1
# Finnish translation for kubuntu-docs
2
# Copyright (c) 2010 Rosetta Contributors and Canonical Ltd 2010
3
# This file is distributed under the same license as the kubuntu-docs package.
4
# FIRST AUTHOR <EMAIL@ADDRESS>, 2010.
8
"Project-Id-Version: kubuntu-docs\n"
9
"Report-Msgid-Bugs-To: FULL NAME <EMAIL@ADDRESS>\n"
10
"POT-Creation-Date: 2011-09-15 02:35-0700\n"
11
"PO-Revision-Date: 2010-04-11 09:57+0000\n"
12
"Last-Translator: Timo Jyrinki <timo.jyrinki@gmail.com>\n"
13
"Language-Team: Finnish <fi@li.org>\n"
15
"Content-Type: text/plain; charset=UTF-8\n"
16
"Content-Transfer-Encoding: 8bit\n"
17
"X-Launchpad-Export-Date: 2011-10-05 10:22+0000\n"
18
"X-Generator: Launchpad (build 14085)\n"
20
#: ../docs/sharing/C/sharing.xml:12(title)
21
msgid "File Sharing in <phrase>Kubuntu</phrase>"
22
msgstr "Tiedostojen jako <phrase>Kubuntulla</phrase>"
24
#: ../docs/sharing/C/sharing.xml:3(title)
25
msgid "Credits and License"
26
msgstr "Tekijät ja lisenssi"
28
#: ../docs/sharing/C/sharing.xml:4(para)
30
"This document is maintained by the Ubuntu documentation team "
31
"(https://wiki.ubuntu.com/DocumentationTeam). For a list of contributors, see "
32
"the <ulink url=\"help:/kubuntu/contributors.html\">contributors page</ulink>"
34
"Tätä ohjetta ylläpitää Ubuntun dokumentaatiotiimi "
35
"(https://wiki.ubuntu.com/DocumentationTeam). Luettelo tekijöistä <ulink "
36
"url=\"help:/kubuntu/contributors.html\">tekijät-sivulla</ulink>"
38
#: ../docs/sharing/C/sharing.xml:5(para)
40
"This document is made available under the Creative Commons ShareAlike 2.5 "
43
"Tämä ohje on käytettävissä Creative Commons ShareAlike 2.5 -lisenssillä (CC-"
46
#: ../docs/sharing/C/sharing.xml:6(para)
48
"You are free to modify, extend, and improve the Ubuntu documentation source "
49
"code under the terms of this license. All derivative works must be released "
52
"Ubuntun ohjeiden lähdekoodia saa muokata, laajentaa ja parantaa tämän "
53
"lisenssin ehtojen mukaan. Kaikkien jatkotuotosten tulee olla julkaistu "
54
"samalla lisenssillä."
56
#: ../docs/sharing/C/sharing.xml:8(para)
58
"This documentation is distributed in the hope that it will be useful, but "
59
"WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY "
60
"or FITNESS FOR A PARTICULAR PURPOSE AS DESCRIBED IN THE DISCLAIMER."
62
"Tämä dokumentaatio jaetaan siinä toivossa, että siitä on hyötyä, mutta ilman "
63
"takuuta; edes epäsuoraa takuuta kaupattavuudesta, tai soveltuvuudesta "
64
"tiettyyn käyttöön kuten vastuuvapauslausekkeessa kuvaillaan, ei anneta."
66
#: ../docs/sharing/C/sharing.xml:11(para)
68
"A copy of the license is available here: <ulink "
69
"url=\"help:/kubuntu/copyright.html\">Creative Commons ShareAlike "
72
"Kopio lisenssistä on saatavilla täällä: <ulink "
73
"url=\"help:/kubuntu/copyright.html\">Creative Commons ShareAlike -"
76
#: ../docs/sharing/C/sharing.xml:14(year)
80
#: ../docs/sharing/C/sharing.xml:15(ulink)
81
msgid "Ubuntu Documentation Project"
82
msgstr "Ubuntun dokumentaatioprojekti"
84
#: ../docs/sharing/C/sharing.xml:15(holder)
85
msgid "Canonical Ltd. and members of the <placeholder-1/>"
86
msgstr "Canonical Ltd. ja seuraavan ryhmän jäsenet: <placeholder-1/>"
88
#: ../docs/sharing/C/sharing.xml:18(publishername)
89
msgid "The Ubuntu Documentation Project"
90
msgstr "Ubuntun dokumentaatioprojekti"
92
#: ../docs/sharing/C/sharing.xml:15(para)
94
"This document explains how to share files between <phrase>Kubuntu</phrase> "
97
"Tämä ohje kertoo tiedostojen jakamisesta <phrase>Kubuntun</phrase> ja "
100
#: ../docs/sharing/C/sharing.xml:22(title)
104
#: ../docs/sharing/C/sharing.xml:24(para)
106
"Computer networks are often comprised of diverse systems. While operating a "
107
"network made up entirely of <phrase>Kubuntu</phrase> desktop and server "
108
"computers would certainly be fun, some network environments will consist of "
109
"<phrase>Kubuntu</phrase> and <trademark "
110
"class=\"registered\">Microsoft</trademark><trademark "
111
"class=\"registered\">Windows</trademark> systems working together. This "
112
"section of the <phrase>Kubuntu</phrase> Server Guide introduces principles "
113
"and tools used for configuring <phrase>Kubuntu</phrase> servers to share "
114
"network resources with Windows computers."
117
#: ../docs/sharing/C/sharing.xml:34(para)
119
"Successfully networking a <phrase>Kubuntu</phrase> system with Windows "
120
"clients involves providing and integrating services common to Windows "
121
"environments. These services support sharing data and information about the "
122
"computers and users on the network, and may be classified into three major "
126
#: ../docs/sharing/C/sharing.xml:43(para)
128
"<emphasis role=\"bold\">File and Printer Sharing Services</emphasis>. The "
129
"Server Message Block (<acronym>SMB</acronym>) protocol is used to facilitate "
130
"sharing files, folders, volumes, and printers throughout the network."
133
#: ../docs/sharing/C/sharing.xml:50(para)
135
"<emphasis role=\"bold\">Directory Services</emphasis>. Vital information is "
136
"shared about the computers and users of the network with such technologies "
137
"as the Lightweight Directory Access Protocol (<acronym>LDAP</acronym>) and "
138
"Microsoft <trademark class=\"registered\">Active Directory</trademark>."
141
#: ../docs/sharing/C/sharing.xml:58(para)
143
"<emphasis role=\"bold\">Authentication and Access</emphasis>. It is "
144
"necessary to be able to establish the identity of a computer or user to "
145
"determine the information the computer or user is authorized to access. "
146
"Authentication and access use principles and technologies such as file "
147
"permissions, group policies, and the Kerberos authentication service."
150
#: ../docs/sharing/C/sharing.xml:68(para)
152
"A <phrase>Kubuntu</phrase> system can provide all such capabilities for "
153
"Windows clients and enable sharing network resources with them. One of the "
154
"principal pieces of software included in a <phrase>Kubuntu</phrase> system "
155
"for Windows networking is the Samba suite of <acronym>SMB</acronym> server "
156
"applications and tools."
159
#: ../docs/sharing/C/sharing.xml:75(para)
161
"This section of the <phrase>Kubuntu</phrase> Server Guide will introduce "
162
"some of the ways Samba is commonly used, and how to install and configure "
163
"the necessary packages. Additional detailed documentation and information on "
164
"Samba can be found on the <ulink url=\"http://www.samba.org\">Samba "
168
#: ../docs/sharing/C/sharing.xml:84(title)
169
msgid "Samba File Server"
170
msgstr "Samba-tiedostopalvelin"
172
#: ../docs/sharing/C/sharing.xml:86(para)
174
"One of the most common ways to network <phrase>Kubuntu</phrase> and Windows "
175
"computers is to configure Samba as a File Server. This section covers "
176
"setting up a <application>Samba</application> server to share files with "
180
#: ../docs/sharing/C/sharing.xml:92(para)
182
"The server will be configured to share files with any client on the network "
183
"without prompting for a password. If the environment requires stricter "
184
"Access Controls, see <xref linkend=\"samba-fileprint-security\"/>"
187
#: ../docs/sharing/C/sharing.xml:99(title) ../docs/sharing/C/sharing.xml:1299(title)
191
#: ../docs/sharing/C/sharing.xml:101(para)
193
"The first step is to install the <application>samba</application> package. "
194
"From a terminal prompt enter:"
196
"Ensimmäinen askel on asentaa <application>samba</application>-paketti. "
197
"Kirjoita päätteeseen:"
199
#: ../docs/sharing/C/sharing.xml:106(command)
200
msgid "sudo apt-get install samba"
201
msgstr "sudo apt-get install samba"
203
#: ../docs/sharing/C/sharing.xml:109(para)
205
"That's all there is to it. Samba is ready to be configured for file sharing."
