{"id":501,"date":"2015-10-16T17:01:46","date_gmt":"2015-10-16T13:01:46","guid":{"rendered":"http:\/\/unlis.ru\/?p=501"},"modified":"2020-06-25T16:49:01","modified_gmt":"2020-06-25T12:49:01","slug":"%d0%ba%d0%be%d0%bd%d1%82%d1%80%d0%be%d0%bb%d0%bb%d0%b5%d1%80-%d0%b4%d0%be%d0%bc%d0%b5%d0%bd%d0%b0-%d0%bd%d0%b0-debian-8-%d0%b2-%d0%ba%d0%be%d1%82%d0%be%d1%80%d0%be%d0%bc-%d1%83%d0%b6%d0%b5-%d0%b5","status":"publish","type":"post","link":"https:\/\/unlis.ru\/?p=501","title":{"rendered":"\u041a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440 \u0434\u043e\u043c\u0435\u043d\u0430 \u043d\u0430 Debian 8 (&#8230;\u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u0441\u043e\u0431\u0440\u0430\u043d\u043d\u0430\u044f Samba4)"},"content":{"rendered":"<p>&#171;\u0410 \u043a\u0430\u043a\u0430\u044f \u0440\u0430\u0437\u043d\u0438\u0446\u0430?&#187; &#8212; \u0441\u043a\u0430\u0436\u0435\u0442\u0435 \u0432\u044b, \u0438 \u0431\u0443\u0434\u0435\u0442\u0435 \u043d\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u043f\u0440\u0430\u0432\u044b. \u0412\u043e-\u043f\u0435\u0440\u0432\u044b\u0445, \u043d\u0435 \u043d\u0430\u0434\u043e \u0443\u0434\u043e\u0432\u043b\u0435\u0442\u0432\u043e\u0440\u044f\u0442\u044c \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438 \u0441\u0431\u043e\u0440\u043a\u0435 \u043f\u0430\u043a\u0435\u0442\u0430, \u0432\u043e-\u0432\u0442\u043e\u0440\u044b\u0445, \u043d\u0435 \u043d\u0430\u0434\u043e \u0435\u0433\u043e \u0441\u043e\u0431\u0438\u0440\u0430\u0442\u044c-\u043a\u043e\u043c\u043f\u0438\u043b\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c, \u0438, \u043d\u0430\u043a\u043e\u043d\u0435\u0446, \u0432-\u0442\u0440\u0435\u0442\u044c\u0438\u0445, \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0440\u043e\u0441\u0442\u043e \u0441\u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0432\u0430\u0442\u044c <em><strong>apt-get update &amp;&amp; apt-get upgrade<\/strong><\/em> &#8212; \u0438 \u0443 \u0432\u0430\u0441 \u043f\u043e\u044f\u0432\u0438\u0442\u0441\u044f \u0441\u0430\u043c\u0430\u044f \u0441\u0432\u0435\u0436\u0430\u044f \u0432\u0435\u0440\u0441\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f. \u0418 \u0432\u0441\u0435 \u044d\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442\u0441\u044f \u044f\u0432\u043d\u043e \u043d\u0435 \u043d\u0430 Ubuntu, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u044f \u0437\u0430 \u043b\u0438\u043d\u0443\u0445 \u043d\u0435 \u0441\u0447\u0438\u0442\u0430\u044e&#8230;<\/p>\n<h5>1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Debian 8<\/h5>\n<p>\u0418\u0442\u0430\u043a, \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c. \u041e\u0442\u043a\u0443\u0434\u0430 \u043a\u0430\u0447\u0430\u0442\u044c \u0438 \u043a\u0430\u043a \u0441\u0442\u0430\u0432\u0438\u0442\u044c, \u044f \u0434\u0443\u043c\u0430\u044e, \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0442\u044c \u0441\u043c\u044b\u0441\u043b\u0430 \u043d\u0435\u0442. \u041e\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u044e\u0441\u044c \u043b\u0438\u0448\u044c \u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0432\u044b\u0445 \u043c\u043e\u043c\u0435\u043d\u0442\u0430\u0445.<\/p>\n<p>\u0412 \u043f\u0435\u0440\u0432\u0443\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c, \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043e\u0442\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u0441\u044f \u043e\u0442 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0441\u0435\u0442\u0438 \u043f\u043e DHCP<\/p>\n<p><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-502\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/5.png\" alt=\"5\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/5.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/5-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a>\u0438 \u0434\u0430\u043b\u0435\u0435 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u0432\u0441\u0435 \u0432\u0440\u0443\u0447\u043d\u0443\u044e.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-503\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/6.png\" alt=\"6\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/6.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/6-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/> \u041c\u043e\u0436\u043d\u043e \u0432\u043e\u043e\u0431\u0449\u0435 \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c, \u0430 \u043f\u043e\u043f\u0440\u0430\u0432\u0438\u0442\u044c <em><strong>\/etc\/network\/interfaces<\/strong><\/em> \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438, \u043d\u043e \u0442\u043e\u0433\u0434\u0430 \u043c\u044b \u043b\u0438\u0448\u0430\u0435\u043c\u0441\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0437\u0435\u0440\u043a\u0430\u043b\u043e \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f \u0432 \u0421\u0435\u0442\u0438 \u0438 \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c\u0441\u044f\u00a0\u043e\u0442\u0442\u0443\u0434\u0430. \u041c\u043d\u043e\u044e \u043f\u0440\u0435\u0434\u043f\u043e\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u0432 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0443 \u0432\u0430\u0441 \u0448\u043b\u044e\u0437 \u0432\u00a0\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0432\u0441\u0435-\u0442\u0430\u043a\u0438 \u0435\u0441\u0442\u044c.