Difference between revisions of "SAMBA Cross-Domain Trust File Server"
Jump to navigation
Jump to search
Michael.mast (talk | contribs) (→Config) |
Michael.mast (talk | contribs) (→Config) |
||
Line 8: | Line 8: | ||
Work in progress | Work in progress | ||
*Prep base OS with automatic updates and a firewall. Make sure to edit the yum-cron config to install security only, and to install updates after downloading. | *Prep base OS with automatic updates and a firewall. Make sure to edit the yum-cron config to install security only, and to install updates after downloading. | ||
+ | <pre> | ||
+ | sudo yum upgrade -y | ||
+ | sudo reboot -h now | ||
+ | </pre> | ||
<pre> | <pre> | ||
sudo yum install epel-release yum-cron firewalld | sudo yum install epel-release yum-cron firewalld | ||
sudo systemctl enable --now firewalld | sudo systemctl enable --now firewalld | ||
sudo systemctl enable --now yum-cron | sudo systemctl enable --now yum-cron | ||
− | |||
− | |||
− | |||
sudo hostnamectl set-hostname myfileserver | sudo hostnamectl set-hostname myfileserver | ||
sudo reboot -h now | sudo reboot -h now |
Revision as of 10:50, 13 January 2020
Purpose
Existing file server is not configured properly. Will be moving this non-critical data to a new server running in AWS. Since I can live with some downtime if needed, it is much cheaper to use a small AWS instance than to use the expensive Windows based file service AWS offers.
Host
Host is t3a.small CentOS7 instance running on EC2. At the time of this writing CentOS8 is not available on the AWS store.
Though not a critical system, it will be holding sensitive data and I want native SELinux.
Config
Work in progress
- Prep base OS with automatic updates and a firewall. Make sure to edit the yum-cron config to install security only, and to install updates after downloading.
sudo yum upgrade -y sudo reboot -h now
sudo yum install epel-release yum-cron firewalld sudo systemctl enable --now firewalld sudo systemctl enable --now yum-cron sudo hostnamectl set-hostname myfileserver sudo reboot -h now
- Install kerberose and related packages.
sudo yum install -y realmd krb5-workstation oddjob oddjob-mkhomedir sssd samba-common samba-common-tools