208
#: ../docs/sharing/C/sharing.xml:115(title)
209
msgid "Configuration"
212
#: ../docs/sharing/C/sharing.xml:117(para)
214
"The main Samba configuration file is located in "
215
"<filename>/etc/samba/smb.conf</filename>. The default configuration file has "
216
"a significant number of comments in order to document various configuration "
220
#: ../docs/sharing/C/sharing.xml:124(para)
222
"Not all the available options are included in the default configuration "
223
"file. See the <filename>smb.conf</filename><application>man</application> "
224
"page or the <ulink url=\"http://samba.org/samba/docs/man/Samba-HOWTO-"
225
"Collection/\">Samba HOWTO Collection</ulink> for more details."
227
"Kaikkia mahdollisia vaihtoehtoja ei olla sisällytetty "
228
"oletusasetustiedostoon. Katso "
229
"<filename>smb.conf</filename><application>man</application> -sivu tai <ulink "
230
"url=\"http://samba.org/samba/docs/man/Samba-HOWTO-Collection/\">Samba HOWTO "
231
"Kokoelma</ulink> tarkempia yksityiskohtia varten."
233
#: ../docs/sharing/C/sharing.xml:134(para)
235
"Edit the following key/value pairs in the <emphasis>[global]</emphasis> "
236
"section of <filename>/etc/samba/smb.conf</filename>:"
239
#: ../docs/sharing/C/sharing.xml:139(programlisting) ../docs/sharing/C/sharing.xml:737(programlisting) ../docs/sharing/C/sharing.xml:969(programlisting)
243
"workgroup = EXAMPLE\n"
248
#: ../docs/sharing/C/sharing.xml:145(para)
250
"The <emphasis>security</emphasis> parameter is farther down in the [global] "
251
"section, and is commented out by default. Change "
252
"<emphasis>EXAMPLE</emphasis> to match the actual environment."
255
#: ../docs/sharing/C/sharing.xml:154(para)
257
"Create a new section at the bottom of the file, or uncomment one of the "
258
"examples for the directory to be shared:"
261
#: ../docs/sharing/C/sharing.xml:159(programlisting)
266
"comment = Ubuntu File Server Share\n"
267
"path = /srv/samba/share\n"
271
"create mask = 0755\n"
274
#: ../docs/sharing/C/sharing.xml:171(para)
276
"<emphasis>comment:</emphasis> a short description of the share. Adjust to "
277
"fit as appropriate."
280
#: ../docs/sharing/C/sharing.xml:177(para)
281
msgid "<emphasis>path:</emphasis> the path to the directory to share."
282
msgstr "<emphasis>path:</emphasis> polku jaettavaan kansioon."
284
#: ../docs/sharing/C/sharing.xml:180(para)
286
"This example uses <filename>/srv/samba/sharename</filename> because, "
287
"according to the <emphasis>Filesystem Hierarchy Standard (FHS)</emphasis>, "
288
"<ulink url=\"http://www.pathname.com/fhs/pub/fhs-2.3. "
289
"html#SRVDATAFORSERVICESPROVIDEDBYSYSTEM\">/srv</ulink> is where site-"
290
"specific data should be served. Technically Samba shares can be placed "
291
"anywhere on the filesystem as long as the permissions are correct, but "
292
"adhering to standards is recommended."
295
#: ../docs/sharing/C/sharing.xml:191(para)
297
"<emphasis>browsable:</emphasis> enables Windows clients to browse the shared "
298
"directory using <application>Windows Explorer</application>."
300
"<emphasis>browsable:</emphasis> sallii Windows-asiakkaiden selata jaettua "
301
"kansiota käyttäen <application>Windows Explorer</application>ia."
303
#: ../docs/sharing/C/sharing.xml:197(para)
305
"<emphasis>guest ok:</emphasis> allows clients to connect to the share "
306
"without supplying a password."
309
#: ../docs/sharing/C/sharing.xml:203(para)
311
"<emphasis>read only:</emphasis> determines if the share is read only or if "
312
"write privileges are granted. Write privileges are allowed only when the "
313
"value is <emphasis>no</emphasis>, as is seen in this example. If the value "
314
"is <emphasis>yes</emphasis>, then access to the share is read only."
317
#: ../docs/sharing/C/sharing.xml:208(para)
319
"<emphasis>create mask:</emphasis> determines the permissions new files will "
322
"<emphasis>create mask:</emphasis> määrittelee uusien luotujen tiedostojen "
325
#: ../docs/sharing/C/sharing.xml:218(para)
327
"Now that <application>Samba</application> is configured, the directory needs "
328
"to be created and the permissions changed. From a terminal enter:"
331
#: ../docs/sharing/C/sharing.xml:224(command)
332
msgid "sudo mkdir -p /srv/samba/share"
333
msgstr "sudo mkdir -p /srv/samba/share"
335
#: ../docs/sharing/C/sharing.xml:225(command)
336
msgid "sudo chown nobody.nogroup /srv/samba/share/"
337
msgstr "sudo chown nobody.nogroup /srv/samba/share/"
339
#: ../docs/sharing/C/sharing.xml:229(para)
341
"The <emphasis>-p</emphasis> switch tells mkdir to create the entire "
342
"directory tree if it doesn't exist. Change the share name to fit the "
346
#: ../docs/sharing/C/sharing.xml:238(para)
348
"Finally, restart the <application>samba</application> services to enable the "
351
"Käynnistä lopuksi <application>samba</application> uudelleen saadaksesi "
352
"uudet asetukset voimaan:"
354
#: ../docs/sharing/C/sharing.xml:243(command) ../docs/sharing/C/sharing.xml:398(command) ../docs/sharing/C/sharing.xml:515(command) ../docs/sharing/C/sharing.xml:910(command) ../docs/sharing/C/sharing.xml:1027(command) ../docs/sharing/C/sharing.xml:1148(command)
355
msgid "sudo /etc/init.d/samba restart"
356
msgstr "sudo /etc/init.d/samba restart"
358
#: ../docs/sharing/C/sharing.xml:250(para)
360
"The above configuration gives all access to any client on the local network. "
361
"For a more secure configuration, see <xref linkend=\"samba-fileprint-"
365
#: ../docs/sharing/C/sharing.xml:256(para)
367
"From a Windows client, it should now be possible to browse to the "
368
"<phrase>Kubuntu</phrase> file server and see the shared directory. To check "
369
"that everything is working, try creating a directory from Windows."
372
#: ../docs/sharing/C/sharing.xml:262(para)
374
"To create additional shares, simply create new <emphasis>[dir]</emphasis> "
375
"sections in <filename>/etc/samba/smb.conf</filename>, and restart "
376
"<emphasis>Samba</emphasis>. Make sure that the directory to be shared "
377
"actually exists and that the permissions are correct."
380
#: ../docs/sharing/C/sharing.xml:270(title) ../docs/sharing/C/sharing.xml:657(title) ../docs/sharing/C/sharing.xml:1049(title) ../docs/sharing/C/sharing.xml:1269(title)
382
msgstr "Tietolähteet"
384
#: ../docs/sharing/C/sharing.xml:274(para) ../docs/sharing/C/sharing.xml:1053(para)
386
"For in depth Samba configurations see the <ulink "
387
"url=\"http://samba.org/samba/docs/man/Samba-HOWTO-Collection/\">Samba HOWTO "
391
#: ../docs/sharing/C/sharing.xml:280(para) ../docs/sharing/C/sharing.xml:667(para) ../docs/sharing/C/sharing.xml:1059(para)
393
"The guide is also available in <ulink "
394
"url=\"http://www.amazon.com/exec/obidos/tg/detail/-/0131882228\">printed "
397
"Opas on saatavilla myös <ulink "
398
"url=\"http://www.amazon.com/exec/obidos/tg/detail/-/0131882228\">painettuna "
401
#: ../docs/sharing/C/sharing.xml:286(para)
404
"url=\"http://www.oreilly.com/catalog/9780596007690/\">Using Samba</ulink> is "
405
"another good reference."
