HP CIFS Server Administrator's Guide (5900-1282, April 2011)

Stopping Winbind...........................................................................................................107
Automatically Starting Winbind at System Startup................................................................107
An Example for File Ownership by Winbind Users....................................................................108
wbinfo Utility.......................................................................................................................108
8 Kerberos Support....................................................................................109
Introduction..........................................................................................................................109
Kerberos Overview...............................................................................................................109
Kerberos CIFS Authentication Example................................................................................110
HP-UX Kerberos Application Co-existence.................................................................................110
Components for Kerberos Configuration..............................................................................110
Configuring krb5.keytab...................................................................................................111
9 HP CIFS Deployment Models....................................................................113
Introduction..........................................................................................................................113
Samba Domain Model..........................................................................................................113
Samba Domain Components.............................................................................................116
HP CIFS Server Acting as a PDC...................................................................................116
HP CIFS Server Acting as a BDC...................................................................................116
HP CIFS Acting as the Member Server...........................................................................117
An example of the Samba Domain Model...........................................................................117
A Sample smb.conf File For a PDC................................................................................117
Configuration Options.................................................................................................118
A Sample smb.conf File For a BDC................................................................................119
Configuration Options.................................................................................................119
A Sample smb.conf File for a Domain Member Server.....................................................119
Configuration Options.................................................................................................120
A Sample /etc/nsswitch.ldap File..................................................................................120
Windows Domain Model......................................................................................................121
Components for Windows Domain Model...........................................................................122
An Example of the ADS Domain Model..............................................................................122
A sample smb.conf file For an HP CIFS ADS Member Server.............................................123
A Sample /etc/krb5.conf File.......................................................................................124
A Sample /etc/nsswitch.conf File..................................................................................125
An Example of Windows NT Domain Model.......................................................................125
A Sample smb.conf File for an HP CIFS Member Server...................................................126
Unified Domain Model..........................................................................................................127
Unified Domain Components.............................................................................................128
HP CIFS Acting as a Windows 200x ADS Member Server...............................................128
Setting up the Unified Domain Model.................................................................................128
Setting up LDAP-UX Client Services on an HP CIFS Server......................................................129
Installing and Configuring LDAP-UX Client Services on an HP CIFS Server...........................129
Configuring /etc/krb5.conf to Authenticate Using Kerberos..............................................129
Installing SFU 3.5 on a Window 2000 or 2003 Domain Controller........................................130
An Example of the Unified Domain Model..........................................................................130
A sample smb.conf file For an HP CIFS Member Server....................................................130
A Sample /etc/krb5.conf File.......................................................................................131
A Sample /etc/nsswitch.conf File..................................................................................132
10 Securing HP CIFS Server........................................................................133
Security Protection Methods...................................................................................................133
Restricting Network Access................................................................................................133
Using Host Restrictions.................................................................................................133
Contents 7