LPIC-300 Objectives V3.0: Difference between revisions

From LPI Wiki
Jump to navigationJump to search
Line 180: Line 180:
<br />
<br />


====<span style="color:navy">392.4 Troubleshooting Samba (weight: 2)</span>====
====<span style="color:navy">392.4 Troubleshooting Samba (weight: 3)</span>====


{|
{|
Line 187: Line 187:
'''Weight'''
'''Weight'''


| style="background:#eaeaea" | 2
| style="background:#eaeaea" | 3
|-
|-
| style="background:#dadada; padding-right:1em" |  
| style="background:#dadada; padding-right:1em" |  
Line 195: Line 195:
| style="background:#eaeaea" |  
| style="background:#eaeaea" |  


Candidates should understand the structure of trivial database files and know how troubleshoot problems.
Candidates should be able to analyze and troubleshoot Samba issues. This includes accessing and modifying LDAP contents of a Samba server hosting an Active directory as well as working with trivial database files. Furthermore, candidates should be able to create a renamed clone of an existing Active Directory for debugging.


|}
|}
Line 201: Line 201:
'''Key Knowledge Areas:'''
'''Key Knowledge Areas:'''


* Configure Samba logging
* Configure Samba logging, including setting log levels for specific debug classes and client-specific logging
* Backup TDB files
* Query and modify the Samba password database
* Restore TDB files
* Understand the contents of important TDB files
* List and edit TDB file content
* Identify TDB file corruption
* Identify TDB file corruption
* Edit / list TDB file content
* Access and modify objects in a Samba LDAP directory
* Enable and use the LDAP recycle bin
* Confirm the integrity of a domain controller’s database
* Create a renamed clone of a domain controller
* Awareness of Samba eventlog shipping
* Use rpcclient to query information on a Samba server
 


'''The following is a partial list of the used files, terms and utilities:'''
'''The following is a partial list of the used files, terms and utilities:'''


* smb.conf:
** log level
** debuglevel
* /var/log/samba/
* /var/log/samba/
* log level
* debuglevel
* smbpasswd
* smbpasswd
* pdbedit
* pdbedit
* registry.tdb
* secrets.tdb
* secrets.tdb
* tdbbackup
* tdbdump
* tdbdump
* tdbrestore
* tdbtool
* tdbtool
* ldbsearch
* ldbmodify
* ldbedit
* ldbadd
* ldbdel
* LDIF
* samba-tool dbcheck
* samba-tool domain backup (including relevant subcommands)
* rpcclient


<br />
<br />

Revision as of 18:47, 23 January 2019

ATTENTION: THIS PAGE IS UNDER CONSTRUCTION



ATTENTION: THIS PAGE IS UNDER CONSTRUCTION

Introduction

A complete description of the LPIC-3 certification program can be found here.


Version Information

These objectives are A DRAFT FOR version 3.0.

LPIC-300 version 1.0 was partially formed from content in the 301 and 302 exams.


Addenda

Version Release (DATE TBD)

  • released version 3.0


Translations of Objectives

The following translations of the objectives are available on this wiki:


Objectives

Topic 392: Samba Basics

392.1 Samba Concepts and Architecture (weight: 2)

Weight

2

Description

Candidates should understand the essential concepts of Samba, including the various Samba server processes and networking protocols used by Samba when acting in various roles.

Key Knowledge Areas:

  • Understand the roles of the various Samba daemons and components
  • Understand key issues regarding heterogeneous networks
  • Understand the networking services used with SMB/CIFS and Active Directory, including their ports
  • Understand the major features of SMB protocol versions 1.0, 2.0, 2.1 and 3.0
  • Knowledge of Samba 3 and Samba 4 differences
  • Awareness of Samba VFS modules
  • Awareness of Samba Clustering and CTDB

Partial list of the used files, terms and utilities:

  • smbd, nmbd, samba, winbindd


392.2 Configure Samba (weight: 4)

Weight

4

Description

Candidates should be able to configure the Samba daemons.

Key Knowledge Areas:

  • Knowledge of Samba server file based configuration
  • Knowledge of Samba server registry based configuration
  • Knowledge of Samba configuration parameters and variables
  • Understand Samba server roles and security modes
  • Configure Samba to use TLS
  • Check the validity of a Samba configuration
  • Troubleshoot and debug configuration problems with Samba
  • Understand Windows tools used to configure a Samba Server


The following is a partial list of the used files, terms and utilities:

  • smb.conf
    • security
    • server role
    • server string
    • server services
    • tls enabled
    • tls keyfile
    • tls certfile
    • tls dh params file
    • tls cafile
    • config backend
    • registry shares
    • include
    • vfs objects
  • samba-regedit
  • HKLM\Software\Samba\
  • REG_SZ, REG_MULTI_SZ
  • testparm
  • net registry (including relevant subcommands)
  • Microsoft RSAT Tools
  • Microsoft MMC
  • Microsoft ADSI Edit
  • Microsoft LDP
  • Microsoft Regedit


392.3 Regular Samba Maintenance (weight: 2)

Weight


2

Description

Candidates should know about the various tools and utilities that are part of a Samba installation.