408
#: ../docs/sharing/C/sharing.xml:297(title)
409
msgid "Securing a Samba File and Print Server"
412
#: ../docs/sharing/C/sharing.xml:300(title)
413
msgid "Samba Security Modes"
414
msgstr "Samban turvallisuustilat"
416
#: ../docs/sharing/C/sharing.xml:302(para)
418
"There are two security levels available to the Common Internet Filesystem "
419
"(CIFS) network protocol <emphasis>user-level</emphasis> and <emphasis>share-"
420
"level</emphasis>. Samba's <emphasis>security mode</emphasis> implementation "
421
"allows more flexibility, providing four ways of implementing user-level "
422
"security and one way to implement share-level:"
425
#: ../docs/sharing/C/sharing.xml:312(para)
427
"<emphasis>security = user:</emphasis> requires clients to supply a username "
428
"and password to connect to shares. Samba user accounts are separate from "
429
"system accounts, but the <application>libpam-smbpass</application> package "
430
"will sync system users and passwords with the Samba user database."
433
#: ../docs/sharing/C/sharing.xml:320(para)
435
"<emphasis>security = domain:</emphasis> this mode allows the Samba server to "
436
"appear to Windows clients as a Primary Domain Controller (PDC), Backup "
437
"Domain Controller (BDC), or a Domain Member Server (DMS). See <xref "
438
"linkend=\"samba-dc\"/> for further information."
441
#: ../docs/sharing/C/sharing.xml:328(para)
443
"<emphasis>security = ADS:</emphasis> allows the Samba server to join an "
444
"Active Directory domain as a native member. See <xref linkend=\"samba-ad-"
445
"integration\"/> for details."
448
#: ../docs/sharing/C/sharing.xml:335(para)
450
"<emphasis>security = server:</emphasis> this mode is left over from before "
451
"Samba could become a member server, and, due to some security issues, should "
452
"not be used. See the <ulink url=\"http://samba.org/samba/docs/man/Samba-"
453
"HOWTO-Collection/ServerType. html#id349531\">Server Security</ulink> section "
454
"of the Samba guide for more details."
457
#: ../docs/sharing/C/sharing.xml:345(para)
459
"<emphasis>security = share:</emphasis> allows clients to connect to shares "
460
"without supplying a username and password."
463
#: ../docs/sharing/C/sharing.xml:352(para)
465
"The preferred security mode depends on the environment and what the Samba "
466
"server needs to accomplish."
469
#: ../docs/sharing/C/sharing.xml:359(title)
470
msgid "Security = User"
471
msgstr "Security = User"
473
#: ../docs/sharing/C/sharing.xml:361(para)
475
"This section will reconfigure the Samba file and print server, from <xref "
476
"linkend=\"samba-fileserver\"/> and the <ulink type=\"help\" "
477
"url=\"help:/kubuntu/printing/\"> Print Server</ulink>, to require "
481
#: ../docs/sharing/C/sharing.xml:368(para)
483
"First, install the <application>libpam-smbpass</application> package which "
484
"will sync the system users to the Samba user database:"
487
#: ../docs/sharing/C/sharing.xml:374(command)
488
msgid "sudo apt-get install libpam-smbpass"
489
msgstr "sudo apt-get install libpam-smbpass"
491
#: ../docs/sharing/C/sharing.xml:378(para)
493
"If the <emphasis>Samba Server</emphasis> task was chosen during "
494
"installation, <application>libpam-smbpass</application> is already installed."
497
#: ../docs/sharing/C/sharing.xml:384(para)
499
"Edit <filename>/etc/samba/smb.conf</filename>, and in the "
500
"<emphasis>[share]</emphasis> section change:"
502
"Muokkaa tiedostoa <filename>/etc/samba/smb.conf</filename>, ja muuta "
503
"<emphasis>[share]</emphasis>-osioon:"
505
#: ../docs/sharing/C/sharing.xml:389(programlisting)
512
#: ../docs/sharing/C/sharing.xml:393(para)
513
msgid "Finally, restart Samba for the new settings to take effect:"
515
"Käynnistä Samba lopuksi uudestaan, jotta uudet asetukset tulevat voimaan:"
517
#: ../docs/sharing/C/sharing.xml:401(para)
519
"Now when connecting to the shared directories or printers, there will be a "
520
"prompt for a username and password."
523
#: ../docs/sharing/C/sharing.xml:407(para)
525
"To map a network drive to the share, <quote>Reconnect at Logon</quote> "
526
"should be checked, which will require the username and password to be "
527
"entered just once, at least until the password changes."
530
#: ../docs/sharing/C/sharing.xml:416(title)
531
msgid "Share Security"
534
#: ../docs/sharing/C/sharing.xml:418(para)
536
"There are several options available to increase the security for each "
537
"individual shared directory. Using the <emphasis>[share]</emphasis> example, "
538
"this section will cover some common options."
541
#: ../docs/sharing/C/sharing.xml:425(title)
545
#: ../docs/sharing/C/sharing.xml:427(para)
547
"Groups define a collection of computers or users which have a common level "
548
"of access to particular network resources and offer a level of granularity "
549
"in controlling access to such resources. For example, if a group <emphasis "
550
"role=\"italic\">qa</emphasis> is defined and contains the users <emphasis "
551
"role=\"italic\">freda</emphasis>, <emphasis "
552
"role=\"italic\">danika</emphasis>, and <emphasis "
553
"role=\"italic\">rob</emphasis> and a second group <emphasis "
554
"role=\"italic\">support</emphasis> is defined and consists of users "
555
"<emphasis role=\"italic\">danika</emphasis>, <emphasis "
556
"role=\"italic\">jeremy</emphasis>, and <emphasis "
557
"role=\"italic\">vincent</emphasis>, then certain network resources "
558
"configured to allow access by the <emphasis role=\"italic\">qa</emphasis> "
559
"group will subsequently enable access by freda, danika, and rob, but not "
560
"jeremy or vincent. Since the user <emphasis "
561
"role=\"italic\">danika</emphasis> belongs to both the <emphasis "
562
"role=\"italic\">qa</emphasis> and <emphasis "
563
"role=\"italic\">support</emphasis> groups, she will be able to access "
564
"resources configured for access by both groups, whereas all other users will "
565
"have only access to resources explicitly allowing the group they are part of."
568
#: ../docs/sharing/C/sharing.xml:448(para)
570
"By default Samba looks for the local system groups defined in "
571
"<filename>/etc/group</filename> to determine which users belong to which "
572
"groups. For more information on adding and removing users from groups see "
573
"<ulink type=\"help\" url=\"help:/kubuntu/basics/\"> Basics</ulink>."
576
#: ../docs/sharing/C/sharing.xml:455(para)
578
"When defining groups in the Samba configuration file, "
579
"<filename>/etc/samba/smb.conf</filename>, the recognized syntax is to "
580
"preface the group name with an \"@\" symbol. For example, to define a group "
581
"named <emphasis role=\"italic\">sysadmin</emphasis> in a certain section of "
582
"the <filename>/etc/samba/smb.conf</filename>, the group name would be "
583
"entered as <emphasis role=\"bold\">@sysadmin</emphasis>."
586
#: ../docs/sharing/C/sharing.xml:466(title)
587
msgid "File Permissions"
588
msgstr "Tiedostojen oikeudet"
590
#: ../docs/sharing/C/sharing.xml:468(para)
592
"File Permissions define the explicit rights a computer or user has to a "
593
"particular directory, file, or set of files. Such permissions may be defined "
594
"by editing the <filename>/etc/samba/smb.conf</filename> file and specifying "
595
"the explicit permissions of a defined file share."
