0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

【検証メモ】Samba4 で AD DC を構築してみる

0
Last updated at Posted at 2026-10-01

■ 概要

Samba のバージョン 3 では Active Directory ドメインに「メンバーサーバー」としてドメイン参加することができます。
バージョン 4 ではなんと Active Directory の「ドメインコントローラー」になれるということで、検証してみました。

便宜上、Windows Server で提供するドメインコントローラーを「Microsoft AD DC」、Samba4 で提供するドメインコントローラーを「Samba4 AD DC」と呼称します。

[参考資料:Setting up Samba as an Active Directory Domain Controller - SambaWiki]
https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Active_Directory_Domain_Controller

■ 前提

OS:Ubuntu 24.04 x86_64 (AWS EC2 インスタンス)
Samba パッケージバージョン:2:4.19.5+dfsg-4ubuntu9.7

■ 作業ログ

細かい解説は抜きにして ( できない )、次同じ手順でやれば再現できそう、という感じでやったことの記録になります。ちょっと長いので雑なのは許してください。

パラメーター等

  • Samba4 サーバーのホスト名
    • samba-dc1
  • Samba4 サーバーのFQDN
    • samba-dc1.samba4.example.test
  • ドメイン名 (= Realm)
    • SAMBA4.EXAMPLE.TEST
  • NetBIOS 名
    • SAMBA4

検証用ユーザー・グループの名前

  • ドメインユーザー
    • 1-samba-user
  • ドメイングループ (セキュリティグループ)
    • 1-samba-group

手順

Samba4 サーバー側の作業 (AD DC のインストール、初期設定)

[1-1]

Samba4 サーバーのホスト名を samba-dc1 に設定する

# hostnamectl set-hostname samba-dc1
<出力無し>

# uname -n
samba-dc1

[1-2]

Samba4 サーバーの /etc/hosts ファイルに以下を設定する

<自身の IP アドレス> samba-dc1 samba-dc1.samba4.example.test

[1-3]

関連パッケージをインストールする

# apt install -y acl attr samba samba-dsdb-modules samba-vfs-modules winbind libpam-winbind libnss-winbind libpam-krb5 krb5-config krb5-user dnsutils chrony ldb-tools

[1-4]

上記実行するとインストールが開始され、以下の画面が表示されるので SAMBA4.EXAMPLE.TESTと入力する

※ 画面に表示された文言

Configuring Kerberos Authentication

When users attempt to use Kerberos and specify a principal or user name without specifying what administrative Kerberos realm that
principal belongs to, the system appends the default realm.  The default realm may also be used as the realm of a Kerberos service
running on the local machine.  Often, the default realm is the uppercase version of the local DNS domain.

Default Kerberos version 5 realm:

image.png

[1-5]

続いて、以下画面で samba-dc1.samba4.example.test と入力する

※ 画面に表示された文言

Configuring Kerberos Authentication

Enter the hostnames of Kerberos servers in the SAMBA4.EXAMPLE.TEST Kerberos realm separated by spaces.

Kerberos servers for your realm:

image.png

[1-6]

続いて、以下画面で samba-dc1.samba4.example.test と入力する

※ 画面に表示された文言

Configuring Kerberos Authentication

Enter the hostname of the administrative (password changing) server for the SAMBA4.EXAMPLE.TEST Kerberos realm.

Administrative server for your Kerberos realm:

image.png

[1-7]

Enter 押下して進めると、ターミナル上に以下が出力され (結構長い)、インストールが無事終了する

9 upgraded, 45 newly installed, 0 to remove and 169 not upgraded.
Need to get 22.9 MB of archives.
After this operation, 109 MB of additional disk space will be used.
Get:1 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble/main amd64 python3-dnspython all 2.6.1-1ubuntu1 [163 kB]
Get:2 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble/main amd64 libtalloc2 amd64 2.4.2-1build2 [27.3 kB]
Get:3 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble/main amd64 libtdb1 amd64 1.4.10-1build1 [46.8 kB]
...
(省略)
...
Get:52 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble-updates/main amd64 samba-ad-provision all 2:4.19.5+dfsg-4ubuntu9.7 [489 kB]
Get:53 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble-updates/main amd64 samba-dsdb-modules amd64 2:4.19.5+dfsg-4ubuntu9.7 [319 kB]
Get:54 http://ap-northeast-1.ec2.archive.ubuntu.com/ubuntu noble-updates/main amd64 samba-vfs-modules amd64 2:4.19.5+dfsg-4ubuntu9.7 [416 kB]
Fetched 22.9 MB in 2s (12.6 MB/s)
Extracting templates from packages: 100%
Preconfiguring packages ...
...
(省略)
...
update-alternatives: using /usr/bin/kadmin.mit to provide /usr/bin/kadmin (kadmin) in auto mode
update-alternatives: using /usr/bin/ktutil.mit to provide /usr/bin/ktutil (ktutil) in auto mode
Setting up libpam-winbind:amd64 (2:4.19.5+dfsg-4ubuntu9.7) ...
Processing triggers for ufw (0.36.2-6) ...
Processing triggers for man-db (2.12.0-4build2) ...
Processing triggers for libc-bin (2.39-0ubuntu8.7) ...
Scanning processes...
Scanning candidates...
Scanning linux images...

