¡¡¡¡ÕâÆª¼¼ÇÉÎÄÕ½«ÏòÄãչʾÔÚÔËÐÐSambaµÄÖ÷»úƽ̨ºÍMicrosoft Windows»·¾³Ö®¼ä½øÐÐÐͬ¹¤×÷µÄÖ÷ÒªÒòËØ£¬ÒÔ¼°´Ë»·¾³Ï±ØÐèµÄ·þÎñ¡£ÔÚµÚÒ»²¿·Ö£¬ÎÒ½«½²ÊöÔÚÒì¹¹ÐÍIT»·¾³ºÍ»î¶¯Ä¿Â¼ÓòÖÐд×÷´æÔڵĹÌÓÐÎÊÌâ¡£ÔÚµÚ¶þ²¿·Ö£¬ÎÒ½«Ìṩȡ´úWindows NT 4ÓòºÍ½«SQUIDºÍWindowsÍøÂçÕûºÏµÄ¼¼ÇÉ¡£
¡¡¡¡µ±È»£¬Ðí¶àITרҵÈËÔ±¶¼ÊÇLinux°®ºÃÕߣ¬ËüÃÇÏëÔÚÆóÒµÖÐÔËÐÐLinux£¬ÉõÖÁÔÚÆóÒµÖÐÖ»ÔËÐÐLinux¡£ÄÇÑùµÄ»°£¬ÄãµÄÔËÆø¿ÉÕæ²»´í;²»¹ý£¬ÁíÒ»·½Ã棬¶àÊýÇé¿öÏ£¬¼¸ºõËùÓеÄÈ˵Ť×÷»·¾³¶¼ÊÇÒì¹¹Ð͵ÄITÊÀ½ç¡£Òò´Ë£¬ÔÚ¶àÖÖÆ½Ì¨ÏÂÐͬ¹¤×÷¶ÔÆóÒµÀ´ËµÊDZØÐèÍê³ÉµÄÇé¿ö£¬Ö»ÓÐÕâÑùÆóÒµ²ÅÄܹ»ÔË×÷µÄ¸üºÃ£¬¶øSambaÄܹ»°ïÖúϵͳ¹ÜÀíÈËÔ±½â¾öÕâÖÖÐèÇó¡£
¡¡¡¡µ±ITÒì¹¹²úÉúʱ£¬Ò»¸öÀíËùÓ¦µ±µÄÇé¿öÊ±ÍøÂç¹ÜÀíÈËÔ±¶ÔÈçºÎ½«SambaµÄÎļþºÍ´òÓ¡·þÎñÕûºÏ½øÈëËûÃÇÒѾ´æÔÚµÄMicrosoft»î¶¯Ä¿Â¼(Active Directory)»·¾³ÖС£Í¬Ñù£¬ÈÔ¾ÉÔÚʹÓÃMicrosoft Windows NT 4·ç¸ñµÄÓëµÄµØµã£¬¶ÔSamba-3ÈçºÎÄܹ»½«ÓòÓû§Õ˺ÅÇ¨ÒÆµ½Samba·þÎñÆ÷ÉϺܸÐÐËȤ£¬¶øÄÇЩʹÓÃMicrosoft ISA´úÀí·þÎñÆ÷µÄµØ·½£¬Ôò¶ÔSamba½áºÏSquidÌṩÓëMicrosoft ISA´úÀí·þÎñÆ÷ÏàËÆÄÜÁ¦µÄ¸Ðµ½·Ç³£¸ßÐË¡£