598
#: ../docs/sharing/C/sharing.xml:475(para)
600
"For example, for a defined Samba share called <emphasis>share</emphasis> and "
601
"the need to give <emphasis role=\"italic\">read-only</emphasis> permissions "
602
"to the group of users known as <emphasis role=\"italic\">qa</emphasis>, "
603
"while allowing write permissions to the share by the group called <emphasis "
604
"role=\"italic\">sysadmin</emphasis> and the user named <emphasis "
605
"role=\"italic\">vincent</emphasis>, then the "
606
"<filename>/etc/samba/smb.conf</filename> file could be edited to add the "
607
"following entries under the <emphasis>[share]</emphasis> entry:"
610
#: ../docs/sharing/C/sharing.xml:486(programlisting)
615
"write list = @sysadmin, vincent\n"
618
#: ../docs/sharing/C/sharing.xml:491(para)
620
"Another possible Samba permission is to declare "
621
"<emphasis>administrative</emphasis> permissions to a particular shared "
622
"resource. Users having administrative permissions may read, write, or modify "
623
"any information contained in the resource where the user has been given "
624
"explicit administrative permissions."
627
#: ../docs/sharing/C/sharing.xml:499(para)
629
"For example, to give the user <emphasis role=\"italic\">melissa</emphasis> "
630
"administrative permissions to the <emphasis role=\"italic\">share</emphasis> "
631
"example, the <filename>/etc/samba/smb.conf</filename> file would be edited "
632
"to add the following line under the <emphasis>[share]</emphasis> entry:"
635
#: ../docs/sharing/C/sharing.xml:506(programlisting)
639
"admin users = melissa\n"
642
#: ../docs/sharing/C/sharing.xml:510(para)
644
"After editing <filename>/etc/samba/smb.conf</filename>, restart Samba for "
645
"the changes to take effect:"
648
#: ../docs/sharing/C/sharing.xml:519(para)
650
"For the <emphasis>read list</emphasis> and <emphasis>write list</emphasis> "
651
"to work the Samba security mode must <emphasis>not</emphasis> be set to "
652
"<emphasis role=\"italic\">security = share</emphasis>"
655
#: ../docs/sharing/C/sharing.xml:526(para)
657
"Now that Samba has been configured to limit which groups have access to the "
658
"shared directory, the filesystem permissions need to be updated."
661
#: ../docs/sharing/C/sharing.xml:531(para)
663
"Traditional Linux file permissions do not map well to Windows NT Access "
664
"Control Lists (ACLs). Fortunately POSIX ACLs are available on "
665
"<phrase>Kubuntu</phrase> servers providing more fine grained control. For "
666
"example, to enable ACLs on <filename>/srv</filename> an EXT3 filesystem, "
667
"edit <filename>/etc/fstab</filename> adding the <emphasis>acl</emphasis> "
671
#: ../docs/sharing/C/sharing.xml:539(programlisting)
675
"UUID=66bcdd2e-8861-4fb0-b7e4-e61c569fe17d /srv ext3 noatime,relatime,acl "
680
#: ../docs/sharing/C/sharing.xml:544(para)
681
msgid "Then remount the partition:"
684
#: ../docs/sharing/C/sharing.xml:549(command)
685
msgid "sudo mount -v -o remount /srv"
686
msgstr "sudo mount -v -o remount /srv"
688
#: ../docs/sharing/C/sharing.xml:553(para)
690
"The above example assumes <filename>/srv</filename> on a separate partition. "
691
"If <filename>/srv</filename>, or wherever the share path is configured, is "
692
"part of the <filename>/</filename> partition, a reboot may be required."
695
#: ../docs/sharing/C/sharing.xml:560(para)
697
"To match the Samba configuration above, the <emphasis>sysadmin</emphasis> "
698
"group will be given read, write, and execute permissions to "
699
"<filename>/srv/samba/share</filename>, the <emphasis>qa</emphasis> group "
700
"will be given read and execute permissions, and the files will be owned by "
701
"the username <emphasis>melissa</emphasis>. Enter the following in a terminal:"
704
#: ../docs/sharing/C/sharing.xml:569(command)
705
msgid "sudo chown -R melissa /srv/samba/share/"
706
msgstr "sudo chown -R melissa /srv/samba/share/"
708
#: ../docs/sharing/C/sharing.xml:570(command)
709
msgid "sudo chgrp -R sysadmin /srv/samba/share/"
710
msgstr "sudo chgrp -R sysadmin /srv/samba/share/"
712
#: ../docs/sharing/C/sharing.xml:571(command)
713
msgid "sudo setfacl -R -m g:qa:rx /srv/samba/share/"
714
msgstr "sudo setfacl -R -m g:qa:rx /srv/samba/share/"
716
#: ../docs/sharing/C/sharing.xml:575(para)
718
"The <application>setfacl</application> command above gives "
719
"<emphasis>execute</emphasis> permissions to all files in the "
720
"<filename>/srv/samba/share</filename> directory, which may or may not be "
724
#: ../docs/sharing/C/sharing.xml:583(para)
726
"A Windows client will show that the new file permissions are implemented. "
727
"See the <application>acl</application> and "
728
"<application>setfacl</application> man pages for more information on POSIX "
732
#: ../docs/sharing/C/sharing.xml:592(title)
733
msgid "Samba AppArmor Profile"
736
#: ../docs/sharing/C/sharing.xml:594(para)
738
"<phrase>Kubuntu</phrase> comes with the <application>AppArmor</application> "
739
"security module, which provides mandatory access controls. The default "
740
"AppArmor profile for Samba will need to be adapted to the proper "
741
"configuration. For more details on using AppArmor, please refer to the<ulink "
742
"url=\"https://help.ubuntu.com/community/AppArmor\"> wiki</ulink>"
745
#: ../docs/sharing/C/sharing.xml:602(para)
747
"There are default AppArmor profiles for <filename>/usr/sbin/smbd</filename> "
748
"and <filename>/usr/sbin/nmbd</filename>, the Samba daemon binaries, as part "
749
"of the <application>apparmor-profiles</application> packages. To install the "
750
"package, from a terminal prompt, enter:"
753
#: ../docs/sharing/C/sharing.xml:610(command)
754
msgid "sudo apt-get install apparmor-profiles"
755
msgstr "sudo apt-get install apparmor-profiles"
757
#: ../docs/sharing/C/sharing.xml:614(para)
758
msgid "This package contains profiles for several other binaries."
759
msgstr "Tämä paketti sisältää profiilitietoja muistakin binääritiedostoista"
761
#: ../docs/sharing/C/sharing.xml:619(para)
763
"By default the profiles for <application>smbd</application> and "
764
"<application>nmbd</application> are in <emphasis>complain</emphasis> mode, "
765
"allowing Samba to work without modifying the profile, and only logging "
766
"errors. To place the <application>smbd</application> profile into "
767
"<emphasis>enforce</emphasis> mode, and have Samba work as expected, the "
768
"profile will need to be modified to reflect any directories that are shared."
771
#: ../docs/sharing/C/sharing.xml:628(para)
773
"Edit <filename>/etc/apparmor.d/usr.sbin.smbd</filename>, adding information "
774
"for <emphasis>[share]</emphasis> from the file server example:"
777
#: ../docs/sharing/C/sharing.xml:633(programlisting)
781
"/srv/samba/share/ r,\n"
782
"/srv/samba/share/** rwkix,\n"
785
#: ../docs/sharing/C/sharing.xml:638(para)
787
"Now place the profile into <emphasis>enforce</emphasis> and reload it:"
790
#: ../docs/sharing/C/sharing.xml:643(command)
791
msgid "sudo aa-enforce /usr/sbin/smbd"
792
msgstr "sudo aa-enforce /usr/sbin/smbd"
794
#: ../docs/sharing/C/sharing.xml:644(command)
795
msgid "cat /etc/apparmor.d/usr.sbin.smbd | sudo apparmor_parser -r"
798
#: ../docs/sharing/C/sharing.xml:647(para)
800
"It is now possible to read, write, and execute files in the shared directory "
801
"as normal, and the <application>smbd</application> binary will have access "
802
"to only the configured files and directories. Be sure to add entries for "
803
"each directory that Samba is configured to share. Any errors will be logged "
804
"to <filename>/var/log/syslog</filename>."
807
#: ../docs/sharing/C/sharing.xml:661(para)
809
"For in depth Samba configurations, see the <ulink "
810
"url=\"http://samba.org/samba/docs/man/Samba-HOWTO-Collection/\">Samba HOWTO "
814
#: ../docs/sharing/C/sharing.xml:673(para) ../docs/sharing/C/sharing.xml:1065(para)
817
"url=\"http://www.oreilly.com/catalog/9780596007690/\">Using Samba</ulink> is "
818
"also a good reference."