Running kernel seems to be up-to-date.

Restarting services...
 systemctl restart ssh.service

Service restarts being deferred:
 systemctl restart unattended-upgrades.service

No containers need to be restarted.

User sessions running outdated binaries:
 ubuntu @ session #2: sshd[2232]
 ubuntu @ session #6: sshd[2593]

No VM guests are running outdated hypervisor (qemu) binaries on this host.

[1-8]

samba サービスのステータスチェックをしてみる。まだ起動していない

# systemctl status samba
○ samba-ad-dc.service - Samba AD Daemon
     Loaded: loaded (/usr/lib/systemd/system/samba-ad-dc.service; enabled; preset: enabled)
     Active: inactive (dead) (Result: exec-condition) since Tue 2026-09-29 09:35:59 UTC; 40s ago
  Condition: start condition unmet at Tue 2026-09-29 09:35:59 UTC; 40s ago
       Docs: man:samba(8)
             man:samba(7)
             man:smb.conf(5)
        CPU: 27ms

Sep 29 09:35:59 samba-dc1 systemd[1]: Starting samba-ad-dc.service - Samba AD Daemon...
Sep 29 09:35:59 samba-dc1 systemd[1]: samba-ad-dc.service: Skipped due to 'exec-condition'.
Sep 29 09:35:59 samba-dc1 systemd[1]: Condition check resulted in samba-ad-dc.service - Samba AD Daemon being skipped.

[1-9]

smb / nmb / winbind サービスは起動していることを確認

# systemctl status smb nmb winbind
● smbd.service - Samba SMB Daemon
     Loaded: loaded (/usr/lib/systemd/system/smbd.service; enabled; preset: enabled)
     Active: active (running) since Tue 2026-09-29 09:35:58 UTC; 6min ago
       Docs: man:smbd(8)
             man:samba(7)
             man:smb.conf(5)
   Main PID: 3737 (smbd)
     Status: "smbd: ready to serve connections..."
      Tasks: 3 (limit: 1013)
     Memory: 10.2M (peak: 10.4M)
        CPU: 90ms
     CGroup: /system.slice/smbd.service
             tq3737 /usr/sbin/smbd --foreground --no-process-group
             tq3740 "smbd: notifyd" .
             mq3741 "smbd: cleanupd "

Sep 29 09:35:58 samba-dc1 systemd[1]: Starting smbd.service - Samba SMB Daemon...
Sep 29 09:35:58 samba-dc1 (smbd)[3737]: smbd.service: Referenced but unset environment variable evaluates to an empty string: SMBDOPTIONS
Sep 29 09:35:58 samba-dc1 systemd[1]: Started smbd.service - Samba SMB Daemon.

● nmbd.service - Samba NMB Daemon
     Loaded: loaded (/usr/lib/systemd/system/nmbd.service; enabled; preset: enabled)
     Active: active (running) since Tue 2026-09-29 09:35:59 UTC; 6min ago
       Docs: man:nmbd(8)
             man:samba(7)
             man:smb.conf(5)
   Main PID: 3801 (nmbd)
     Status: "nmbd: ready to serve connections..."
      Tasks: 1 (limit: 1013)
     Memory: 3.3M (peak: 3.7M)
        CPU: 102ms
     CGroup: /system.slice/nmbd.service
             mq3801 /usr/sbin/nmbd --foreground --no-process-group

Sep 29 09:35:59 samba-dc1 systemd[1]: Starting nmbd.service - Samba NMB Daemon...
Sep 29 09:35:59 samba-dc1 (nmbd)[3801]: nmbd.service: Referenced but unset environment variable evaluates to an empty string: NMBDOPTIONS
Sep 29 09:35:59 samba-dc1 systemd[1]: Started nmbd.service - Samba NMB Daemon.

