AskOverflow.Dev

AskOverflow.Dev Logo AskOverflow.Dev Logo

AskOverflow.Dev Navigation

  • Início
  • system&network
  • Ubuntu
  • Unix
  • DBA
  • Computer
  • Coding
  • LangChain

Mobile menu

Close
  • Início
  • system&network
    • Recentes
    • Highest score
    • tags
  • Ubuntu
    • Recentes
    • Highest score
    • tags
  • Unix
    • Recentes
    • tags
  • DBA
    • Recentes
    • tags
  • Computer
    • Recentes
    • tags
  • Coding
    • Recentes
    • tags
Início / server / Perguntas / 770007
Accepted
Łukasz
Łukasz
Asked: 2016-04-14 03:33:42 +0800 CST2016-04-14 03:33:42 +0800 CST 2016-04-14 03:33:42 +0800 CST

samba classicatualização de samba3 para samba4

  • 772

Estou muito confuso com a atualização do samba do samba 3.5 (debian squezze) para o samba 4.1 (ubuntu 14.04 lts) O que acabei agora? tudo da wiki oficial do samba:

[ https://wiki.samba.org/index.php/Migrating_a_Samba_NT4_domain_to_a_Samba_AD_domain_%28classic_upgrade%29]

Meu cenário é fazer backup do samba 3 existente na máquina antiga, transferir arquivos para a nova máquina e fazer a atualização clássica deste arquivo. Não consigo fazer a atualização clássica na máquina antiga porque está no site de produção e não pode estar indisponível.

Agora, na nova máquina, estou trabalhando com o ldap aberto com o banco de dados importado da máquina antiga e também tenho os arquivos smb.conf e /var/lib/samba/* da máquina antiga. Verifiquei o ldap em busca de nomes duplicados de usuários e grupos.

Para fazer classicupgrade eu executo o comando:

samba-tool domain classicupgrade --dbdir=/dir/with/files/from/old/machine/var/lib/samba/ --use-xattrs=yes \ 
--realm=office.mycompany.com --dns-backend=SAMBA_INTERNAL /patch/to/samba3/smb.conf

e a saída desse comando é:

