LookupAccountSid and trust relationship

Torsten Curdt tcurdt at dff.st
Thu Dec 14 08:40:06 GMT 2000


Something seems to be wrong with our/the W2k<->Samba 2.2.0 CVS
trust relationsship!

1. Our domain admins has almost no rights to do anything!
2. I cannot grant rights to the "domain users" group
   (how is the domain users group defined?)

I'm somehow lost but tried to track this down:

In our smb.conf we have "domain admin users = root"
and no "domain admin group"

I now logged in as DFF\root (=domain admin) and executed
"gpresult" from the W2k resource kit. This is what I get:

###############################################################
  User Group Policy results for:
  DFF\root
  Domain Name:          DFF
  Domain Type:          Windows NT v4
  Roaming profile:      \\mogh\profiles\root
  Local profile:        C:\Dokumente und Einstellungen\root.DFF
  The user is a member of the following security groups:
LookupAccountSid failed with 1789.
        \Jeder
        VORDEFINIERT\Benutzer
LookupAccountSid failed with 1789.
        \LOKAL
        NT-AUTORIT-T\INTERAKTIV
        NT-AUTORIT-T\Authentifizierte Benutzer
###############################################################
Last time Group Policy was applied: Mittwoch, 13. Dezember 2000 at 15:33:09
###############################################################
  Computer Group Policy results for:
  DFF\SHODAN$
  Domain Name:          DFF
  Domain Type:          Windows NT v4
  The computer is a member of the following security groups:
        VORDEFINIERT\Administratoren
        \Jeder
        NT-AUTORIT-T\Authentifizierte Benutzer
###############################################################

Seems like the machine is fully accepted but not the user
so gets only really limited access.

Can someone with more insight comment on this, please ;-)
--
Torsten




More information about the samba-ntdom mailing list