<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ngud.de</title>
	<atom:link href="http://www.ngud.de/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ngud.de</link>
	<description>Carpe diem Carpe noctem</description>
	<lastBuildDate>Wed, 04 Jan 2012 15:32:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>vmkfstools &#8211; usefull hints</title>
		<link>http://www.ngud.de/2011/11/vmkfstools-usefull-hints/</link>
		<comments>http://www.ngud.de/2011/11/vmkfstools-usefull-hints/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 09:55:34 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[ESXi]]></category>
		<category><![CDATA[Komputa]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=316</guid>
		<description><![CDATA[You can use the &#8216;vmkfstools&#8217; in an ESXi SSH-Shell to copy virtual disks, or expand them, or whatever Expand a virtual disk: vmkfstools -X 30G ./DISK.vmdk Be sure not to use the *-flat.vmdk file! After expansion use GParted to expand the partition inside the virtual disk. Clone a virtual disk: vmkfstools -i ./OLD.vmdk ./NEW.vmdk &#160; [...]]]></description>
			<content:encoded><![CDATA[<p>You can use the &#8216;vmkfstools&#8217; in an ESXi SSH-Shell to copy virtual disks, or expand them, or whatever</p>
<p><span style="text-decoration: underline;">Expand a virtual disk:</span></p>
<pre>vmkfstools -X 30G ./DISK.vmdk</pre>
<p>Be sure not to use the *-flat.vmdk file!</p>
<p>After expansion use <a title="GParted" href="http://gparted.sourceforge.net/" target="_blank">GParted</a> to expand the partition inside the virtual disk.</p>
<p><span style="text-decoration: underline;">Clone a virtual disk:</span></p>
<pre>vmkfstools -i ./OLD.vmdk ./NEW.vmdk</pre>
<p>&nbsp;</p>
<pre><span style="text-decoration: underline;"># vmkfstools - OPTIONS FOR FILE SYSTEMS:</span>

vmkfstools -C --createfs vmfs3
 -b --blocksize #[mMkK]
 -S --setfsname fsName
 -Z --spanfs span-partition
 -G --growfs grown-partition
 deviceName

 -P --queryfs -h --humanreadable
 -T --upgradevmfs
 vmfsPath

OPTIONS FOR VIRTUAL DISKS:

vmkfstools -c --createvirtualdisk #[gGmMkK]
 -d --diskformat [zeroedthick|
 thin|
 eagerzeroedthick]
 -a --adaptertype [buslogic|lsilogic|ide]
 -w --writezeros
 -j --inflatedisk
 -k --eagerzero
 -K --punchzero
 -U --deletevirtualdisk
 -E --renamevirtualdisk srcDisk
 -i --clonevirtualdisk srcDisk
 -d --diskformat [zeroedthick|
 thin|
 eagerzeroedthick|
 rdm:&lt;device&gt;|rdmp:&lt;device&gt;|
 2gbsparse]
 -X --extendvirtualdisk #[gGmMkK]
 [-d --diskformat eagerzeroedthick]
 -r --createrdm /vmfs/devices/disks/...
 -q --queryrdm
 -z --createrdmpassthru /vmfs/devices/disks/...
 -v --verbose #
 -g --geometry
 -x --fix [check|repair]
 vmfsPath

OPTIONS FOR DEVICES:

 -L --lock [reserve|release|lunreset|targetreset|busreset|readkeys|readresv] /vmfs/devices/disks/...
 -B --breaklock /vmfs/devices/disks/...</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2011/11/vmkfstools-usefull-hints/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Synology DiskStation autoindex Multimedia files by mediaserver</title>
		<link>http://www.ngud.de/2011/08/synology-diskstation-autoindex-multimedia-files-by-mediaserver/</link>
		<comments>http://www.ngud.de/2011/08/synology-diskstation-autoindex-multimedia-files-by-mediaserver/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 09:20:48 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[DS410]]></category>
		<category><![CDATA[Synology]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=311</guid>
		<description><![CDATA[NAS&#62; cat /etc/rc.local mount --bind /volume1/Multimedia/MP3 /volume1/music mount --bind /volume1/Multimedia/video /volume1/video mount --bind /volume1/Multimedia/Bilder /volume1/photo chmod 755 /etc/rc.local Thanks to Wim http://dev.eek.be/2010/01/change-folders-for-synology-media-server/ to do: echo repair &#62; /sys/block/md2/md/sync_action see --&#62; http://forum.synology.com/enu/viewtopic.php?f=39&#38;t=32727&#38;p=129722&#38;hilit=echo+repair+%3E+%2Fsys%2Fblock%2Fmd2%2Fmd%2Fsync_action#p129722]]></description>
			<content:encoded><![CDATA[<pre>NAS&gt;
cat /etc/rc.local
mount --bind /volume1/Multimedia/MP3 /volume1/music
mount --bind /volume1/Multimedia/video /volume1/video
mount --bind /volume1/Multimedia/Bilder /volume1/photo</pre>
<pre>chmod 755 /etc/rc.local

Thanks to Wim
<a href="http://dev.eek.be/2010/01/change-folders-for-synology-media-server/" target="_blank">http://dev.eek.be/2010/01/change-folders-for-synology-media-server/</a>

to do:
echo repair &gt; /sys/block/md2/md/sync_action

see --&gt; <a href="http://forum.synology.com/enu/viewtopic.php?f=39&amp;t=32727&amp;p=129722&amp;hilit=echo+repair+%3E+%2Fsys%2Fblock%2Fmd2%2Fmd%2Fsync_action#p129722">http://forum.synology.com/enu/viewtopic.php?f=39&amp;t=32727&amp;p=129722&amp;hilit=echo+repair+%3E+%2Fsys%2Fblock%2Fmd2%2Fmd%2Fsync_action#p129722</a></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2011/08/synology-diskstation-autoindex-multimedia-files-by-mediaserver/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Synoindex Synology DS410</title>
		<link>http://www.ngud.de/2011/07/synoindex-synology-ds410/</link>
		<comments>http://www.ngud.de/2011/07/synoindex-synology-ds410/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 11:54:22 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[DS410]]></category>
		<category><![CDATA[Komputa]]></category>
		<category><![CDATA[Synology]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=305</guid>
		<description><![CDATA[use this with SSH to add files to your Mediaserverindex. &#160; NAS&#62; synoindex Copyright (c) 2003-2011 Synology Inc. All rights reserved. usage: Add:    synoindex -a filename Delete: synoindex -d filename Add folder:    synoindex -A folder Delete folder: synoindex -D folder Rename/move file/folder:    synoindex -N newfullpath oldfullpath Update Photo Images:        synoindex -U photo Execute file index: [...]]]></description>
			<content:encoded><![CDATA[<p>use this with SSH to add files to your Mediaserverindex.</p>
<p>&nbsp;</p>
<pre>NAS&gt; synoindex
Copyright (c) 2003-2011 Synology Inc. All rights reserved.

usage:
 Add:    synoindex -a filename
 Delete: synoindex -d filename
 Add folder:    synoindex -A folder
 Delete folder: synoindex -D folder
 Rename/move file/folder:    synoindex -N newfullpath oldfullpath
 Update Photo Images:        synoindex -U photo
 Execute file index: synoindex -f {index option}
 Get from DB:         synoindex -g filename -t [video|music|photo|playlist]

There is also an additional option witch is as follows.
synoindex -R [video|music|photo|playlist]

