[Samba] Samba 2.2.5-1 problems joining domain - W2K PDC

Aaron D. lists at aaronsplace.org
Mon Sep 9 22:32:00 GMT 2002


smb.conf:



# Global parameters
[global]
         password server = SERVER
         interfaces = 10.7.7.200/24 127.0.0.1
         bind interfaces only = Yes
         wins server = 10.7.7.201
         debug level = 0
         browse list = No
         dns proxy = No
         security = domain
         encrypt passwords = Yes
         workgroup = DOMAIN
         server string = Samba Server
         comment = File and Print Services on LINUX
         local master = No
         socket options = TCP_NODELAY SO_SNDBUF=8192 SO_RCVBUF=8192
         netbios name = smbsvr
         mangled names = No
#       case sensitive = yes
         max log size = 50
         preferred master = no
         name resolve order = wins lmhosts host bcast

[homes]
         comment = Home Directories
         writeable = Yes
         browseable = No

[printers]
         comment = All Printers
         path = /var/spool/samba
         printable = Yes
         browseable = Yes

[netlogon]
         path = /tmp

[installs]
         comment = Software stores for Linux
         path = /installs
         admin users = @admin
         writeable = Yes

[apps]
         comment = Root Website share
         path = /smb/apps
         admin users = adonaldson
         force user = nobody
         force group = nobody
         writeable = Yes

[cdrom]
         comment = CDROM on Samba
         path = /mnt/cdrom
         guest account =