● winbind.service - Samba Winbind Daemon
     Loaded: loaded (/usr/lib/systemd/system/winbind.service; enabled; preset: enabled)
     Active: active (running) since Tue 2026-09-29 09:36:01 UTC; 6min ago
       Docs: man:winbindd(8)
             man:samba(7)
             man:smb.conf(5)
    Process: 3986 ExecCondition=/usr/share/samba/is-configured winbind (code=exited, status=0/SUCCESS)
   Main PID: 3989 (winbindd)
     Status: "winbindd: ready to serve connections..."
      Tasks: 2 (limit: 1013)
     Memory: 4.9M (peak: 30.1M)
        CPU: 1.760s
     CGroup: /system.slice/winbind.service
             tq3989 /usr/sbin/winbindd --foreground --no-process-group
             mq3992 "winbindd: domain child [SAMBA-DC1]"

Sep 29 09:36:01 samba-dc1 systemd[1]: Starting winbind.service - Samba Winbind Daemon...
Sep 29 09:36:01 samba-dc1 (winbindd)[3989]: winbind.service: Referenced but unset environment variable evaluates to an empty string: WINBINDOPTIONS
Sep 29 09:36:01 samba-dc1 systemd[1]: Started winbind.service - Samba Winbind Daemon.

[1-10]

各サービスを停止する

# systemctl stop smb nmb winbind
<出力無し>

[1-11]

各サービスを disable する

# systemctl disable smb nmb winbind
Synchronizing state of winbind.service with SysV service script with /usr/lib/systemd/systemd-sysv-install.
Executing: /usr/lib/systemd/systemd-sysv-install disable winbind
Removed "/etc/systemd/system/multi-user.target.wants/smbd.service".
Removed "/etc/systemd/system/multi-user.target.wants/winbind.service".
Removed "/etc/systemd/system/multi-user.target.wants/nmbd.service".
Removed "/etc/systemd/system/smb.service".
Removed "/etc/systemd/system/nmb.service".

[1-12]

各サービスのステータス確認

  • smb / nmb は service ファイルのシンボリックリンクが削除されている
  • winbind は停止されている
# systemctl status smb nmb winbind
Unit smb.service could not be found.
Unit nmb.service could not be found.
○ winbind.service - Samba Winbind Daemon
     Loaded: loaded (/usr/lib/systemd/system/winbind.service; disabled; preset: enabled)
     Active: inactive (dead)
       Docs: man:winbindd(8)
             man:samba(7)
             man:smb.conf(5)

Sep 29 09:36:01 samba-dc1 systemd[1]: Starting winbind.service - Samba Winbind Daemon...
Sep 29 09:36:01 samba-dc1 (winbindd)[3989]: winbind.service: Referenced but unset environment variable evaluates to an empty string: WINBINDOPTIONS
Sep 29 09:36:01 samba-dc1 systemd[1]: Started winbind.service - Samba Winbind Daemon.
Sep 29 09:45:08 samba-dc1 systemd[1]: Stopping winbind.service - Samba Winbind Daemon...
Sep 29 09:45:08 samba-dc1 systemd[1]: winbind.service: Deactivated successfully.
Sep 29 09:45:08 samba-dc1 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.
Sep 29 09:45:08 samba-dc1 systemd[1]: winbind.service: Consumed 3.290s CPU time, 30.1M memory peak, 0B memory swap peak.

[1-13]

smbd / nmbd / winbind サービスのマスク (mask) を行う

# systemctl mask smb nmb winbind
Created symlink /etc/systemd/system/smbd.service → /dev/null.
Created symlink /etc/systemd/system/nmbd.service → /dev/null.
Created symlink /etc/systemd/system/winbind.service → /dev/null.

# systemctl status smb nmb winbind
Unit smb.service could not be found.
Unit nmb.service could not be found.
○ winbind.service
     Loaded: masked (Reason: Unit winbind.service is masked.)
     Active: inactive (dead)

Sep 29 09:36:01 samba-dc1 systemd[1]: Starting winbind.service - Samba Winbind Daemon...
Sep 29 09:36:01 samba-dc1 (winbindd)[3989]: winbind.service: Referenced but unset environment variable evaluates to an empty string: WINBINDOPTIONS
Sep 29 09:36:01 samba-dc1 systemd[1]: Started winbind.service - Samba Winbind Daemon.
Sep 29 09:45:08 samba-dc1 systemd[1]: Stopping winbind.service - Samba Winbind Daemon...
Sep 29 09:45:08 samba-dc1 systemd[1]: winbind.service: Deactivated successfully.
Sep 29 09:45:08 samba-dc1 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.
Sep 29 09:45:08 samba-dc1 systemd[1]: winbind.service: Consumed 3.290s CPU time, 30.1M memory peak, 0B memory swap peak.