<\/p>\n<p>\u0418\u0442\u0430\u043a, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b \u0441\u0435\u0442\u0438 \u0443 \u043d\u0430\u0441 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435:<\/p>\n<p><code>\u0430\u0434\u0440\u0435\u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430: 192.168.1.2;<\/code><br \/>\n<code> \u043c\u0430\u0441\u043a\u0430 \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e 255.255.255.0;<\/code><br \/>\n<code> \u0448\u043b\u044e\u0437 \u043f\u043e-\u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0443 \u043d\u0430\u0441 192.168.1.1;<\/code><br \/>\n<code> DNS-\u0441\u0435\u0440\u0432\u0435\u0440 192.168.1.1<\/code><br \/>\n<code> \u0438\u043c\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u0430 debian<\/code><br \/>\n<code> \u0438\u043c\u044f \u0434\u043e\u043c\u0435\u043d\u0430 unlis.local<\/code><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-504\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/7.png\" alt=\"7\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/7.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/7-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a> <a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-505\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/8.png\" alt=\"8\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/8.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/8-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a> <a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-506\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/9.png\" alt=\"9\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/9.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/9-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a> <a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/10\/10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-682\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/10\/10.png\" alt=\"10\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/10\/10.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/10\/10-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-508\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/11.png\" alt=\"11\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/11.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/11-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a> <a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-509\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/12.png\" alt=\"12\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/12.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/12-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a>\u041f\u043e\u0441\u043b\u0435 \u0437\u0430\u0434\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u0435\u0439, \u0447\u0430\u0441\u043e\u0432\u044b\u0445 \u043f\u043e\u044f\u0441\u043e\u0432 \u0438 \u0440\u0430\u0437\u043c\u0435\u0442\u043a\u0438 \u0434\u0438\u0441\u043a\u0430 \u043c\u043e\u0436\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 (\u0441\u043a\u043e\u0440\u043c\u0438\u0442\u044c apt \u0432\u0441\u0435 \u0442\u0440\u0438 DVD-\u0434\u0438\u0441\u043a\u0430 \u0441 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u043e\u043c \u043f\u0440\u0438 \u0438\u0445 \u043d\u0430\u043b\u0438\u0447\u0438\u0438, \u043b\u0438\u0431\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0437\u0435\u0440\u043a\u0430\u043b\u043e \u0438\u0437 \u0441\u0435\u0442\u0438):<\/p>\n<p><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/24.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-511\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/24.png\" alt=\"24\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/24.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/24-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/25.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-512\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/25.png\" alt=\"25\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/25.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/25-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/26.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-513\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/26.png\" alt=\"26\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/26.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/26-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a> <a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/27.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-514\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/27.png\" alt=\"27\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/27.