¡¡¡¡ÐèÒª½â¾öµÄÎÊÌâ
¡¡¡¡SambaÊÇÒ»¸öÔËÐÐÓÚ¶àÖÖ²Ù×÷ϵͳƽ̨ÉϵÄÓû§¿Õ¼äÓ¦ÓÃÈí¼þ£¬²»¹ýËüÖ÷ÒªÔÚUnixºÍLinuxϵͳÉÏʹÓ㬲¢Ìṩ¸ßˮƽµÄÐͬ¹¤×÷ÄÜÁ¦¡£Àí½âSambaÖ÷»ú»·¾³ºÍMicrosoft WindowsÍøÂçÊÀ½çÖ®¼äµÄһЩ¹Ø¼ü²îÒ죬Äܹ»°ïÖúÎÒÃÇ¿´Çå³þËüÃÇÖ®¼ä´æÔڵĴí×Û¸´ÔÓµÄÐͬ¹¤×÷ÎÊÌâ¡£ÎÞÂÛÄÄÒ»ÖÖÎÊÌ⣬¶¼¿ÉÄÜÔì³ÉÕâÁ½¸öÍêÈ«²»Í¬ÊÀ½çµÄƽ̨Ðͬ¹¤×÷ÉϵÄÁÑ϶£¬Òò´ËÀí½âËüÃÇ£¬¶ÔÍøÂç¹ÜÀíÈËÔ±À´Ëµ£¬·Ç³£ÓаïÖú¡£
¡¡¡¡µäÐ͵ÄWindowsÍøÂç¹ÜÀíÈËÔ±²»ÐèÒª¹Ø×¢SambaÈçºÎ½øÐй¤×÷£¬ËûÖ»ÏëÔÚ¿ìËÙ¶à±äµÄITÉÏÃæ£¬ÈçºÎÄܹ»Âú×ãÓû§µÄÐèÒª¡£
¡¡¡¡¹ÜÀíÔ±ºÍÍøÂç¾ÀíµÄ´ú±íÐÔÎÊÌâÓÐÒÔϼ¸¸ö:
¡¡¡¡l ÎÒÔõÑù×ö²ÅÄܹ»°ÑÎÒµÄSamba·þÎñÆ÷ÕûºÏ½øÎҵĻĿ¼(Active Directory)ÖУ¬ÒÔ±ãÓû§Äܹ»Í¸Ã÷µÄ·ÃÎÊËûÃǵÄÎļþ£¬¶øÎÞÐè¹ØÐÄËûÃǵÄÎļþ´æ´¢ÔÚÄÄÖÖ·þÎñÆ÷ÉÏ?
¡¡¡¡l ÎÒÔõÑù×ö²ÅÄܹ»Ìæ»»ÎÒÄÇÀÏ»¯µÄWindows NT 4Óò£¬²¢ÇÒÔÚ±ÜÃâÇ¨ÒÆµ½»î¶¯Ä¿Â¼(Active Directory)µÄÇé¿öÏ£¬±£Ö¤Ìæ»»¹ý³ÌÖв»»á¶ªÊ§Óû§Õ˺źÍÃÜÂë?
¡¡¡¡l ÎÒÔõÑù×ö²ÅÄܹ»ÏÞÖÆÃ¿¸öµÇ¼µ½Windows¹¤×÷Õ¾ÉϵÄÓû§£¬·ÃÎÊ´úÀí·þÎñÆ÷µÄȨÏÞ?