[1-14]

samba-ad-dc サービスのアンマスク (unmask) を行い、有効化する
※ アンマスクの実行は環境によっては不要かも

# systemctl unmask samba-ad-dc

# systemctl enable samba-ad-dc
Synchronizing state of samba-ad-dc.service with SysV service script with /usr/lib/systemd/systemd-sysv-install.
Executing: /usr/lib/systemd/systemd-sysv-install enable samba-ad-dc

# systemctl status samba-ad-dc
○ samba-ad-dc.service - Samba AD Daemon
     Loaded: loaded (/usr/lib/systemd/system/samba-ad-dc.service; enabled; preset: enabled)
     Active: inactive (dead) (Result: exec-condition) since Tue 2026-09-29 09:35:59 UTC; 14min ago
  Condition: start condition unmet at Tue 2026-09-29 09:35:59 UTC; 14min ago
       Docs: man:samba(8)
             man:samba(7)
             man:smb.conf(5)
        CPU: 27ms

Sep 29 09:35:59 samba-dc1 systemd[1]: Starting samba-ad-dc.service - Samba AD Daemon...
Sep 29 09:35:59 samba-dc1 systemd[1]: samba-ad-dc.service: Skipped due to 'exec-condition'.
Sep 29 09:35:59 samba-dc1 systemd[1]: Condition check resulted in samba-ad-dc.service - Samba AD Daemon being skipped.

[1-15]

/etc/samba/smb.conf ファイルをリネームする

# cd /etc/samba
<出力無し>

# mv smb.conf smb.conf.orig
<出力無し>

[1-16]

Ubuntu 24.04 は systemd-resolved が 53 番を使うので、DC 用に無効化する

# systemctl disable --now systemd-resolved
Removed "/etc/systemd/system/dbus-org.freedesktop.resolve1.service".
Removed "/etc/systemd/system/sysinit.target.wants/systemd-resolved.service".

[1-17]

/etc/resolv.conf の nameserver に localhost 127.0.0.1 を指定し、search の部分を以下のように修正する
※ 事前バックアップ推奨

nameserver 127.0.0.1
search samba4.example.test

[1-18]

AD DC のプロビジョニングを開始する
対話形式で必要な情報を入力していく

※ DNS forwarder に指定する IP は、多くの EC2 インスタンスは AmazonProvidedDNS (Route 53 VPC Resolver) を指定すれば OK
※ いわゆる 「.2 リゾルバー」
※ VPC CIDR が 192.168.1.0/24 だったら 192.168.1.2 を指定

# samba-tool domain provision --use-rfc2307 --interactive
Realm [SAMBA4.EXAMPLE.TEST]:
Domain [SAMBA4]:
Server Role (dc, member, standalone) [dc]:
DNS backend (SAMBA_INTERNAL, BIND9_FLATFILE, BIND9_DLZ, NONE) [SAMBA_INTERNAL]:
DNS forwarder IP address (write 'none' to disable forwarding) [127.0.0.53]:  <DNS フォワーダーとして指定する IP>
Administrator password:
Retype password:

[1-19]

対話形式で上記の入力が完了すると、プロビジョニングが以下のように進む。

INFO 2026-09-29 09:56:23,857 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2128: Looking up IPv4 addresses
INFO 2026-09-29 09:56:23,857 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2145: Looking up IPv6 addresses
WARNING 2026-09-29 09:56:23,857 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2152: No IPv6 address will be assigned
...
(省略)
...
Applied Domain Update 87: 7f950403-0ab3-47f9-9730-5d7b0269f9bd
Applied Domain Update 88: 434bb40d-dbc9-4fe7-81d4-d57229f7b080
Applied Domain Update 89: a0c238ba-9e30-4ee6-80a6-43f731e9a5cd
INFO 2026-09-29 09:56:31,262 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2432: A Kerberos configuration suitable for Samba AD has been generated at /var/lib/samba/private/krb5.conf
INFO 2026-09-29 09:56:31,262 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2434: Merge the contents of this file with your system krb5.conf or replace it with this one. Do not create a symlink!
INFO 2026-09-29 09:56:31,339 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #2102: Setting up fake yp server settings
INFO 2026-09-29 09:56:31,402 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #493: Once the above files are installed, your Samba AD server will be ready to use
INFO 2026-09-29 09:56:31,403 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #498: Server Role:           active directory domain controller
INFO 2026-09-29 09:56:31,403 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #499: Hostname:              samba-dc1
INFO 2026-09-29 09:56:31,403 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #500: NetBIOS Domain:        SAMBA4
INFO 2026-09-29 09:56:31,403 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #501: DNS Domain:            samba4.example.test
INFO 2026-09-29 09:56:31,403 pid:4735 /usr/lib/python3/dist-packages/samba/provision/__init__.py #502: DOMAIN SID:            S-1-5-21-3970784122-3985089099-2754044133