This will re-index everything in to that current region.</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2011/07/synoindex-synology-ds410/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Schon mal &#8220;Desktop anzeigen&#8221; verlegt?</title>
		<link>http://www.ngud.de/2011/07/schon-mal-desktop-anzeigen-verlegt/</link>
		<comments>http://www.ngud.de/2011/07/schon-mal-desktop-anzeigen-verlegt/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 08:58:26 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=302</guid>
		<description><![CDATA[C:\Dokumente und Einstellungen\UserName\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch Datei erzeugen namens &#8220;Desktop anzeigen.scf&#8221; Inhalt: [Shell] Command=2 IconFile=explorer.exe,3 [Taskbar] Command=ToggleDesktop &#160; &#8230;und wieda da]]></description>
			<content:encoded><![CDATA[<p>C:\Dokumente und Einstellungen\UserName\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch</p>
<p>Datei erzeugen namens &#8220;Desktop anzeigen.scf&#8221;</p>
<p><span style="text-decoration: underline;">Inhalt:</span></p>
<pre>[Shell]
Command=2
IconFile=explorer.exe,3
[Taskbar]
Command=ToggleDesktop</pre>
<p>&nbsp;</p>
<p>&#8230;und wieda da <img src='http://www.ngud.de/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2011/07/schon-mal-desktop-anzeigen-verlegt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Catch all network traffic except ssh with tcpdump</title>
		<link>http://www.ngud.de/2011/05/catch-all-network-traffic-except/</link>
		<comments>http://www.ngud.de/2011/05/catch-all-network-traffic-except/#comments</comments>
		<pubDate>Mon, 30 May 2011 08:06:23 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Komputa]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=299</guid>
		<description><![CDATA[tcpdump -p -s0 -w tcpdump_file.cap port not 22]]></description>
			<content:encoded><![CDATA[<pre>tcpdump -p -s0 -w tcpdump_file.cap port not 22</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2011/05/catch-all-network-traffic-except/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>copy backup ntds.dit Active Directory</title>
		<link>http://www.ngud.de/2010/12/copy-backup-ntds-dit-active-directory-2/</link>
		<comments>http://www.ngud.de/2010/12/copy-backup-ntds-dit-active-directory-2/#comments</comments>
		<pubDate>Tue, 14 Dec 2010 09:26:12 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[AD]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[ntds.dit]]></category>

		<guid isPermaLink="false">http://www.ngud.de/?p=289</guid>
		<description><![CDATA[If you want to copy / backup Active Directory Information do the following: (tested on Server 2008) Stop Active Directory Domain Services cmd.exe ntdsutil &#8211;&#62; Activate Instance NTDS &#8211;&#62; files &#8211;&#62; compact to c:\horst (temp Folder) now U have a copy of your AD Information in C:\horst\ntds.dit Now, say you backup your AD Data every [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">If you want to copy / backup Active Directory Information do the following:</span></p>
<p><span style="font-size: small;">(tested on Server 2008)</span></p>
<ul>
<li>
<div><span style="font-size: small;">Stop Active Directory Domain Services</span></div>
</li>
<li>
<div><span style="font-size: small;">cmd.exe</span></div>
</li>
<li>
<div><span style="font-size: small;">ntdsutil &#8211;&gt; Activate Instance NTDS &#8211;&gt; files &#8211;&gt; compact to c:\horst (temp Folder)</span></div>
</li>
</ul>
<p><span style="font-size: small;">now U have a copy of your AD Information in C:\horst\ntds.dit</span></p>
<p><span style="font-size: small;">Now,  say you backup your AD Data every night, in folders that represent  every day of a month. (I know that stopping AD Services every day in  your productive environment is a decision you have to make <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  )</span></p>
<p><span style="font-size: small;">You  can take that copy of ntds.dit, seperate your server from your  productive network (stop AD Services, replace file, delete log files in  c:\windows\NTDS\*.log),  and you have a look in your AD at that time.</span></p>
<p><span style="font-size: small;">Before you start the AD Services again you have to insert the following reg key to the registry</span></p>
<p><span style="font-size: small;">HKLM/System/CurrentControlSet/Services/NTDS/Parameters: &#8220;Disable DSA Database Epoch Check&#8221;:REG_DWORD=0&#215;00000001</span></p>
<p><span style="font-size: small;">or  change &#8220;HKLM/System/CurrentControlSet/Services/NTDS/Parameters/DSA  Database Epoch&#8221; &#8211; minus times you started the AD Services since then <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   i prefer &#8221;Disable DSA Database Epoch Check&#8221;</span></p>
<p><span style="font-size: small;">have phun <img src='http://www.ngud.de/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2010/12/copy-backup-ntds-dit-active-directory-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Squid Proxy Cache mit Einbindung Windows AD</title>
		<link>http://www.ngud.de/2010/09/squid-proxy-cache-mit-einbindung-windows-ad/</link>
		<comments>http://www.ngud.de/2010/09/squid-proxy-cache-mit-einbindung-windows-ad/#comments</comments>
		<pubDate>Sun, 12 Sep 2010 17:35:00 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Komputa]]></category>
		<category><![CDATA[NTLM]]></category>
		<category><![CDATA[krb5-config]]></category>
		<category><![CDATA[krb5-user]]></category>
		<category><![CDATA[ntp]]></category>
		<category><![CDATA[samba]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[winbind]]></category>

