[global] realm = DIRECTORY.SLACKWARE.UK.INTERNAL netbios name = DIRECTORY workgroup = SLACKWAREUKINT server string = "directory.slackware.uk.internal Domain Controller" bind interfaces only = yes interfaces = lo eth1 # FIXME: # dns forwarder = 5.101.171.216 5.101.171.217 185.176.90.169 dns forwarder = 216.119.155.58 185.176.90.169 allow dns updates = secure tls cafile = /etc/ssl/certs/ca-certificates.crt tls certfile = /etc/certificates/core.slackware.uk.internal_cert.pem tls keyfile = /etc/certificates/core.slackware.uk.internal_key.pem tls verify peer = ca_and_name_if_available log level = 1 logging = syslog:local5 log file = /var/log/samba/samba-debug debug syslog format = always debug hires timestamp = yes enable core files = no idmap config * : backend = tdb # There are only 568 IDs mapped into the container by TrueNAS, so limit the number that can be used. idmap config * : range = 10000-10500 idmap_ldb:use rfc2307 = yes password hash userPassword schemes = CryptSHA512 server role = active directory domain controller username map = /etc/samba/smbusers vfs objects = dfs_samba4 posixacl acl_xattr nfs4acl_xattr:encoding = nfs nfs4acl_xattr:version = 41 nfs4acl_xattr:xattr_name = user.nfs4_acl nfs4acl_xattr:default acl style = windows acl_xattr:security_acl_name = user.NTACL acl_xattr:default acl style = windows add machine script = /usr/sbin/useradd -c "%u machine account" -d /dev/null -g machines -M -N -s /bin/false %u add user script = /usr/sbin/useradd -c "%u domain user" -d /dev/null -g users -M -N -s /bin/false %u # [homes] # [printers] [sysvol] path = /var/lib/samba/sysvol write list = @'Domain Admins@directory.slackware.uk.internal' [netlogon] path = /var/lib/samba/sysvol/directory.slackware.uk.internal/scripts write list = @'Domain Admins@directory.slackware.uk.internal'