Samba / FreeBSD member server in MSFT 2003 AD domain


 
Thread Tools Search this Thread
Top Forums UNIX for Dummies Questions & Answers Samba / FreeBSD member server in MSFT 2003 AD domain
# 1  
Old 09-29-2004
Samba / FreeBSD member server in MSFT 2003 AD domain

By following the Samba.org how-to's and various finds on groups.google.com I've succeeded in getting a FreeBSD (5.2.1-RELEASE) / Samb-3.0.0,1 server in to my MSFT 2003 Active Directory domain as a member server, but there is a little problem I'm having trouble resolving.

Newly created user accounts (read as created after joining the Samba server to the domain) in the AD domain gain access to the Samba shares just fine. However, pre-existing user accounts in the AD domain cannot authenticate to the Samba server properly. They receive an NT_STATUS_LOGON_FAILURE.

#kinit newADuser

receives a kerberos key successfully, and

#wbinfo --authenticate=newADuser%'userspassword'

authenticates successfully in all cases.

There is some mention of having to change the passwords of users after some setup step in order to get things working correctly, which I have tried, but it makes no change. My new AD users work, my old ones don't.

This acts like its something I need to do on the Microsoft AD side.

Anyone's experience or ideas on where to find more info would be greatly appreciated.

- CCY
 
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Ubuntu Server 14.04 LTS - domain controller configuration (SAMBA)

Hello! Never configured a Linux server from a scratch. Reviewed the official documentation and dozens of different "how to", but now one of them helped me to solve the issue. The need: My final goal is to install a small network (later with around 10 stations) where I can controle the... (0 Replies)
Discussion started by: AQwert
0 Replies

2. UNIX and Linux Applications

Server migration from samba+ldap to windows server 2003

Hi, i have a server installed samba+openldap (pdc). Need to migration windows server 2003 (active directory) object users, computers. Where you can read how to do it? Or can tell me how to do it? Thanks. P.S. Sorry for bad english (0 Replies)
Discussion started by: ap0st0l
0 Replies

3. Windows & DOS: Issues & Discussions

Lost Domain Admin Privileges in Samba

Hello, I have apparently lost all domain admin privledges in Samba. I have had several problems ever since I installed the 1/31 Solaris patch cluster. I had to roll out one Samba update (146363-01), which denied all logons network access. However, this particular problem seems to have begun... (0 Replies)
Discussion started by: stringman
0 Replies

4. Debian

Testing a SAMBA Domain Controller

Hello,,, We have an existing(working) MS PDC in our office. I have already installed SAMBA with LDAP Authentication on a TEST machine (on same LAN). But, am unable to join a WinXP machine to this domain. in smb.conf i have: WORKGROUP = mydomain and tried to join the XP machine to... (0 Replies)
Discussion started by: coolatt
0 Replies

5. UNIX for Dummies Questions & Answers

Samba change domain controller

Hello people i have a samba and they changed domain controller from a windows 2003 to a windows 2008, there is a problem with the version of samba maybe incompatibilities i dont know what show me this domain_client_validate: unable to validate password for user xxxx in domain xxxx to Domain... (0 Replies)
Discussion started by: enkei17
0 Replies

6. Homework & Coursework Questions

cannot join xp or vista to samba domain (PDC)

Use and complete the template provided. The entire template must be completed. If you don't, your post may be deleted! 1. The problem statement, all variables and given/known data: I have a barebones XP Pro SP2 with no firewall. CentOS 5.xx running a Samba 3.xx Domain (PDC) The XP machine... (2 Replies)
Discussion started by: pogipants
2 Replies

7. UNIX for Advanced & Expert Users

Windows 2003 use Samba user database

Hi, I have been looking for information on how to make a Windows 2003 server use the user database of an existing Samba installation. What I want is to use the Win3K as a (second) file server allowing users (using Win2K & Win XP computers) to access its shares using their existing user... (0 Replies)
Discussion started by: jcd
0 Replies

8. Red Hat

Samba: Authenticating and joining AD domain as a member

Hi all, I'm having some problems with joining an active directory domain as a member. My Linux servers using the same configuration across the board are all joining as domain controllers, which is bad. I am running Samba 3.0.25b-0.4E.6 on all of my RHEL servers. Here is my global... (1 Reply)
Discussion started by: Bert
1 Replies