		<guid isPermaLink="false">http://www.ngud.de/2010/09/squid-proxy-cache-mit-einbindung-windows-ad/</guid>
		<description><![CDATA[Der folgende Text wurde Quick&#38;Dirty aus Word eingefügt, daher gibt es noch ein “hübscheres” PDF ngud.de &#8211; Squid Proxy Cache mit Einbindung Windows AD_anon Verwendete Software Debian Lenny 5.0.6 Linux 2.6.26-2-686 #1 SMP Mon Aug 30 07:01:57 UTC 2010 i686 GNU/Linux Squid 2.7.STABLE3 Samba 3.2.5-41 Kerberos krb5-config 1.22 / krb5-user 1.6.dfsg.4 Winbind 3.2.5-41 Für das [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoTitle"><em>Der folgende Text wurde Quick&amp;Dirty aus Word eingefügt, daher gibt es noch ein “hübscheres” PDF</em></p>
<p class="MsoTitle"><em><a href="http://www.ngud.de/wp-content/uploads/2010/09/ngud.de-Squid-Proxy-Cache-mit-Einbindung-Windows-AD_anon.pdf"></a></em></p>
<div id="attachment_207" class="wp-caption alignleft" style="width: 42px"><em><a href="http://www.ngud.de/wp-content/uploads/2010/09/ngud.de-Squid-Proxy-Cache-mit-Einbindung-Windows-AD_anon.pdf"><em> </em></a><em><a href="http://www.ngud.de/wp-content/uploads/2009/11/pdficon_large.gif"><img class="size-full wp-image-207 " title="pdficon_large" src="http://www.ngud.de/wp-content/uploads/2009/11/pdficon_large.gif" alt="PDF Dokument" width="32" height="32" /></a></em></em><p class="wp-caption-text"> </p></div>
<p><em><br />
</em></p>
<p><em><a href="http://www.ngud.de/wp-content/uploads/2010/09/ngud.de-Squid-Proxy-Cache-mit-Einbindung-Windows-AD_anon.pdf" target="_blank">ngud.de &#8211;  Squid Proxy Cache mit Einbindung Windows AD_anon</a></em></p>
<p><em><br />
</em></p>
<p class="MsoTitle"><em> </em></p>
<p class="MsoTitle">
<p class="MsoTitle">
<p class="MsoTitle"><em>Verwendete Software</em></p>
<p class="MsoTitle">Debian Lenny 5.0.6</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle">Linux 2.6.26-2-686 #1 SMP Mon Aug 30 07:01:57 UTC 2010 i686 GNU/Linux</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle">Squid 2.7.STABLE3</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle">Samba 3.2.5-41</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle">Kerberos krb5-config 1.22 / krb5-user 1.6.dfsg.4</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast">Winbind 3.2.5-41</p>
<p class="MsoNormal">Für das Verständniss dieses Dokuments wird der Umgang mit Netzwerken, Linux Debian, Windows Domänen und VMware ESXI Servern vorausgesetzt. Hilfreich sind Kenntnisse in Kerberos, Samba und Squid.</p>
<div style="background: #4f81bd; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; border: #4f81bd 3pt solid; padding: 0cm;">
<p class="MsoTocHeading">Inhaltsverzeichnis<span style="font-weight: normal; font-size: 10pt; text-transform: none; color: windowtext; line-height: 115%; letter-spacing: 0pt;"> </span></p>
</div>
<p class="MsoToc1" style="tab-stops: 20.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes; mso-font-kerning: 14.0pt;">1</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes; mso-font-kerning: 14.0pt;">Installation Server</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">3</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.1</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Installation VM</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">&#8230; </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">3</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.2</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Installation benötigte Programme</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">5</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Konfiguration der Programme</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">7</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc3" style="tab-stops: 55.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3.1</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Allgemeine Hinweise</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">7</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc3" style="tab-stops: 55.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3.2</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">etc/samba/smb.conf</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;"> </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">7</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc3" style="tab-stops: 55.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3.3</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">etc/krb5.conf – Kerberos Konfiguration</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">8</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc3" style="tab-stops: 55.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3.4</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Konfiguration Winbind</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">10</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc3" style="tab-stops: 55.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.3.5</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">etc/nsswitch.conf</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;"> </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">10</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.4</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Testen der Konfiguration</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">11</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.5</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Konfiguration Squid</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">13</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">1.6</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Last Words</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">15</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc1" style="tab-stops: 20.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">2</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">Anhang</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">16</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;"><span style="mso-no-proof: yes;">2.1</span><span style="font-size: 11pt; color: windowtext; line-height: 115%; text-decoration: none; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi; text-underline: none;"><span style="mso-tab-count: 1;"> </span></span><span style="mso-no-proof: yes;">http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory</span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">. </span></span><span style="display: none; color: windowtext; text-decoration: none; mso-no-proof: yes; text-underline: none; mso-hide: screen;">16</span><span style="font-size: 11pt; line-height: 115%; mso-fareast-language: de; mso-bidi-language: ar-sa; mso-no-proof: yes; mso-bidi-font-family: &amp;amp;amp; mso-bidi-theme-font: minor-bidi;"> </span></p>
<p class="MsoToc2" style="tab-stops: 44.0pt right dotted 453.1pt;">
<p><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-font-kerning: 14.0pt; mso-fareast-theme-font: minor-fareast;"> <br style="page-break-before: always; mso-special-character: line-break;" /></span></p>
<p class="MsoNormal"><span style="mso-font-kerning: 14.0pt;"> </span></p>
<div style="background: #4f81bd; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; border: #4f81bd 3pt solid; padding: 0cm;">
<h1><a name="_Toc271876215"><span style="mso-ansi-language: de; mso-fareast-font-family: calibri; mso-font-kerning: 14.0pt; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span style="mso-ansi-language: de; mso-font-kerning: 14.0pt;">Installation Server</span></a><span style="mso-ansi-language: de; mso-font-kerning: 14.0pt;"></p>
<p></span></h1>
</div>
<p class="MsoNormal">Als Basis wird ein aktuelles Debian Netinst. verwendet. Zu beziehen ist dies unter <a href="http://www.debian.org/CD/netinst/">http://www.debian.org/CD/netinst/</a></p>
<p class="MsoNormal">Es wird eine VM unter ESXi installiert. Ich empfehle Squid erst ohne Authentifizierung, zur besseren Fehlersuche, zu testen</p>
<p class="MsoNormal">Eine funktionierende DNS Umgebung ist für die Kommunikation mit dem AD <em style="mso-bidi-font-style: normal;">zwingende</em> Vorraussetzung.</p>
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876216"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.1<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Installation VM</a></h2>
</div>
<p class="MsoNormal">
<p class="MsoNormal">Im<span style="mso-spacerun: yes;"> </span>Folgenden nur die „wichtigen“ Screenshots.</p>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb.png" border="0" alt="image" width="275" height="214" /></a></p>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image1.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb1.png" border="0" alt="image" width="244" height="162" /></a></p>
<p class="MsoNormal">
<p><a href="http://www.ngud.de/wp-content/uploads/2010/09/image2.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb2.png" border="0" alt="image" width="244" height="119" /></a></p>
<p class="MsoNormal">Für Testzwecke ist ein „Speicherplatz nach Bedarf zuteilen“ in Ordnung. Für die produktive Maschine sollte man die Festplatte komplett zuweisen.</p>
<p class="MsoNormal">
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image3.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb3.png" border="0" alt="image" width="244" height="122" /></a></p>
<p class="MsoNormal">Anschließend in den Eigenschaften der VM noch die passenden Einstellungen vornehmen (Arbeitsspeicher, CPUs, CD/DVD Laufwerk (vorweg geladenes Debian Netinst. ISO einbinden)).</p>
<p class="MsoNormal">Nun kann die virtuelle Maschine gestartet werden.</p>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image4.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb4.png" border="0" alt="image" width="244" height="222" /></a></p>
<p class="MsoNormal">
<p>Als Vorschlag zur Installation nur das Standard System auswählen (SPACE wählt an und ab)</p>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image5.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb5.png" border="0" alt="image" width="244" height="161" /></a></p>
<p class="MsoNormal">
<p>Als root anmelden und ssh installieren, die weiteren Schritte sind dann mit Putty einfacher.</p>
<p class="MsoNormal"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">apt-get install ssh</span><span style="font-family: &amp;amp;amp;"> </span></p>
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876217"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.2<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Installation benötigte Programme</a></h2>
</div>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid2:~# apt-get update </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://ftp.de.debian.org lenny Release.gpg </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://ftp.de.debian.org lenny/main Translation-en_US </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://ftp.de.debian.org lenny Release </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://security.debian.org lenny/updates Release.gpg </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://security.debian.org lenny/updates/main Translation-en_US </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://ftp.de.debian.org lenny/main Packages/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://security.debian.org lenny/updates Release </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://ftp.de.debian.org lenny/main Sources/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://security.debian.org lenny/updates/main Packages/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://ftp.de.debian.org lenny/main Packages </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://security.debian.org lenny/updates/main Sources/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://volatile.debian.org lenny/volatile Release.gpg </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://ftp.de.debian.org lenny/main Sources </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://security.debian.org lenny/updates/main Packages </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://security.debian.org lenny/updates/main Sources </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://volatile.debian.org lenny/volatile/main Translation-en_US </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://volatile.debian.org lenny/volatile Release </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://volatile.debian.org lenny/volatile/main Packages/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Ign http://volatile.debian.org lenny/volatile/main Sources/DiffIndex </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://volatile.debian.org lenny/volatile/main Packages </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Hit http://volatile.debian.org lenny/volatile/main Sources </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Reading package lists&#8230; Done </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid2:~# apt-get upgrade </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Reading package lists&#8230; Done </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Building dependency tree </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Reading state information&#8230; Done </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="MsoNormal"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># apt-get install htop ntp squid samba winbind krb5-config krb5-user </span></p>
