.co.jp web
hostsã«ãä¸è¨ã®ãããªæãã§ãWebãµã¼ã(Sambaã稼åãã¦ãããµã¼ã)ã®IPã¢ãã¬ã¹ã¨ãã¹ãå(FQDNããããã¦)ãè¨è¿°ãã¾ãã
â»ãããè¨è¼ãã¦ãããªãã¨ãå¾è¿°ã®ããã¡ã¤ã³ã¸ã®åå ããã¾ããããªãã£ãã
/etc/resolv.conf
æå¾ã«ã/etc/resolv.confãç·¨éã
search domain.hoge.co.jp nameserver xxx.xxx.xxx.xxx
DNSã¨ãã¦ããã¡ã¤ã³ã³ã³ããã¼ã©ãåç
§ããããã«è¨å®ãã¾ãã
ããããã¡ã¤ã³ã³ã³ããã¼ã©ããDHCPã§åå¾ãã¦ããå ´åã¯ããããããã®é¨åã¯æ¸ãæããå¿
è¦ãç¡ããã¨æãã¾ãã
ãã¡ã¤ã³ã«åå ãã
ããã¾ã§æºåã§ããããWebãµã¼ã(Samba稼å)ãWindowsãã¡ã¤ã³ã«åå ããã¾ãã
# /etc/init.d/winbind start
ã¾ãwinbinddãèµ·åãã¾ãã
# net ads join -U username username's password: Using short domain name -- DOMAIN Joined 'WEB' to realm 'DOMAIN.HOGE.CO.JP'
ä¸è¨ã³ãã³ããå®è¡ãã"Joined"ã¨è¡¨ç¤ºãããã¨ãWebãµã¼ã(Samba稼å)ã®ãã¡ã¤ã³ã¸ã®åå ãå®äºã§ãã
å°ãusernameã®é¨åã«ãã¡ã¤ã³ã«åå ãã¦ããã¦ã¼ã¶å(ID)ãå
¥ããããã«ãã¦ãã ããã
[注æç¹] ãã¡ã¤ã³åå ã«å¤±æ(ã¨ã©ã¼)ããå ´åã»ã»ã»
ã¡ãªã¿ã«ãããã§å ã»ã©æ¸ãè¨ããã/etc/hostsã®è¨å®ãä¸æããã£ã¦ããªãã¨ã
# net ads join -U username username's password: Using short domain name -- DOMAIN Failed to set servicePrincipalNames. Please ensure that the DNS domain of this server matches the AD domain, Or rejoin with using Domain Admin credentials. Deleted account for 'WEB' in realm 'DOMAIN.HOGE.CO.JP'
ãããªæãã§"Failed"ã¨è¡¨ç¤ºããããã¡ã¤ã³ã¸ã®åå ã«å¤±æãã¾ãã
/etc/hostsã«èªåèªèº«ã¨ãªãWebãµã¼ã(Samba稼å)ã®ãã¹ãåãè¨è¼ããã¦ãããã確èªãã¦ãã ããã
ãã1ã¤æ³¨æç¹ã
# net ads join -U username Host is not configured as a member server. Invalid configuration. Exiting.... Failed to join domain: Invalid domain role
ãããªæãã§"Failed"ã¨ãªãå ´åã¯ã
smb.confã®securityã®é
ç®ã"ads"ã¨ãªã£ã¦ããã確èªãã¦ãã ããã
"security = ads"
ãã¡ã¤ã³ã«åå ã§ãããã»ã»ã»
以ä¸ã®ãããªã³ãã³ããã¡(ä¸ä¾)ãå®è¡ãããã¨ã§ãåå ç¶æ³ã確èªã§ãã¾ãã
# net ads info LDAP server: xxx.xxx.xxx.xxx LDAP server name: domain.hoge.co.jp Realm: DOMAIN.HOGE.CO.JP Bind Path: dc=DOMAIN,dc=HOGE,dc=CO,dc=JP LDAP port: 389 Server time: ç«, 17 3æ 2009 21:57:27 JST KDC server: xxx.xxx.xxx.xxx Server time offset: 0
# net ads testjoin Join is OK
# ntlm_auth --username=DOMAIN\\username password: NT_STATUS_OK: Success (0x0)
Apacheã®è¨å®
ã¾ããApacheã®ã¤ã³ã¹ãã¼ã«ãè¡ãã¾ãã
Apacheã®ã¤ã³ã¹ãã¼ã«
ç§ã¯ææ°çã使ãããã£ãã®ã§ãã½ã¼ã¹ããã³ã³ãã¤ã«ãè¡ãã¤ã³ã¹ãã¼ã«ãè¡ãã¾ããã
以ä¸ããã®åæã§æ¸ãã¦ããã¾ãã
# yum install gcc
ã¾ããã³ã³ãã¤ã«ãè¡ãããã«gccãã¤ã³ã¹ãã¼ã«ã(ããã¯å
¥ã£ã¦ããå ´åãå¤ãã¨æãã)
# wget http://ftp.riken.jp/net/apache/httpd/httpd-2.2.11.tar.gz # tar zxvf httpd-2.2.11.tar.gz # cd httpd-2.2.11 # ./configure # make # make install # cd ..
