一、环境信息
1.1、主机列表
IP | Hostname | role |
---|---|---|
10.10.100.60 | ad01 | 主域控 |
10.10.100.61 | ad02 | 辅域控 |
1.2、网络配置
ad01:
![](https://img.haomeiwen.com/i16382603/e0085a8da8e3327a.png)
ad02:
![](https://img.haomeiwen.com/i16382603/8b89866be4e22c2a.png)
二、安装主域控
2.1、依次打开服务器管理器,添加角色和功能
![](https://img.haomeiwen.com/i16382603/74679e43f8468a12.png)
2.2、进入“添加角色和功能向导”界面,点击“下一步”
![](https://img.haomeiwen.com/i16382603/f7f75ed7f3b6da8a.png)
2.3、选择安装类型,点击“下一步”
![](https://img.haomeiwen.com/i16382603/cd5cfc8e35eab607.png)
2.4、选择目标服务器,点击“下一步”
![](https://img.haomeiwen.com/i16382603/5a9a6fc627b7b394.png)
2.5、勾选“Active Directory域服务”
![](https://img.haomeiwen.com/i16382603/4516e92fe3598480.png)
2.6、弹出确认,点击“添加功能”,然后点击“下一步”
![](https://img.haomeiwen.com/i16382603/eb8adcddd14f66e3.png)
2.7、选择功能,直接点击“下一步”
![](https://img.haomeiwen.com/i16382603/9fb29eda5b43c77a.png)
2.8、进入AD DS菜单,直接点击“下一步”
![](https://img.haomeiwen.com/i16382603/503c02b4e5aadb9e.png)
2.9、确认安装所选内容,勾选“如果需要,自动重启目标服务器”,然后点击“安装”
![](https://img.haomeiwen.com/i16382603/696fadfa69cb75c1.png)
2.10、开始安装
![](https://img.haomeiwen.com/i16382603/c5bbd4725469b7ef.png)
2.11、角色安装完成后,点击“将此服务器提升为域控制器”
![](https://img.haomeiwen.com/i16382603/708b7520be11499e.png)
2.12、进入AD域服务配置向导,勾选“添加新林”,并“根域名”输入框内填入自己的域名(尽量不要跟自己已有外网访问域名冲突),然后点击“下一步”
![](https://img.haomeiwen.com/i16382603/6d448cf699963da6.png)
2.13、选择林和域功能级别,并输入目录还原模式密码,然后点击“下一步”
![](https://img.haomeiwen.com/i16382603/289fa0bb65d595da.png)
2.14、进入DNS选项,会出现一个警告,因为还没有安装DNS,直接忽略,点击“下一步”
![](https://img.haomeiwen.com/i16382603/a37e64f98c8799db.png)
2.15、其他选项菜单,直接下一步
![](https://img.haomeiwen.com/i16382603/34547796c802da4e.png)
2.16、配置路径,使用默认的,直接点击“下一步”
![](https://img.haomeiwen.com/i16382603/31fc3f527e31fe09.png)
2.17、查看选项,直接“下一步”
![](https://img.haomeiwen.com/i16382603/5dd4c22f566921c1.png)
2.18、进入先决条件检查
![](https://img.haomeiwen.com/i16382603/2d082fe58c8f6fc8.png)
2.19、等待所有先决条件检查通过后,点击“安装”
![](https://img.haomeiwen.com/i16382603/8889f473f568fc68.png)
2.20、等待安装完成
![](https://img.haomeiwen.com/i16382603/10baf2f4fdbefb49.png)
2.21、安装完成后,会提示重启。重启完成后,重新登陆域服务器
![](https://img.haomeiwen.com/i16382603/90f5010c23172a53.png)
2.22、升级为域控后,计算机管理中就不存在用户和组管理了
![](https://img.haomeiwen.com/i16382603/e379563443dd7851.png)
2.23、用户和组管理都在“Active Directory用户和计算机”中
![](https://img.haomeiwen.com/i16382603/1c5849750982eda8.png)
2.24、域控安装完成
![](https://img.haomeiwen.com/i16382603/c0600f80fcd320bd.png)
三、安装辅助域控
3.1、将辅助域控加入域
![](https://img.haomeiwen.com/i16382603/2ec6b23f8bcb540b.png)
![](https://img.haomeiwen.com/i16382603/48713b0302e1de9b.png)
3.2、主域控制器和DNS集成,为了让辅域控制器的DNS同步主域控制器DNS,需要把主域控制器的DNS服务器_msdcs.k8sre.com和k8sre.com 的起始授权机构(SOA)区域传送设置成允许。
![](https://img.haomeiwen.com/i16382603/404ba2e46d9348c0.png)
![](https://img.haomeiwen.com/i16382603/00c24ffa09ede746.png)
3.3、辅域控加入域重启后,使用主域管理员账号密码进行登录。然后打开服务管理器,添加角色和功能
![](https://img.haomeiwen.com/i16382603/53faf31c302d6029.png)
3.4、进入添加角色和功能向导,点击“下一步”
![](https://img.haomeiwen.com/i16382603/02cfb4de0947ab67.png)
3.5、进入选择安装类型,点击“下一步”
![](https://img.haomeiwen.com/i16382603/985d0a96946dacda.png)
3.6、进入服务器选择,点击“下一步”