[1-20]

krb5.conf を置き換える
/etc/krb5.conf を /var/lib/samba/private/krb5.conf で置き換える

cp -ip /var/lib/samba/private/krb5.conf /etc/krb5.conf
cp: overwrite '/etc/krb5.conf'? y

※ 以下が、Samba が生成した新しい設定内容 (置き換えたい内容)

# cat /var/lib/samba/private/krb5.conf
[libdefaults]
        default_realm = SAMBA4.EXAMPLE.TEST
        dns_lookup_realm = false
        dns_lookup_kdc = true

[realms]
SAMBA4.EXAMPLE.TEST = {
        default_domain = samba4.example.test
}

[domain_realm]
        samba-dc1 = SAMBA4.EXAMPLE.TEST

※ 以下が、置き換える前の元々の設定内容
  元々 /etc/krb5.conf には不要なサンプルドメイン例が多く記載されていることが分かる

# cat /etc/krb5.conf
[libdefaults]
        default_realm = SAMBA4.EXAMPLE.TEST

# The following krb5.conf variables are only for MIT Kerberos.
        kdc_timesync = 1
        ccache_type = 4
        forwardable = true
        proxiable = true
        rdns = false


# The following libdefaults parameters are only for Heimdal Kerberos.
        fcc-mit-ticketflags = true

[realms]
        SAMBA4.EXAMPLE.TEST = {
                kdc = samba-dc1.samba4.example.test
                admin_server = samba-dc1.samba4.example.test
        }
        ATHENA.MIT.EDU = {
                kdc = kerberos.mit.edu
                kdc = kerberos-1.mit.edu
                kdc = kerberos-2.mit.edu:88
                admin_server = kerberos.mit.edu
                default_domain = mit.edu
        }
        ZONE.MIT.EDU = {
                kdc = casio.mit.edu
                kdc = seiko.mit.edu
                admin_server = casio.mit.edu
        }
        CSAIL.MIT.EDU = {
                admin_server = kerberos.csail.mit.edu
                default_domain = csail.mit.edu
        }
        IHTFP.ORG = {
                kdc = kerberos.ihtfp.org
                admin_server = kerberos.ihtfp.org
        }
        1TS.ORG = {
                kdc = kerberos.1ts.org
                admin_server = kerberos.1ts.org
        }
        ANDREW.CMU.EDU = {
                admin_server = kerberos.andrew.cmu.edu
                default_domain = andrew.cmu.edu
        }
        CS.CMU.EDU = {
                kdc = kerberos-1.srv.cs.cmu.edu
                kdc = kerberos-2.srv.cs.cmu.edu
                kdc = kerberos-3.srv.cs.cmu.edu
                admin_server = kerberos.cs.cmu.edu
        }
        DEMENTIA.ORG = {
                kdc = kerberos.dementix.org
                kdc = kerberos2.dementix.org
                admin_server = kerberos.dementix.org
        }
        stanford.edu = {
                kdc = krb5auth1.stanford.edu
                kdc = krb5auth2.stanford.edu
                kdc = krb5auth3.stanford.edu
                master_kdc = krb5auth1.stanford.edu
                admin_server = krb5-admin.stanford.edu
                default_domain = stanford.edu
        }
        UTORONTO.CA = {
                kdc = kerberos1.utoronto.ca
                kdc = kerberos2.utoronto.ca
                kdc = kerberos3.utoronto.ca
                admin_server = kerberos1.utoronto.ca
                default_domain = utoronto.ca
        }

[domain_realm]
        .mit.edu = ATHENA.MIT.EDU
        mit.edu = ATHENA.MIT.EDU
        .media.mit.edu = MEDIA-LAB.MIT.EDU
        media.mit.edu = MEDIA-LAB.MIT.EDU
        .csail.mit.edu = CSAIL.MIT.EDU
        csail.mit.edu = CSAIL.MIT.EDU
        .whoi.edu = ATHENA.MIT.EDU
        whoi.edu = ATHENA.MIT.EDU
        .stanford.edu = stanford.edu
        .slac.stanford.edu = SLAC.STANFORD.EDU
        .toronto.edu = UTORONTO.CA
        .utoronto.ca = UTORONTO.CA