ãç´æã§ãããâã®ãããªæµãã§ã¤ã³ã¹ãã¼ã«ã¯å®äºã
ããã©ã«ãã§ã¯ã/usr/local/apache2ã¸ã¤ã³ã¹ãã¼ã«ããã¾ãã
ã¡ãªã¿ã«Apacheãyumã§ã¤ã³ã¹ãã¼ã«ããã¨ã»ã»ã»
yumã³ãã³ãä¸çºã§æ¸ã¿ã¾ãã
# yum install httpd httpd-devel
ãã¼ã¸ã§ã³ã«ãã ãããç¡ãå ´åã¯ããã¡ãã§ãè¯ãã§ãããã
â»ãã®å ´åãã¤ã³ã¹ãã¼ã«å ´æãã½ã¼ã¹ããã¤ã³ã¹ãã¼ã«ããå ´åã¨ç°ãªãã¾ãã®ã§ã以éããã£ã¬ã¯ããªãã¹ãªã©ãèªã¿æ¿ããããã«ãã¦ãã ããã
mod_auth_ntlm_winbindã®ã¤ã³ã¹ãã¼ã«
mod_auth_ntlm_winbindã¯ãSubversionãªãã¸ããªã¨gitãªãã¸ããªã§ç®¡çããã¦ãã¾ãã
gitãªãã¸ããªã«ã¯ãconfigure.inãå«ã¾ãã¦ãã¾ããã§ããã®ã§ãä»åã¯Subversionãªãã¸ããªããåå¾ããããã«ãã¾ãã
yum install subversion autoconf
ã¨ãããã¨ã§ãã¾ããSubversionã¨ãconfigureã®çæãè¡ãããã®autoconfãyumã§ã¤ã³ã¹ãã¼ã«ãã¾ãã
# svn co svn://svnanon.samba.org/lorikeet/trunk/mod_auth_ntlm_winbind mod_auth_ntlm_winbind
ã§ãmod_auth_ntlm_winbindã®ã½ã¼ã¹ä¸å¼ãsvnã³ãã³ãã§åå¾ãã¾ãã
# cd mod_auth_ntlm_winbind # autoconf # ./configure --with-apxs=/usr/local/apache2/bin/apxs --with-apache=/usr/local/apache2/bin/httpd # make # make install # cd ..
ãã¨ã¯ãâã®ããã«ã決ã¾ãã®ãã¿ã¼ã³ã§ãã
ãããªæãã§ã
Apacheã§èªè¨¼é¢é£ã®è¨å®
試ãã«ãããã¥ã¡ã³ãã«ã¼ã以ä¸ã®"/ntlm_auth/"ã¨ããURLã«èªè¨¼ãããããã¨ã«ãã¾ãã
ãã®å ´åã®httpd.confã®è¨å®ä¾ã¯ã以ä¸ã¨ãªãã¾ãã
# vi /usr/local/apache2/conf/httpd.conf
KeepAlive On LoadModule auth_ntlm_winbind_module modules/mod_auth_ntlm_winbind.so Alias /ntlm_auth/ "/usr/local/apache2/htdocs/ntlm_auth/" <Directory "/usr/local/apache2/htdocs/ntlm_auth/"> NTLMAuth on AuthType NTLM AuthName "NTLM Authentication" NTLMAuthHelper "/usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp" NTLMBasicAuthoritative on require valid-user </Directory>
ä¸è¨ã追è¨ããæãã§ãè¨å®ã«è¨è¼ãã¦ãã ããã
ã¾ããLoadModuleã¯å½ç¶ã®ãã¨ãªããã"KeepAlive On"ã¯NTLMèªè¨¼ã«å¿
é ã§ãã
/usr/local/apache2/htdocs/ntlm_auth/ 以ä¸ã«è©¦ãã«index.htmlãé
ç½®ããèªè¨¼ãæåãããindex.htmlã表示ãããããã«ãã¾ãã
æå¾ã«ã以ä¸ã®chgrpã³ãã³ããå®è¡ããwinbindd_privilegedãã£ã¬ã¯ããªã«Apache(mod_auth_ntlm_winbind)ã®ããã»ã¹ã®ã¦ã¼ã¶ãã¢ã¯ã»ã¹ã§ããããã«ã¢ã¯ã»ã¹æ¨©ãè¨å®ãã¾ãã
# chgrp daemon /var/cache/samba/winbindd_privileged
ä¸è¨ã®"daemon"ã®é¨åã¯ãApacheããã»ã¹ã®ã¦ã¼ã¶åã«æ¸ãæãã¦ãã ããã