¡¡¡¡Under the hood(ñµ×ǬÀ¤£¬ÄÚÄ»Óë½âÃÜ)
¡¡¡¡¾ÙÊÀ¹«ÈϵÄÒ»¸öÊÂʵÊÇ£¬Microsoft WindowsʹÓõݲȫģÐÍÓëµäÐ͵ÄÔËÐÐSambaµÄUNIXÖ÷»úÍêÈ«²»Í¬¡£SambaÖ´ÐлúÖÆ½«Windows°²È«±êʶ·û(security identifiers£¬SIDs)ת»»ÎªUnix°²È«±êʶ·û(Unix security identifiers£¬UIDsºÍGIDs)£¬Ëù²ÉÓõÄת»»·½·¨ÒÀÀµÓÚSambaÊÇÈçºÎ²¿ÊðµÄ¡£
¡¡¡¡»î¶¯Ä¿Â¼(Active Directory)ÓòÓû§
¡¡¡¡½«Samba-3·þÎñÆ÷ÕûºÏ½øÈëÒ»¸öÒѾ´æÔÚµÄMicrosoft Windows »î¶¯Ä¿Â¼(Active Directory£¬ADS)»·¾³£¬ÐèҪʹÓûùÓÚKerberosµÄÑéÖ¤¡£Samba-3Äܹ»±»±àÒë³ÉÓëMIT Kerberos 1.3.1(»òÒÔÉϰ汾)»òHeimdal Kerberos 0.6.3(»òÒÔÉϰ汾)ÏàÁ¬½Ó¡£
¡¡¡¡ÓëADSÐͬ¹¤×÷µÄÅäÖÃÏîÄ¿¿ÉÒÔÔÚSamba-HOWTO-CollectionÎĵµ(µØ6Õ£¬6.4½Ú)ÖÐÕÒµ½¡£Ò»¸öSamba-3·þÎñÆ÷×÷ΪÓòÓû§·þÎñÆ÷¼ÓÈë»î¶¯Ä¿Â¼(Active Directory)ÓòµÄ¸üÏêϸµÄÀý×ÓÔòÔÚSamba GuideÎĵµµÄµÚ¾ÅÕÂÌṩ¡£
¡¡¡¡ÓйØWindows SIDsµ½UNIX UIDs/GIDsµÄÓ³É䣬Çë¹ÜÀíÈËÔ±·µ½Samba-HOWTO-CollectionµÄµÚ12Õ£¬ÕâÀïÓÐÈýÖÖ¿ÉÒÔʹÓÃÖ÷ÒªÓ³Éä·½·¨:
¡¡¡¡l ʹÓÃwinbindΪÿ̨»úÆ÷×öÓ³Éä(×¢Òâ:ÔÚËùÓÐ×÷ΪÓò³ÉÔ±µÄSamba·þÎñÆ÷ÉÏ£¬±»ÌØÊâµÄSIDÓ³Éäµ½µÄʵ¼ÊUID²¢²»Ò»¶¨Ïàͬ¡£);
¡¡¡¡l ʹÓÃwinbind_idmap£¬Õ⽫ʹÓÃÏà¹Ø±êʶ·û(relative identifier£¬RID)×é¼þ£¬½«Óû§µÄSID×÷ΪËûµÄUID(ÕâÖÖ·½·¨Ö»ÄÜÔÚµ¥Ò»ADSÓòÖÐʹÓÃ);
¡¡¡¡l ʹÓÃÒ»¸öLDAPĿ¼´æ´¢IDMAPÊý¾Ý¡£
¡¡¡¡IDMAP¹¦ÄÜÐèÒªName Service Switcher (NSS)ƽ̨֧³Ö¡£´ËÍ⣬ÔÚÖ§³Ö¿É²å°ÎÑé֤ģ¿é(Pluggable Authentication Modules£¬APM)µÄƽ̨ÉÏ£¬winbindÄܹ»ÌṩÒԻĿ¼(Active Directory)ÖлñµÃµÄµÇ¼Õ˺ŵǼ±¾µØUnix/LinuxµÄ¹¦ÄÜ¡£