[1-21]

samba サービスを起動する

# systemctl start samba
<出力無し>

# systemctl status samba
● samba-ad-dc.service - Samba AD Daemon
     Loaded: loaded (/usr/lib/systemd/system/samba-ad-dc.service; enabled; preset: enabled)
     Active: active (running) since Tue 2026-09-29 23:02:22 UTC; 1s ago
       Docs: man:samba(8)
             man:samba(7)
             man:smb.conf(5)
    Process: 2054 ExecCondition=/usr/share/samba/is-configured samba (code=exited, status=0/SUCCESS)
   Main PID: 2058 (samba)
     Status: "samba: ready to serve connections..."
      Tasks: 52 (limit: 1013)
     Memory: 220.8M (peak: 235.7M)
        CPU: 2.801s
     CGroup: /system.slice/samba-ad-dc.service
             tq2058 "samba: root process"
             tq2059 "samba: tfork waiter process(2060)"
             tq2060 "samba: task[s3fs] pre-fork master"
             tq2061 "samba: tfork waiter process(2063)"
             tq2062 "samba: tfork waiter process(2064)"
             tq2063 "samba: task[rpc] pre-fork master"
             tq2064 /usr/sbin/smbd -D "--option=server role check:inhibit=yes" --foreground
             tq2065 "samba: tfork waiter process(2066)"
             tq2066 "samba: task[nbt] pre-fork master"
             tq2067 "samba: tfork waiter process(2068)"
             tq2068 "samba: task[wrepl] pre-fork master"
             tq2069 "samba: tfork waiter process(2070)"
             tq2070 "samba: task[ldap] pre-fork master"
             tq2071 "samba: tfork waiter process(2073)"
             tq2072 "samba: tfork waiter process(2074)"
             tq2073 "samba: task[rpc] pre-forked worker(0)"
             tq2074 "samba: task[cldap] pre-fork master"
             tq2075 "samba: tfork waiter process(2077)"
             tq2076 "samba: tfork waiter process(2078)"
             tq2077 "samba: task[rpc] pre-forked worker(1)"
             tq2078 "samba: task[kdc] pre-fork master"
             tq2079 "samba: tfork waiter process(2082)"
             tq2080 "samba: tfork waiter process(2081)"
             tq2081 "samba: task[kdc] pre-forked worker(0)"
             tq2082 "samba: task[drepl] pre-fork master"
             tq2083 "samba: tfork waiter process(2086)"
             tq2084 "samba: tfork waiter process(2085)"
             tq2085 "samba: task[kdc] pre-forked worker(1)"
             tq2086 "samba: task[rpc] pre-forked worker(2)"
             tq2087 "samba: tfork waiter process(2089)"
             tq2088 "samba: tfork waiter process(2090)"
             tq2089 "samba: task[winbindd] pre-fork master"
             tq2090 "samba: task[kdc] pre-forked worker(2)"
             tq2091 "samba: tfork waiter process(2093)"
             tq2092 "samba: tfork waiter process(2096)"
             tq2093 "samba: task[kdc] pre-forked worker(3)"
             tq2094 "samba: tfork waiter process(2097)"
             tq2095 "samba: tfork waiter process(2099)"
             tq2096 "samba: task[rpc] pre-forked worker(3)"
             tq2097 "samba: task[ntp_signd] pre-fork master"
             tq2098 "samba: tfork waiter process(2100)"
             tq2099 /usr/sbin/winbindd -D "--option=server role check:inhibit=yes" --foreground
             tq2100 "samba: task[kcc] pre-fork master"
             tq2101 "samba: tfork waiter process(2102)"
             tq2102 "samba: task[dnsupdate] pre-fork master"
             tq2103 "samba: tfork waiter process(2104)"
             tq2104 "samba: task[dns] pre-fork master"
             tq2106 "samba: tfork waiter process(2107)"
             tq2107 /usr/bin/python3 /usr/sbin/samba_dnsupdate
             tq2111 "smbd: notifyd" .
             tq2112 "smbd: cleanupd "
             mq2113 "winbindd: domain child [SAMBA4]"

Sep 29 23:02:22 samba-dc1 samba[2058]:   Copyright Andrew Tridgell and the Samba Team 1992-2023
Sep 29 23:02:22 samba-dc1 samba[2058]: [2026/09/29 23:02:22.372449,  0] lib/util/become_daemon.c:150(daemon_status)
Sep 29 23:02:22 samba-dc1 samba[2058]:   daemon 'samba' : Starting process...
Sep 29 23:02:22 samba-dc1 smbd[2064]: [2026/09/29 23:02:22.700583,  0] source3/smbd/server.c:1746(main)
Sep 29 23:02:22 samba-dc1 smbd[2064]:   smbd version 4.19.5-Ubuntu started.
Sep 29 23:02:22 samba-dc1 smbd[2064]:   Copyright Andrew Tridgell and the Samba Team 1992-2023
Sep 29 23:02:22 samba-dc1 systemd[1]: Started samba-ad-dc.service - Samba AD Daemon.
Sep 29 23:02:22 samba-dc1 winbindd[2099]: [2026/09/29 23:02:22.757802,  0] source3/winbindd/winbindd.c:1441(main)
Sep 29 23:02:22 samba-dc1 winbindd[2099]:   winbindd version 4.19.5-Ubuntu started.
Sep 29 23:02:22 samba-dc1 winbindd[2099]:   Copyright Andrew Tridgell and the Samba Team 1992-2023

