FreeIPA
Installation
Docker
There is an official Docker container that has a complete FreeIPA installation. This container uses systemd to start up FreeIPA along with the other related services such as OpenLDAP, Bind, and Kerberos. See more at: https://github.com/freeipa/freeipa-container
Use the following docker-compose.yml stack to quickly get started with FreeIPA:
version: '3.3'
services:
freeipa:
image: freeipa/freeipa-server:rocky-8
restart: unless-stopped
tty: true
stdin_open: true
hostname: ipa
domainname: home.steamr.com
extra_hosts:
- "ipa.home.steamr.com:10.1.2.12"
environment:
- IPA_SERVER_HOSTNAME=ipa.home.steamr.com
- IPA_SERVER_IP=10.1.2.12
- DNS=10.1.0.8
- TZ=America/Edmonton
command:
- ipa-server-install
- --realm=home.steamr.com
- --domain=home.steamr.com
- --ds-password=xxxxxxxxxx
- --admin-password=xxxxxxxxxx
- --no-host-dns
- --setup-dns
- --auto-forwarders
- --allow-zone-overlap
- --no-dnssec-validation
- --unattended
sysctls:
- net.ipv6.conf.all.disable_ipv6=0
volumes:
- ./data:/data
- ./logs:/var/logs
- /sys/fs/cgroup:/sys/fs/cgroup:ro
tmpfs:
- /run
- /var/cache
- /tmp
cap_add:
- SYS_TIME
ports:
- "10.1.2.12:80:80/tcp"
- "10.1.2.12:443:443/tcp"
# DNS
- "10.1.2.12:53:53/tcp"
- "10.1.2.12:53:53/udp"
# LDAP(S)
- "10.1.2.12:389:389/tcp"
- "10.1.2.12:636:636/tcp"
# Kerberos
- "10.1.2.12:88:88/tcp"
- "10.1.2.12:464:464/tcp"
- "10.1.2.12:88:88/udp"
- "10.1.2.12:464:464/udp"
Samba integration
The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.
To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.
First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:
# ldapmodify <<EOF
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
changetype: modify
add: ipaUserObjectClasses
ipaUserObjectClasses: sambaSAMAccount
-
add: ipaGroupObjectClasses
ipaGroupObjectClasses: sambaGroupMapping
EOF
Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running kinit admin).
ldapadd <<EOF
dn: cn=SambaSid,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
dnatype: sambaSID
dnaprefix: S-1-5-21-2049073866-1371207509-1214748462
dnainterval: 1
dnamagicregen: assign
dnafilter: (|(objectclass=sambasamaccount)(objectclass=sambagroupmapping))
dnascope: dc=home,dc=steamr,dc=com
cn: SambaSid
dnanextvalue: 2
dn: cn=sambaGroupType,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
cn: sambaGroupType
dnatype: sambaGroupType
dnainterval: 1
dnamagicregen: assign
dnafilter: (objectClass=sambagroupmapping)
dnascope: dc=home,dc=steamr,dc=com
dnanextvalue: 2
EOF
Troubleshooting
Error: did not receive Kerberos credentials
Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an ipa: ERROR: did not receive Kerberos credentials error. Fix this by running:
## Renew/obtain Kerberos tickets for 'admin'
# kinit admin
Password for admin@HOME.STEAMR.COM: ****
Verify if your tickets are available with klist:
# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@STEAMR.COM
Valid starting Expires Service principal
03/06/22 14:44:35 03/07/22 14:39:47 krbtgt/STEAMR.COM@STEAMR.COM