![](https://img.haomeiwen.com/i16382603/ef84bb8216eaf92d.png)
3.7、进入服务器角色选择,勾选“Active Directory域服务和DNS服务器”,点击“下一步”
![](https://img.haomeiwen.com/i16382603/835ac5725af8f366.png)
3.8、进入功能选择,点击“下一步”
![](https://img.haomeiwen.com/i16382603/48c5cc24eebf2395.png)
3.9、进入AD DS,点击“下一步”
![](https://img.haomeiwen.com/i16382603/0a2f3385a6bf71f2.png)
3.10、进入DNS服务器菜单,点击“下一步”
![](https://img.haomeiwen.com/i16382603/02257c1892d21db2.png)
3.11、进入确认菜单,勾选“如果需要,自动重新启动目标服务器”,点击安装
![](https://img.haomeiwen.com/i16382603/c75a5095e84e85e4.png)
3.12、开始安装辅域控
![](https://img.haomeiwen.com/i16382603/7a6f2e10b635c4be.png)
3.13、安装完成,点击“将服务器提升为域控制器”
![](https://img.haomeiwen.com/i16382603/3a8b93a72f1ae4d1.png)
3.14、进入部署配置,选择“将域控制器添加到现有域”,并指定域及凭证,然后点击“下一步”
![](https://img.haomeiwen.com/i16382603/35d757851916b4af.png)
3.15、设置安装主域控时设置的目录还原密码,点击“下一步”
![](https://img.haomeiwen.com/i16382603/44418999b230945d.png)
3.16、进入DNS选项,点击“下一步”
![](https://img.haomeiwen.com/i16382603/6dc95803cf382273.png)
3.17、进入其他选项,指定其他复制选项,点击“下一步”
![](https://img.haomeiwen.com/i16382603/b713d3c1b7351df0.png)
3.18、进入路径选项,点击“下一步”
![](https://img.haomeiwen.com/i16382603/ae9e587962756b00.png)
3.19、进入查看选项,点击“下一步”
![](https://img.haomeiwen.com/i16382603/e2f22e16016bf1bb.png)
3.20、进入先决条件检查,完成后点击“安装”
![](https://img.haomeiwen.com/i16382603/1cf122735d48d98c.png)
3.21、安装完成后,重启辅域控
![](https://img.haomeiwen.com/i16382603/0c1d0a344688b559.png)
3.22、打开辅域控上的DNS服务,确认安装是否正常
![](https://img.haomeiwen.com/i16382603/8473803226981ab0.png)
3.23、至此,辅域控部署完毕
四、配置LDAPS
4.1、打开服务器管理器,添加角色和功能
![](https://img.haomeiwen.com/i16382603/c003ca25cbff34c2.png)
4.2、后面步骤都点击“下一步”,进入到选择服务器角色菜单,勾选“Actice Directory证书服务”
![](https://img.haomeiwen.com/i16382603/96289e36cac0d8eb.png)
4.3、后面步骤点击“下一步”,直到进入角色服务菜单,勾选“证书颁发机构”
![](https://img.haomeiwen.com/i16382603/f68f8c32b90ce96d.png)
4.4、后面步骤点击“下一步”,直到进入安装
![](https://img.haomeiwen.com/i16382603/95508f2760342477.png)
4.5、安装完成后,点击“配置目标服务器上的Actice Directory证书服务”
![](https://img.haomeiwen.com/i16382603/22cadbd0588f1b4c.png)
4.6、凭据,直接“下一步”
![](https://img.haomeiwen.com/i16382603/dd10afe7fa584cb6.png)
4.7、角色服务,勾选“证书颁发机构”,然后“下一步”
![](https://img.haomeiwen.com/i16382603/606c2b7f746f0336.png)
4.8、CA设置类型必须选择企业CA,如此选项是灰色的,请检查AD配置
![](https://img.haomeiwen.com/i16382603/65655551eebfe3d4.png)
4.9、CA类型选择“根CA”,点击“下一步”
![](https://img.haomeiwen.com/i16382603/e161034c1bb40204.png)
4.10、私钥类型选择“创建新的私钥”,点击“下一步”
![](https://img.haomeiwen.com/i16382603/9f19bc95b8db8386.png)
4.11、使用默认加密选项即可
![](https://img.haomeiwen.com/i16382603/e71afdf720535fbd.png)
4.12、指定CA名称,会根据主机名自动生成,点击“下一步”
![](https://img.haomeiwen.com/i16382603/799c564a390a1445.png)
4.13、指定证书有效期
![](https://img.haomeiwen.com/i16382603/4faa605e27d26452.png)
4.14、指定CA数据库位置,点击“下一步”
![](https://img.haomeiwen.com/i16382603/c4cee2a68ba62f4a.png)
4.15、确认配置,然后点击“配置”
![](https://img.haomeiwen.com/i16382603/d2b3e5ee5e678378.png)
4.16、配置完成
![](https://img.haomeiwen.com/i16382603/82b92fc0e8b2e361.png)
4.17 、辅域控也同样按照上面的步骤安装AD证书服务
4.18、重启下服务器,然后打开服务器管理器,工具,然后找到“证书颁发机构”,查看颁发的证书
![](https://img.haomeiwen.com/i16382603/3ccb05eb2fa40210.png)
![](https://img.haomeiwen.com/i16382603/a6fab129083cf100.png)
网友评论