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/27-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a>\u041c\u043e\u0436\u043d\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438, \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 <em><strong>\/etc\/apt\/sources.list<\/strong><\/em> \u043a \u0432\u0438\u0434\u0443<\/p>\n<p><code># deb cdrom:[Debian GNU\/Linux 8.0.0 _Jessie_ - Official i386 DVD Binary-1 20150425-11:43]\/ jessie contrib main<\/code><\/p>\n<p><code># deb cdrom:[Debian GNU\/Linux 8.0.0 _Jessie_ - Official i386 DVD Binary-1 20150425-11:43]\/ jessie contrib main<\/code><\/p>\n<p><code>deb http:\/\/ftp.ru.debian.org\/debian\/ jessie main contrib non-free<\/code><br \/>\n<code> deb-src http:\/\/ftp.ru.debian.org\/debian\/ jessie main contrib non-free<\/code><\/p>\n<p><code>deb http:\/\/security.debian.org\/ jessie\/updates main contrib non-free<\/code><br \/>\n<code> deb-src http:\/\/security.debian.org\/ jessie\/updates main contrib non-free<\/code><\/p>\n<p><code># jessie-updates, previously known as 'volatile'<\/code><br \/>\n<code> deb http:\/\/ftp.ru.debian.org\/debian\/ jessie-updates main contrib non-free<\/code><br \/>\n<code> deb-src http:\/\/ftp.ru.debian.org\/debian\/ jessie-updates main contrib non-free<\/code><\/p>\n<p>\u0414\u043e\u0445\u043e\u0434\u0438\u043c \u0434\u043e \u0448\u0430\u0433\u0430 \u0432\u044b\u0431\u043e\u0440\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f, \u0432\u044b\u0431\u0438\u0440\u0430\u0435\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0439 \u043c\u0438\u043d\u0438\u043c\u0443\u043c<\/p>\n<p><a href=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/30.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-515\" src=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/30.png\" alt=\"30\" width=\"800\" height=\"600\" srcset=\"https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/30.png 800w, https:\/\/unlis.ru\/wp-content\/uploads\/2015\/05\/30-300x225.png 300w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<h5>2. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0441\u0435\u0442\u0438, \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c, \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u043d\u0443\u0436\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432<\/h5>\n<p>\u041f\u043e\u0441\u0442\u0430\u0432\u0438\u043b\u0438, \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u043b\u0438\u0441\u044c, \u043b\u043e\u0433\u0438\u043d\u0438\u043c\u0441\u044f \u043f\u043e\u0434 root, \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 SSH \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u043e\u0434 \u043e\u0431\u044b\u0447\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u043b\u0438 \u043f\u0440\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435, \u043f\u043e\u0442\u043e\u043c \u0447\u0435\u0440\u0435\u0437 su \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u0441\u044f \u043d\u0430 root. \u0418\u043c\u0435\u043d\u043d\u043e, \u0432 Debian 8 \u0443\u0436\u0435 \u043d\u0435\u043b\u044c\u0437\u044f \u0437\u0430\u0439\u0442\u0438 \u0447\u0435\u0440\u0435\u0437 SSH \u0441\u0440\u0430\u0437\u0443 \u043f\u043e\u0434 root-\u043e\u043c \u043f\u043e \u043f\u0430\u0440\u043e\u043b\u044e, \u043d\u043e \u043c\u044b-\u0442\u043e \u0441 \u0432\u0430\u043c\u0438 \u0437\u043d\u0430\u0435\u043c, \u0433\u0434\u0435 \u0441\u043e\u0431\u0430\u043a\u0430 \u043f\u043e\u0440\u044b\u043b\u0430\u0441\u044c)<\/p>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u0441\u0435\u0442\u0438. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0441\u043c\u043e\u0442\u0440\u0438\u043c <strong>\/etc\/network\/interfaces<\/strong>, \u0438\u0437\u043c\u0435\u043d\u044f\u0435\u043c \u043f\u0440\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438<\/p>\n<p><code># This file describes the network interfaces available on your system<\/code><br \/>\n<code> # and how to activate them. For more information, see interfaces(5).<\/code><\/p>\n<p><code>source \/etc\/network\/interfaces.d\/*<\/code><\/p>\n<p><code># The loopback network interface<\/code><br \/>\n<code> auto lo<\/code><br \/>\n<code> iface lo inet loopback<\/code><\/p>\n<p><code># The primary network interface<\/code><br \/>\n<code> allow-hotplug eth0<\/code><br \/>\n<code> iface eth0 inet static<\/code><br \/>\n<code> address 192.168.1.2<\/code><br \/>\n<code> netmask 255.255.255.0<\/code><br \/>\n<code> network 192.168.1.0<\/code><br \/>\n<code> broadcast 192.168.1.255<\/code><br \/>\n<code> gateway 192.168.1.1<\/code><br \/>\n<code> # dns-* options are implemented by the resolvconf package, if installed<\/code><br \/>\n<code> dns-nameservers 192.168.1.1<\/code><br \/>\n<code> dns-search unlis.local<\/code><\/p>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 <strong>\/etc\/hosts<\/strong><\/p>\n<p class=\"toolbar:2 lang:sh decode:true \"><code>127.0.0.1 localhost<\/code><br \/>\n<code> 192.168.1.2 debian.unlis.local debian<\/code><\/p>\n<p>\u0412 \u0444\u0430\u0439\u043b\u0435 <strong>\/etc\/hostname<\/strong> \u0434\u043e\u043b\u0436\u043d\u043e \u0431\u044b\u0442\u044c \u0441\u043e\u043a\u0440\u0430\u0449\u0435\u043d\u043d\u043e\u0435 \u0438\u043c\u044f \u0445\u043e\u0441\u0442\u0430<\/p>\n<p><code>debian<\/code><\/p>\n<p>\u0417\u0430\u0442\u0435\u043c\u00a0\u043a\u043e\u043c\u0430\u043d\u0434\u0443\u0435\u043c \u043f\u043e \u043e\u0447\u0435\u0440\u0435\u0434\u0438 <em><strong>hostname<\/strong><\/em> \u0438 <em><strong>hostname -f<\/strong><\/em><\/p>\n<p><code>root@debian:\/root# hostname<\/code><br \/>\n<code> debian<\/code><br \/>\n<code> root@debian:\/root# hostname -f<\/code><br \/>\n<code> debian.unlis.local<\/code><\/p>\n<p>\u0414\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430 \u0432 \u044f\u0434\u0440\u0435 \u0434\u043e\u043b\u0436\u043d\u0430 \u0431\u044b\u0442\u044c\u00a0\u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 XATTR, SECURITY \u0438 POSIX_ACL \u0434\u043b\u044f \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b ext4. \u041f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043e\u043d\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0442\u043e\u043b\u044c\u043a\u043e \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0435\u0435\u00a0\u0434\u043b\u044f \u043d\u0443\u0436\u043d\u044b\u0445 \u043d\u0430\u043c \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u0432 \u0444\u0430\u0439\u043b\u0435 <strong><em>\/etc\/fstab<\/em><\/strong> (\u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043e \u0436\u0438\u0440\u043d\u044b\u043c \u0448\u0440\u0438\u0444\u0442\u043e\u043c):<\/p>\n<p class=\"toolbar:2 lang:sh decode:true \"><code># &lt;file system&gt; &lt;mount point&gt; &lt;type&gt; &lt;options&gt; &lt;dump&gt; &lt;pass&gt;<\/code><br \/>\n<code> # \/ was on \/dev\/sda1 during installation<\/code><br \/>\n<code> UUID=a4535997-a41b-4555-b0bc-66df0436d3a4 \/ ext4 errors=remount-ro,<strong>user_xattr,acl,barrier=1<\/strong> 0 1<\/code><br \/>\n<code> # \/home was on \/dev\/sda8 during installation<\/code><br \/>\n<code> UUID=566fec99-cb7d-4e57-9192-b0ed57ef796b \/home ext4 <strong>user_xattr,acl,barrier=1<\/strong> 0 2<\/code><br \/>\n<code> # \/tmp was on \/dev\/sda7 during installation<\/code><br \/>\n<code> UUID=21e19722-9c99-4152-8ebc-e5553892bc30 \/tmp ext4 <strong>user_xattr,acl,barrier=1<\/strong> 0 2<\/code><br \/>\n<code> # \/var was on \/dev\/sda5 during installation<\/code><br \/>\n<code> UUID=06430bc9-9357-4fbe-a261-a3118993726c \/var ext4 <strong>user_xattr,acl,barrier=1<\/strong> 0 2<\/code><br \/>\n<code> # swap was on \/dev\/sda6 during installation<\/code><br \/>\n<code> UUID=3335a698-5854-496b-a000-fe6fa6ae3a9b none swap sw 0 0<\/code><br \/>\n<code> \/dev\/sr0 \/media\/cdrom0 udf,iso9660 user,noauto 0 0<\/code><\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043f\u0440\u043e\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 XATTR \u0434\u043b\u044f \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b. \u0412\u044b\u043f\u043e\u043b\u043d\u0438\u043c:<\/p>\n<p><em><strong>touch testfile<\/strong><\/em><br \/>\n<em><strong>setfattr -n user.test -v test1 testfile<\/strong><\/em><br \/>\n<em><strong>setfattr -n security.test -v test2 testfile<\/strong><\/em><\/p>\n<p>\u0415\u0441\u043b\u0438 \u0440\u0443\u0433\u0430\u0435\u0442\u0441\u044f \u043d\u0430 setfattr, \u0447\u0442\u043e \u043d\u0435\u0442 \u0442\u0430\u043a\u043e\u0439 \u043a\u043e\u043c\u0430\u043d\u0434\u044b &#8212; \u043d\u0430\u0434\u043e \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442 <strong>attr<\/strong> (<em><strong>apt-get install attr<\/strong><\/em>). \u041a\u043e\u043c\u0430\u043d\u0434\u0430<em><strong> getfattr -d testfile\u00a0<\/strong><\/em>\u0434\u043e\u043b\u0436\u043d\u0430 \u0432\u0435\u0440\u043d\u0443\u0442\u044c:<\/p>\n<p><code>file: testfile<\/code><br \/>\n<code> user.test=\"test1\"<\/code><\/p>\n<p>\u041a\u043e\u043c\u0430\u043d\u0434\u0430<em><strong> getfattr -n security.test -d testfile\u00a0<\/strong><\/em>\u0434\u043e\u043b\u0436\u043d\u0430 \u0432\u0435\u0440\u043d\u0443\u0442\u044c:<\/p>\n<p><code>file: testfile<\/code><br \/>\n<code> security.test=\"test2\"<\/code><\/p>\n<p>\u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 ACL \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c:<\/p>\n<p><em><strong>touch testfile2<\/strong><\/em><br \/>\n<em><strong>setfacl -m g:adm:rwx testfile2<\/strong><\/em><\/p>\n<p>\u041a\u043e\u043c\u0430\u043d\u0434\u0430 <em><strong>\u00a0getfacl testfile2<\/strong><\/em>\u00a0\u0434\u043e\u043b\u0436\u043d\u0430 \u0432\u0435\u0440\u043d\u0443\u0442\u044c:<\/p>\n<p><code>group:adm:rwx<\/code><\/p>\n<p>\u0414\u0430\u043b\u0435\u0435, \u043a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u043d\u0443\u0436\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c\u0441\u044f. \u0415\u0441\u043b\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u043b\u0438 \u0437\u0435\u0440\u043a\u0430\u043b\u043e \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f \u043f\u0440\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435, \u0442\u043e \u0432\u0441\u0435 \u0443\u0436\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043e. \u0415\u0441\u043b\u0438 \u043d\u0435\u0442, \u0442\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c (\u0441\u043c \u0432\u044b\u0448\u0435 \u043f\u0440\u043e\u00a0<strong><em>\/etc\/apt\/sources.list<\/em><\/strong>), \u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u0443\u0435\u043c\u00a0 <em><strong>apt-get update &amp;&amp; apt-get upgrade.<\/strong><\/em><\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c <strong>samba4.<\/strong> \u0422\u0430\u043a\u0436\u0435 \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u043f\u0430\u043a\u0435\u0442 <strong>krb5-user, ntp, smbclient, winbind <\/strong>(\u0440\u0430\u043d\u044c\u0448\u0435 \u0431\u0435\u0437 \u043d\u0435\u0433\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u043b\u043e, \u043d\u043e \u0432 \u043d\u043e\u0432\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 samba \u043f\u0430\u0434\u0430\u0435\u0442)<strong>\u00a0<\/strong>\u0438 <strong>bind9<\/strong> (\u0442\u0430\u043a \u043a\u0430\u043a \u043c\u044b \u043d\u0435 \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 DNS \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u0439 \u0432 Samba4), \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c \u0432\u044b\u0448\u0435\u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u0435\u043d\u043d\u043e\u0435\u00a0\u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <em><strong>apt-get install samba ntp smbclient krb5-user bind9 winbind<\/strong><\/em>. \u0412\u0441\u0435 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u043f\u043e\u0441\u0442\u0430\u0432\u044f\u0442\u0441\u044f \u0441\u0430\u043c\u0438. \u041f\u0440\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 krb5-user \u0441\u043f\u0440\u043e\u0441\u0438\u0442 realm, \u043c\u043e\u0436\u043d\u043e \u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u043f\u0443\u0441\u0442\u044b\u043c, \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u043c \u0432\u0440\u0443\u0447\u043d\u0443\u044e \u043f\u043e\u0437\u0436\u0435.