ã¡ãªã¿ã«ãã½ã¼ã¹ããã³ã³ãã¤ã«ããã¨ãã¯ã"daemon"ã"nobody"ãyumã§ã¤ã³ã¹ãã¼ã«ããã¨ãã¯"apache"ã ã£ãæ°ããã¾ãã
ãããã«ãããhttpd.confã«è¨è¼ããã¦ãã¾ãã®ã§ã確èªãã¦ãã ããã
Apacheãèµ·å
è¨å®ãå®äºããããæå¾ã«Apacheãèµ·åãã¾ãã
/usr/local/apache2/bin/apachectl start
ããã§ãè¨å®ã¯å®äºã§ãã
å°ãyumã§ã¤ã³ã¹ãã¼ã«ããå ´åã¯ã
# /etc/init.d/httpd start
ã§ãApacheãèµ·åãããã¨ãå¯è½ã§ãã
ãã©ã¦ã¶ããã¢ã¯ã»ã¹ï¼
æ©éããã©ã¦ã¶ãããã¢ã¯ã»ã¹ãã¦ã¿ã¾ãããã
http://web/ntlm_auth/
è¨å®ãåé¡ãªãè¡ãããå ´åã¯ããã¡ã¤ã³ãã°ãªã³ããã¯ã©ã¤ã¢ã³ãããã¢ã¯ã»ã¹ããéã¯ãã¦ã¼ã¶ã¼èªè¨¼ã®ãã¤ã¢ãã°ã表示ããããã¨ãªãèªè¨¼ã«æåããWebãµã¼ãã¹ã®ç»é¢ã表示ããã¾ãã
ã¡ãªã¿ã«ããã¡ã¤ã³ãã°ãªã³ãã¦ããªãã¯ã©ã¤ã¢ã³ãããã¢ã¯ã»ã¹ããéã¯ãã¦ã¼ã¶ã¼èªè¨¼ã®ãã¤ã¢ãã°ã表示ããã¾ãã®ã§ãã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããå ¥åããèªè¨¼ãæåããã¨Webãµã¼ãã¹ã®ç»é¢ã表示ããã¾ãã
å°ãFQDNå½¢å¼ã®ã
http://web.hoge.co.jp/ntlm_auth/
ã§ãä¸æããã°ã¤ã³ã§ããªãå ´åããã©ã¦ã¶ã®ã»ãã¥ãªãã£è¨å®ãè¦ç´ãå¿
è¦ãããã¾ãã
FQDNå½¢å¼ã§ãã¨ããã©ã¦ã¶ãã¤ã³ãã©ãããã§ã¯ãªãã¤ã³ã¿ã¼ãããã¸ã®ã¢ã¯ã»ã¹ã¨èªèãã¾ãã®ã§ãé常ã®ã»ãã¥ãªãã£è¨å®ã ã¨ãèªåã§ãã°ã¤ã³ã¯ã§ããªãå¯è½æ§ãé«ãã§ãã
ãã®å ´åã¯ãIEã ã¨ã¤ã³ã¿ã¼ããããªãã·ã§ã³ã®ã»ãã¥ãªãã£ã¿ãã«ããã"ä¿¡é ¼æ¸ã¿ãµã¤ã"ã«åå¥ã«ç»é²ããããã«ãã¾ãããã
ä¸å³ã®ã"ã¤ã³ã¿ã¼ããã"ã®ã¬ãã«ã®ã«ã¹ã¿ãã¤ãºã«ãã"ã¦ã¼ã¶èªè¨¼"ã®è¨å®ãå¤ãã¦ã対å¿ã¯åºæ¥ã¾ãããã»ãã¥ãªãã£ä¸æ¨å¥¨ãã¾ããã
FirefoxããNTLMèªè¨¼
ãã©ã¦ã¶ãFirefoxã®å ´åã¯ãå°ãè¨å®ãå¿ è¦ã§ãã
ã¾ãããã©ã¦ã¶ã®URLãå ¥åããæ¬ã«"about:config"ã¨å ¥åãã¾ãã
ã§ãè¨å®å"network.automatic-ntlm-auth.trusted-uris"ã®å¤ã®é¨åã«ãNTLMèªè¨¼ã許å¯ãããã¡ã¤ã³åãå
¥åãã¾ããè¤æ°ããã¨ãã¯ã«ã³ãåºåãã¨ãã¾ãã
追è¨ï¼NTLMèªè¨¼ã«å¤±æããå ´å
ããã¤ãééãã対å¦ãã¦ããã®ã§ãä¸æããããªãå ´åã¯åèã«ãªãããããã¾ããã
NTLMèªè¨¼ããã¾ãåããªãã¨ã
ä¸è¨ã§æ¸ããã¨ããã«æ§ç¯ãããããã¾ãèªè¨¼ãããªãã¨ãããã
NTLMã§èªè¨¼ãã¦ãã形跡ãç¡ãå ´åãã²ãã£ã¨ãããããã¡ã¤ã³ã«ã¸ã§ã¤ã³(Join)ãå¿ãã¦ããå¯è½æ§ãããã¾ãã
ã§ãããã«ä¼´ãWinbinddã®èµ·åã«å¤±æãã¦ããå¯è½æ§ãããã¾ãããã®æã¯âã®ãããªãã°ãåºãã
[2009/06/25 20:21:53, 0] nsswitch/winbindd_cache.c:initialize_winbindd_cache(2229) initialize_winbindd_cache: clearing cache and re-creating with version number 1 [2009/06/25 20:21:53, 0] nsswitch/winbindd_util.c:init_domain_list(506) Could not fetch our SID - did we join? [2009/06/25 20:21:53, 0] nsswitch/winbindd.c:main(1114) unable to