[1-22]

自身のレコードを引けることを確認する

# host -t SRV _ldap._tcp.samba4.example.test
_ldap._tcp.samba4.example.test has SRV record 0 100 389 samba-dc1.samba4.example.test.

# host -t SRV _kerberos._udp.samba4.example.test
_kerberos._udp.samba4.example.test has SRV record 0 100 88 samba-dc1.samba4.example.test.

# host -t A samba-dc1.samba4.example.test
samba-dc1.samba4.example.test has address 10.0.19.139

[1-23]

起動プロセスを確認

# ps -ef | grep samba | grep -v grep
root        2058       1  0 23:02 ?        00:00:00 samba: root process
root        2059    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2060)
root        2060    2059  0 23:02 ?        00:00:00 samba: task[s3fs] pre-fork master
root        2061    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2063)
root        2062    2060  0 23:02 ?        00:00:00 samba: tfork waiter process(2064)
root        2063    2061  0 23:02 ?        00:00:00 samba: task[rpc] pre-fork master
root        2065    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2066)
root        2066    2065  0 23:02 ?        00:00:00 samba: task[nbt] pre-fork master
root        2067    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2068)
root        2068    2067  0 23:02 ?        00:00:00 samba: task[wrepl] pre-fork master
root        2069    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2070)
root        2070    2069  0 23:02 ?        00:00:01 samba: task[ldap] pre-fork master
root        2071    2063  0 23:02 ?        00:00:00 samba: tfork waiter process(2073)
root        2072    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2074)
root        2073    2071  0 23:02 ?        00:00:00 samba: task[rpc] pre-forked worker(0)
root        2074    2072  0 23:02 ?        00:00:00 samba: task[cldap] pre-fork master
root        2075    2063  0 23:02 ?        00:00:00 samba: tfork waiter process(2077)
root        2076    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2078)
root        2077    2075  0 23:02 ?        00:00:00 samba: task[rpc] pre-forked worker(1)
root        2078    2076  0 23:02 ?        00:00:00 samba: task[kdc] pre-fork master
root        2079    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2082)
root        2080    2078  0 23:02 ?        00:00:00 samba: tfork waiter process(2081)
root        2081    2080  0 23:02 ?        00:00:00 samba: task[kdc] pre-forked worker(0)
root        2082    2079  0 23:02 ?        00:00:00 samba: task[drepl] pre-fork master
root        2083    2063  0 23:02 ?        00:00:00 samba: tfork waiter process(2086)
root        2084    2078  0 23:02 ?        00:00:00 samba: tfork waiter process(2085)
root        2085    2084  0 23:02 ?        00:00:00 samba: task[kdc] pre-forked worker(1)
root        2086    2083  0 23:02 ?        00:00:00 samba: task[rpc] pre-forked worker(2)
root        2087    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2089)
root        2088    2078  0 23:02 ?        00:00:00 samba: tfork waiter process(2090)
root        2089    2087  0 23:02 ?        00:00:00 samba: task[winbindd] pre-fork master
root        2090    2088  0 23:02 ?        00:00:00 samba: task[kdc] pre-forked worker(2)
root        2091    2078  0 23:02 ?        00:00:00 samba: tfork waiter process(2093)
root        2092    2063  0 23:02 ?        00:00:00 samba: tfork waiter process(2096)
root        2093    2091  0 23:02 ?        00:00:00 samba: task[kdc] pre-forked worker(3)
root        2094    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2097)
root        2095    2089  0 23:02 ?        00:00:00 samba: tfork waiter process(2099)
root        2096    2092  0 23:02 ?        00:00:00 samba: task[rpc] pre-forked worker(3)
root        2097    2094  0 23:02 ?        00:00:00 samba: task[ntp_signd] pre-fork master
root        2098    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2100)
root        2100    2098  0 23:02 ?        00:00:00 samba: task[kcc] pre-fork master
root        2101    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2102)
root        2102    2101  0 23:02 ?        00:00:00 samba: task[dnsupdate] pre-fork master
root        2103    2058  0 23:02 ?        00:00:00 samba: tfork waiter process(2104)
root        2104    2103  0 23:02 ?        00:00:00 samba: task[dns] pre-fork master
root        2116    2070  0 23:02 ?        00:00:00 samba: tfork waiter process(2117)
root        2117    2116  0 23:02 ?        00:00:00 samba: task[ldap] pre-forked worker(0)
root        2118    2070  0 23:02 ?        00:00:00 samba: tfork waiter process(2119)
root        2119    2118  0 23:02 ?        00:00:00 samba: task[ldap] pre-forked worker(1)
root        2120    2070  0 23:02 ?        00:00:00 samba: tfork waiter process(2121)
root        2121    2120  0 23:02 ?        00:00:00 samba: task[ldap] pre-forked worker(2)
root        2122    2070  0 23:02 ?        00:00:00 samba: tfork waiter process(2123)
root        2123    2122  0 23:02 ?        00:00:00 samba: task[ldap] pre-forked worker(3)