¡¡¡¡SambaµÄwinbind¹¤¾ßΪÕûºÏÌṩÁËÒ»ÖÖ¼òµ¥Ò×ÓõÄÊֶΣ¬²¢ÇÒ³ýÈ¥ÁË´´½¨±¾µØUNIX»òLinuxÕ˺ŵÄÐèÒª¡£½á¹ûÊÇ×îÖÕÄܹ»Ìṩµ¥Ò»µÇ¼(Single-Sign-On£¬SSO)£¬²»¹ýÕâ²¢²»ÊÇÕâÖÖ¹¦ÄܵÄÕýÈ·ÊõÓï¡£´ËÖÖ¹¦ÄÜ×îÕýÈ·µÄÃèÊöÊǼ¯ÖйÜÀíºÍ¼¯Öд洢Óû§ºÍ×éÕ˺š£
¡¡¡¡ÔÚÁ÷Ðв¿ÊðSamba-3µÄ½ñÌ죬½«Samba-3·þÎñÆ÷ÕûºÏ½øÈë»î¶¯Ä¿Â¼(Active Directory)ÊÇÒ»¸ö¸ßÔö³¤µÄÁìÓò¡£
¡¡¡¡ÔÚµÄÒ»²¿·Ö£¬ÎÒÃÇÌÖÂÛÁËÔÚÒì¹¹ÐÍIT»·¾³ºÍ»î¶¯Ä¿Â¼(Active Directory)Óò³ÉÔ±ÖÐËù´æÔڵĹÌÓÐÎÊÌâ¡£¶øÔÚÕâ¸öµÚ¶þ²¿·ÖÖУ¬ÎÒ½«ÏòÄãÕ¹Ê¾Ìæ»»Windows NT 4ÓòºÍʹSQUIDÓëWindowsÍøÂçÕûºÏ¹¤×÷µÄ¼¼ÇÉ¡£
¡¡¡¡Ìæ»»Windows NT 4Óò
¡¡¡¡MicrosoftÔÚÐí¶àÄêǰÒѾ·¢³öÁËÍ£Ö¹Windows NT 4²Ù×÷ϵͳ֧³ÖµÄÏûÏ¢¡£ÏÖÔÚ£¬Microsoft¹Ù·½ÒѾ²»ÔÚΪWindows NT 4ÌṩÈκθüУ¬Õâ¾ÍʹÐí¶àÉÌÒµ¹«Ë¾²»µÃ²»ÑÏË࿼ÂÇ£¬ÊÇʹÓûĿ¼(Active Directory)Ìæ»»Windows NT 4£¬»¹ÊÇʹÓÃSamba-3³Ðµ£ÏñWindows NT 4Ò»Ñù·ç¸ñµÄÓò¿ØÖÆ¡£
¡¡¡¡ÐèÒªWindows NT 4Óò¿ØÖƵÄÕ¾µãͨ³£ÐèҪһ̨Ö÷Óò¿ØÖÆÆ÷(primary domain controller£¬PDC)£¬Ò²ÐèҪһ̨»ò¶ą̀±¸·ÝÓò¿ØÖÆÆ÷(backup domain controller£¬BDC)¡£ÔÚÕâÖÖÇé¿öÏ£¬ÊµÏÖSamba-3Óò¿ØÖÆÆ÷(PDC¼ÓÉÏBDC)µÄΨһ¿É¿¿µÄ·½·¨ÊÇʹÓÃLDAP´æ´¢Óû§¡¢×éºÍ»úÆ÷Õ˺ÅÐÅÏ¢¡£
¡¡¡¡Samba-3Óò¿ØÖÆÆ÷ʹÓõÄLDAPÄܹ»Ìṩ±ÈWindows NT 4Óò½á¹¹¸üÇ¿µÄÀ©Õ¹ÐÔÄÜ£¬ÒѾ³¬³öÁËMicrosoft Windows NT 4×ÊÉîµÄ¿ÉÄÜ¡£Samba-3Äܹ»±»ÅäÖÃΪʹÓöàÖØ²¢·¢LDAPĿ¼£¬Ã¿Ò»¸öLDAPĿ¼¶¼Äܹ»Ö´ÐÐÄ¿Â¼ÖØ¶¨ÏòºÍ/»òÖ¸Ïò¡£