Key Knowledge Areas:

  • Start and stop Samba services on domain controllers and file servers
  • Monitor and interact with running Samba daemons
  • Backup and restore TDB files
  • Backup and restore an Active Directory domain controller
  • Understand backup and recovery strategies for Active Directory domain controllers
  • Understand the impact of virtualization on Active Directory domain controllers

The following is a partial list of the used files, terms and utilities:

  • systemctl
  • smbcontrol (including relevant message types)
  • smbstatus
  • tdbbackup
  • tdbrestore
  • samba-tool domain backup (including subcommands)
  • Virtual Machine Generation Identifier
  • Virtual Machine Snapshots


392.4 Troubleshooting Samba (weight: 3)

Weight

3

Description

Candidates should be able to analyze and troubleshoot Samba issues. This includes accessing and modifying LDAP contents of a Samba server hosting an Active directory as well as working with trivial database files. Furthermore, candidates should be able to create a renamed clone of an existing Active Directory for debugging.

Key Knowledge Areas:

  • Configure Samba logging, including setting log levels for specific debug classes and client-specific logging
  • Query and modify the Samba password database
  • Understand the contents of important TDB files
  • List and edit TDB file content
  • Identify TDB file corruption
  • Access and modify objects in a Samba LDAP directory
  • Enable and use the LDAP recycle bin
  • Confirm the integrity of a domain controller’s database
  • Create a renamed clone of a domain controller
  • Awareness of Samba eventlog shipping
  • Use rpcclient to query information on a Samba server


The following is a partial list of the used files, terms and utilities:

  • smb.conf:
    • log level
    • debuglevel
  • /var/log/samba/
  • smbpasswd
  • pdbedit
  • registry.tdb
  • secrets.tdb
  • tdbdump
  • tdbtool
  • ldbsearch
  • ldbmodify
  • ldbedit
  • ldbadd
  • ldbdel
  • LDIF
  • samba-tool dbcheck
  • samba-tool domain backup (including relevant subcommands)
  • rpcclient


392.5 Internationalization (weight: 1)

Weight

1

Description

Candidates should be able to work with internationalization character codes and code pages.

Key Knowledge Areas:

  • Understand internationalization character codes and code pages
  • Understand the difference in the name space between Windows and Linux/Unix with respect to share, file and directory names in a non-English environment
  • Understand the difference in the name space between Windows and Linux/Unix with respect to user and group naming in a non-English environment
  • Understand the difference in the name space between Windows and Linux/Unix with respect to computer naming in a non-English environment

The following is a partial list of the used files, terms and utilities:

  • internationalization
  • character codes
  • code pages
  • smb.conf
  • dos charset, display charset and unix charset


Topic 393: Samba Share Configuration

393.1 File Services (weight: 4)

Weight

4

Description

Candidates should be able to create and configure file shares in a mixed environment.

Key Knowledge Areas:

  • Create and configure file sharing
  • Plan file service migration
  • Limit access to IPC$
  • Create scripts for user and group handling of file shares
  • Samba share access configuration parameters

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • [homes]
  • smbcquotas
  • smbsh
  • browseable, writeable, valid users, write list, read list, read only and guest ok
  • IPC$
  • mount, smbmount


393.2 Linux File System and Share/Service Permissions (weight: 3)

Weight

3

Description

Candidates should understand file permissions on a Linux file system in a mixed environment.

Key Knowledge Areas:

  • Knowledge of file / directory permission control
  • Understand how Samba interacts with Linux file system permissions and ACLs
  • Use Samba VFS to store Windows ACLs

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • chmod, chown
  • create mask, directory mask, force create mode, force directory mode
  • smbcacls
  • getfacl, setfacl
  • vfs_acl_xattr, vfs_acl_tdb and vfs objects


393.3 Print Services (weight: 2)

Weight

2

Description

Candidates should be able to create and manage print shares in a mixed environment.

Key Knowledge Areas:

  • Create and configure printer sharing
  • Configure integration between Samba and CUPS
  • Manage Windows print drivers and configure downloading of print drivers
  • Configure [print$]
  • Understand security concerns with printer sharing
  • Uploading printer drivers for Point'n'Print driver installation using 'Add Print Driver Wizard' in Windows

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • [print$]
  • CUPS
  • cupsd.conf
  • /var/spool/samba/
  • smbspool
  • rpcclient
  • net


Topic 394: Samba User and Group Management

394.1 Managing User Accounts and Groups (weight: 4)

Weight

4

Description

Candidates should be able to manage user and group accounts in a mixed environment.

Key Knowledge Areas:

  • Manager user and group accounts
  • Understand user and group mapping
  • Knowledge of user account management tools
  • Use of the smbpasswd program
  • Force ownership of file and directory objects

The following is a partial list of the used files, terms and utilities:

  • pdbedit
  • smb.conf
  • samba-tool user (with subcommands)
  • samba-tool group (with subcommands)
  • smbpasswd
  • /etc/passwd
  • /etc/group
  • force user, force group
  • idmap


394.2 Authentication, Authorization and Winbind (weight: 5)

Weight

5

Description

Candidates should understand the various authentication mechanisms and configure access control. Candidates should be able to install and configure the Winbind service.