<\/p>\n<h5>3. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u00a0samba \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430.<\/h5>\n<p>\u041a\u043e\u043c\u0430\u043d\u0434\u043e\u0439<strong><em>\u00a0samba-tool domain provision &#8212;use-rfc2307 &#8212;interactive <\/em><\/strong>\u0441\u043e\u0437\u0434\u0430\u0435\u043c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440 \u0434\u043e\u043c\u0435\u043d\u0430. \u0415\u0441\u043b\u0438 \u043f\u0440\u0438 \u044d\u0442\u043e\u043c \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c \u043e\u0448\u0438\u0431\u043a\u0430<\/p>\n<p><code>ERROR(&lt;class 'samba.provision.ProvisioningError'&gt;): Provision failed - ProvisioningError: guess_names: 'server role=standalone server' in \/etc\/samba\/smb.conf must match chosen server role 'active directory domain controller'! Please remove the smb.conf file and let provision generate it<\/code><strong><em><br \/>\n<\/em><\/strong><\/p>\n<p>\u0443\u0434\u0430\u043b\u044f\u0435\u043c \u0438\u043b\u0438 \u043f\u0435\u0440\u0435\u043c\u0435\u0449\u0430\u0435\u043c \u0444\u0430\u0439\u043b<strong><em> \/etc\/samba\/smb.conf<\/em> <\/strong>\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u0443 \u0437\u0430\u043d\u043e\u0432\u043e<\/p>\n<p><code>Realm [UNLIS.LOCAL]:\u00a0<em><strong>UNLIS.LOCAL<\/strong><\/em><\/code><br \/>\n<code> Domain [UNLIS]:\u00a0<strong>UNLIS<\/strong><\/code><br \/>\n<code> Server Role (dc, member, standalone) [dc]: <strong>dc<\/strong><\/code><br \/>\n<code> DNS backend (SAMBA_INTERNAL, BIND9_FLATFILE, BIND9_DLZ, NONE) [SAMBA_INTERNAL]: <strong>BIND9_DLZ<\/strong><\/code><br \/>\n<code> Administrator password: <strong>&lt;\u041f\u0430\u0440\u043e\u043b\u044c_\u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430_\u0434\u043e\u043c\u0435\u043d\u0430&gt;<\/strong><\/code><br \/>\n<code> Retype password: <strong>&lt;\u041f\u0430\u0440\u043e\u043b\u044c_\u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430_\u0434\u043e\u043c\u0435\u043d\u0430&gt;<\/strong><\/code><br \/>\n<code> Looking up IPv4 addresses<\/code><br \/>\n<code> Looking up IPv6 addresses<\/code><br \/>\n<code> No IPv6 address will be assigned<\/code><br \/>\n<code> Setting up secrets.ldb<\/code><br \/>\n<code> Setting up the registry<\/code><br \/>\n<code> Setting up the privileges database<\/code><br \/>\n<code> Setting up idmap db<\/code><br \/>\n<code> Setting up SAM db<\/code><br \/>\n<code> Setting up sam.ldb partitions and settings<\/code><br \/>\n<code> Setting up sam.ldb rootDSE<\/code><br \/>\n<code> Pre-loading the Samba 4 and AD schema<\/code><br \/>\n<code> Adding DomainDN: DC=unlis,DC=local<\/code><br \/>\n<code> Adding configuration container<\/code><br \/>\n<code> Setting up sam.ldb schema<\/code><br \/>\n<code> Setting up sam.ldb configuration data<\/code><br \/>\n<code> Setting up display specifiers<\/code><br \/>\n<code> Modifying display specifiers<\/code><br \/>\n<code> Adding users container<\/code><br \/>\n<code> Modifying users container<\/code><br \/>\n<code> Adding computers container<\/code><br \/>\n<code> Modifying computers container<\/code><br \/>\n<code> Setting up sam.ldb data<\/code><br \/>\n<code> Setting up well known security principals<\/code><br \/>\n<code> Setting up sam.ldb users and groups<\/code><br \/>\n<code> Setting up self join<\/code><br \/>\n<code> Adding DNS accounts<\/code><br \/>\n<code> Creating CN=MicrosoftDNS,CN=System,DC=unlis,DC=local<\/code><br \/>\n<code> Creating DomainDnsZones and ForestDnsZones partitions<\/code><br \/>\n<code> Populating DomainDnsZones and ForestDnsZones partitions<\/code><br \/>\n<code> See \/var\/lib\/samba\/private\/named.conf for an example configuration include file for BIND<\/code><br \/>\n<code> and \/var\/lib\/samba\/private\/named.txt for further documentation required for secure DNS updates<\/code><br \/>\n<code> Setting up sam.ldb rootDSE marking as synchronized<\/code><br \/>\n<code> Fixing provision GUIDs<\/code><br \/>\n<code> A Kerberos configuration suitable for Samba 4 has been generated at \/var\/lib\/samba\/private\/krb5.conf<\/code><br \/>\n<code> Setting up fake yp server settings<\/code><br \/>\n<code> Once the above files are installed, your Samba4 server will be ready to use<\/code><br \/>\n<code> Server Role: active directory domain controller<\/code><br \/>\n<code> Hostname: debian<\/code><br \/>\n<code> NetBIOS Domain: UNLIS<\/code><br \/>\n<code> DNS Domain: unlis.local<\/code><br \/>\n<code> DOMAIN SID: S-1-5-21-2700703666-2339786236-4269973824<\/code><\/p>\n<h5>4. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430.