From c97b7846ced63e38ad20a60f335adde3026d6d17 Mon Sep 17 00:00:00 2001 From: phil Date: Sun, 25 Jun 2023 00:51:10 +0200 Subject: [PATCH] ajout samba-ad-dc pour debian 12 --- README.md | 4 +- samba-ad-dc/Vagrantfile | 78 ++++++++++++++++ samba-ad-dc/playbook.yml | 186 +++++++++++++++++++++++++++++++++++++++ 3 files changed, 267 insertions(+), 1 deletion(-) create mode 100644 samba-ad-dc/Vagrantfile create mode 100644 samba-ad-dc/playbook.yml diff --git a/README.md b/README.md index 0ab52f0..b497d54 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # vagrant -le 2023-05-04 11h46 - ps +le 2023-06-25 00h30 - ps Ce dépôt héberge des **Vagrantfile** dont : * **dns** : Vagrantfile pour 2 serveurs **Bind9** (1 maitre et un esclave), tests **goss** chainés @@ -21,4 +21,6 @@ Ce dépôt héberge des **Vagrantfile** dont : * **k3s-awx** : Vagrantfile + script **inst-awx** pour installation **Ansible AWX** sur **k3s** avec **awx-on-k3s** * **minione** * **rundeck** : Vagrantfile + playbook pour installation avec Mariadb + * **samba-ad-dc** : Vagrantfile + playbook pour **Samba 4.17 ad-dc** sur **Debian 12 Bookworm** + * **wp-lb** : Wordpress web1 et web2, lb HaProxy, nfs, db Mariadb - Vagrantfile + playbooks diff --git a/samba-ad-dc/Vagrantfile b/samba-ad-dc/Vagrantfile new file mode 100644 index 0000000..0730b91 --- /dev/null +++ b/samba-ad-dc/Vagrantfile @@ -0,0 +1,78 @@ +# -*- mode: ruby -*- +# vi: set ft=ruby : + +# All Vagrant configuration is done below. The "2" in Vagrant.configure +# configures the configuration version (we support older styles for +# backwards compatibility). Please don't change it unless you know what +# you're doing. +Vagrant.configure("2") do |config| + # The most common configuration options are documented and commented below. + # For a complete reference, please see the online documentation at + # https://docs.vagrantup.com. + + # Every Vagrant development environment requires a box. You can search for + # boxes at https://vagrantcloud.com/search. + config.vm.box = "debian/bookworm64" + config.vm.hostname = "dc1" + + # Disable automatic box update checking. If you disable this, then + # boxes will only be checked for updates when the user runs + # `vagrant box outdated`. This is not recommended. + # config.vm.box_check_update = false + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine. In the example below, + # accessing "localhost:8080" will access port 80 on the guest machine. + # NOTE: This will enable public access to the opened port + # config.vm.network "forwarded_port", guest: 80, host: 8080 + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine and only allow access + # via 127.0.0.1 to disable public access + # config.vm.network "forwarded_port", guest: 80, host: 8080, host_ip: "127.0.0.1" + + # Create a private network, which allows host-only access to the machine + # using a specific IP. + # config.vm.network "private_network", ip: "192.168.33.10" + config.vm.network "private_network", ip: "192.168.56.10" + + # Create a public network, which generally matched to bridged network. + # Bridged networks make the machine appear as another physical device on + # your network. + # config.vm.network "public_network" + + # Share an additional folder to the guest VM. The first argument is + # the path on the host to the actual folder. The second argument is + # the path on the guest to mount the folder. And the optional third + # argument is a set of non-required options. + # config.vm.synced_folder "../data", "/vagrant_data" + + # Disable the default share of the current code directory. Doing this + # provides improved isolation between the vagrant box and your host + # by making sure your Vagrantfile isn't accessable to the vagrant box. + # If you use this you may want to enable additional shared subfolders as + # shown above. + # config.vm.synced_folder ".", "/vagrant", disabled: true + + # Provider-specific configuration so you can fine-tune various + # backing providers for Vagrant. These expose provider-specific options. + # Example for VirtualBox: + # + # config.vm.provider "virtualbox" do |vb| + # # Display the VirtualBox GUI when booting the machine + # vb.gui = true + # + # # Customize the amount of memory on the VM: + # vb.memory = "1024" + # end + # + # View the documentation for the provider you are using for more + # information on available options. + + # Enable provisioning with a