¡¡¡¡Ò»¸öʾ·¶Ê¹ÓÃLDAPĿ¼×÷ΪSamba-3ºó¶ËµÄ²¿ÊðÀý×ÓÔÚ¡¶Samba-3 by Example.¡·Ò»ÊéµÄµÚ6Õ¸ø³ö£¬Äú¿ÉÒÔ´ÓÄÇÀï²é¿´¡£
¡¡¡¡ÔÚÒ»¸öSamba-3ÓòÖУ¬Samba-3Óò³ÉÔ±·þÎñÆ÷¿ÉÒÔ±»ÅäÖÃΪʹÓÃwinbind»òʹÓÃLDAPÌṩIDMAP¹¦ÄܺÍ×ÊÔ´ÔÚ¡¶Samba-3 by Example.¡·Ò»ÊéµÄµÚ9Õ£¬ÌṩÁËÒ»¸öÕâÑùµÄÀý×Ó¡£
¡¡¡¡SquidÓëWindowsÍøÂçµÄÕûºÏ
¡¡¡¡SquidÊÇÒ»¸öÁ÷ÐеÄWebºÍFTP´úÀí·þÎñÆ÷£¬ËüÖ§³Ö·þÎñÆ÷¶Ë²å¼þÄ£¿é¡£Ò»¸öÕâÑùµÄ²å¼þÄܹ»Ìṩ͸Ã÷µÄÑéÖ¤£¬ÒÔÏÞÖÆÄÇЩʹÓÃMicrosoft Internet ExplorerµÄWindows¿Í»§µÄ·ÃÎÊȨÏÞ¡£
¡¡¡¡Ò»¸ö¹ãΪÈËÖªµÄËùʹÓõÄÐÒéÊÇntlm_auth £¬ËüÄܹ»ÌṩNTLMSSP(NT¾ÖÓòÍø¹ÜÀí°²È«·þÎñÐÒ飬NT LanManager Security Service Protocol)¡£Õâ¸öÄ£¿éʹÓÃSambaµÄwinbindÀ´Ö´ÐÐNT/LMÑéÖ¤£¬ÔÚSquidµÄÍøÕ¾(http://devel.squid-cache.org/ntlm/squid_helper_protocol.html)ÉÏ£¬ÄúÄܹ»ÕÒµ½ÓйشËÐÒéµÄÏêϸÐÅÏ¢¡£
¡¡¡¡ÔÚ¡¶Samba-3 by Example.¡·Ò»ÊéµÄµÚ11Õ£¬Äú»¹¿ÉÒÔÕÒµ½Ê¹Óô˹¦ÄܵÄÒ»¸öÀý×Ó¡£ÐèҪעÒâµÄÊÇ£¬´ËÄ£¿éÖ»ÔÚÓû§ÊÇSquidÅäÖÃÎļþÖÐËùÖ¸³öµÄµ¥Ò»Óò³ÉԱʱ£¬²Å»áÓÐЧ¡£¹ÜÀíÔ±Ó¦¸Ã²é¿´ntlm_authÄ£¿éµÄmanÒ³Ãæ£¬»ñµÃ¸ü¶àÌØÊâµÄ¸½¼ÓÅäÖÃÐÅÏ¢ºÍÀý×Ó¡£
¡¡¡¡×ܽá
¡¡¡¡ÔÚÌṩÐͬ¹¤×÷£¬³¬Ô½µ¥´¿µÄÎļþºÍ´òÓ¡¹²Ïí·½Ãæ£¬Samba¾ßÓÐÖÚ¶àµÄÌØµã¡£Ç°ÃæµÄÌÖÂÛÌṩÁ˷dz£ÓмÛÖµµÄ²Î¿¼Äܹ»°ïÖúWindowsÍøÂç¹ÜÀíÈËÔ±ÕÒµ½ÓÐÓõÄÐÅÏ¢£¬ÕâЩÐÅÏ¢Óи÷ÖÖ¹¦ÄܵÄÌØµãÒÔ¼°ÈçºÎʹÓÃËüÃÇ¡£
,| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |