FreeIPA: Difference between revisions

From Leo's Notes
This page was last edited on 7 March 2022, at 04:54.
No edit summary
No edit summary
Line 1: Line 1:
== Installation ==
== Installation ==
Here are my notes as I fumble my way setting up FreeIPA.


=== Docker ===
=== Docker ===
Line 66: Line 67:


=== Samba integration ===
=== Samba integration ===
The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.
The <code>freeipa-client-samba</code> tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.


To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.
To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.


First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:
==== On the FreeIPA server ====
{{Highlight
First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:{{Highlight
| code = # ldapmodify <<EOF
| code = # ldapmodify <<EOF
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
Line 83: Line 84:
| lang = terminal
| lang = terminal
}}
}}
Install the adtrust components on the FreeIPA server. Install <code>ipa-server-trust-ad</code> and run <code>ipa-adtrust-install --add-sids</code>. Ensure that your hostname is set to the FQDN of the hostname otherwise this process will fail. If you are using an external DNS server, ensure that the additional service records are present.
Once this is done, try changing an account password. You should see the <code>ipaNTHash</code> field get populated. This is important as the samba ipasam module will use this.
'''The following is probably not needed:'''
Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running <code>kinit admin</code>).
Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running <code>kinit admin</code>).
{{Highlight
{{Highlight
Line 112: Line 121:
}}
}}


==== On the Samba server ====
You can either use a specific binding credential that's shared across all your samba servers, or use the machine's cifs service account to authenticate to the LDAP server.
I tried to do the following using the admin account as the bind DN: ('''this is probably a bad idea''')
{{Highlight
| code = [global]
# freeipa configurations
passdb backend = ipasam:ldap://home.steamr.com
ldap admin dn = uid=admin,cn=users,cn=accounts,dc=home,dc=steamr,dc=com
ldapsam:trusted = yes
ldap suffix = cn=accounts,dc=home,dc=steamr,dc=com
ldap user suffix = cn=users,cn=accounts
ldap machine suffix = cn=computers,cn=accounts
ldap group suffix = cn=groups,cn=accounts
ldap passwd sync = only
ldap ssl = no
| lang = text
}}
Run <code>smbpasswd -w password</code> to set your bind credential passwords. 
The other way would be to use a service account. The easiest way is to install the <code>freeipa-client-samba</code> package and then run <code>ipa-client-samba</code>. This should automatically set up the cifs service accounts for this particular samba server, get the samba keytab file in /etc/samba/samba.keytab, and then tweak the smb.conf file to use this keytab file. This also doesn't seem to work as samba doesn't start... hmm
Alternatively, you could try setting a keytab file here so that samba uses a service account in the keytab to authenticate. Perhaps something like this, as [https://web.tecnico.ulisboa.pt/~joaomiguelvieira/public/docs/tutorials/configure_samba_to_use_freeipa_authentication.pdf outlined in this document].
{{Highlight
| code = dedicated keytab file = FILE:/etc/samba/samba.keytab
kerberos method = dedicated keytab
| lang = text
}}


On the FreeIPA server, run ipa-adtrust-install --add-sids. Ensure  that your hostname is set to the FQDN of the hostname otherwise this process will fail.
Your samba server should have the ipa-adtrust-install package. If you don't see it, you likely need to enable a dnf module stream.


== Tasks ==


=== Join a computer to a FreeIPA ===
Use the <code>ipa-client-install</code> command to add a computer to a FreeIPA server. This should also automatically add a computer account, generate a keytab file, and tweak sssd to use FreeIPA as an authentication mechanism.
{{Highlight
| code = # ipa-client-install -U -p admin -w $Password --server ipa.home.steamr.com --domain home.steamr.com --force-join --no-ntp --fixed-primary
| lang = terminal
}}


== Troubleshooting ==
== Troubleshooting ==
Line 147: Line 192:
| lang = text
| lang = text
}}
}}
==== Can't find the ipa-adtrust-install package ====
The FreeIPA packages are under a different app stream repo. Enable it by running <code>dnf -y module enable idm:DL1</code>.

Revision as of 04:54, 7 March 2022

Installation

Here are my notes as I fumble my way setting up FreeIPA.

Docker

There is an official Docker container that has a complete FreeIPA installation. This container uses systemd to start up FreeIPA along with the other related services such as OpenLDAP, Bind, and Kerberos. See more at: https://github.com/freeipa/freeipa-container

Use the following docker-compose.yml stack to quickly get started with FreeIPA:

version: '3.3'

services:

  freeipa:
    image: freeipa/freeipa-server:rocky-8
    restart: unless-stopped
    tty: true
    stdin_open: true
    hostname: ipa
    domainname: home.steamr.com
    extra_hosts:
      - "ipa.home.steamr.com:10.1.2.12"
    environment:
      - IPA_SERVER_HOSTNAME=ipa.home.steamr.com
      - IPA_SERVER_IP=10.1.2.12
      - DNS=10.1.0.8
      - TZ=America/Edmonton
    command:
      - ipa-server-install
      - --realm=home.steamr.com
      - --domain=home.steamr.com
      - --ds-password=xxxxxxxxxx
      - --admin-password=xxxxxxxxxx
      - --no-host-dns
      - --setup-dns
      - --auto-forwarders
      - --allow-zone-overlap
      - --no-dnssec-validation
      - --unattended
    sysctls:
      - net.ipv6.conf.all.disable_ipv6=0
    volumes:
      - ./data:/data
      - ./logs:/var/logs
      - /sys/fs/cgroup:/sys/fs/cgroup:ro
    tmpfs:
      - /run
      - /var/cache
      - /tmp
    cap_add:
      - SYS_TIME
    ports:
      - "10.1.2.12:80:80/tcp"
      - "10.1.2.12:443:443/tcp"
      # DNS
      - "10.1.2.12:53:53/tcp"
      - "10.1.2.12:53:53/udp"
      # LDAP(S)
      - "10.1.2.12:389:389/tcp"
      - "10.1.2.12:636:636/tcp"
      # Kerberos
      - "10.1.2.12:88:88/tcp"
      - "10.1.2.12:464:464/tcp"
      - "10.1.2.12:88:88/udp"
      - "10.1.2.12:464:464/udp"