821
#: ../docs/sharing/C/sharing.xml:679(para)
823
"<ulink url=\"http://samba.org/samba/docs/man/Samba-HOWTO-Collection/securing-"
824
"samba.html\">Chapter 18</ulink> of the Samba HOWTO Collection is devoted to "
828
#: ../docs/sharing/C/sharing.xml:686(para)
830
"For more information on Samba and ACLs, see the <ulink "
831
"url=\"http://samba.org/samba/docs/man/Samba-HOWTO-"
832
"Collection/AccessControls.html#id397568\">Samba ACLs page </ulink>."
835
#: ../docs/sharing/C/sharing.xml:697(title)
836
msgid "Samba as a Domain Controller"
839
#: ../docs/sharing/C/sharing.xml:699(para)
841
"Although it cannot act as an Active Directory Primary Domain Controller "
842
"(PDC), a Samba server can be configured to appear as a Windows NT4-style "
843
"domain controller. A major advantage of this configuration is the ability to "
844
"centralize user and machine credentials. Samba can also use multiple "
845
"backends to store the user information."
848
#: ../docs/sharing/C/sharing.xml:708(title)
849
msgid "Primary Domain Controller"
852
#: ../docs/sharing/C/sharing.xml:710(para)
854
"This section covers configuring Samba as a Primary Domain Controller (PDC) "
855
"using the default smbpasswd backend."
858
#: ../docs/sharing/C/sharing.xml:718(para)
860
"Install Samba and <application>libpam-smbpass</application> to sync the user "
861
"accounts, by entering the following in a terminal prompt:"
864
#: ../docs/sharing/C/sharing.xml:724(command) ../docs/sharing/C/sharing.xml:958(command)
865
msgid "sudo apt-get install samba libpam-smbpass"
866
msgstr "sudo apt-get install samba libpam-smbpass"
868
#: ../docs/sharing/C/sharing.xml:730(para)
870
"Next, configure Samba by editing <filename>/etc/samba/smb.conf</filename>. "
871
"The <emphasis>security</emphasis> mode should be set to <emphasis "
872
"role=\"italic\">user</emphasis>, and the <emphasis>workgroup</emphasis> "
873
"should relate to the organization properly:"
876
#: ../docs/sharing/C/sharing.xml:746(para)
878
"In the commented <quote>Domains</quote> section, add or uncomment the "
882
#: ../docs/sharing/C/sharing.xml:750(programlisting)
886
"domain logons = yes\n"
887
"logon path = \\\\%N\\%U\\profile\n"
889
"logon home = \\\\%N\\%U\n"
890
"logon script = logon.cmd\n"
891
"add machine script = sudo /usr/sbin/useradd -N -g machines -c Machine -d "
892
"/var/lib/samba -s /bin/false %u\n"
895
#: ../docs/sharing/C/sharing.xml:761(para)
897
"<emphasis>domain logons:</emphasis> provides the netlogon service causing "
898
"Samba to act as a domain controller."
901
#: ../docs/sharing/C/sharing.xml:767(para)
903
"<emphasis>logon path:</emphasis> places the user's Windows profile into "
904
"their home directory. It is also possible to configure a "
905
"<emphasis>[profiles]</emphasis> share placing all profiles under a single "
909
#: ../docs/sharing/C/sharing.xml:775(para)
911
"<emphasis>logon drive:</emphasis> specifies the home directory local path."
914
#: ../docs/sharing/C/sharing.xml:780(para)
916
"<emphasis>logon home:</emphasis> specifies the home directory location."
919
#: ../docs/sharing/C/sharing.xml:785(para)
921
"<emphasis>logon script:</emphasis> determines the script to be run locally "
922
"once a user has logged in. The script needs to be placed in the "
923
"<emphasis>[netlogon]</emphasis> share."
926
#: ../docs/sharing/C/sharing.xml:792(para)
928
"<emphasis>add machine script:</emphasis> a script that will automatically "
929
"create the <emphasis>Machine Trust Account</emphasis> needed for a "
930
"workstation to join the domain."
933
#: ../docs/sharing/C/sharing.xml:797(para)
935
"In this example, the <emphasis>machines</emphasis> group will need to be "
936
"created using the <application>addgroup</application> utility. See <ulink "
937
"type=\"help\" url=\"help:/kubuntu/basics/\"> Basics</ulink> for details."
940
#: ../docs/sharing/C/sharing.xml:806(para)
942
"If <emphasis>Roaming Profiles</emphasis> will not be used, leave the "
943
"<emphasis>logon home</emphasis> and <emphasis>logon path</emphasis> options "
947
#: ../docs/sharing/C/sharing.xml:816(para)
949
"Uncomment the <emphasis>[homes]</emphasis> share to allow the <emphasis "
950
"role=\"italic\">logon home</emphasis> to be mapped:"
953
#: ../docs/sharing/C/sharing.xml:821(programlisting)
958
"comment = Home Directories\n"
961
"create mask = 0700\n"
962
"directory mask = 0700\n"
966
#: ../docs/sharing/C/sharing.xml:834(para)
968
"When configured as a domain controller, a <emphasis>[netlogon]</emphasis> "
969
"share needs to be configured. To enable the share, uncomment:"
972
#: ../docs/sharing/C/sharing.xml:839(programlisting)
977
"comment = Network Logon Service\n"
978
"path = /srv/samba/netlogon\n"
984
#: ../docs/sharing/C/sharing.xml:849(para)
986
"The original <emphasis>netlogon</emphasis> share path is "
987
"<filename>/home/samba/netlogon</filename>, but according to the Filesystem "
988
"Hierarchy Standard (FHS), <ulink url=\"http://www.pathname.com/fhs/pub/fhs-"
989
"2.3. html#SRVDATAFORSERVICESPROVIDEDBYSYSTEM\">/srv</ulink> is the correct "
990
"location for site-specific data provided by the system."
993
#: ../docs/sharing/C/sharing.xml:862(para)
995
"Now create the <filename role=\"directory\">netlogon</filename> directory, "
996
"and an empty (for now) <filename>logon.cmd</filename> script file:"
999
#: ../docs/sharing/C/sharing.xml:868(command)
1000
msgid "sudo mkdir -p /srv/samba/netlogon"
1001
msgstr "sudo mkdir -p /srv/samba/netlogon"
1003
#: ../docs/sharing/C/sharing.xml:869(command)
1004
msgid "sudo touch /srv/samba/netlogon/logon.cmd"
1005
msgstr "sudo touch /srv/samba/netlogon/logon.cmd"
1007
#: ../docs/sharing/C/sharing.xml:872(para)
1009
"Any normal Windows logon script commands can be entered in "
1010
"<filename>logon.cmd</filename> to customize the client's environment."
1013
#: ../docs/sharing/C/sharing.xml:880(para)
1015
"With <emphasis>root</emphasis> being disabled by default, in order to join a "
1016
"workstation to the domain, a system group must be mapped to the Windows "
1017
"<emphasis>Domain Admins</emphasis> group. Using the "
1018
"<application>net</application> utility, from a terminal enter:"
1021
#: ../docs/sharing/C/sharing.xml:888(command)
1023
"sudo net groupmap add ntgroup=\"Domain Admins\" unixgroup=sysadmin rid=512 "
1027
#: ../docs/sharing/C/sharing.xml:893(para)
1029
"Change <emphasis role=\"italic\">sysadmin</emphasis> to the preferred group. "
1030
"The user used to join the domain needs to be a member of the "
1031
"<emphasis>sysadmin</emphasis> group, as well as a member of the system "
1032
"<emphasis>admin</emphasis> group. The <emphasis>admin</emphasis> group "
1033
"allows <application>sudo</application> use."
1036
#: ../docs/sharing/C/sharing.xml:905(para)
1037
msgid "Finally, restart Samba to enable the new domain controller:"
1040
#: ../docs/sharing/C/sharing.xml:916(para)
1042
"It is now possible to join Windows clients to the Domain in the same manner "
1043
"as joining them to an NT4 domain running on a Windows server."
1046
#: ../docs/sharing/C/sharing.xml:926(title)
1047
msgid "Backup Domain Controller"
1050
#: ../docs/sharing/C/sharing.xml:928(para)
1052
"With a Primary Domain Controller (PDC) on the network, it is best to have a "
1053
"Backup Domain Controller (BDC) as well. This will allow clients to "
1054
"authenticate in case the PDC becomes unavailable."
