Files
configpolicy/roles/samba-dc/templates/smb.conf.j2
Dustin C. Hatch 5a91cb731a samba-dc: Configure samba4 winbind
The *samba-dc* role now configures `winbindd` on domain controllers to
support identity mapping on the local machine. This will allow domain
users to log into the domain controller itself, e.g. via SSH.

The Fedora packaging of *samba4* still has some warts. Specifically, it
does not have a proper SELinux policy, so some work-arounds need to be
put into place in order for confined processes to communicate with
winbind.
2018-03-11 18:16:17 -05:00

21 lines
497 B
Django/Jinja

# Global parameters
[global]
netbios name = {{ ansible_hostname|upper }}
realm = {{ krb5_realm }}
server role = active directory domain controller
workgroup = {{ workgroup }}
{% if samba_is_first_dc and samba_dc_use_rfc2307 %}
idmap_ldb:use rfc2307 = yes
{% endif %}
template homedir = {{ winbind_template_homedir }}
template shell = /bin/bash
[netlogon]
path = /var/lib/samba/sysvol/{{ krb5_realm|lower }}/scripts
read only = No
[sysvol]
path = /var/lib/samba/sysvol
read only = No