Samba integration

The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.

To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.

On the FreeIPA server

First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:

# ldapmodify <<EOF
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
changetype: modify
add: ipaUserObjectClasses
ipaUserObjectClasses: sambaSAMAccount
-
add: ipaGroupObjectClasses
ipaGroupObjectClasses: sambaGroupMapping
EOF


Install the adtrust components on the FreeIPA server. Install ipa-server-trust-ad and run ipa-adtrust-install --add-sids. Ensure that your hostname is set to the FQDN of the hostname otherwise this process will fail. If you are using an external DNS server, ensure that the additional service records are present.

Once this is done, try changing an account password. You should see the ipaNTHash field get populated. This is important as the samba ipasam module will use this.

The following is probably not needed:

Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running kinit admin).

ldapadd <<EOF
dn: cn=SambaSid,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
dnatype: sambaSID
dnaprefix: S-1-5-21-2049073866-1371207509-1214748462
dnainterval: 1
dnamagicregen: assign
dnafilter: (|(objectclass=sambasamaccount)(objectclass=sambagroupmapping))
dnascope: dc=home,dc=steamr,dc=com
cn: SambaSid
dnanextvalue: 2

dn: cn=sambaGroupType,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
cn: sambaGroupType
dnatype: sambaGroupType
dnainterval: 1
dnamagicregen: assign
dnafilter: (objectClass=sambagroupmapping)
dnascope: dc=home,dc=steamr,dc=com
dnanextvalue: 2
EOF

On the Samba server

You can either use a specific binding credential that's shared across all your samba servers, or use the machine's cifs service account to authenticate to the LDAP server.

I tried to do the following using the admin account as the bind DN: (this is probably a bad idea)

[global]
	# freeipa configurations
	passdb backend = ipasam:ldap://home.steamr.com
	ldap admin dn = uid=admin,cn=users,cn=accounts,dc=home,dc=steamr,dc=com
	ldapsam:trusted = yes
	ldap suffix = cn=accounts,dc=home,dc=steamr,dc=com
	ldap user suffix = cn=users,cn=accounts
	ldap machine suffix = cn=computers,cn=accounts
	ldap group suffix = cn=groups,cn=accounts
	ldap passwd sync = only
	ldap ssl = no

Run smbpasswd -w password to set your bind credential passwords.

The other way would be to use a service account. The easiest way is to install the freeipa-client-samba package and then run ipa-client-samba. This should automatically set up the cifs service accounts for this particular samba server, get the samba keytab file in /etc/samba/samba.keytab, and then tweak the smb.conf file to use this keytab file. This also doesn't seem to work as samba doesn't start... hmm

Alternatively, you could try setting a keytab file here so that samba uses a service account in the keytab to authenticate. Perhaps something like this, as outlined in this document.

dedicated keytab file = FILE:/etc/samba/samba.keytab
 kerberos method = dedicated keytab

Your samba server should have the ipa-adtrust-install package. If you don't see it, you likely need to enable a dnf module stream.

Tasks

Join a computer to a FreeIPA

Use the ipa-client-install command to add a computer to a FreeIPA server. This should also automatically add a computer account, generate a keytab file, and tweak sssd to use FreeIPA as an authentication mechanism.

# ipa-client-install -U -p admin -w $Password --server ipa.home.steamr.com --domain home.steamr.com --force-join --no-ntp --fixed-primary

Troubleshooting

Error: did not receive Kerberos credentials

Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an ipa: ERROR: did not receive Kerberos credentials error. Fix this by running:

## Renew/obtain Kerberos tickets for 'admin'
# kinit admin
Password for admin@HOME.STEAMR.COM:  ****

Verify if your tickets are available with klist:

# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@STEAMR.COM

Valid starting     Expires            Service principal
03/06/22 14:44:35  03/07/22 14:39:47  krbtgt/STEAMR.COM@STEAMR.COM

Container issues

  • mounting /var/log causes the install to break. Something about unable to delete a file in /var/log for whatever reason.
  • Error with AssertionError: Another instance named 'HOME-STEAMR-COM' may already exist. I can't figure out what's causing lib389 to think there's another instance. I built a container image on top of this image with the assertion patched out. This seemed to have fixed the issue.
  • FROM freeipa/freeipa-server:rocky-8
    RUN sed 's/assert_c(len(insts)/# assert_c(len(insts)/' -i /usr/lib/python3.6/site-packages/lib389/instance/setup.py
    

Can't find the ipa-adtrust-install package

The FreeIPA packages are under a different app stream repo. Enable it by running dnf -y module enable idm:DL1.