<p class="MsoNormal"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="MsoNormal">Im weiteren Verlauf folgen ein paar Fragen zu den installierenden Packeten, hier kann entweder der Default Wert eingetragen werden oder sinnvolle Werte. Die entsprechenden Eintragungen in den Configdateien von Samba, Winbind und Kerberos werden im weiteren Verlauf angepasst.</p>
<p class="MsoNormal">
<p class="MsoNormal">OK, die benötigten Programme sind installiert.</p>
<p class="MsoNormal"><strong>Htop</strong> – ist ein persönlicher Favorit von mir</p>
<p class="MsoNormal"><strong>Ntp</strong> – wird benötigt damit die Uhrzeit synchronisiert ist, damit im weiteren Verlauf die Kommunikation mit der Windows AD Domäne funktioniert.</p>
<p class="MsoNormal"><strong>Squid</strong> – ja, wir wollten ja einen Proxy installieren <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p class="MsoNormal"><strong>samba winbind krb5-config krb5-user</strong> – werden für die Anbindung an die AD benötigt.</p>
<p><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast;"> <br style="page-break-before: always; mso-special-character: line-break;" /></span></p>
<p class="MsoNormal">
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876218"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Konfiguration der Programme</a></h2>
</div>
<p class="MsoNormal">Zuallererst müssen die Daemons gestoppt werden.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid2:~# /etc/init.d/samba stop </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Stopping Samba daemons: nmbd smbd. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid2:~# /etc/init.d/winbind stop </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">Stopping the Winbind daemon: winbind. </span></p>
<div style="border-right: medium none; padding-right: 0cm; border-top: #4f81bd 1pt solid; padding-left: 2pt; padding-bottom: 0cm; border-left: #4f81bd 1pt solid; padding-top: 2pt; border-bottom: medium none; mso-border-top-alt: solid #4f81bd .75pt; mso-border-left-alt: solid #4f81bd .75pt; mso-element: para-border-div; mso-border-top-themecolor: accent1; mso-border-left-themecolor: accent1;">
<h3><a name="_Toc271876219"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3.1<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Allgemeine Hinweise</a></h3>
</div>
<p class="MsoNormal">Die Konfiguration der Dienste ist diffizil und fehleranfällig. Deswegen im weiteren Verlauf Beispiele der Configdateien für ein Copy und Paste. Diese Dokumentation ist auf einer neuen Serverversion erfolgreich getestet worden. Ich hoffe die Namen für workgroup, realm, etc. sind sprechend.</p>
<div style="border-right: medium none; padding-right: 0cm; border-top: #4f81bd 1pt solid; padding-left: 2pt; padding-bottom: 0cm; border-left: #4f81bd 1pt solid; padding-top: 2pt; border-bottom: medium none; mso-border-top-alt: solid #4f81bd .75pt; mso-border-left-alt: solid #4f81bd .75pt; mso-element: para-border-div; mso-border-top-themecolor: accent1; mso-border-left-themecolor: accent1;">
<h3><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3.2<span style="font: 7pt &amp;amp;amp;"> </span></span></span>/<a name="_Toc271876220">etc/samba/smb.conf</a></h3>
</div>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# cat /etc/samba/smb.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[global] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">workgroup = DOMAENEKURZNAME </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">realm = DOMAENE.FQDN.TLD </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">preferred master = no </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">security = ADS </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">encrypt passwords = true </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">winbind separator = + </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">idmap uid = 600-20000 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">idmap gid = 600-20000 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">client ntlmv2 auth = yes </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[homes] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">valid users = %S</span><span style="font-family: &amp;amp;amp;"> </span></p>
<p class="MsoNormal"><span style="text-decoration: underline;">Kurze Erklärung: </span></p>
<p class="MsoNormal">Wichtig ist die GROßSCHREIBUNG der <span style="font-family: &amp;amp;amp;">workgroup</span> und des <span style="font-family: &amp;amp;amp;">realms</span>, sonst funktioniert später die Einbindung in die AD nicht.</p>
<p class="MsoNormal"><span style="font-family: &amp;amp;amp;">Preferred master</span> ist optional, würde ich aber auf jeden Fall setzten – wenn der Linux host der Master ist wird wahrscheinlich das anmelden in der Domäne schwierig <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p class="MsoNormal">Der <span style="font-family: &amp;amp;amp;">winbind seperator</span> spielt nachher in der Kerberos und Squid Konfiguration eine wichtige Rolle, der gewohnte Backslash „\“ ist kaum brauchbar, da man immer daran denken müsste ihn durch einen vorangestellen „\“, also „\\“ in den Configs brauchbar zu machen. <span style="mso-spacerun: yes;"> </span>Von daher ist ein Pluszeichen i.O.</p>
<p class="MsoNormal">Die Parameter <span style="font-family: &amp;amp;amp;">idmap_uid</span> und <span style="font-family: &amp;amp;amp;">idmap_gid</span> haben mit den Informationen zu tun die der Linux Server aus der AD zieht, ist z.B der erste Wert (600) zu hoch gesetzt können keine Gruppen oder Benutzerinformationen übertragen werden. Diese Werte stammen aus dem Samba Wiki (<a href="http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory" target="_blank">http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory</a> ) und funktonieren. Die komplette Anleitung findet sich im Anhang (2.1).</p>
<p class="MsoNormal"><span style="font-family: &amp;amp;amp;">Client ntlmv2 auth</span> legt die Kommunikation mit dem AD auf das sichere NTLMv2 fest.</p>
<p class="MsoNormal">
<div style="border-right: medium none; padding-right: 0cm; border-top: #4f81bd 1pt solid; padding-left: 2pt; padding-bottom: 0cm; border-left: #4f81bd 1pt solid; padding-top: 2pt; border-bottom: medium none; mso-border-top-alt: solid #4f81bd .75pt; mso-border-left-alt: solid #4f81bd .75pt; mso-element: para-border-div; mso-border-top-themecolor: accent1; mso-border-left-themecolor: accent1;">
<h3><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3.3<span style="font: 7pt &amp;amp;amp;"> </span></span></span>/<a name="_Toc271876221">etc/krb5.conf – Kerberos Konfiguration</a></h3>
</div>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# cat /etc/krb5.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[logging] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">default = FILE:/var/log/krb5libs.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">kdc = FILE:/var/log/krb5kdc.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">admin_server = FILE:/var/log/kadmind.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[libdefaults] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>default_realm = DOMAENE.FQDN.TLD </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>dns_lookup_realm = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>dns_lookup_kdc = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>ticket_lifetime = 24h </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>forwardable = yes </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># The following krb5.conf variables are only for MIT Kerberos. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>krb4_config = /etc/krb.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>krb4_realms = /etc/krb.realms </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>kdc_timesync = 1 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>ccache_type = 4 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>forwardable = true </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>proxiable = true </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># The following encryption type specification will be used by MIT Kerberos </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># if uncommented.<span style="mso-spacerun: yes;"> </span>In general, the defaults in the MIT Kerberos code are </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># correct and overriding these specifications only serves to disable new </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># encryption types as they are added, creating interoperability problems. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># Thie only time when you might need to uncomment these lines and change </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># the enctypes is if you have local software that will break on ticket </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># caches containing ticket encryption types it doesn&#8217;t know about (such as </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># old versions of Sun Java). </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">#<span style="mso-spacerun: yes;"> </span>default_tgs_enctypes = des3-hmac-sha1 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">#<span style="mso-spacerun: yes;"> </span>default_tkt_enctypes = des3-hmac-sha1 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">#<span style="mso-spacerun: yes;"> </span>permitted_enctypes = des3-hmac-sha1 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># The following libdefaults parameters are only for Heimdal Kerberos. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>v4_instance_resolve = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>v4_name_convert = { </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>host = { </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>rcmd = host </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>ftp = ftp </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>} </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>plain = { </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>something = something-else </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span>} </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>} </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>fcc-mit-ticketflags = true </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[realms] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>DOMAENE.FQDN.TLD = { </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>kdc = dc.domaene.tld </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>admin_server = dc.domaene.tld </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>} </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[domain_realm] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.mit.edu = ATHENA.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>mit.edu = ATHENA.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.media.mit.edu = MEDIA-LAB.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>media.mit.edu = MEDIA-LAB.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.csail.mit.edu = CSAIL.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>csail.mit.edu = CSAIL.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.whoi.edu = ATHENA.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>whoi.edu = ATHENA.MIT.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.stanford.edu = stanford.edu </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>.slac.stanford.edu = SLAC.STANFORD.EDU </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[login] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>krb4_convert = true </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>krb4_get_tickets = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="MsoNormal">Ich habe zu der Standardconfig die Domäne hinzugefügt, und teilweise die Einträge belassen, zur besseren Übersicht hier nochmals die wichtigen Einstellungen separiert.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[realms] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>DOMAENE.FQDN.TLD = { </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>kdc = dc.domaene.tld </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>admin_server = dc.domaene.tld </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>} </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[libdefaults] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>default_realm = DOMAENE.FQDN.TLD </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>dns_lookup_realm = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>dns_lookup_kdc = false </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>ticket_lifetime = 24h </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"><span style="mso-spacerun: yes;"> </span>forwardable = yes </span></p>
