Trust

Jonas Oberg jonas at coyote.org
Tue Oct 5 14:31:24 GMT 1999


I've read a few messages about trust relationships and I know
that they are supposedly semi-operational. What I want to do
is to have an NT server trust my Samba PDC and make it possible
for users of the Samba-domain to use resources from the NT
server.

So what I've done is to try to establish a one-way inter-domain
trust between the NT server and the Samba PDC using the latest
sources from CVS.  I added an account called NTSERVER$ to my
Samba PDC using '-i' to smbpasswd to mark it as an Inter-domain
trust account.  I set the password for the trust account to
'foo', walk to the NT server and Add a trust. After a long
wait (30 seconds or so), I get a message saying that the domain
has been added successfully.

However, in the Samba PDC logs are these messages;

[1999/10/05 15:58:03, 0] smbd/reply.c:session_trust_account(455)
  session_trust_account: Domain trust account NTSERVER$ denied by server
[1999/10/05 15:58:15, 0] smbd/reply.c:reply_sesssetup_and_X(738)
  NT Password did not match ! Defaulting to Lanman
[1999/10/05 15:58:15, 0] smbd/reply.c:reply_sesssetup_and_X(738)
  NT Password did not match ! Defaulting to Lanman

and when I try to use a resource on the NT server using a client
connected to the Samba PDC I get an error message.

I never see any attempts by the NT server to verify the
authentication on the Samba PDC when the client connects.

Is this something that is supposed to work, and if so, how?


Regards,

Jonas


More information about the samba-ntdom mailing list