    eading smb.conf
    Provisioning
    Exporting account policy
    Exporting groups
    Exporting users
      Skipping wellknown rid=500 (for username=administrator)
    Next rid = 10003
    Exporting posix attributes
    Reading WINS database
    Looking up IPv4 addresses
    Looking up IPv6 addresses
    No IPv6 address will be assigned
    Setting up share.ldb
    Setting up secrets.ldb
    Setting up the registry
    Setting up the privileges database
    Setting up idmap db
    Setting up SAM db
    Setting up sam.ldb partitions and settings
    Setting up sam.ldb rootDSE
    Pre-loading the Samba 4 and AD schema
    Adding DomainDN: DC=office,DC=mycompany,DC=com
    Adding configuration container
    Setting up sam.ldb schema
    Setting up sam.ldb configuration data
    Setting up display specifiers
    Modifying display specifiers
    Adding users container
    Modifying users container
    Adding computers container
    Modifying computers container
    Setting up sam.ldb data
    Setting up well known security principals
    Setting up sam.ldb users and groups
    Setting up self join
    Setting acl on sysvol skipped
    Adding DNS accounts
    Creating CN=MicrosoftDNS,CN=System,DC=office,DC=mycompany,DC=com
    Creating DomainDnsZones and ForestDnsZones partitions
    Populating DomainDnsZones and ForestDnsZones partitions
    Setting up sam.ldb rootDSE marking as synchronized
    Fixing provision GUIDs
    A Kerberos configuration suitable for Samba 4 has been generated at /var/lib/samba/private/krb5.conf
    Setting up fake yp server settings
    Once the above files are installed, your Samba4 server will be ready to use
    Admin password:        ..........................
    Server Role:           active directory domain controller
    Hostname:              DC1
    NetBIOS Domain:        mycompany
    DNS Domain:            office.mycompany.com
    DOMAIN SID:            S-1-5-21-2669135327-1831268680-3250772662
    Importing WINS database
    Importing Account policy
    Importing idmap database
    Adding groups
    Importing groups
    Group already exists sid=S-1-5-21-2669135327-1831268680-3250772662-513, groupname=Domain Users existing_groupname=Domain Users, Ignoring.
    Group already exists sid=S-1-5-21-2669135327-1831268680-3250772662-514, groupname=Domain Guests existing_groupname=Domain Guests, Ignoring.
    Group already exists sid=S-1-5-21-2669135327-1831268680-3250772662-515, groupname=Domain Computers existing_groupname=Domain Computers, Ignoring.
    Commiting 'add groups' transaction to disk
    Adding users
    Importing users
    Commiting 'add users' transaction to disk
    Adding users to groups
   Commiting 'add users to groups' transaction to disk
    idmapping sid_to_xid failed for id[0]=S-1-5-32-549: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-549: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-18: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-18: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-11: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-11: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-544: NT_STATUS_NONE_MAPPED
    enum_group_memberships failed for S-1-5-21-2669135327-1831268680-3250772662-500: NT_STATUS_NONE_MAPPED
    Fall back to unix uid lookup
    idmap range not specified for domain '*'
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    account_policy_get: tdb_fetch_uint32 failed for type 1 (min password length), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 2 (password history), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 3 (user must logon to change password), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 4 (maximum password age), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 5 (minimum password age), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 6 (lockout duration), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 7 (reset count minutes), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 8 (bad lockout attempt), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 9 (disconnect time), returning 0
    account_policy_get: tdb_fetch_uint32 failed for type 10 (refuse machine password change), returning 0
    idmapping sid_to_xid failed for id[0]=S-1-5-32-544: NT_STATUS_NONE_MAPPED
    enum_group_memberships failed for S-1-5-21-2669135327-1831268680-3250772662-500: NT_STATUS_NONE_MAPPED
    Fall back to unix uid lookup
    idmap range not specified for domain '*'
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-549: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-549: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-18: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-18: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-11: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-11: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-544: NT_STATUS_NONE_MAPPED
    enum_group_memberships failed for S-1-5-21-2669135327-1831268680-3250772662-500: NT_STATUS_NONE_MAPPED
    Fall back to unix uid lookup
    idmap range not specified for domain '*'
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
Fall back to unix uid lookup
idmap range not specified for domain '*'
idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[0]=S-1-5-32-544: NT_STATUS_NONE_MAPPED
enum_group_memberships failed for S-1-5-21-2669135327-1831268680-3250772662-500: NT_STATUS_NONE_MAPPED
    Fall back to unix uid lookup
    idmap range not specified for domain '*'
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
    idmapping sid_to_xid failed for id[0]=S-1-5-21-2669135327-1831268680-3250772662-512: NT_STATUS_NONE_MAPPED
    ERROR(<class 'passdb.error'>): uncaught exception - Unable to get id for sid
      File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line 175, in _run
        return self.run(*args, **kwargs)
      File "/usr/lib/python2.7/dist-packages/samba/netcmd/domain.py", line 1318, in run
        useeadb=eadb, dns_backend=dns_backend, use_ntvfs=use_ntvfs)
      File "/usr/lib/python2.7/dist-packages/samba/upgrade.py", line 983, in upgrade_from_samba3
        result.names.domaindn, result.lp, use_ntvfs)
      File "/usr/lib/python2.7/dist-packages/samba/provision/__init__.py", line 1581, in setsysvolacl
        set_gpos_acl(sysvol, dnsdomain, domainsid, domaindn, samdb, lp, use_ntvfs, passdb=s4_passdb)
      File "/usr/lib/python2.7/dist-packages/samba/provision/__init__.py", line 1511, in set_gpos_acl
        passdb=passdb)
      File "/usr/lib/python2.7/dist-packages/samba/provision/__init__.py", line 1474, in set_dir_acl
        setntacl(lp, path, acl, domsid, use_ntvfs=use_ntvfs, skip_invalid_chown=True, passdb=passdb, service=service)
      File "/usr/lib/python2.7/dist-packages/samba/ntacls.py", line 104, in setntacl
        (owner_id, owner_type) = passdb.sid_to_id(sd.owner_sid)

Depois disso, a ferramenta samba pode listar usuários e grupos, mas não pode adicionar computadores e comandar

samba-tool ntacl sysvolreset

sair com erro:

ERROR(<class 'passdb.error'>): uncaught exception - Unable to get id for sid
  File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line 175, in _run
    return self.run(*args, **kwargs)
  File "/usr/lib/python2.7/dist-packages/samba/netcmd/ntacl.py", line 208, in run
    (BA_gid,BA_type) = s4_passdb.sid_to_id(BA_sid)

Alguém pode me ajudar a entender o que estou fazendo de errado ou o que fechei para fazer mais?

Quando estou tentando fazer login como alguém para compartilhar a rede nos logs do samba4, tenho isto:

idmapping sid_to_xid failed for id[2]=S-1-5-21-2669135327-1831268680-3250772662-520: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[3]=S-1-5-21-2669135327-1831268680-3250772662-572: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[4]=S-1-5-21-2669135327-1831268680-3250772662-519: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[5]=S-1-5-21-2669135327-1831268680-3250772662-518: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[7]=S-1-1-0: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[8]=S-1-5-2: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[9]=S-1-5-11: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[10]=S-1-5-32-544: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[11]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[12]=S-1-5-32-554: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[6]=S-1-1-0: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[7]=S-1-5-2: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[8]=S-1-5-11: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[9]=S-1-5-32-545: NT_STATUS_NONE_MAPPED
idmapping sid_to_xid failed for id[10]=S-1-5-32-554: NT_STATUS_NONE_MAPPED

Acho que é algo com mapeamentos de grupos, mas não sei como consertar isso. Existe a possibilidade de editar alguns arquivos samba3 ou ldap, mesmo manualmente para corrigir esse problema?

Cumprimentos

samba upgrade samba4
  • 1 1 respostas
  • 2846 Views

1 respostas

  • Voted
  1. Best Answer
    Łukasz
    2016-04-19T10:18:44+08:002016-04-19T10:18:44+08:00

    Ok, entendi, não devo copiar todos os arquivos de /var/lib/samba do servidor antigo, mas apenas estes arquivos:

    # secrets.tdb
    # schannel_store.tdb
    # passdb.tdb
    # group_mapping.tdb
    # account_policy.tdb
    # smb.conf
    

    e use apenas este arquivo para o procedimento clássico de atualização.

    • 1

relate perguntas

Sidebar

Stats

  • Perguntas 205573
  • respostas 270741
  • best respostas 135370
  • utilizador 68524
  • Highest score
  • respostas
  • Marko Smith

    Você pode passar usuário/passar para autenticação básica HTTP em parâmetros de URL?

    • 5 respostas
  • Marko Smith

    Ping uma porta específica

    • 18 respostas
  • Marko Smith

    Verifique se a porta está aberta ou fechada em um servidor Linux?

    • 7 respostas
  • Marko Smith

    Como automatizar o login SSH com senha?

    • 10 respostas
  • Marko Smith

    Como posso dizer ao Git para Windows onde encontrar minha chave RSA privada?

    • 30 respostas
  • Marko Smith

    Qual é o nome de usuário/senha de superusuário padrão para postgres após uma nova instalação?

    • 5 respostas
  • Marko Smith

    Qual porta o SFTP usa?

    • 6 respostas
  • Marko Smith

    Linha de comando para listar usuários em um grupo do Windows Active Directory?

    • 9 respostas
  • Marko Smith

    O que é um arquivo Pem e como ele difere de outros formatos de arquivo de chave gerada pelo OpenSSL?

    • 3 respostas
  • Marko Smith

    Como determinar se uma variável bash está vazia?

    • 15 respostas
  • Martin Hope
    Davie Ping uma porta específica 2009-10-09 01:57:50 +0800 CST
  • Martin Hope
    kernel O scp pode copiar diretórios recursivamente? 2011-04-29 20:24:45 +0800 CST
  • Martin Hope
    Robert ssh retorna "Proprietário incorreto ou permissões em ~/.ssh/config" 2011-03-30 10:15:48 +0800 CST
  • Martin Hope
    Eonil Como automatizar o login SSH com senha? 2011-03-02 03:07:12 +0800 CST
  • Martin Hope
    gunwin Como lidar com um servidor comprometido? 2011-01-03 13:31:27 +0800 CST
  • Martin Hope
    Tom Feiner Como posso classificar a saída du -h por tamanho 2009-02-26 05:42:42 +0800 CST
  • Martin Hope
    Noah Goodrich O que é um arquivo Pem e como ele difere de outros formatos de arquivo de chave gerada pelo OpenSSL? 2009-05-19 18:24:42 +0800 CST
  • Martin Hope
    Brent Como determinar se uma variável bash está vazia? 2009-05-13 09:54:48 +0800 CST

Hot tag

linux nginx windows networking ubuntu domain-name-system amazon-web-services active-directory apache-2.4 ssh

Explore

  • Início
  • Perguntas
    • Recentes
    • Highest score
  • tag
  • help

Footer

AskOverflow.Dev

About Us

  • About Us
  • Contact Us

Legal Stuff

  • Privacy Policy

Language

  • Pt
  • Server
  • Unix

© 2023 AskOverflow.DEV All Rights Reserve