Anonymous domain joining

Tom Alsberg alsbergt at cs.huji.ac.il
Sun Mar 9 11:17:57 GMT 2003


Hi there.

This question might have confused the last time I sent it, because I
did not provide much details in the same message.  I hope you have
answers or ideas to discuss about at least some of the questions I am
asking here.

So - this is Windows NT, 2000, and XP, with a solution for XP being
the most (but not only) interest for me, and Samba post-3.0-HEAD from
CVS.

Here are the questions:

I am trying to achieve something that will let any machine be a member
of the domain, without needing authentication as an admin to join.

The basic idea is that all machines will be in the domain in the
server's opinion, and joining it will be necessary only for Windows to
know it is in the domain.

So the first thing I want is joining the domain anonymously.

What I ultimately strive to is that Samba will have to keep no state
or information about machines in the domain - so that a machine
joining will get a positive reply from Samba, but no real state will
change at the server, at least not on disk.

I definitely do not want separate local accounts (/etc/passwd), or for
that matter any Unix accounts for machines in the domain.

So, right now we have a few ugly source hacks, as well as some script
that is called and keeps some state.  I am hoping for a cleaner
solution.  I am working on the Samba sources to achieve this, but I
would love any advice on how to do it with as little source
modifications as possible.

Any advice, then?

  Thanks, any help appreciated,
  -- Tom

-- 
  Tom Alsberg - hacker (being the best description fitting this space)
  Web page:	http://www.cs.huji.ac.il/~alsbergt/
DISCLAIMER:  The above message does not even necessarily represent what
my fingers have typed on the keyboard, save anything further.


More information about the samba-technical mailing list