9. UNIX for Advanced & Expert Users

Insert data from Unix Server to DB in a MS Server 2003

Hi, I need to create a script that executes weekly in a Unix server to collect data from new files added in certain directories. Then i need to send that data to an MS Access data base (planning to migrate to SQL Server 2005) located in a MS Server 2003. So my question is how can i send the... (1 Reply)
Discussion started by: Metalero de Oz
1 Replies

10. UNIX for Advanced & Expert Users

Samba does not connect to domain

I have a samba server and a raid SAN which is actually running samba. Neither one lets me access anything on the samba unix side. I really do not know where to look anymore. there are no errors. When I try to connect to the samba server I get prompted with login and password repeatedly. Frank (4 Replies)
Discussion started by: frankkahle
4 Replies
Login or Register to Ask a Question
WBINFO(1)																 WBINFO(1)

NAME
wbinfo - Query information from winbind daemon SYNOPSIS
wbinfo [ -u ] [ -g ] [ -h name ] [ -i ip ] [ -n name ] [ -s sid ] [ -U uid ] [ -G gid ] [ -S sid ] [ -Y sid ] [ -t ] [ -m ] [ -r user ] [ -a user%password ] [ -A user%password ] DESCRIPTION
This tool is part of the Samba suite. The wbinfo program queries and returns information created and used by the winbindd(8) daemon. The winbindd(8) daemon must be configured and running for the wbinfo program to be able to return information. OPTIONS
-u This option will list all users available in the Windows NT domain for which the winbindd(8) daemon is operating in. Users in all trusted domains will also be listed. Note that this operation does not assign user ids to any users that have not already been seen by winbindd(8). -g This option will list all groups available in the Windows NT domain for which the winbindd(8) daemon is operating in. Groups in all trusted domains will also be listed. Note that this operation does not assign group ids to any groups that have not already been seen by winbindd(8). -h name The -h option queries winbindd(8) to query the WINS server for the IP address associated with the NetBIOS name specified by the name parameter. -i ip The -i option queries winbindd(8) to send a node status request to get the NetBIOS name associated with the IP address specified by the ip parameter. -n name The -n option queries winbindd(8) for the SID associated with the name specified. Domain names can be specified before the user name by using the winbind separator character. For example CWDOM1/Administrator refers to the Administrator user in the domain CWDOM1. If no domain is specified then the domain used is the one specified in the smb.conf workgroup parameter. -s sid Use -s to resolve a SID to a name. This is the inverse of the -n option above. SIDs must be specified as ASCII strings in the tradi- tional Microsoft format. For example, S-1-5-21-1455342024-3071081365-2475485837-500. -U uid Try to convert a UNIX user id to a Windows NT SID. If the uid specified does not refer to one within the winbind uid range then the operation will fail. -G gid Try to convert a UNIX group id to a Windows NT SID. If the gid specified does not refer to one within the winbind gid range then the operation will fail. -S sid Convert a SID to a UNIX user id. If the SID does not correspond to a UNIX user mapped by winbindd(8) then the operation will fail. -Y sid Convert a SID to a UNIX group id. If the SID does not correspond to a UNIX group mapped by winbindd(8) then the operation will fail. -t Verify that the workstation trust account created when the Samba server is added to the Windows NT domain is working. -m Produce a list of domains trusted by the Windows NT server winbindd(8) contacts when resolving names. This list does not include the Windows NT domain the server is a Primary Domain Controller for. -r username Try to obtain the list of UNIX group ids to which the user belongs. This only works for users defined on a Domain Controller. -a username%password Attempt to authenticate a user via winbindd. This checks both authenticaion methods and reports its results. -A username%password Store username and password used by winbindd during session setup to a domain controller. This enables winbindd to operate in a Win- dows 2000 domain with Restrict Anonymous turned on (a.k.a. Permissions compatiable with Windows 2000 servers only). EXIT STATUS
The wbinfo program returns 0 if the operation succeeded, or 1 if the operation failed. If the winbindd(8) daemon is not working wbinfo will always return failure. VERSION
This man page is correct for version 2.2 of the Samba suite. SEE ALSO
winbindd(8) AUTHOR
The original Samba software and related utilities were created by Andrew Tridgell. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. wbinfo and winbindd were written by Tim Potter. The conversion to DocBook for Samba 2.2 was done by Gerald Carter 19 November 2002 WBINFO(1)