<p class="MsoNormal">Auch das Logging habe ich hinzugefügt.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">[logging] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">default = FILE:/var/log/krb5libs.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">kdc = FILE:/var/log/krb5kdc.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">admin_server = FILE:/var/log/kadmind.log </span></p>
<p class="MsoNormal">Falls Fragen auftauchen empfehle ich nach /etc/krb5.conf und den entsprechenden Schlagwörtern (kdc, admin_server) zu googlen, eine ausreichende Erklärung ist in diesem Dokument nicht möglich. Das Thema ist zu umfangreich.</p>
<p class="MsoNormal">Die Einstellungen hierzu sind wieder aus dem Samba Wiki</p>
<p><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast;"> <br style="page-break-before: always; mso-special-character: line-break;" /></span></p>
<p class="MsoNormal">
<div style="border-right: medium none; padding-right: 0cm; border-top: #4f81bd 1pt solid; padding-left: 2pt; padding-bottom: 0cm; border-left: #4f81bd 1pt solid; padding-top: 2pt; border-bottom: medium none; mso-border-top-alt: solid #4f81bd .75pt; mso-border-left-alt: solid #4f81bd .75pt; mso-element: para-border-div; mso-border-top-themecolor: accent1; mso-border-left-themecolor: accent1;">
<h3><a name="_Toc271876222"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3.4<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Konfiguration Winbind</a></h3>
</div>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image6.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb6.png" border="0" alt="image" width="244" height="123" /></a></p>
<p class="MsoNormal">Squid und seine Helfer laufen als User Proxy auf dem Linuxserver, daher muss mit</p>
<p class="KBBStandard-AufzhlungmitEinzug"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">gpasswd -a proxy winbindd_priv</span><span style="font-family: &amp;amp;amp;"> </span>auf der Kommandozeile (Putty) der User proxy der Gruppe winbindd_priv hinzugefügt werden.</p>
<div style="border-right: medium none; padding-right: 0cm; border-top: #4f81bd 1pt solid; padding-left: 2pt; padding-bottom: 0cm; border-left: #4f81bd 1pt solid; padding-top: 2pt; border-bottom: medium none; mso-border-top-alt: solid #4f81bd .75pt; mso-border-left-alt: solid #4f81bd .75pt; mso-element: para-border-div; mso-border-top-themecolor: accent1; mso-border-left-themecolor: accent1;">
<h3><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.3.5<span style="font: 7pt &amp;amp;amp;"> </span></span></span>/<a name="_Toc271876223">etc/nsswitch.conf</a></h3>
</div>
<p class="MsoNormal">In der /etc/nsswitch.conf muss winbind zu passwd, group und shadow hinzugefügt werden, hier die Ansicht der bearbeiteten Datei.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# cat /etc/nsswitch.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># /etc/nsswitch.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># Example configuration of GNU Name Service Switch functionality. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># If you have the `glibc-doc-reference&#8217; and `info&#8217; packages installed, try: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"># `info libc &#8220;Name Service Switch&#8221;&#8216; for information about this file. </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">passwd:<span style="mso-spacerun: yes;"> </span>compat <strong style="mso-bidi-font-weight: normal;">winbind</strong> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">group:<span style="mso-spacerun: yes;"> </span>compat <strong style="mso-bidi-font-weight: normal;">winbind</strong> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">shadow:<span style="mso-spacerun: yes;"> </span>compat <strong style="mso-bidi-font-weight: normal;">winbind</strong> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">hosts:<span style="mso-spacerun: yes;"> </span>files dns </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">networks:<span style="mso-spacerun: yes;"> </span>files </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">protocols:<span style="mso-spacerun: yes;"> </span>db files </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">services:<span style="mso-spacerun: yes;"> </span>db files </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">ethers:<span style="mso-spacerun: yes;"> </span>db files </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">rpc:<span style="mso-spacerun: yes;"> </span>db files </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">netgroup:<span style="mso-spacerun: yes;"> </span>nis </span></p>
<p><span style="font-size: 10pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-fareast-font-family: &amp;amp;amp; mso-fareast-theme-font: minor-fareast; mso-highlight: silver;"> <br style="page-break-before: always; mso-special-character: line-break;" /></span></p>
<p class="MsoNormal"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876224"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.4<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Testen der Konfiguration</a></h2>
</div>
<p class="MsoNormal">Die Dienste bitte in der folgenden Reihenfolge starten</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">/etc/init.d/samba start </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">/etc/init.d/winbind start </span></p>
<p class="MsoNormal">Jetzt kann der Linuxserver als Mitgliedsserver in die Windows AD gefahren werden.</p>
<p class="KBBStandard-AufzhlungmitEinzug"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">net ads join -U Adminaccount </span></p>
<p class="MsoNormal">Hierbei wird das Passwort abgefragt.<a style="mso-footnote-id: ftn1;" name="_ftnref1" href="file://ztrfs2/#_ftn1"><span class="MsoFootnoteReference"><span style="mso-special-character: footnote;"><span class="MsoFootnoteReference"><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast;">[1]</span></span></span></span></a></p>
<p class="MsoNormal">Hat das funktioniert liefert das folgende Kommando einen Erfolg.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# net ads testjoin </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">Join is OK </span></p>
<p class="MsoNormal">Gleichzeit sollte der Server in der AD auftauchen.</p>
<p class="MsoNormal"><a href="http://www.ngud.de/wp-content/uploads/2010/09/image7.png"><img style="display: inline; border-width: 0px;" title="image" src="http://www.ngud.de/wp-content/uploads/2010/09/image_thumb7.png" border="0" alt="image" width="244" height="142" /></a></p>
<p class="MsoNormal">Folgend ein paar Kommandos, mit denen sich eine erfolgreiche Verbindung testen lässt.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# kinit testuser@DOMAENE.FQDN.TLD </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">Password for testuser@DOMAENE.FQDN.TLD: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# kinit -V </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">Password for testuser@DOMAENE.FQDN.TLD: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">Authenticated to Kerberos v5 </span></p>
<p class="MsoNormal">…zeigt eine erfolgreiche Erstellung eines Kerberos Tickets, was will der Admin mehr <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<blockquote>
<p class="MsoNormal"><em style="mso-bidi-font-style: normal;">An dieser Stelle ist ein Neustart des Servers erforderlich, fragt mich nicht warum <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ich weiss es nicht. Ich habe nur reproduzierbar festgestellt das wbinfo erst Info’s liefert, nach dem der Server neu gestartet wurde. </em></p>
</blockquote>
<p class="MsoNormal"><span style="text-decoration: underline;">wbinfo –u liefert die User der Domäne </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# wbinfo -u </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+testuser </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+gast </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+support_388945a0 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+testuser2 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+administrator </span></p>
<p class="MsoNormal">
<p><span style="text-decoration: none;"> </span></p>
<p class="MsoNormal"><span style="text-decoration: underline;">wbinfo –t liefert das Ergebniss zum Trust </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# wbinfo -t </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">checking the trust secret via RPC calls succeeded </span></p>
<p class="MsoNormal">
<p><span style="text-decoration: none;"> </span></p>
<p class="MsoNormal"><span style="text-decoration: underline;">wbinfo –g liefert die Gruppen </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# wbinfo -g </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+sqlserver2005sqlbrowseruser$&#8230; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+sqlserver2005mssqlserveradhelperuser$&#8230; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+sqlserver2005mssqluser$erpdc02$&#8230; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+sqlserver2005msfteuser$erpdc02$&#8230; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+domÃ¤nencomputer </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+domÃ¤nencontroller </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+zertifikatherausgeber </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+domÃ¤nen-admins </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+domÃ¤nen-benutzer </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">… </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+inet </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+domÃ¤nen-gÃ¤ste </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+ras- und ias-server </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+wins-benutzer </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 8pt; background: silver; line-height: 115%; font-family: &amp;amp;amp; mso-highlight: silver; mso-bidi-font-size: 10.0pt;">DOMAENE+dnsadmins</span><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></p>
<p class="MsoNormal">
<p><span style="text-decoration: none;"> </span></p>
<p class="MsoNormal"><span style="text-decoration: underline;">Wbinfo –a macht eine Probeanmeldung </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">squid:~# wbinfo -a ERP+testuser%Passwort </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">plaintext password authentication failed </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">Could not authenticate user testuser with plaintext password </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><strong style="mso-bidi-font-weight: normal;"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;">challenge/response password authentication succeeded </span></strong></p>