1057
#: ../docs/sharing/C/sharing.xml:934(para)
1059
"When configuring Samba as a BDC, there must be a way to sync account "
1060
"information with the PDC. There are multiple ways of accomplishing this, "
1061
"such as <application>scp</application>, <application>rsync</application>, or "
1062
"by using <application>LDAP</application> as the <emphasis>passdb "
1063
"backend</emphasis>."
1066
#: ../docs/sharing/C/sharing.xml:941(para)
1068
"Using LDAP is the most robust way to sync account information, because both "
1069
"domain controllers can use the same information in real time. However, "
1070
"setting up a LDAP server may be overly complicated for a small number of "
1071
"user and computer accounts. See Samba<ulink "
1072
"url=\"http://wiki.samba.org/index.php/Samba_&_LDAP\"> LDAP</ulink> page "
1076
#: ../docs/sharing/C/sharing.xml:953(para)
1078
"First, install <application>samba</application> and <application>libpam-"
1079
"smbpass</application>. From a terminal enter:"
1082
#: ../docs/sharing/C/sharing.xml:964(para)
1084
"Now, edit <filename>/etc/samba/smb.conf</filename> and uncomment the "
1085
"following in the <emphasis>[global]</emphasis>:"
1088
#: ../docs/sharing/C/sharing.xml:978(para)
1089
msgid "In the commented <emphasis>Domains</emphasis> uncomment or add:"
1092
#: ../docs/sharing/C/sharing.xml:982(programlisting)
1096
"domain logons = yes\n"
1097
"domain master = no\n"
1100
#: ../docs/sharing/C/sharing.xml:990(para)
1102
"Make sure a user has rights to read the files in "
1103
"<filename>/var/lib/samba</filename>. For example, to allow users in the "
1104
"<emphasis>admin</emphasis> group to <application>scp</application> the "
1108
#: ../docs/sharing/C/sharing.xml:997(command)
1109
msgid "sudo chgrp -R admin /var/lib/samba"
1112
#: ../docs/sharing/C/sharing.xml:1003(para)
1114
"Next, sync the user accounts, using <application>scp</application> to copy "
1115
"the <filename>/var/lib/samba</filename> directory from the PDC:"
1118
#: ../docs/sharing/C/sharing.xml:1009(command)
1119
msgid "sudo scp -r username@pdc:/var/lib/samba /var/lib"
1122
#: ../docs/sharing/C/sharing.xml:1013(para)
1124
"Replace <emphasis>username</emphasis> with a valid username and "
1125
"<emphasis>pdc</emphasis> with the hostname or IP Address of the actual PDC."
1128
#: ../docs/sharing/C/sharing.xml:1022(para)
1129
msgid "Finally, restart <application>samba</application>:"
1132
#: ../docs/sharing/C/sharing.xml:1033(para)
1134
"Test that the Backup Domain controller is working by stopping the Samba "
1135
"daemon on the PDC, then trying to login to a Windows client joined to the "
1139
#: ../docs/sharing/C/sharing.xml:1038(para)
1141
"If the <emphasis>logon home</emphasis> option has been configured as a "
1142
"directory on the PDC, and the PDC becomes unavailable, access to the user's "
1143
"<emphasis>Home</emphasis> drive will also be unavailable. For this reason, "
1144
"it is best to configure the <emphasis>logon home</emphasis> to reside on a "
1145
"separate file server from the PDC and BDC."
1148
#: ../docs/sharing/C/sharing.xml:1071(para)
1150
"<ulink url=\"http://samba.org/samba/docs/man/Samba-HOWTO-Collection/samba-"
1151
"pdc.html\"> Chapter 4</ulink> of the Samba HOWTO Collection explains setting "
1152
"up a Primary Domain Controller."
1155
#: ../docs/sharing/C/sharing.xml:1079(para)
1157
"<ulink url=\"http://us3.samba.org/samba/docs/man/Samba-HOWTO-"
1158
"Collection/samba-bdc.html\"> Chapter 5</ulink> of the Samba HOWTO Collection "
1159
"explains setting up a Backup Domain Controller."
1162
#: ../docs/sharing/C/sharing.xml:1092(title)
1163
msgid "Samba Active Directory Integration"
1166
#: ../docs/sharing/C/sharing.xml:1095(title)
1167
msgid "Accessing a Samba Share"
1170
#: ../docs/sharing/C/sharing.xml:1097(para)
1172
"Another use for Samba is to integrate into an existing Windows network. Once "
1173
"part of an Active Directory (AD) domain, Samba can provide file and print "
1174
"services to AD users."
1177
#: ../docs/sharing/C/sharing.xml:1103(para)
1179
"The simplest way to join an AD domain is to use <application>Likewise-"
1180
"open</application>. For detailed instructions, see <xref linkend=\"likewise-"
1184
#: ../docs/sharing/C/sharing.xml:1109(para)
1186
"Once part of the domain, enter the following command in the terminal prompt:"
1189
#: ../docs/sharing/C/sharing.xml:1114(command)
1190
msgid "sudo apt-get install samba smbfs smbclient"
1193
#: ../docs/sharing/C/sharing.xml:1117(para)
1195
"Since the <application>likewise-open</application> and "
1196
"<application>samba</application> packages use separate "
1197
"<filename>secrets.tdb</filename> files, a symlink must be created in "
1198
"<filename role=\"directory\">/var/lib/samba</filename>:"
1201
#: ../docs/sharing/C/sharing.xml:1124(command)
1202
msgid "sudo mv /var/lib/samba/secrets.tdb /var/lib/samba/secrets.tdb.orig"
1205
#: ../docs/sharing/C/sharing.xml:1125(command)
1206
msgid "sudo ln -s /etc/samba/secrets.tdb /var/lib/samba"
1209
#: ../docs/sharing/C/sharing.xml:1128(para)
1210
msgid "Next, edit <filename>/etc/samba/smb.conf</filename> changing:"
1213
#: ../docs/sharing/C/sharing.xml:1132(programlisting)
1217
"workgroup = EXAMPLE\n"
1220
"realm = EXAMPLE.COM\n"
1222
"idmap backend = lwopen\n"
1223
"idmap uid = 50-9999999999\n"
1224
"idmap gid = 50-9999999999\n"
1227
#: ../docs/sharing/C/sharing.xml:1143(para)
1229
"Restart <application>samba</application> for the new settings to take effect:"
1232
#: ../docs/sharing/C/sharing.xml:1151(para)
1234
"It should now be possible to access any <application>Samba</application> "
1235
"shares from a Windows client. However, be sure to give the appropriate AD "
1236
"users or groups access to the share directory. See <xref linkend=\"samba-"
1237
"fileprint-security\"/> for more details."
1240
#: ../docs/sharing/C/sharing.xml:1162(title)
1241
msgid "Accessing a Windows Share"
1244
#: ../docs/sharing/C/sharing.xml:1164(para)
1246
"Now that the Samba server is part of the Active Directory domain, any "
1247
"Windows server shares can be accessed:"
1250
#: ../docs/sharing/C/sharing.xml:1172(para)
1252
"To mount a Windows file share, enter the following in a terminal prompt:"
1255
#: ../docs/sharing/C/sharing.xml:1176(command)
1256
msgid "mount.cifs //fs01.example.com/share mount_point"
1259
#: ../docs/sharing/C/sharing.xml:1179(para)
1261
"It is also possible to access shares on computers not part of an AD domain, "
1262
"but a username and password must be provided."
1265
#: ../docs/sharing/C/sharing.xml:1187(para)
1267
"To mount the share during boot, place an entry in "
1268
"<filename>/etc/fstab</filename>, for example:"
1271
#: ../docs/sharing/C/sharing.xml:1192(programlisting)
1275
"//192.168.0.5/share /mnt/windows cifs auto,username=steve,password=secret,rw "
1279
#: ../docs/sharing/C/sharing.xml:1199(para)
1281
"Another way to copy files from a Windows server is to use the "
1282
"<application>smbclient</application> utility. To list the files in a Windows "
1286
#: ../docs/sharing/C/sharing.xml:1206(command)
1287
msgid "smbclient //fs01.example.com/share -k -c \"ls\""
1290
#: ../docs/sharing/C/sharing.xml:1212(para)
1291
msgid "To copy a file from the share, enter:"
1294
#: ../docs/sharing/C/sharing.xml:1217(command)
1295
msgid "smbclient //fs01.example.com/share -k -c \"get file.txt\""
1298
#: ../docs/sharing/C/sharing.xml:1220(para)
1300
"This will copy the <filename>file.txt</filename> into the current directory."