以上で、Samba4 AD DC のセットアップは完了。

Windows Server での作業 (セットアップした Samba AD ドメインにメンバーサーバーとしてドメイン参加)

[2-1]

Windows Server 2025 の EC2 インスタンスを用意する

[2-2]

ドメイン参加する
ドメイン:SAMBA4.EXAMPLE.TEST
image.png

image.png

→ セキュリティグループが適切に許可されていないため、失敗した
 「すべての TCP」「すべての UDP」を許可することで対処 (TCP だけだとダメ)
image.png

[2-3]

認証画面が出るのでドメイン Administrator で認証する
image.png

無事、ドメイン参加完了
image.png

[2-4]

再起動する
image.png

ドメインに所属されたことを確認する
image.png

[2-5]

ドメインユーザーで RDP 接続できることを確認する
ユーザー名:Administrator@samba4 または Administrator@samba4.example.test または SAMBA4\Administrator

Windows Server での作業 (各種 AD 管理ツールでの確認)

[3-1]

以下の機能を追加 (インストール) する

  • AD DS スナップインおよびコマンドライン ツール
  • DNS サーバー ツール
  • グループポリシーの管理

image.png
image.png

[3-2]

各種ツールで確認してみる

<ユーザーとコンピューター>
image.png
image.png
image.png

<ドメインと信頼関係>
image.png

<サイトとサービス>
image.png

<DNS マネージャー>
最初は何も登録されていない
image.png

Samba サーバ (Ubuntu) に接続してみる
image.png

接続できた
image.png
image.png

Windows Server での作業 (ドメインユーザー作成やグループポリシーの動作検証)

[4-1]

まずは OU「OU-samba4」を作り、そこにドメインユーザー「1-samba-user」を作成する

[4-2]

デフォルトだと RDP 接続できない。以下のような手順で、ローカルグループに対して許可を与える必要がある

  • 「コンピュータの管理」のローカルグループ「Remote Desktop Users」に、対象のドメインユーザー/ドメイングループを追加する
    • 但し、ドメインのビルトイングループは追加できないので、ドメインの「Remote Desktop Users」グループは追加できない
    • AD DC に対する RDP 接続ならドメインの「Remote Desktop Users」グループへ対象のドメインユーザー追加が必要だが、今回はメンバーサーバへの RDP 接続のため、ローカルの「コンピュータの管理」でのローカルグループへの追加が必要になる

image.png

  • 「Remote Desktop Users」グループに、ドメインの「1-samba-rdp-group」グループを追加した。

image.png

  • ドメインの「1-samba-rdp-group」グループには、ドメインユーザー「1-samba-user」が所属している

image.png
image.png

[4-3]

以上の設定により、無事ドメインユーザーでメンバーサーバーへ RDP 接続できるようになった
image.png
image.png
image.png

[4-4]

デスクトップから「ゴミ箱」を消す
image.png

GPO を作成し、「ユーザーの構成」配下のデスクトップ設定「デスクトップから [ごみ箱] アイコンを削除する」を有効にする
image.png
image.png

[4-5]

GPO を、対象ユーザーが所属する OU にリンクする
image.png

[4-6]

「gpupdate /force」を実行する
※ 適用させたい「1-samba-user」で実行するのが推奨

[4-7]

ごみ箱が消えた
image.png

★ 注意点 (少しハマった点) ★
GPO の変更を適用して動作確認するために、対象ユーザー「1-samba-user」を一度「サインアウト」してから再度 RDP 接続する必要がある。既存 RDP 接続を「× バツ」閉じして再度 RDP 接続しても、既存セッションに再接続するため GPO の適用が行われない。

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?