[docs]
         path = /usr/doc

_____________________________________________
And the output of testparm:

Load smb config files from /etc/samba/smb.conf
Processing section "[homes]"
Processing section "[printers]"
Processing section "[netlogon]"
Processing section "[installs]"
Processing section "[html]"
Processing section "[cdrom]"
Processing section "[docs]"
Loaded services file OK.
Press enter to see a dump of your service definitions
# Global parameters
[global]
         coding system =
         client code page = 850
         code page directory = /etc/codepages
         workgroup = DOMAIN
         netbios name = SMBSVR
         netbios aliases =
         netbios scope =
         server string = Samba Server
         interfaces = 10.7.7.200/24 127.0.0.1
         bind interfaces only = No
         security = DOMAIN
         encrypt passwords = Yes
         update encrypted = No
         allow trusted domains = Yes
         hosts equiv =
         min passwd length = 5
         map to guest = Never
         null passwords = No
         obey pam restrictions = No
         password server = SERVER
         smb passwd file = /etc/samba/smbpasswd
         root directory =
         pam password change = No
         passwd program = /usr/bin/passwd
         passwd chat = *new*password* %n\n *new*password* %n\n *changed*
         passwd chat debug = No
         username map =
         password level = 0
         username level = 0
         unix password sync = No
         restrict anonymous = No
         lanman auth = Yes
         use rhosts = No
         admin log = No
         log level = 0
         syslog = 1
         syslog only = No
         log file =
         max log size = 50
         timestamp logs = Yes
         debug hires timestamp = No
         debug pid = No
         debug uid = No
         protocol = NT1
         large readwrite = No
         max protocol = NT1
         min protocol = CORE
         read bmpx = No
         read raw = Yes
         write raw = Yes
         nt smb support = Yes
         nt pipe support = Yes
         nt status support = Yes
         announce version = 4.5
         announce as = NT
         max mux = 50
         max xmit = 65535
         name resolve order = lmhosts host wins bcast
         max packet = 65535
         max ttl = 259200
         max wins ttl = 518400
         min wins ttl = 21600
         time server = No
         unix extensions = No
         change notify timeout = 60
         deadtime = 0
         getwd cache = Yes
         keepalive = 300
         lpq cache time = 10
         max smbd processes = 0
         max disk size = 0
         max open files = 10000
         read size = 16384
         socket options = TCP_NODELAY SO_SNDBUF=8192 SO_RCVBUF=8192
         stat cache size = 50
         use mmap = Yes
         total print jobs = 0
         load printers = Yes
         printcap name = /etc/printcap
         disable spoolss = No
         enumports command =
         addprinter command =
         deleteprinter command =
         show add printer wizard = Yes
         os2 driver map =
         strip dot = No
         mangling method = hash
         character set =
         mangled stack = 50
         stat cache = Yes
         domain admin group =
         domain guest group =
         machine password timeout = 604800
         add user script =
         delete user script =
         logon script =
         logon path = \\%N\%U\profile
         logon drive =
         logon home = \\%N\%U
         domain logons = No
         os level = 20
         lm announce = Auto
         lm interval = 60
         preferred master = False
         local master = No
         domain master = Auto
         browse list = No
         enhanced browsing = Yes
         dns proxy = No
         wins proxy = No
         wins server = 10.7.7.201
         wins support = No
         wins hook =
         kernel oplocks = Yes
         lock spin count = 3
         lock spin time = 10
         oplock break wait time = 0
         add share command =
         change share command =
         delete share command =
         config file =
         preload =
         lock dir = /var/cache/samba
         pid directory = /var/run/samba
         utmp directory =
         wtmp directory =
         utmp = No
         default service =
         message command =
         dfree command =
         valid chars =
         remote announce =
         remote browse sync =
         socket address = 0.0.0.0
         homedir map =
         time offset = 0
         NIS homedir = No
         source environment =
         panic action =
         hide local users = No
         host msdfs = No
         winbind uid =
         winbind gid =
         template homedir = /home/%D/%U
         template shell = /bin/false
         winbind separator = \
         winbind cache time = 15
         winbind enum users = Yes
         winbind enum groups = Yes
         winbind use default domain = No
         comment = NT File and Print Services on LINUX
         path =
         alternate permissions = No
         username =
         guest account = nobody
         invalid users =
         valid users =
         admin users =
         read list =
         write list =
         printer admin =
         force user =
         force group =
         read only = Yes
         create mask = 0744
         force create mode = 00
         security mask = 0777
         force security mode = 00
         directory mask = 0755
         force directory mode = 00
         directory security mask = 0777
         force directory security mode = 00
         force unknown acl user = 00
         inherit permissions = No
         inherit acls = No
         guest only = No
         guest ok = No
         only user = No
         hosts allow =
         hosts deny =
         status = Yes
         nt acl support = Yes
         block size = 1024
         max connections = 0
         min print space = 0
         strict allocate = No
         strict sync = No
         sync always = No
         write cache size = 0
         max print jobs = 1000
         printable = No
         postscript = No
         printing = bsd
         print command = lpr -r -P%p %s
         lpq command = lpq -P%p
         lprm command = lprm -P%p %j
         lppause command =
         lpresume command =
         queuepause command =
         queueresume command =
         printer name =
         use client driver = No
         default devmode = No
         printer driver =
         printer driver file = /etc/samba/printers.def
         printer driver location =
         default case = lower
         case sensitive = No
         preserve case = Yes
         short preserve case = Yes
         mangle case = No
         mangling char = ~
         hide dot files = Yes
         hide unreadable = No
         delete veto files = No
         veto files =
         hide files =
         veto oplock files =
         map system = No
         map hidden = No
         map archive = Yes
         mangled names = No
         mangled map =
         browseable = Yes
         blocking locks = Yes
         csc policy = manual
         fake oplocks = No
         locking = Yes
         oplocks = Yes
         level2 oplocks = Yes
         oplock contention limit = 2
         posix locking = Yes
         strict locking = No
         share modes = Yes
         copy =
         include =
         exec =
         preexec close = No
         postexec =
         root preexec =
         root preexec close = No
         root postexec =
         available = Yes
         volume =
         fstype = NTFS
         set directory = No
         wide links = Yes
         follow symlinks = Yes
         dont descend =
         magic script =
         magic output =
         delete readonly = No
         dos filemode = No
         dos filetimes = No
         dos filetime resolution = No
         fake directory create times = No
         vfs object =
         vfs options =
         msdfs root = No




