winbind cross forest trust

amit kumar amitkuma at redhat.com
Thu Apr 6 12:43:16 UTC 2017


Hello,

Can you assist me in this:

I am trying to change password by setting "Change password on next login in AD". 
Winbind version:	samba-winbind-4.2.10-7.el7_2.x86_64

*Failing Scenario*
+----------------------------+                      +--------------------+
| ABC1/test-user-abc         |  +---------------->  |XYZ1                |
| Users' AD forest           |                      |Resources AD forest |
| (Single domain)            |  <----------------+  |(Single domain)     |
|                            |                      |                    |
+----------------------------+       2-Way          +-------+------------+
                                     Trust                  ^
                                                            | AD-Join(winbind)
                                                            |
                                                       +----+------+
                                                       |RHEL       |
                                                       |Machine    |
                                                       |Winbind    |
                                                       +-----------+

*Issue is*: From RHEL-client when I try to change password of user present in ABC1/test-user-abc. It fails

*Success*: From RHEL i can change password of user present in XYZ1.

*Query*:
Is it a bug in samba-winbind or some configs I may be missing.

-- 
Thanks
Amit Kumar
There are three ways to get something done:
  (1) Do it yourself.
  (2) Hire someone to do it for you.
  (3) Forbid your kids to do it.


More information about the samba-technical mailing list