<p class="MsoNormal">Bei dieser Ausgabe ist zu sehen das Plaintext nicht funktioniert (Domäneneinstellung), eine Anmeldung aber doch (challenge/response password authentication succeeded (in diesem Fall über das sichere NTLMv2))</p>
<p class="KBBStandard-AufzhlungmitEinzug"><strong style="mso-bidi-font-weight: normal;"><span style="background: silver; font-family: &amp;amp;amp; mso-highlight: silver;"> </span></strong></p>
<p class="MsoNormal">
<p class="MsoNormal">Okay, damit ist die Testphase abgeschlossen, der Server ist Mitglied der Domäne und kann erfolgreich Nutzer authentifizieren. Jetzt kann Squid eingerichtet werden.</p>
<p><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast;"> <br style="page-break-before: always; mso-special-character: line-break;" /></span></p>
<p class="MsoNormal">
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876225"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.5<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Konfiguration Squid</a></h2>
</div>
<p class="MsoNormal">Die Squid Konfiguration ist in der Datei <strong style="mso-bidi-font-weight: normal;"><em style="mso-bidi-font-style: normal;">/etc/squid/squid.conf</em></strong> gesammelt. Diese Datei ist sehr umfangreich und nicht einfach zu konfigurieren. Anbei meine geänderten Zeilen die eine erfolgreiche Authentifizierung mit der Domäne bewirken. (Bei Zeilenumbrüchen bitte die Zeile als Ganzes betrachten). Ich gehe die squid.conf von oben nach unten durch.</p>
<p class="MsoNormal">Zur besseren Übersichtlichkeit kann man nach denm <strong style="mso-bidi-font-weight: normal;"><span style="font-size: 11pt; line-height: 115%; mso-bidi-font-size: 10.0pt;"># fettgedruckten Text</span></strong> suchen, dann ist man schneller im entsprechenden Block</p>
<p class="MsoNormal"><span style="text-decoration: underline;">Hinweise zur Formatierung: </span></p>
<p class="KBBStandard-AufzhlungmitEinzug" style="margin-left: 35.4pt; mso-add-space: auto;"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">Ist die Zeile in der Configdatei </span></p>
<p class="MsoNormal" style="margin-left: 35.4pt;">Sind meine Anmerkungen (darunter)</p>
<p class="MsoNormal">
<p class="MsoNormal"><span style="text-decoration: underline;">Änderungen /etc/squid/squid.conf </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>WELCOME TO SQUID 2.7.STABLE3 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># OPTIONS FOR AUTHENTICATION </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">auth_param ntlm program /usr/bin/ntlm_auth &#8211;helper-protocol=squid-2.5-ntlmssp &#8211;require-membership-of=&#8221;DOMAENE+inet&#8221; </span></p>
<p class="MsoNormal">&#8211;require-membership-of=&#8221;DOMAENE+inet&#8221; steht für die Gruppe in der Domäne, in diesem Fall also die Gruppe INET. Benutzer die Mitglieder dieser Gruppe sind wird der Zugang über den Proxy gewährt</p>
<p class="KBBStandard-AufzhlungmitEinzug"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#auth_param ntlm program /usr/bin/ntlm_auth &#8211;helper-protocol=squid-2.5-ntlmssp </span></p>
<p class="MsoNormal">Dieser Parameter ist auskommentiert, bedeutet aber das jedem authentifizierten Nutzer das Surfen erlaubt wird.</p>
<p class="KBBStandard-AufzhlungmitEinzug"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">auth_param ntlm children 15 </span></p>
<p class="MsoNormal">Anzahl der Threads, die Squid öffnen darf um Anfragen an das AD zu stellen. Bei Bedarf sollten diese erhöht werden. Erfahrungen dazu habe ich noch nicht.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">auth_param ntlm keep_alive on </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: acl </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>Defining an Access List </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">… </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl AuthorizedUsers proxy_auth REQUIRED </span></p>
<p class="MsoNormal">Damit wird die ACL Auth.Users kreiert, über proxy_auth wird auf auth_param ntlm verwiesen. Es heisst also nichts anderes als definiere eine Gruppe Auth.User, die sich zuvor über proxy_auth authentifiziert haben.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl SSL_ports port 443<span style="mso-spacerun: yes;"> </span># https </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl SSL_ports port 563<span style="mso-spacerun: yes;"> </span># snews </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl SSL_ports port 873<span style="mso-spacerun: yes;"> </span># rsync </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 80<span style="mso-spacerun: yes;"> </span># http </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 21<span style="mso-spacerun: yes;"> </span># ftp </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 443<span style="mso-spacerun: yes;"> </span># https </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 70<span style="mso-spacerun: yes;"> </span># gopher </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 210<span style="mso-spacerun: yes;"> </span># wais </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 1025-65535<span style="mso-spacerun: yes;"> </span># unregistered ports </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 280<span style="mso-spacerun: yes;"> </span># http-mgmt </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 488<span style="mso-spacerun: yes;"> </span># gss-http </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 591<span style="mso-spacerun: yes;"> </span># filemaker </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 777<span style="mso-spacerun: yes;"> </span># multiling http </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 631<span style="mso-spacerun: yes;"> </span># cups </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 873<span style="mso-spacerun: yes;"> </span># rsync </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl Safe_ports port 901<span style="mso-spacerun: yes;"> </span># SWAT </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl purge method PURGE </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">acl CONNECT method CONNECT </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="MsoNormal">Bei den Ports habe ich nichts verändert, die Liste scheint vollsändig. Bei Bedarf an weiteren Ports, diese hier anfügen.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: http_access </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">http_access allow all AuthorizedUsers </span></p>
<p class="MsoNormal">Über diese http_access Regel wird den Auth.Usern der Zugriff gewährt (weiter oben wurde Auth.Users definiert). Benutzer müssen in der Gruppe DOMAENE\inet sein.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># http_access allow localnet </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">http_access allow localhost </span></p>
<p class="MsoNormal">Localhost darf auch</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># And finally deny all other access to this proxy </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">http_access deny all </span></p>
<p class="MsoNormal">der verbleibende Rest darf nicht mehr</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: http_port </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>Usage:<span style="mso-spacerun: yes;"> </span>port [options] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>hostname:port [options] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>1.2.3.4:port [options] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># Squid normally listens to port 3128 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">http_port 3128 </span></p>
<p class="MsoNormal">Port bei Bedarf verändern, z.B. 8888</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># MEMORY CACHE OPTIONS </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: cache_mem<span style="mso-spacerun: yes;"> </span>(bytes) </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">cache_mem 16 MB </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># maximum_object_size_in_memory 8 KB </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># memory_replacement_policy lru </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># DISK CACHE OPTIONS </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: cache_replacement_policy </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># cache_replacement_policy lru </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># cache_dir ufs /var/spool/squid 100 16 256 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># minimum_object_size 0 KB </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># maximum_object_size 20480 KB </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># cache_swap_low 90 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># cache_swap_high 95 </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># LOGFILE OPTIONS </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>TAG: logformat </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#<span style="mso-spacerun: yes;"> </span>The default formats available (which do not need re-defining) are: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#logformat squid %ts.%03tu %6tr %&gt;a %Ss/%03Hs %&lt;st %rm %ru %un %Sh/%&lt;A %mt </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#logformat squidmime %ts.%03tu %6tr %&gt;a %Ss/%03Hs %&lt;st %rm %ru %un %Sh/%&lt;A %mt [%&gt;h] [%&lt;h] </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#logformat common %&gt;a %ui %un [%tl] &#8220;%rm %ru HTTP/%rv&#8221; %Hs %&lt;st %Ss:%Sh </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#logformat combined %&gt;a %ui %un [%tl] &#8220;%rm %ru HTTP/%rv&#8221; %Hs %&lt;st &#8220;%{Referer}&gt;h&#8221; &#8220;%{User-Agent}&gt;h&#8221; %Ss:%Sh </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">access_log /var/log/squid/access.log squid </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">cache_log /var/log/squid/cache.log </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">cache_store_log /var/log/squid/store.log </span></p>
<p class="MsoNormal">Das access_log kann bei Bedarf verändert werden, in dieser Einstellung sieht eine Zeile so aus:</p>
<p class="MsoNormal">1284045145.911<span style="mso-spacerun: yes;"> </span>910 123.123.123.136 TCP_MISS/200 55024 GET http://www.ngud.de/ DOMAENE+testuser2 DIRECT/87.230.78.108 text/html</p>
<p class="MsoNormal">Wenn nicht alle relavanten Informationen zu sehen sind kann das Log über „logformat squid“ angepasst werden.</p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># OPTIONS FOR FTP GATEWAYING </span></strong></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"># &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">#Default: </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpMiddle"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">ftp_user </span><a href="mailto:Squid@domain.tld"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">Squid@domain.tld</span></a><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="KBBStandard-AufzhlungmitEinzugCxSpLast"><span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;"> </span></p>
<p class="MsoNormal">Ist das editieren der squid.conf beendet kann man mit <span style="font-size: 9pt; line-height: 115%; font-family: &amp;amp;amp; mso-bidi-font-size: 10.0pt;">/etc/init.d/squid restart (oder reload) </span>die Konfiguration testen.</p>
<p class="MsoNormal">Ich persönlich ziehe noch einen kompletten Serverneustart vor, um sicherzugehen das alle Dienste in der richtigen Reihenfolge geladen weden.</p>
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><a name="_Toc271876226"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">1.6<span style="font: 7pt &amp;amp;amp;"> </span></span></span>Last Words</a></h2>
</div>
<p class="MsoNormal">Nun sollte ein User, der in der Gruppe „inet“ ist surfen können. Ein Nutzer, aus der gleichen Domäne, der nicht in der Gruppe ist, nicht.</p>
<p class="MsoNormal">Happy Testing <img src='http://www.ngud.de/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<div style="background: #4f81bd; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; border: #4f81bd 3pt solid; padding: 0cm;">
<h1><a name="_Toc271876227"><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;" lang="EN-US"><span style="mso-list: ignore;">2<span style="font: 7pt &amp;amp;amp;"> </span></span></span><span lang="EN-US">Quellen</span></a></h1>