<\/h5>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438<strong> bind9<\/strong>\u00a0\u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u0435\u0433\u043e \u0432\u0435\u0440\u0441\u0438\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <strong><em>named -v<\/em><\/strong>, \u0434\u043e\u043b\u0436\u043d\u043e \u0432\u0435\u0440\u043d\u0443\u0442\u044c\u0441\u044f \u00a0\u0447\u0442\u043e-\u0442\u043e \u0442\u0438\u043f\u0430\u00a0<strong><em>BIND 9.9.5-9+deb8u3-Debian (Extended Support Version). <\/em><\/strong>\u0422\u043e \u0435\u0441\u0442\u044c \u0432\u0435\u0440\u0441\u0438\u044f bind \u0443 \u043d\u0430\u0441 9.9. \u0412\u0441\u0435 \u043d\u0438\u0436\u0435\u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u043d\u044b\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0431\u0443\u0434\u0435\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c \u0438\u043c\u0435\u043d\u043d\u043e \u0434\u043b\u044f \u044d\u0442\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438.<\/p>\n<p>\u0414\u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0432 \u043a\u043e\u043d\u0435\u0446 \u0444\u0430\u0439\u043b\u0430\u00a0<em><strong>\/etc\/bind\/named.conf\u00a0<\/strong><\/em><\/p>\n<p><code>include \"\/var\/lib\/samba\/private\/named.conf\";<\/code><\/p>\n<p>\u0414\u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0432 \u043a\u043e\u043d\u0435\u0446 \u0444\u0430\u0439\u043b\u0430 <em><strong>\/etc\/bind\/named.conf.options<\/strong> \u043f\u043e\u0441\u043b\u0435 \u0441\u0438\u043c\u0432\u043e\u043b\u0430 };<\/em><\/p>\n<p><code><em>tkey-gssapi-keytab \"\/var\/lib\/samba\/private\/dns.keytab\";<\/em><\/code><\/p>\n<p>\u0418 \u0432 \u0444\u0430\u0439\u043b\u0435<em><strong>\u00a0<\/strong><strong>\/var\/lib\/samba\/private\/named.conf<\/strong>\u00a0<\/em>\u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0438\u0440\u0443\u0435\u043c\/\u0440\u0430\u0441\u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0438\u0440\u0443\u0435\u043c \u0441\u0442\u0440\u043e\u043a\u0443 \u043f\u043e\u0434 \u043d\u0430\u0448\u0443 \u0432\u0435\u0440\u0441\u0438\u044e bind<\/p>\n<p><code>dlz \"AD DNS Zone\" {<\/code><br \/>\n<code> # For BIND 9.8.x<\/code><br \/>\n<code> # database \"dlopen \/usr\/lib\/i386-linux-gnu\/samba\/bind9\/dlz_bind9.so\";<\/code><\/p>\n<p><code># For BIND 9.9.x<\/code><br \/>\n<code> database \"dlopen \/usr\/lib\/i386-linux-gnu\/samba\/bind9\/dlz_bind9_9.so\";<\/code><\/p>\n<p><code># For BIND 9.10.x<\/code><br \/>\n<code> # database \"dlopen \/usr\/lib\/i386-linux-gnu\/samba\/bind9\/dlz_bind9_10.so\";<\/code><br \/>\n<code> };<\/code><\/p>\n<p>\u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440 \u0434\u043e\u043c\u0435\u043d\u0430\u00a0\u0437\u043d\u0430\u043b \u0432\u0441\u0435\u0445 \u0447\u043b\u0435\u043d\u043e\u0432 \u0434\u043e\u043c\u0435\u043d\u0430 \u043f\u043e \u0438\u0445\u00a0DNS-\u0438\u043c\u0435\u043d\u0430\u043c, \u0432\u043d\u0435\u0441\u0435\u043c \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u0444\u0430\u0439\u043b <strong>\/etc\/resolv.conf<\/strong><\/p>\n<p><code>domain\u00a0unlis.local<\/code><br \/>\n<code> nameserver 192.168.1.2<\/code><\/p>\n<p>\u041c\u043e\u0436\u043d\u043e \u0435\u0449\u0435 \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u0430\u0434\u0440\u0435\u0441 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u0432 \u0444\u0430\u0439\u043b\u0435\u00a0<strong>\/etc\/network\/interfaces<\/strong><\/p>\n<p><code>dns-nameservers 192.168.1.2<\/code><\/p>\n<p>\u0415\u0441\u043b\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u00a0\u043f\u0430\u043a\u0435\u0442 <strong>resolvconf<\/strong>, \u0442\u043e\u00a0\u0432 \u0444\u0430\u0439\u043b\u0435\u00a0<strong>\/etc\/network\/interfaces\u00a0<\/strong>\u043d\u0435 \u043c\u043e\u0436\u043d\u043e, \u0430 \u043d\u0443\u0436\u043d\u043e<strong>\u00a0<\/strong>\u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u00a0<em>dns-nameservers<\/em>, \u0430 \u0444\u0430\u0439\u043b<em>\u00a0<\/em><strong>\/etc\/resolv.conf<\/strong>\u00a0\u043c\u043e\u0436\u043d\u043e \u0432\u043e\u043e\u0431\u0449\u0435 \u043d\u0435 \u0442\u0440\u043e\u0433\u0430\u0442\u044c, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043e\u043d \u0431\u0443\u0434\u0435\u0442 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u043d \u043f\u0430\u043a\u0435\u0442\u043e\u043c<strong> resolvconf <\/strong>\u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u0438\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043a dns-* \u0438\u0437 \u0444\u0430\u0439\u043b\u0430<strong> \/etc\/network\/interfaces<\/strong>\u00a0(\u041f\u043e\u0434\u0441\u043a\u0430\u0437\u0430\u043d\u043e \u0447\u0438\u0442\u0430\u0442\u0435\u043b\u0435\u043c).<\/p>\n<p>\u0415\u0441\u043b\u0438 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 bind\u00a0\u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0441\u044b\u043b\u043a\u0438 DNS-\u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0430\u0434\u0440\u0435\u0441\u0430 forwardes \u0432 \u0444\u0430\u0439\u043b\u0435\u00a0<em><strong>\/etc\/bind\/named.conf.options<\/strong><\/em><\/p>\n<p><code>forwarders {<\/code><br \/>\n<code> 192.168.1.1;<\/code><br \/>\n<code> };<\/code><\/p>\n<h5>4. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Kerberos.