1303
#: ../docs/sharing/C/sharing.xml:1227(para)
1304
msgid "And to copy a file to the share:"
1307
#: ../docs/sharing/C/sharing.xml:1232(command)
1308
msgid "smbclient //fs01.example.com/share -k -c \"put /etc/hosts hosts\""
1311
#: ../docs/sharing/C/sharing.xml:1235(para)
1313
"This will copy the <filename>/etc/hosts</filename> to "
1314
"<filename>//fs01.example.com/share/hosts</filename>."
1317
#: ../docs/sharing/C/sharing.xml:1242(para)
1319
"The <emphasis>-c</emphasis> option used above allows execution of the "
1320
"<application>smbclient</application> command all at once. This is useful for "
1321
"scripting and minor file operations. To enter the <emphasis>smb: \\"
1322
"></emphasis> prompt, an FTP-like prompt where normal file and directory "
1323
"commands can be executed, simply run the following in Konsole:"
1326
#: ../docs/sharing/C/sharing.xml:1251(command)
1327
msgid "smbclient //fs01.example.com/share -k"
1330
#: ../docs/sharing/C/sharing.xml:1258(para)
1332
"Replace all instances of <emphasis>fs01.example.com/share</emphasis>, "
1333
"<emphasis>//192.168.0.5/share</emphasis>, "
1334
"<emphasis>username=steve,password=secret</emphasis>, and "
1335
"<emphasis>file.txt</emphasis> with the proper server IP, hostname, share "
1336
"name, file name, and an actual username and password with rights to the "
1340
#: ../docs/sharing/C/sharing.xml:1271(para)
1342
"For more <application>smbclient</application> options see the man page: "
1343
"<command>man smbclient</command>, also available <ulink "
1344
"url=\"http://manpages.ubuntu.com/manpages/jaunty/en/man1/smbclient.1.html\">o"
1348
#: ../docs/sharing/C/sharing.xml:1277(para)
1350
"The <application>mount.cifs</application><ulink "
1351
"url=\"http://manpages.ubuntu.com/manpages/jaunty/en/man8/mount.cifs.8.html\">"
1352
"man page</ulink> is also useful for more detailed information."
1355
#: ../docs/sharing/C/sharing.xml:1288(title)
1356
msgid "Likewise Open"
1359
#: ../docs/sharing/C/sharing.xml:1290(para)
1361
"<application>Likewise Open</application> simplifies the necessary "
1362
"configuration needed to authenticate a Linux machine to an Active Directory "
1363
"domain. Based on <application>winbind</application>, the "
1364
"<application>likewise-open</application> package takes the pain out of "
1365
"integrating <phrase>Kubuntu</phrase> authentication into an existing Windows "
1369
#: ../docs/sharing/C/sharing.xml:1301(para)
1371
"There are two ways to use Likewise Open, <application>likewise-"
1372
"open</application> the command line utility and <application>likewise-open-"
1373
"gui</application>. This section focuses on the command line utility."
1376
#: ../docs/sharing/C/sharing.xml:1308(para)
1378
"To install the <application>likewise-open</application> package, open a "
1379
"terminal prompt and enter:"
1381
"Asentaaksesi paketin <application>likewise-open</application>, avaa pääte ja "
1384
#: ../docs/sharing/C/sharing.xml:1313(command)
1385
msgid "sudo apt-get install likewise-open"
1386
msgstr "sudo apt-get install likewise-open"
1388
#: ../docs/sharing/C/sharing.xml:1316(para)
1390
"Starting with <phrase>Kubuntu</phrase> 9.04, <application>Likewise Open "
1391
"5.0</application> is available in the <emphasis>Universe</emphasis> "
1392
"repository. However, since upgrading from <application>Likewise Open "
1393
"4.1</application> currently requires the system to leave the domain and re-"
1394
"join, a separate package for version five was created."
1397
#: ../docs/sharing/C/sharing.xml:1324(para)
1398
msgid "To install <application>Likewise Open 5.0</application> enter:"
1401
#: ../docs/sharing/C/sharing.xml:1329(command)
1402
msgid "sudo apt-get install likewise-open5"
1405
#: ../docs/sharing/C/sharing.xml:1333(para)
1407
"Installing likewise-open5 over an existing likewise-open (4.1) installation "
1408
"will replace it. The domain will have to be rejoined after install."
1411
#: ../docs/sharing/C/sharing.xml:1341(title)
1412
msgid "Joining a Domain"
1415
#: ../docs/sharing/C/sharing.xml:1343(para)
1417
"The main executable file of the <application>likewise-open</application> "
1418
"package is <filename>/usr/bin/domainjoin-cli</filename>, which is used to "
1419
"join a computer to the domain. Before joining a domain, the following are "
1423
#: ../docs/sharing/C/sharing.xml:1351(para)
1425
"Access to an Active Directory user with appropriate rights to join the "
1429
#: ../docs/sharing/C/sharing.xml:1356(para)
1431
"The <emphasis>Fully Qualified Domain Name</emphasis> (FQDN) of the domain "
1432
"being joined. If the AD domain does not match a valid domain such as "
1433
"<emphasis role=\"italic\">example.com</emphasis>, it is likely that it is in "
1434
"the form of <emphasis>domainname.local</emphasis>."
1437
#: ../docs/sharing/C/sharing.xml:1364(para)
1439
"DNS for the domain set up properly. In a production AD environment, this is "
1440
"typically the case. Proper Microsoft DNS is needed so that client "
1441
"workstations can determine that the Active Directory domain is available."
1444
#: ../docs/sharing/C/sharing.xml:1369(para)
1446
"If there is not a Windows DNS server on the network, see <xref "
1447
"linkend=\"likewise-open-ms-dns\"/> for details."
1450
#: ../docs/sharing/C/sharing.xml:1377(para)
1451
msgid "To join a domain, from a terminal prompt enter:"
1454
#: ../docs/sharing/C/sharing.xml:1382(command)
1455
msgid "sudo domainjoin-cli join example.com Administrator"
1458
#: ../docs/sharing/C/sharing.xml:1386(para)
1460
"Replace <emphasis>example.com</emphasis> with the proper domain name, and "
1461
"<emphasis>Administrator</emphasis> with the appropriate user name."
1464
#: ../docs/sharing/C/sharing.xml:1392(para)
1466
"There will be a prompt for the user's password. If all goes well, a "
1467
"<emphasis>SUCCESS</emphasis> message should be printed to the console."
1470
#: ../docs/sharing/C/sharing.xml:1398(para)
1472
"After joining the domain, it is necessary to reboot before attempting to "
1473
"authenticate against the domain."
1476
#: ../docs/sharing/C/sharing.xml:1404(para)
1478
"After successfully joining an <phrase>Kubuntu</phrase> machine to an Active "
1479
"Directory domain, any valid AD user can be used to authenticate. To login, "
1480
"the user name must be entered as 'domain\\username'. For example to ssh to a "
1481
"server joined to the domain, enter:"
1484
#: ../docs/sharing/C/sharing.xml:1412(command)
1485
msgid "ssh 'example\\steve'@hostname"
1488
#: ../docs/sharing/C/sharing.xml:1416(para)
1490
"If configuring a Desktop, the user name will need to be prefixed with "
1491
"<emphasis role=\"italic\">domain\\</emphasis> in the graphical logon as well."
1494
#: ../docs/sharing/C/sharing.xml:1422(para)
1496
"To make likewise-open use a default domain, the following statement can be "
1497
"added to <filename>/etc/samba/lwiauthd.conf</filename>:"
1500
#: ../docs/sharing/C/sharing.xml:1427(programlisting)
1504
"winbind use default domain = yes\n"
1507
#: ../docs/sharing/C/sharing.xml:1431(para)
1508
msgid "Then restart the <application>likewise-open</application> daemons:"
1511
#: ../docs/sharing/C/sharing.xml:1436(command)
1512
msgid "sudo /etc/init.d/likewise-open restart"
1515
#: ../docs/sharing/C/sharing.xml:1440(para)
1517
"Once configured for a <emphasis>default domain</emphasis>, the <emphasis "
1518
"role=\"italic\">'domain\\'</emphasis> is no longer required. Users can login "
1519
"using only their username."