</div>
<div style="background: #dbe5f1; mso-element: para-border-div; mso-border-themecolor: accent1; mso-background-themecolor: accent1; mso-border-themetint: 51; mso-background-themetint: 51; border: #dbe5f1 3pt solid; padding: 0cm;">
<h2><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;">2.1<span style="font: 7pt &amp;amp;amp;"> </span></span></span><a href="http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory"><span style="mso-bookmark: _toc271876228;"><span style="mso-bookmark: _ref271875161;"> </span></span><span style="mso-bookmark: _ref271875161;"> </span><span style="mso-bookmark: _toc271876228;"> </span></a><a name="_Ref271875161"></a><a name="_Toc271876228"></a></h2>
<h4><span style="mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin;"><span style="mso-list: ignore;"><span style="font: 7pt &amp;amp;amp;"> </span></span></span><a href="http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory"><span style="mso-bookmark: _toc271876228;"><span style="mso-bookmark: _ref271875161;">http://wiki.samba.org/index.php/Samba_&amp;_Active_Directory</span></span></a></h4>
</div>
<p class="KBBStandard-AufzhlungmitEinzugCxSpFirst">
<hr size="1" />
<div style="mso-element: footnote-list;">
<div id="ftn1" style="mso-element: footnote;">
<p class="MsoFootnoteText"><a style="mso-footnote-id: ftn1;" name="_ftn1" href="file://ztrfs2/#_ftnref1"><span class="MsoFootnoteReference"><span style="mso-special-character: footnote;"><span class="MsoFootnoteReference"><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp; mso-ansi-language: de; mso-fareast-language: en-us; mso-bidi-language: en-us; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: &amp;amp;amp; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast;">[1]</span></span></span></span></a> <span style="font-size: 9pt; line-height: 115%; mso-bidi-font-size: 10.0pt;">Ich habe bei dieser Gelegenheit mit tcpdump die Packete mitgeschnitten und diese mit Whireshark untersucht. Mein Passwort konnte ich nicht entdecken, daher scheint die Verschlüsselung zu funktionieren <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </span></p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2010/09/squid-proxy-cache-mit-einbindung-windows-ad/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Powershell: read eventlogs from remote servers and send them as mail</title>
		<link>http://www.ngud.de/2010/08/powershell-read-eventlogs-from-remote-servers-and-send-them-as-mail/</link>
		<comments>http://www.ngud.de/2010/08/powershell-read-eventlogs-from-remote-servers-and-send-them-as-mail/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 10:15:18 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Komputa]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.ngud.de/2010/08/powershell-read-eventlogs-from-remote-servers-and-send-them-as-mail/</guid>
		<description><![CDATA[with the help of the Microsoft Community here is a script which reads the eventlogs from multiple Servers and finally sends the output with the help of the Send-MailMessage Cmdlet (Powershell v 2.0) It has 2 forech () Sections because it should go server by server. $meldungen = @() $compName = $(&#34;server1&#34;, &#34;server2&#34;) $Logs =$(&#34;System&#34;, [...]]]></description>
			<content:encoded><![CDATA[<p>with the help of the Microsoft Community <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>here is a script which reads the eventlogs from multiple Servers and finally sends the output with the help of the Send-MailMessage Cmdlet (Powershell v 2.0)</p>
<p>It has 2 forech () Sections because it should go server by server.</p>
<blockquote><p>$meldungen = @()      <br />$compName = $(&quot;server1&quot;, &quot;server2&quot;)      <br />$Logs =$(&quot;System&quot;, &quot;Application&quot;, &quot;Directory Service&quot;, &quot;DNS Server&quot;, &quot;File Replication Service&quot;)      <br />Foreach ($server in $compName){      <br />&#160;&#160;&#160; forEach ($log in $logs){      <br />&#160;&#160;&#160; $meldungen += Get-EventLog $log -EntryType Error,Warning -ComputerName $server -after (get-date).AddHours(-24) | where{$_.EventID -ne &quot;3000&quot;} | select MachineName,TimeWritten,EntryType,Source,EventID,Message | ConvertTo-Html -As List -PreContent &quot;&lt;H3&gt;Servername: $server Log: $log &lt;/h3&gt;&quot; -PostContent &quot;&lt;hr&gt;&quot; | Out-String      <br />&#160;&#160;&#160; }      <br />} </p>
<p>$compName = $(&quot;server3&quot;, &quot;server4&quot;, &quot;server5&quot;, &quot;server6&quot;, &quot;server7&quot;)     <br />$Logs =$(&quot;System&quot;, &quot;Application&quot;) </p>
<p>Foreach ($server in $compName){     <br />&#160;&#160;&#160; forEach ($log in $logs){      <br />&#160;&#160;&#160; $meldungen += Get-EventLog $log -EntryType Error,Warning -ComputerName $server -after (get-date).AddHours(-24) | where{$_.Source -ne &quot;Print&quot; -and $_.EventID -ne &quot;1111&quot;} | select MachineName,TimeWritten,EntryType,Source,EventID,Message | ConvertTo-Html -As List -PreContent &quot;&lt;H3&gt;Servername: $server Log: $log &lt;/h3&gt;&quot; -PostContent &quot;&lt;hr&gt;&quot; | Out-String      <br />&#160;&#160;&#160; }      <br />}      <br />$body = $meldungen | Out-String </p>
<p>$from = &quot;<a href="mailto:mail@somewhere.tld">mail@somewhere.tld</a>&quot;      <br />$Subject = &quot;Eventlogs ERP Error, Warning, letzte 24 Stunden&quot;      <br />$To = <a href="mailto:user@2getmail.tld">user@2getmail.tld</a>      <br />Send-MailMessage -from $from -Subject $Subject -To $To -Body $body -SmtpServer &quot;your_smtp_server&quot; -BodyAsHtml -Priority Low</p>
</blockquote>
<p># with “$meldungen = @()” i create an array &#8211; and with “$meldungen += Get-EventLog…” i put all the entry&#8217;s one after another</p>
<p># (get-date).AddHours(-24) means – get the eventlogs for the last 24 hours, script is run at 07:00 in the morning. </p>
<p># where{$_.EventID -ne &quot;3000&quot;} means filter out Events with EventID 3000 (DNS Server has found multiple…..)</p>
<p># the “ConvertTo-Html -As List -PreContent &quot;&lt;H3&gt;Servername: $server Log: $log &lt;/h3&gt;&quot; -PostContent &quot;&lt;hr&gt;&quot; “ does a nice job, in the email it produces nice sections, Output looks like this (no entry’s means nothing to worry about <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  )</p>
<p>&#160;</p>
<p><b>Von:</b> Ereignislogs 123[mailto:some@email]     <br /><b>Gesendet:</b> Mittwoch, 25. August 2010 11:51    <br /><b>An:</b>&#160; Roman    <br /><b>Betreff:</b> Eventlogs ERP Error, Warning, letzte 24 Stunden    <br /><b>Wichtigkeit:</b> Niedrig</p>
<h5>Servername: Server1 Log: System </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>&#160;</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server1 Log: Application </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>
<p>MachineName:</p>
</td>
<td>
<p>Server1</p>
</td>
</tr>
<tr>
<td>
<p>TimeWritten:</p>
</td>
<td>
<p>25.08.2010 03:36:12</p>
</td>
</tr>
<tr>
<td>
<p>EntryType:</p>
</td>
<td>
<p>Warning</p>
</td>
</tr>
<tr>
<td>
<p>Source:</p>
</td>
<td>
<p>Userenv</p>
</td>
</tr>
<tr>
<td>
<p>EventID:</p>
</td>
<td>
<p>1517</p>
</td>
</tr>
<tr>
<td>
<p>Message:</p>
</td>
<td>
<p>Die Registrierung des Benutzers &quot;xxx&quot; wurde gespeichert, obwohl eine Anwendung oder ein Dienst auf die Registrierung während der Abmeldung zugegriffen hat. Der von der Registrierung des Benutzers verwendete Speicher wurde nicht freigegeben. Der Upload der Registrierung wird durchgeführt, wenn diese nicht mehr verwendet wird. Dies wird oft durch Dienste verursacht, die unter einem Benutzerkonto ausgeführt werden. Versuchen Sie diese so zu Konfigurieren, dass sie unter den Konten &quot;Lokaler Dienst&quot; oder &quot;Netzwerkdienst&quot; ausgeführt werden.</p>
</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server1 Log: Directory Service </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>&#160;</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server1 Log: DNS Server </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>&#160;</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server1 Log: File Replication Service </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>&#160;</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server2 Log: System </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>&#160;</td>
</tr>
</tbody>
</table>
<hr align="center" width="100%" size="2" />
<h5>Servername: Server2 Log: Application </h5>
<table cellpadding="0" border="0">
<tbody>
<tr>
<td>
<p>MachineName:</p>
</td>
<td>
<p>Server2</p>
</td>
</tr>
<tr>
<td>
<p>TimeWritten:</p>
</td>
<td>
<p>25.08.2010 10:40:10</p>
</td>
</tr>
<tr>
<td>
<p>EntryType:</p>
</td>
<td>
<p>Warning</p>
</td>
</tr>
<tr>
<td>
<p>Source:</p>
</td>
<td>
<p>Userenv</p>
</td>
</tr>
<tr>
<td>
<p>EventID:</p>
</td>
<td>
<p>1517</p>
</td>
</tr>
<tr>
<td>
<p>Message:</p>
</td>
<td>
<p>Die Registrierung des Benutzers &quot;Horst <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ” wurde gespeichert, obwohl eine Anwendung oder ein Dienst auf die Registrierung während der Abmeldung zugegriffen hat. Der von der Registrierung des Benutzers verwendete Speicher wurde nicht freigegeben. Der Upload der Registrierung wird durchgeführt, wenn diese nicht mehr verwendet wird. Dies wird oft durch Dienste verursacht, die unter einem Benutzerkonto ausgeführt werden. Versuchen Sie diese so zu Konfigurieren, dass sie unter den Konten &quot;Lokaler Dienst&quot; oder &quot;Netzwerkdienst&quot; ausgeführt werden.</p>
</td>
</tr>
<tr>
<td>
<hr align="center" width="100%" size="2" /></td>
<td>&#160;</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2010/08/powershell-read-eventlogs-from-remote-servers-and-send-them-as-mail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Copy directories depending on LastWriteTime with Powershell</title>
		<link>http://www.ngud.de/2010/08/copy-directories-depending-on-lastwritetime-with-powershell/</link>
		<comments>http://www.ngud.de/2010/08/copy-directories-depending-on-lastwritetime-with-powershell/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 19:37:00 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.ngud.de/2010/08/copy-directories-depending-on-lastmodified-with-powershell/</guid>
		<description><![CDATA[This is my first PowerShell Script, Comments welcome. Thanks to Google and all the Scripting Gods out there The intention of this Powershell Script is not to know what it has to copy, the only filter is in “$dirs = Get-ChildItem $Quelle -filter erp* &#124; % {$_.fullname}“. I filter for erp as the first three [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-family: tahoma,arial,helvetica,sans-serif;">This is my first PowerShell Script, Comments welcome.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: tahoma,arial,helvetica,sans-serif;">Thanks to Google and all the Scripting Gods out there <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </span></span></p>
<p><span style="font-size: small;"><span style="font-family: tahoma,arial,helvetica,sans-serif;">The intention of this Powershell Script is not to know what it has to copy, the only filter is in “$dirs = Get-ChildItem $Quelle -filter erp* | % {$_.fullname}“. I filter for erp as the</span></span><span style="font-size: small;"><span style="font-family: tahoma,arial,helvetica,sans-serif;"> first three characters of the filename. The first Get-Childitem gets the directories, the second Get-Childitem gets the subdirectories and copies just the dirs (-recurse) which are not older than six days ( $Zeitvergleich = (Get-date).AddDays(-6) ).</span></span></p>
<pre>$Quelle = "D:\somewhere\onyourdisk"
$Ziel = "D:\somewhereelse\onyourdisk"
$Zeitvergleich = (Get-date).AddDays(-6)
$dirs = Get-ChildItem $Quelle -filter erp* | % {$_.fullname}
foreach($dir in $dirs){
$dir = Get-Childitem $dirs | where-object {$_.LastWriteTime -gt $Zeitvergleich} | Copy-Item -Path {$_.Fullname} $Ziel -recurse
}</pre>
<p><span style="font-size: small;"><span style="font-family: tahoma,arial,helvetica,sans-serif;">I pimp&#8217;d my script to move the directories with move-item, there is a nice way to change the -Destination String with Replace<br />
</span></span></p>
<pre>$Quelle = "D:\somewhere\onyourdisk"
$Ziel = "D:\somewhereelse\onyourdisk"
$Zeitvergleich = (Get-date).AddDays(-6)

