[Samba] Winbind basic questions

DICKENS,CARY (HP-Loveland,ex2) cary_dickens2 at hp.com
Mon Nov 18 21:02:01 GMT 2002


> - Do I have to use PAM if all I want is to access the 
> following Samba share from my W2K clients?

Nope.  Should work just fine.

> - Should I install Samba configured using --with-winbind, or 
> --with-winbind-auth-challenge as well (I have tried both but 
> neither work)

It shouldn't matter, but I am not sure.

> - If I do need PAM, I am reading conflicting info from the 
> /swat/help/PAM-Authentication-And-Samba.html file. It states 
> "Note that Samba always ignores PAM for authentication in the 
> case of encrypt passwords = yes", which I need if I am using 
> security = domain

I'm sorry.  Once again, I don't know.  I have found that I can generally
trust the documentation.

> - If I do not need PAM to authenticate and it "appears" that 
> I have installed and configured samba / winbind properly as 
> per the wbinfo lines above, why can't I access the share?

I think the problem is in your smb.conf.  Try removing your valid users line
in the share and see if you can get in without any constraints.  Once you
get connected, then you can tighten up to the proper level.  I would suggest
you try adding your domain in something like:
valid users = @"DOMAIN+Domain Users"

> - Do I need to create user accounts on the samba server? (I 
> hope not, I understand that's what winbind is for)

No.  Your right about what winbind is.

> - Do I need to create any machine accounts? (Other than 
> joining the samba server to the domain.)

You should be golden.

Hope this helps and that I didn't lead you down the wrong path.

Cary



More information about the samba mailing list