Key Knowledge Areas:

  • Setup a local password database
  • Perform password synchronization
  • Knowledge of different passdb backends
  • Convert between Samba passdb backends
  • Integrate Samba with LDAP
  • Configure Winbind service
  • Configure PAM and NSS

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • smbpasswd, tdbsam, ldapsam
  • passdb backend
  • libnss_winbind
  • libpam_winbind
  • libpam_smbpass
  • wbinfo
  • getent
  • SID and foreign SID
  • /etc/passwd
  • /etc/group


Topic 395: Samba Domain Integration

395.1 Samba as a PDC and BDC (weight: 3)

Weight

3

Description

Candidates should be able to setup and maintain primary and backup domain controllers. Candidates should be able to manage Windows/Linux client access to the NT-Style domains.

Key Knowledge Areas:

  • Understand and configure domain membership and trust relationships
  • Create and maintain a primary domain controller with Samba3 and Samba4
  • Create and maintain a backup domain controller with Samba3 and Samba4
  • Add computers to an existing domain
  • Configure logon scripts
  • Configure roaming profiles
  • Configure system policies

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • security mode
  • server role
  • domain logons
  • domain master
  • logon script
  • logon path
  • NTConfig.pol
  • net
  • profiles
  • add machine script
  • profile acls


395.2 Samba4 as an AD compatible Domain Controller (weight: 3)

Weight

3

Description

Candidates should be able to configure Samba 4 as an AD Domain Controller.

Key Knowledge Areas:

  • Configure and test Samba 4 as an AD DC
  • Using smbclient to confirm AD operation
  • Understand how Samba integrates with AD services: DNS, Kerberos, NTP, LDAP

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • server role
  • samba-tool domain (with subcommands)
  • samba


395.3 Configure Samba as a Domain Member Server (weight: 3)

Weight

3

Description

Candidates should be able to integrate Linux servers into an environment where Active Directory is present.

Key Knowledge Areas:

  • Joining Samba to an existing NT4 domain
  • Joining Samba to an existing AD domain
  • Ability to obtain a TGT from a KDC

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • server role
  • server security
  • net command
  • kinit, TGT and REALM



Topic 396: Samba Name Services

396.1 NetBIOS and WINS (weight: 3)

Weight

3

Description

Candidates should be familiar with NetBIOS/WINS concepts and understand network browsing.

Key Knowledge Areas:

  • Understand WINS concepts
  • Understand NetBIOS concepts
  • Understand the role of a local master browser
  • Understand the role of a domain master browser
  • Understand the role of Samba as a WINS server
  • Understand name resolution
  • Configure Samba as a WINS server
  • Configure WINS replication
  • Understand NetBIOS browsing and browser elections
  • Understand NETBIOS name types

The following is a partial list of the used files, terms and utilities:

  • smb.conf
  • nmblookup
  • smbclient
  • name resolve order
  • lmhosts
  • wins support, wins server, wins proxy, dns proxy
  • domain master, os level, preferred master


396.2 Active Directory Name Resolution (weight: 2)

Weight

2

Description

Candidates should be familiar with the internal DNS server with Samba4.

Key Knowledge Areas:

  • Understand and manage DNS for Samba4 as an AD Domain Controller
  • DNS forwarding with the internal DNS server of Samba4

The following is a partial list of the used files, terms and utilities:

  • samba-tool dns (with subcommands)
  • smb.conf
  • dns forwarder
  • /etc/resolv.conf
  • dig, host


Topic 397: Working with Linux and Windows Clients

397.1 CIFS Integration (weight: 3)

Weight

3

Description

Candidates should be comfortable working with CIFS in a mixed environment.

Key Knowledge Areas:

  • Understand SMB/CIFS concepts
  • Access and mount remote CIFS shares from a Linux client
  • Securely storing CIFS credentials
  • Understand features and benefits of CIFS
  • Understand permissions and file ownership of remote CIFS shares

The following is a partial list of the used files, terms and utilities:

  • SMB/CIFS
  • mount, mount.cifs
  • smbclient
  • smbget
  • smbtar
  • smbtree
  • findsmb
  • smb.conf
  • smbcquotas
  • /etc/fstab


397.2 Working with Windows Clients (weight: 2)

Weight

2

Description

Candidates should be able to interact with remote Windows clients, and configure Windows workstations to access file and print services from Linux servers.

Key Knowledge Areas:

  • Knowledge of Windows clients
  • Explore browse lists and SMB clients from Windows
  • Share file / print resources from Windows
  • Use of the smbclient program
  • Use of the Windows net utility

The following is a partial list of the used files, terms and utilities:

  • Windows net command
  • smbclient
  • control panel
  • rdesktop
  • workgroup