<\/h5>\n<p class=\"code bash\">\u0422\u0438\u043f\u043e\u0432\u0430\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f \u00a0\u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442\u0441\u044f \u0432 \u0444\u0430\u0439\u043b\u0435 <strong>\/etc\/krb5.conf<\/strong>. \u0412 \u043c\u043e\u043c\u0435\u043d\u0442 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0434\u043e\u043c\u0435\u043d\u0430 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0444\u0430\u0439\u043b<strong> \/var\/lib\/samba\/private\/krb5.conf<\/strong>, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0439 \u043c\u0438\u043d\u0438\u043c\u0430\u043b\u044c\u043d\u0443\u044e \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0443\u044e \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b AD.\u00a0\u041c\u043e\u0436\u043d\u043e \u043e\u0431\u043e\u0439\u0442\u0438\u0441\u044c\u00a0\u0438 \u044d\u0442\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0435\u0439, \u0441\u043e\u0437\u0434\u0430\u0432 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0441\u0441\u044b\u043b\u043a\u0443 \u043d\u0430 \u0444\u0430\u0439\u043b \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439\u00a0<strong>ln -sf \/var\/lib\/samba\/private\/krb5.conf \/etc\/krb5.conf. <\/strong>\u041d\u043e \u043c\u044b \u043d\u0435 \u0438\u0449\u0435\u043c \u043b\u0435\u0433\u043a\u0438\u0445 \u043f\u0443\u0442\u0435\u0439, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u043c \u0444\u0430\u0439\u043b\u00a0<strong>\/etc\/krb5.conf<\/strong> \u043a \u0432\u0438\u0434\u0443 (\u043f\u0435\u0440\u0432\u044b\u0435 \u0442\u0440\u0438 \u0441\u0442\u0440\u043e\u043a\u0438 \u0432 \u0441\u0435\u043a\u0446\u0438\u0438 [libdefaults] \u0438 \u0435\u0441\u0442\u044c \u043c\u0438\u043d\u0438\u043c\u0430\u043b\u044c\u043d\u0430\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f)<\/p>\n<p><code>[libdefaults]<\/code><br \/>\n<code> default_realm = UNLIS.LOCAL<\/code><br \/>\n<code> dns_lookup_realm = false<\/code><br \/>\n<code> dns_lookup_kdc = true<\/code><br \/>\n<code> krb4_config = \/etc\/krb.conf<\/code><br \/>\n<code> krb4_realms = \/etc\/krb.realms<\/code><br \/>\n<code> kdc_timesync = 1<\/code><br \/>\n<code> ccache_type = 4<\/code><br \/>\n<code> forwardable = true<\/code><br \/>\n<code> proxiable = true<\/code><\/p>\n<p><code>v4_instance_resolve = false<\/code><br \/>\n<code> v4_name_convert = {<\/code><br \/>\n<code> host = {<\/code><br \/>\n<code> rcmd = host<\/code><br \/>\n<code> ftp = ftp<\/code><br \/>\n<code> }<\/code><br \/>\n<code> plain = {<\/code><br \/>\n<code> something = something-else<\/code><br \/>\n<code> }<\/code><br \/>\n<code> }<\/code><br \/>\n<code> fcc-mit-ticketflags = true<\/code><br \/>\n<code> [realms]<\/code><br \/>\n<code> UNLIS.LOCAL = {<\/code><br \/>\n<code> kdc = debian<\/code><br \/>\n<code> admin_server = debian<\/code><br \/>\n<code> default_domain = UNLIS.LOCAL<\/code><br \/>\n<code> }<\/code><\/p>\n<p><code>[domain_realm]<\/code><br \/>\n<code> .unlis.local = UNLIS.LOCAL<\/code><br \/>\n<code> unlis.local = UNLIS.LOCAL<\/code><\/p>\n<h5>4. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 NTP.<\/h5>\n<p>\u041c\u0438\u043d\u0438\u043c\u0430\u043b\u044c\u043d\u0430\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f <strong>\/etc\/ntp.conf<\/strong><\/p>\n<p><code># Local clock (Note: This is not the localhost address!)<\/code><br \/>\n<code> server 127.127.1.0<\/code><br \/>\n<code> fudge 127.127.1.0 stratum 10<\/code><\/p>\n<p><code># The source, where we are receiving the time from<\/code><br \/>\n<code> server 0.pool.ntp.org iburst prefer<\/code><\/p>\n<p><code>driftfile \/var\/lib\/ntp\/ntp.drift<\/code><br \/>\n<code> logfile \/var\/log\/ntp<\/code><br \/>\n<code> ntpsigndsocket \/var\/lib\/samba\/\/ntp_signd\/<\/code><\/p>\n<p><code># Access control<\/code><br \/>\n<code> # Default restriction: Only allow querying time (incl. ms-sntp) from this machine<\/code><br \/>\n<code> restrict default kod nomodify notrap nopeer mssntp<\/code><\/p>\n<p><code># Allow everything from localhost<\/code><br \/>\n<code> restrict 127.0.0.1<\/code><\/p>\n<p><code># Allow that our time source can only provide time and do nothing else<\/code><br \/>\n<code> restrict 0.pool.ntp.org mask 255.255.255.255 nomodify notrap nopeer noquery<\/code><\/p>\n<h5>5. \u041c\u044b \u0441\u0442\u0440\u043e\u0438\u043b\u0438-\u0441\u0442\u0440\u043e\u0438\u043b\u0438, \u0438 \u043d\u0430\u043a\u043e\u043d\u0435\u0446 \u043f\u043e\u0441\u0442\u0440\u043e\u0438\u043b\u0438!<\/h5>\n<p>\u041f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u0440\u044f\u0434 \u0442\u0435\u0441\u0442\u043e\u0432<\/p>\n<p>\u0422\u0435\u0441\u0442\u0438\u0440\u0443\u0435\u043c samba:<\/p>\n<p><code>root@debian:\/root# smbclient -L localhost -U%<\/code><br \/>\n<code> Domain=[UNLIS] OS=[Unix] Server=[Samba 4.1.17-Debian]<\/code><\/p>\n<p><code>Sharename Type Comment<\/code><br \/>\n<code> --------- ---- -------<\/code><br \/>\n<code> netlogon Disk<\/code><br \/>\n<code> sysvol Disk<\/code><br \/>\n<code> IPC$ IPC IPC Service (Samba 4.1.17-Debian)<\/code><br \/>\n<code> Domain=[UNLIS] OS=[Unix] Server=[Samba 4.1.17-Debian]<\/code><\/p>\n<p><code>Server Comment<\/code><br \/>\n<code> --------- -------<\/code><\/p>\n<p><code>Workgroup Master<\/code><br \/>\n<code> --------- -------<\/code><\/p>\n<p>\u0422\u0435\u0441\u0442\u0438\u0440\u0443\u0435\u043c DNS<\/p>\n<p><code>root@debian:\/root# nslookup unlis.local<\/code><br \/>\n<code> Server: 192.168.1.2<\/code><br \/>\n<code> Address: 192.168.1.2#53<\/code><\/p>\n<p><code>Name: unlis.local<\/code><br \/>\n<code> Address: 192.168.1.2<\/code><\/p>\n<p>\u0422\u0435\u0441\u0442\u0438\u0440\u0443\u0435\u043c