$dirs = Get-ChildItem $Quelle -filter erp* | % {$_.fullname}

$dir = Get-Childitem $dirs | where-object {$_.LastWriteTime -gt $Zeitvergleich}

foreach($item in $dir){

move-Item -Path $item.FullName -Destination $item.FullName.ToString().Replace($Quelle,$Ziel)

}</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2010/08/copy-directories-depending-on-lastwritetime-with-powershell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tagesdatum in Batchdatei</title>
		<link>http://www.ngud.de/2010/08/tagesdatum-in-batchdatei/</link>
		<comments>http://www.ngud.de/2010/08/tagesdatum-in-batchdatei/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 12:50:15 +0000</pubDate>
		<dc:creator>Roman</dc:creator>
				<category><![CDATA[Komputa]]></category>

		<guid isPermaLink="false">http://www.ngud.de/2010/08/tagesdatum-in-batchdatei/</guid>
		<description><![CDATA[So, damit ich es nicht schon wieder vergesse jetzt mal als Blog. Lösung für ein Tagesdatum in einer Batchdatei FOR /F "tokens=1-3 delims=." %%J IN ("%date%") DO SET "Tagesdatum=%%L-%%K-%%J" echo %Tagesdatum%     have a nice day (-:]]></description>
			<content:encoded><![CDATA[<p>So, damit ich es nicht schon wieder vergesse <img src='http://www.ngud.de/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  jetzt mal als Blog.
</p>
<p>Lösung für ein Tagesdatum in einer Batchdatei
</p>
<p>
<pre><code>FOR /F "tokens=1-3 delims=." %%J IN ("%date%") DO SET "Tagesdatum=%%L-%%K-%%J"
</code></pre>
</p>
<p>
<pre><code>echo %Tagesdatum%
</code></pre>
</p>
<p> <br />
 </p>
<p>have a nice day (-: </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ngud.de/2010/08/tagesdatum-in-batchdatei/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