initalize domain list [2009/06/25 20:21:54, 1] nsswitch/winbindd.c:main(1013) winbindd version 3.0.33-3.7.el5 started. Copyright Andrew Tridgell and the Samba Team 1992-2008 [2009/06/25 20:21:54, 0] nsswitch/winbindd_cache.c:initialize_winbindd_cache(2229) initialize_winbindd_cache: clearing cache and re-creating with version number 1 [2009/06/25 20:21:54, 0] nsswitch/winbindd_util.c:init_domain_list(506) Could not fetch our SID - did we join? [2009/06/25 20:21:54, 0] nsswitch/winbindd.c:main(1114) unable to initalize domain list
ãã®å¾å度ããã¡ã¤ã³ã«åå ããå度winbinddãèµ·åãããã¨ã§ãèªè¨¼ã¯ä¸æãããã«ãªãåãã¯ãã
NTLMèªè¨¼å®ç¾ã«åãã¦ã®winbindã¨ã®æ ¼éãã®1
Apache + mod_auth_ntlm_winbindãªç°å¢ã§ãNTLMèªè¨¼ãå®ç¾ããã¨ãã®è©±ã
NTLMèªè¨¼ã«ãªãããApacheã®ã¨ã©ã¼ãã°ã«ã¯ã以ä¸ã®ããã«åºåããã¦ããå ´åã
[Wed Jul 01 17:41:16 2009] [notice] child pid 18372 exit signal Segmentation fault (11) [2009/07/01 17:41:16, 0] utils/ntlm_auth.c:winbind_pw_check(515) Login for user [hoge]\[foo]@[bar] failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/cache/samba/winbindd_privileged are set correctly.] [2009/07/01 17:41:16, 0] utils/ntlm_auth.c:manage_squid_ntlmssp_request(776) NTLMSSP BH: NT_STATUS_ACCESS_DENIED [Wed Jul 01 17:41:16 2009] [error] [client xxx.xxx.xxx.xxx] (20014)Internal error: ntlm_auth reports Broken Helper: BH NT_STATUS_ACCESS_DENIED, referer: http://your.domain.com/id/login
"/var/cache/samba/winbindd_privileged"以ä¸ã¸ã®ã¢ã¯ã»ã¹ãã
Apacheã®ããã»ã¹ããããåºæ¥ãªããªã£ã¦ããã®ãåå ã
ãã¼ããã·ã§ã³ãé©åã«è¨å®ããããâã®ãããªæãã§è¨å®ã
# chgrp apache /var/cache/samba/winbindd_privileged
# Apacheãã"apache"ã¦ã¼ã¶ã§ç¨¼åããã¦ããå ´å
NTLMèªè¨¼å®ç¾ã«åãã¦ã®winbindã¨ã®æ ¼éãã®2
Apache + mod_auth_ntlm_winbindãªç°å¢ã§ãNTLMèªè¨¼ãå®ç¾ããã¨ãã®è©±ã
ç¸å¤ããããNTLMèªè¨¼ã«ã¯ãªãããWinbindã®ã¨ã©ã¼ãã°ã«ã¯ã以ä¸ã®ããã«åºåããã¦ããå ´åã
ãã£ã¤ãã¯ã¾ã£ãã(ã°ã°ãã¦ãæ¥æ¬èªã®ãã¼ã¸åºã¦ããªãã^^;)
[2009/07/01 18:07:26, 0] utils/ntlm_auth.c:get_winbind_domain(146) could not obtain winbind domain name! [2009/07/01 18:07:26, 0] utils/ntlm_auth.c:get_winbind_netbios_name(172) could not obtain winbind netbios name!