Kerberos<\/p>\n<p><code>root@debian:\/root# kinit Administrator@UNLIS.LOCAL<\/code><br \/>\n<code> Password for Administrator@UNLIS.LOCAL:<\/code><br \/>\n<code> Warning: Your password will expire in 41 days on \u041f\u0442 27 \u043d\u043e\u044f 2015 14:34:46<\/code><\/p>\n<p><code>root@debian:\/root# klist<\/code><br \/>\n<code> Ticket cache: FILE:\/tmp\/krb5cc_0<\/code><br \/>\n<code> Default principal: Administrator@UNLIS.LOCAL<\/code><\/p>\n<p><code>Valid starting Expires Service principal<\/code><br \/>\n<code> 16.10.2015 15:07:12 17.10.2015 01:07:12 krbtgt\/UNLIS.LOCAL@UNLIS.LOCAL<\/code><br \/>\n<code> renew until 17.10.2015 15:07:07<\/code><\/p>\n<p>\u0422\u0435\u0441\u0442\u0438\u0440\u0443\u0435\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 DNS-\u0437\u0430\u043f\u0438\u0441\u0435\u0439<\/p>\n<p><code>root@debian:\/root# samba_dnsupdate --verbose --all-names<\/code><br \/>\n<code> IPs: ['192.168.1.2']<\/code><br \/>\n<code> Calling nsupdate for A debian.unlis.local 192.168.1.2 (add)<\/code><br \/>\n<code> Outgoing update query:<\/code><br \/>\n<code> ;; -&gt;&gt;HEADER&lt;&lt;- opcode: UPDATE, status: NOERROR, id: 0<\/code><br \/>\n<code> ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0<\/code><br \/>\n<code> ;; UPDATE SECTION:<\/code><br \/>\n<code> debian.unlis.local. 900 IN A 192.168.1.2<\/code><\/p>\n<p><code>&lt;...&gt;<\/code><\/p>\n<p>\u0414\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u043e\u043c \u0434\u043e\u043c\u0435\u043d\u0430 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u00a0<strong><a href=\"http:\/\/www.microsoft.com\/ru-RU\/download\/details.aspx?id=7887\">\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f Windows 7<\/a>, \u00a0<\/strong>\u0434\u043b\u044f \u00a0<strong><a title=\"http:\/\/www.microsoft.com\/downloads\/en\/details.aspx?FamilyID=86b71a4f-4122-44af-be79-3f101e533d95\" href=\"http:\/\/www.microsoft.com\/downloads\/en\/details.aspx?FamilyID=86b71a4f-4122-44af-be79-3f101e533d95\">Windows XP Pro<\/a> <\/strong>+<strong> <a title=\"http:\/\/download.microsoft.com\/download\/3\/e\/4\/3e438f5e-24ef-4637-abd1-981341d349c7\/WindowsServer2003-KB892777-SupportTools-x86-ENU.exe\" href=\"http:\/\/download.microsoft.com\/download\/3\/e\/4\/3e438f5e-24ef-4637-abd1-981341d349c7\/WindowsServer2003-KB892777-SupportTools-x86-ENU.exe\">\u0432\u0442\u043e\u0440\u0430\u044f \u0447\u0430\u0441\u0442\u044c<\/a>.<\/strong><\/p>\n<h5>6.\u00a0\u041b\u0438\u0442\u0435\u0440\u0430\u0434\u0443\u0440\u0430<\/h5>\n<ol>\n<li><strong><a href=\"https:\/\/wiki.samba.org\/index.php\/Setup_a_Samba_Active_Directory_Domain_Controller\" target=\"_blank\" rel=\"noopener noreferrer\">\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Samba \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430<\/a><\/strong><\/li>\n<li><strong><a href=\"https:\/\/wiki.samba.org\/index.php\/Configure_BIND_as_backend_for_Samba_AD\" target=\"_blank\" rel=\"noopener noreferrer\">\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 BIND \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430<\/a><\/strong><\/li>\n<li><strong><a href=\"https:\/\/wiki.samba.org\/index.php\/Time_syncronisation\" target=\"_blank\" rel=\"noopener noreferrer\">\u0421\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0430\u0446\u0438\u044f \u0432\u0440\u0435\u043c\u0435\u043d\u0438<\/a><\/strong><\/li>\n<\/ol>\n<p>\u0415\u0441\u043b\u0438 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430 \u043a\u043e\u043c\u0443-\u0442\u043e \u043f\u043e\u043a\u0430\u0437\u0430\u043b\u043e\u0441\u044c \u043c\u0430\u043b\u043e &#8212; \u0447\u0438\u0442\u0430\u0435\u043c \u0441\u0442\u0430\u0442\u044c\u044e \u043f\u0440\u043e\u00a0<a href=\"https:\/\/unlis.ru\/?p=1017\" target=\"_blank\" rel=\"noopener noreferrer\">\u0440\u0435\u0437\u0435\u0440\u0432\u043d\u044b\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440 \u0434\u043e\u043c\u0435\u043d\u0430 \u043d\u0430 Debian 8<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#171;\u0410 \u043a\u0430\u043a\u0430\u044f \u0440\u0430\u0437\u043d\u0438\u0446\u0430?&#187; &#8212; \u0441\u043a\u0430\u0436\u0435\u0442\u0435 \u0432\u044b, \u0438 \u0431\u0443\u0434\u0435\u0442\u0435 \u043d\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u043f\u0440\u0430\u0432\u044b. \u0412\u043e-\u043f\u0435\u0440\u0432\u044b\u0445, \u043d\u0435 \u043d\u0430\u0434\u043e \u0443\u0434\u043e\u0432\u043b\u0435\u0442\u0432\u043e\u0440\u044f\u0442\u044c \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[16,14,15,13,17],"class_list":["post-501","post","type-post","status-publish","format-standard","hentry","category-computers","tag-activedirectory","tag-debian","tag-linux","tag-samba","tag-17","wpcat-6-id"],"_links":{"self":[{"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/posts\/501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/unlis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=501"}],"version-history":[{"count":29,"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/posts\/501\/revisions"}],"predecessor-version":[{"id":1815,"href":"https:\/\/unlis.ru\/index.php?rest_route=\/wp\/v2\/posts\/501\/revisions\/1815"}],"wp:attachment":[{"href":"https:\/\/unlis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unlis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unlis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}