Hi Alexander,
The way update encrypted works is that your windows users, when they attempt
to access your samba server, negotiate cleartext password in the smb
negotiate protocol call that the client makes.  So the username and password
that the user has is sent cleartext to samba; samba then encrypts the
password in standard unix 1way encryption and validates it against the
/etc/passwd file password.  If this matches, it allows access, AND then
encrypts the plaintext password it now has into the lm and nt password
hashes that go into the smbpasswd file.
Once all of your users have successfully accessed samba, and thus have their
encrypted passwords in smbpassword, you can then turn OFF update encrypted,
and change encrypt passwords from NO to YES.
Hope this helps,

we can allow cleartext, no problem (we've been using nis for years). and i
can't/won't crack 600 passwords. i just want to avoid telling 600 people
that they have to re-enter their passwords, and i think i get the idea
that it's possible, but i just dont understand it yet.

if there is no way to get encrypted passwords into the smbpasswd file,
then, if what im what to do is possible, there must be some other way to
get cleartext passwords into the smbpasswd file.

so how do i get my encrypted NIS file -> cleartext -> smbpasswd?

wait a second, i just read your email again and i think i got it:

i use that script to generate the smbpasswd file (minus the passwords). 
then i set the smb.conf with 'update encrypted = yes'. then force all my
clients to send cleartext passwords. will this do what i want? if so, then
how does samba validate a user who is loging on if that user's password is
not in the smbpasswd file? if it works this way, then anyone could login
(assuming they know a user alias name), submit any password they want and
take control over that persons logon. it must not work this way. that
would be a huge security hole. what am i misunderstanding?

or do i just have to make all my users re-enter their passwords? once
that's done, i would be set to go...

thanks as always,

