Примечание
/etc/bind/options.conf:
options {
forwarders { 8.8.8.8; };
};
/etc/bind/options.conf:
zone "trust.dom" {
type forward;
forwarders { 10.64.224.10; };
};
Таблица 38.1. Исходные данные
| |
Имя домена
|
Контроллер домена
|
IP-адрес
|
ОС контроллера домена
|
Версия Samba
|
|---|---|---|---|---|---|
|
Домен Linux
|
TEST.ALT
|
dc1.test.alt
|
192.168.0.132
|
ALT Server 11
|
4.21.7-alt4
|
|
Домен Linux
|
EXAMPLE.ALT
|
s1.example.alt
|
192.168.0.172
|
ALT Server 11
|
4.21.7-alt4
|
|
Выделенный DNS-сервер
|
|
|
192.168.0.150
|
ALT Server 11
|
|
/etc/bind/options.conf:
zone "example.alt" {
type forward;
forwarders { 192.168.0.172; };
};
zone "test.alt" {
type forward;
forwarders { 192.168.0.132; };
};
# systemctl restart bind.service
Примечание
/etc/bind/options.conf в секцию options добавить параметр:
dnssec-validation no;И перезапустить службу DNS:
# systemctl restart bind.service
/etc/samba/smb.conf (в параметре dns forwarder). Например:
dns forwarder = 192.168.0.150 8.8.8.8
# systemctl restart samba
/etc/bind/options.conf:
options добавить параметр:
dnssec-validation no;
/etc/bind/options.conf (или /etc/bind/ddns.conf) добавить информацию о зонах:
zone "example.alt" {
type forward;
forwarders { 192.168.0.172; };
};
zone "test.alt" {
type forward;
forwarders { 192.168.0.132; };
};
# systemctl restart bind.service
#host -t srv _kerberos._tcp.example.alt_kerberos._tcp.example.alt has SRV record 0 100 88 s1.example.alt. #host -t srv _kerberos._tcp.test.alt_kerberos._tcp.test.alt has SRV record 0 100 88 dc1.test.alt.
#host -t srv _kerberos._tcp.example.alt_kerberos._tcp.example.alt has SRV record 0 100 88 s1.example.alt. #host -t srv _kerberos._tcp.test.alt_kerberos._tcp.test.alt has SRV record 0 100 88 dc1.test.alt.
#kinit administrator@EXAMPLE.ALTPassword for administrator@EXAMPLE.ALT: #klistTicket cache: KEYRING:persistent:0:krb_ccache_eFyZ8Tr Default principal: administrator@EXAMPLE.ALT Valid starting Expires Service principal 16.06.2025 12:12:06 16.06.2025 22:12:06 krbtgt/EXAMPLE.ALT@EXAMPLE.ALT renew until 23.06.2025 12:12:02
#kinit administrator@TEST.ALTPassword for administrator@TEST.ALT: #klistTicket cache: FILE:/tmp/krb5cc_0 Default principal: administrator@TEST.ALT Valid starting Expires Service principal 16.06.2025 12:13:30 16.06.2025 22:13:30 krbtgt/TEST.ALT@TEST.ALT renew until 23.06.2025 12:13:26
Важно