winbindd: error opening lsa handle on dc

Andrew Bartlett abartlet at pcug.org.au
Sat Jan 5 01:46:02 GMT 2002


Paul Miller wrote:
> 
> I just started working on getting winbindd to work and I'm receiving the
> following error regarding not begining able to open lsa handle on dc:
> 
> (Samba 2.2.2-4 Debian package, latest Debian 'testing' distribution)
> 

> --- partial smb.conf ---
> 
> [global]
> 
> domain admin group = @smbusers
> 
> # identification
>     netbios name = PENGUIN
>     workgroup = HOME
>     server string = Server
> 
> # domain (PDC)
>     security = user
>     os level = 250
>     domain master = yes
>     domain logons = yes
>     local master = yes
>     preferred master = yes
>     logon drive = H:
>     logon home = \\penguin\%u
>     logon path = \\penguin\profiles\%u
>     logon script = logon.bat
> 
> # winbind
>     winbind separator = +
>     winbind cache time = 10
>     template shell = /bin/false
>     template homedir = /home/%D/%u
>     winbind uid = 10000-20000
>     winbind gid = 10000-20000
> 
> # wins server
>     wins support = yes
>     name resolve order = wins lmhosts hosts bcast
> 
> ... one thing I noticed about the previous winbindd posts was that they
> all had 'security = domain' instead of user.  I don't think I need to
> change this parameter because I want Samba to be the PDC.

So, is this machine a PDC or domain member?

And if its a PDC, why are you running winbind? 

If its not a PDC, why have security = user?

What role do you want winbind to play?
-- 
Andrew Bartlett                                 abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net




More information about the samba mailing list