shell script. Additional provisioners such as + # Ansible, Chef, Docker, Puppet and Salt are also available. Please see the + # documentation for more information about their specific syntax and use. + config.vm.provision "ansible" do |ansible| + ansible.playbook = "playbook.yml" + end +end diff --git a/samba-ad-dc/playbook.yml b/samba-ad-dc/playbook.yml new file mode 100644 index 0000000..c36c29e --- /dev/null +++ b/samba-ad-dc/playbook.yml @@ -0,0 +1,186 @@ +--- +- hosts: all + become: true + + vars: + samba_dc_dns_domain: "ad.sio.lan" + samba_dc_hostname: "dc1.ad.sio.lan" + samba_dc_hostname_short: "dc1" + samba_dc_ip: "192.168.56.10" + samba_dc_net: "192.168.56.0/24" + samba_dc_realm: "AD.SIO.LAN" + samba_dc_workgroup: "AD" + samba_dc_domain: "AD" + samba_dc_admin_password: "Azerty1+" + samba_dc_dns_backend: "SAMBA_INTERNAL" # ou bien "BIND9_DLZ"  + + pre_tasks: + - name: Set timezone to Europe/Paris + timezone: + name: Europe/Paris + + - name: Update apt cache if needed. + apt: + update_cache: true + cache_valid_time: 3600 + + tasks: + - name: Pre - set hostname {{ samba_dc_hostname }} + copy: + content: | + {{ samba_dc_hostname }} + dest: /etc/hostname + + - name: Pre - set /etc/hosts + copy: + content: | + 127.0.0.1 localhost + {{ samba_dc_ip }} {{ samba_dc_hostname }} {{ samba_dc_hostname_short }} + dest: /etc/hosts + + - name: Pre - "Installe paquets de base" + ansible.builtin.apt: + state: present + name: + - acl + - git + - curl + - wget + - sudo + - unzip + - vim + - gnupg + - tmux + - dnsutils + - apt-transport-https + - chrony + + - name: Samba - "Installe paquets Samba" + ansible.builtin.apt: + state: present + name: + - samba + - winbind + - libnss-winbind + - krb5-user + - smbclient + - ldb-tools + - python3-cryptography + + - name: Samba - Configuration Kerberos + copy: + content: | + [libdefaults] + default_realm = {{ samba_dc_realm }} + dns_lookup_kdc = true + dns_lookup_realm = false + dest: /etc/krb5.conf + + - name: Samba - Nettoie smb.conf + file: + path: "/etc/samba/smb.conf" + state: absent + + - name: Samba - Configure DC + command: samba-tool domain provision --realm={{ samba_dc_realm }} --domain {{ samba_dc_domain }} --server-role=dc + + - name: Samba - Mdp Administrator + command: samba-tool user setpassword administrator --newpassword={{ samba_dc_admin_password }} + + - name: Samba - Set dns forwarder . + lineinfile: + dest: "/etc/samba/smb.conf" + regexp: "dns forwarder =.*" + line: "dns forwarder = 9.9.9.9" + state: present + + - name: Samba - set resolv.conf + copy: + content: | + search {{ samba_dc_dns_domain }} + nameserver 127.0.0.1 + dest: /etc/resolv.conf + + - name: Samba - rm krb5.conf dans samba + file: + path: /var/lib/samba/private/krb5.conf + state: absent + + - name: Samba - ln krb5.conf de samba vers standard + file: + src: /etc/krb5.conf + dest: /var/lib/samba/private/krb5.conf + force: true + state: link + + - name: SAmba - unmask and enable samba-ad-dc + ansible.builtin.systemd: + name: samba-ad-dc + masked: false + enabled: true + + - name: Samba - mask samba + ansible.builtin.systemd: + name: samba + masked: true + enabled: false + + - name: Samba - mask winbind + ansible.builtin.systemd: + name: winbind + masked: true + enabled: false + + - name: Samba - mask smbd + ansible.builtin.systemd: + name: smbd + masked: true + enabled: false + + - name: Samba - mask nmbd + ansible.builtin.systemd: + name: nmbd + masked: true + enabled: false + + - name: Samba - reboot + reboot: + + - name: Samba - set resolv.conf + copy: + content: | + search {{ samba_dc_dns_domain }} + nameserver 127.0.0.1 + dest: /etc/resolv.conf + + + - name: Samba - Test smbclient + command: smbclient -L localhost -N + + - name: SAmba - test DNS SRV _ldap sur TCP + command: host -t SRV _ldap._tcp.{{ samba_dc_dns_domain }} + + - name: Samba - test DNS SRV _kerberos sur UDP + command: host -t SRV _kerberos._udp.{{ samba_dc_dns_domain }} + + - name: Samba - test DNS A pour dc + command: host -t A {{ samba_dc_hostname }} + + - name: Chrony - configuration + ansible.builtin.blockinfile: + path: /etc/chrony/chrony.conf + block: | + bindcmdaddress {{ samba_dc_ip }} + + # The source, where we are receiving the time from + server 0.pool.ntp.org iburst + server 1.pool.ntp.org iburst + server 2.pool.ntp.org iburst + + allow {{ samba_dc_net }} + + - name: Chrony - redemarrage + service: + name: chrony + state: restarted +