Active Directory Domain Join
Install required packages
sudo apt install sssd-ad sssd-tools realmd adcliConfirm domain discovery via DNS
sudo realm -v discover ad1.example.com * Resolving: _ldap._tcp.ad1.example.com * Performing LDAP DSE lookup on: 10.51.0.5 * Successfully discovered: ad1.example.comad1.example.com type: kerberos realm-name: AD1.EXAMPLE.COM domain-name: ad1.example.com configured: no server-software: active-directory client-software: sssd required-package: sssd-tools required-package: sssd required-package: libnss-sss required-package: libpam-sss required-package: adcli required-package: samba-common-binJoin device to domain
adcli join -U yout_user@YOUR.REALM --domain-controller=your.dc.fqdn --verbose --ldap-passwdConfigure SSSD
[sssd]domains = ad1.example.comconfig_file_version = 2services = nss, pam[domain/ad1.example.com]default_shell = /bin/bashkrb5_store_password_if_offline = Truecache_credentials = Truekrb5_realm = AD1.EXAMPLE.COMrealmd_tags = manages-system joined-with-adcliid_provider = adfallback_homedir = /home/%u@%dad_domain = ad1.example.comuse_fully_qualified_names = Trueldap_id_mapping = Trueaccess_provider = adAllow user home directory creation
Testing setup
Fetch AD User information
Fetch AD Group membership information
Last updated