Different workgroup= in the same domain with domain logons?

Sam Silvester sam at quadlink.com.au
Wed Jan 17 13:24:14 GMT 2001

On Tue, 16 Jan 2001, Axel Thimm wrote:

> Hello,
> Is this compatible to having a central authorization? Or do all
> security=domain Sambas need to carry the same workgroup= setting as the
> password server?

I think what you are looking for is the security=server setting - as I
understand it, using this doesn't mean the server has to be on the same
I believe you also need a WINS server to be set up in order for this to
work though. All samba servers should point to the same wins server.
Also, set domain master = yes only on the PDC, and local master = yes on
the samba server in each workgroup (I'm not sure of this. Might be worth
checking elsewhere)
> Would this mean, that only one Samba server per domain may be set to "domain
> login=yes", making this server act as a PDC? I suspect that login servers
> would claim a special netbios name, just as domain browsers do, so having
> multiple domain logon servers in one domain would break thinks, or not?
Assuming that you are going to keep your multiple workgroups and have a
single domain, you would set domain login = yes only on the PDC - ie the
machine that you want to do all authentication through.

Hope this helps,

Programming is an art form that fights back.

Sam Silvester
<sam at quadlink.com.au>

Ph:  0408 492 205 
Fax: (08) 8849 2376


More information about the samba-ntdom mailing list