ãã¨çç¶ã¨ãã¦ã¯ä»¥ä¸ã®ãããªã¨ã©ã¼ãã°ãåæ§ã ã£ãã
[2009/07/01 18:02:31, 0] lib/util_sock.c:create_pipe_sock(1280) invalid permissions on socket directory /var/cache/samba/winbindd_privileged open_winbind_socket: ãã®ãããªãã¡ã¤ã«ããã£ã¬ã¯ããªã¯ããã¾ãã
ãã®å ´åã以ä¸ã®ã³ãã³ããå®è¡ããã¨ãRPCã§ã®callã«å¤±æãã¦ããããããã¨ãããã¨ããããã
# wbinfo -t checking the trust secret via RPC calls failed error code was (0x0) Could not check secret
ããããAD(ActiveDiretory)ã¸ã®Joinã¯ã§ãã¦ããã
# net ads testjoin Join is OK
ã§ããã®æã"/var/cache/samba/winbindd_privileged"ã®ãã¼ããã·ã§ã³ãè¦ãã¨ä»¥ä¸ã®ãããªæãã ã£ãã
drwxr-x--- 2 apache apache 4096 7æ 2 11:03 winbindd_privileged
ããã以ä¸ã®ããã«ããªã¼ãã®ææ権ã®ã¿ã"root"ã«æ»ãã¦ããã¨ä¸æãåãå§ããã
drwxr-x--- 2 root apache 4096 7æ 2 11:03 winbindd_privileged
ãã®çµæã¯ãããªã解ããªãã¨ãããããã®ã ãã
winbindã®ãã§ãã¯æ©æ§ã§ä½ãããã£ã¦ããã®ãããããªããªã
# wbinfo -t checking the trust secret via RPC calls succeeded
ä¸æããåãå§ããã¨ãâã®ãããªçµæã¨ãªã£ãã
æå¾ã«
ã¡ãã£ã¨è¨å®ã¯é¢åã§ãããã·ã³ã°ã«ãµã¤ã³ãªã³ã¯é常ã«ä¾¿å©ãªä»çµã¿ã§ãã
ãã¡ã¤ã³ã³ã³ããã¼ã©ã稼åããã¤ã³ãã©ãããå
ã§ã®Webãµã¼ãã¹ã«å¯¾ãã¦ã¯ãå©ä¾¿æ§ã®é«ãä»çµã¿ã ã¨æãã¾ãã®ã§ã試ãã¦ã¿ãã®ãé¢ç½ãããããã¾ããã
åè
- NTLM Authentication Scheme for HTTP
- [Samba TIPS]WindowsドメインとApache Webサーバー間でのシングルサインオン実現手順 | 日経 xTECH(クロステック)
- Apacheで統合Windows認証を使う - daily dayflower

- ä½è : Ben Laurie,Peter Laurie,大å·ä½³ç¹,ç°è¾ºèä¹
- åºç社/ã¡ã¼ã«ã¼: ãªã©ã¤ãªã¼ã¸ã£ãã³
- çºå£²æ¥: 2003/09/01
- ã¡ãã£ã¢: åè¡æ¬
- ã¯ãªãã¯: 73å
- ãã®ååãå«ãããã° (40件) ãè¦ã

Apacheã¯ãã¯ãã㯠第2ç âWebãµã¼ã管çè ã®ããã®ã¬ã·ãé
- ä½è : Ken Coar,Rich Bowen,笹äºå´å¸
- åºç社/ã¡ã¼ã«ã¼: ãªã©ã¤ãªã¼ã¸ã£ãã³
- çºå£²æ¥: 2008/09/26
- ã¡ãã£ã¢: 大åæ¬
- è³¼å ¥: 6人 ã¯ãªãã¯: 144å
- ãã®ååãå«ãããã° (32件) ãè¦ã