1522
#: ../docs/sharing/C/sharing.xml:1447(para)
1524
"The <application>domainjoin-cli</application> utility can also be used to "
1525
"leave the domain. From a terminal:"
1528
#: ../docs/sharing/C/sharing.xml:1453(command)
1529
msgid "sudo domainjoin-cli leave"
1532
#: ../docs/sharing/C/sharing.xml:1458(title)
1533
msgid "Other Utilities"
1536
#: ../docs/sharing/C/sharing.xml:1460(para)
1538
"The <application>likewise-open</application> package comes with a few other "
1539
"utilities that may be useful for gathering information about the Active "
1540
"Directory environment. These utilities are used to join the machine to the "
1541
"domain, and are the same as those available in the <application>samba-"
1542
"common</application> and <application>winbind</application> packages:"
1545
#: ../docs/sharing/C/sharing.xml:1471(para)
1547
"<application>lwinet</application>: Returns information about the network and "
1551
#: ../docs/sharing/C/sharing.xml:1476(para)
1553
"<application>lwimsg</application>: Allows interaction with the "
1554
"<application>likewise-winbindd</application> daemon."
1557
#: ../docs/sharing/C/sharing.xml:1481(para)
1559
"<application>lwiinfo</application>: Displays information about various parts "
1563
#: ../docs/sharing/C/sharing.xml:1488(para)
1564
msgid "Please refer to each utility's man page specific for details."
1567
#: ../docs/sharing/C/sharing.xml:1494(title)
1568
msgid "Troubleshooting"
1569
msgstr "Ongelmanratkaisu"
1571
#: ../docs/sharing/C/sharing.xml:1498(para)
1573
"If the client has trouble joining the domain, check that the Microsoft DNS "
1574
"is listed first in <filename>/etc/resolv.conf</filename>. For example:"
1577
#: ../docs/sharing/C/sharing.xml:1504(programlisting)
1581
"nameserver 192.168.0.1\n"
1584
#: ../docs/sharing/C/sharing.xml:1509(para)
1586
"For more information when joining a domain, use the <emphasis>--loglevel "
1587
"verbose</emphasis> or <emphasis>--advanced</emphasis> option of the "
1588
"<application>domainjoin-cli</application> utility:"
1591
#: ../docs/sharing/C/sharing.xml:1515(command)
1592
msgid "sudo domainjoin-cli --loglevel verbose join example.com Administrator"
1595
#: ../docs/sharing/C/sharing.xml:1519(para)
1597
"If an Active Directory user has trouble logging in, check the "
1598
"<filename>/var/log/auth.log</filename> for details."
1601
#: ../docs/sharing/C/sharing.xml:1524(para)
1603
"When joining an <phrase>Kubuntu</phrase> Desktop workstation to a domain, it "
1604
"may be necessary to edit <filename>/etc/nsswitch.conf</filename> if the AD "
1605
"domain uses the <emphasis role=\"italic\">.local</emphasis> syntax. In order "
1606
"to join the domain, the <emphasis>\"mdns4\"</emphasis> entry should be "
1607
"removed from the <emphasis>hosts</emphasis> option. For example:"
1610
#: ../docs/sharing/C/sharing.xml:1532(programlisting)
1614
"hosts: files mdns4_minimal [NOTFOUND=return] dns mdns4\n"
1617
#: ../docs/sharing/C/sharing.xml:1536(para)
1618
msgid "Change the above to:"
1621
#: ../docs/sharing/C/sharing.xml:1540(programlisting)
1625
"hosts: files dns [NOTFOUND=return]\n"
1628
#: ../docs/sharing/C/sharing.xml:1544(para)
1629
msgid "Then restart networking by entering:"
1632
#: ../docs/sharing/C/sharing.xml:1549(command)
1633
msgid "sudo /etc/init.d/networking restart"
1636
#: ../docs/sharing/C/sharing.xml:1552(para)
1637
msgid "It should now be possible to join the Active Directory domain."
1640
#: ../docs/sharing/C/sharing.xml:1560(title)
1641
msgid "Microsoft DNS"
1644
#: ../docs/sharing/C/sharing.xml:1562(para)
1646
"The following are instructions for installing DNS on an Active Directory "
1647
"domain controller running Windows Server 2003, but the instructions should "
1648
"be similar for other versions:"
1651
#: ../docs/sharing/C/sharing.xml:1572(para)
1654
"<menuchoice><guimenuitem>Start</guimenuitem><guimenuitem>Administrative Tools"
1655
"</guimenuitem><guimenuitem>Manage Your Server</guimenuitem></menuchoice>. "
1656
"This will open the <application>Server Role Management</application> utility."
1659
#: ../docs/sharing/C/sharing.xml:1580(para)
1660
msgid "Click <guilabel>Add or remove a role</guilabel>"
1663
#: ../docs/sharing/C/sharing.xml:1581(para) ../docs/sharing/C/sharing.xml:1583(para) ../docs/sharing/C/sharing.xml:1586(para)
1667
#: ../docs/sharing/C/sharing.xml:1582(para)
1668
msgid "Select \"DNS Server\""
1671
#: ../docs/sharing/C/sharing.xml:1584(para)
1672
msgid "Click Next again to proceed"
1675
#: ../docs/sharing/C/sharing.xml:1585(para)
1676
msgid "Select \"Create a forward lookup zone\" if it is not selected."
1679
#: ../docs/sharing/C/sharing.xml:1587(para)
1681
"Make sure \"This server maintains the zone\" is selected and click Next."
1684
#: ../docs/sharing/C/sharing.xml:1588(para)
1685
msgid "Enter the domain name and click Next"
1688
#: ../docs/sharing/C/sharing.xml:1589(para)
1689
msgid "Click Next to \"Allow only secure dynamic updates\""
1692
#: ../docs/sharing/C/sharing.xml:1591(para)
1694
"Enter the IP for DNS servers to forward queries to, or Select \"No, it "
1695
"should not forward queries\" and click Next."
1698
#: ../docs/sharing/C/sharing.xml:1595(para) ../docs/sharing/C/sharing.xml:1596(para)
1699
msgid "Click Finish"
1702
#: ../docs/sharing/C/sharing.xml:1598(para)
1704
"DNS is now installed and can be further configured using the "
1705
"<application>Microsoft Management Console</application> DNS snap-in."
1708
#: ../docs/sharing/C/sharing.xml:1606(para)
1712
#: ../docs/sharing/C/sharing.xml:1607(para)
1713
msgid "Control Panel"
1714
msgstr "Ohjauspaneeli"
1716
#: ../docs/sharing/C/sharing.xml:1608(para)
1717
msgid "Network Connections"
1718
msgstr "Verkkoyhteydet"
1720
#: ../docs/sharing/C/sharing.xml:1609(para)
1721
msgid "Right Click \"Local Area Connection\""
1724
#: ../docs/sharing/C/sharing.xml:1610(para)
1725
msgid "Click Properties"
1728
#: ../docs/sharing/C/sharing.xml:1611(para)
1729
msgid "Double click \"Internet Protocol (TCP/IP)\""
1732
#: ../docs/sharing/C/sharing.xml:1612(para)
1733
msgid "Enter the Server's IP Address as the \"Preferred DNS server\""
1736
#: ../docs/sharing/C/sharing.xml:1613(para)
1740
#: ../docs/sharing/C/sharing.xml:1614(para)
1741
msgid "Click Ok again to save the settings"
1744
#: ../docs/sharing/C/sharing.xml:1603(para)
1746
"Next, configure the Server to use itself for DNS queries: <placeholder-1/>"
1749
#: ../docs/sharing/C/sharing.xml:1621(title)
1751
msgstr "Viittaukset"
1753
#: ../docs/sharing/C/sharing.xml:1623(para)
1755
"Please refer to the <ulink "
1756
"url=\"http://www.likewisesoftware.com/\">Likewise</ulink> home page for "
1757
"further information."
1760
#: ../docs/sharing/C/sharing.xml:1627(para)
1762
"For more <application>domainjoin-cli</application> options see the man page: "
1763
"<command>man domainjoin-cli</command>."
1766
#. Put one translator per line, in the form of NAME <EMAIL>, YEAR1, YEAR2
1767
#: ../docs/sharing/C/sharing.xml:0(None)
1768
msgid "translator-credits"
1770
"Launchpad Contributions:\n"
1771
" Timo Jyrinki https://launchpad.net/~timo-jyrinki"