At 04:23 PM 9/9/2002, you wrote:
>please send your smb.conf completely
>
>
>--- "Aaron D." <lists at aaronsplace.org> wrote:
> > I've used both the w2k\administrator and an account
> > with membership in the
> > administrators group, both with the same result.
> >
> > Additionally, encrypt passwords  is set to Yes in
> > the smb.conf.
> >
> >
> >
> > At 02:19 PM 9/9/2002, you wrote:
> > >try:
> > >smbpasswd -j DOM -r SERVER -U <W2K administrator>
> > >and press enter and type administrator password.
> > >
> > >
> > >--- "Aaron D." <lists at aaronsplace.org> wrote:
> > > > OK Ladies and Gentlemen I could use a hand on
> > this
> > > > one.  I'm new to the
> > > > list, so please excuse me if I violate a
> > protocol
> > > > which is as yet unknown
> > > > to me.  However I am having some problems that
> > seem
> > > > to be beyond my
> > > > abilities to find a solution to.  Any help would
> > be
> > > > greatly appreciated.
> > > >
> > > > Technical Info:
> > > > LINUX Box is a Red Hat 7.1 Kernel version is
> > > > 2.4.9-34.  Samba version(S)
> > > > that I am working with are 2.2.5-1 (Red Hat
> > Binary
> > > > RPM downloaded from
> > > > samba.org) and 2.0.10-2 (from Red Hat's site).
> > > >
> > > > Windows 2000 Advanced Server SP2 (SP3 was
> > applied,
> > > > and then
> > > > removed).  Since the application of SP3, and the
> > > > subsequent removal I've
> > > > restored from tape returning to PRE SP3
> > operations
> > > > completely with no
> > > > change in results.  PDC - Native mode.
> > > >
> > > > Course of events:
> > > > I had Samba 2.0.10-2 up and running perfectly
> > fine
> > > > as a domain member
> > > > (security=domain) and all was well.  I read up
> > on
> > > > the latest Samba release,
> > > > and decided I wanted to give it a try, utilizing
> > the
> > > > new winbind appliance.
> > > >
> > > > I researched briefly on the Red Hat site, and
> > > > determined that they did not
> > > > have anything above 2.0.10-2 available
> > "packaged"
> > > > for my version of Red
> > > > Hat.  A quick trip to Samba.org produced a ready
> > to
> > > > roll rpm, and all was
> > > > well.  I've made complete backups of my
> > /etc/samba
> > > > directory, and the
> > > > Windows 2000 server before any changes were
> > made.
> > > >
> > > > After performing a complete un install of the
> > > > existing Samba version, and
> > > > installing the new package, I found that I was
> > > > unable to get the Samba
> > > > re-joined to the domain.  Items checked and
> > > > verified:
> > > > I've verified more then once that the
> > "Pre-windows
> > > > 2000" box is checked
> > > > when adding the machine account on the PDC.
> > > > I've double and tipple checked the account
> > > > credentials used with the
> > > > smbpasswd join command.
> > > > I've verified my syntax is correct
> > > > lmhosts and hosts files have proper entries
> > > > W2K wins server is up and has correct records
> > > > smb.conf has Samba pointed in the correct
> > direction
> > > > for the WINS server on
> > > > the W2K box.
> > > > nmblookup is able to resolve the server, and
> > domain
> > > > correctly and as expected.
> > > >
> > > > When I run the smbpasswd -j DOM -R SERVER -A
> > user I
> > > > am prompted for the
> > > > password.  With Version 2.2.5-1 I receive the
> > > > expected message that the
> > > > domain was joined, and a quick check reveals
> > that
> > > > the secrets.tdb is
> > > > created and in the proper location. Ownership
> > and
> > > > group are both root, with
> > > > only root having rw access. I am able to
> > enumerate
> > > > groups and users from
> > > > the domain using wbinfo -u or -g, and getent
> > does
> > > > reveal domain users and
> > > > groups as well.  However, no users or groups are
> > > > able to authenticate into
> > > > the Samba server, despite what I believe to be
> > > > correct pam.d settings.
> > > > Message examples will appear below from logs.
> > > >
> > > > With Version 2.0.10-2 I run the same command,
> > > > however I receive an error
> > > > message, and am told that it was unable to join
> > the
> > > > domain.   The
> > > > MACHINE.SID is created, and matches the record
> > in
> > > > the W2K registry, however
> > > > the DOM.MACH.mac is not created.
> > > >
> > > >
> > > > The most common message that I see in the
> > log.smdb
> > > > is:
> > > >
> > > >
> >
> >smbd/password.c:connect_to_domain_password_server(1328)
> > > >    connect_to_domain_password_server: machine
> > SERVER
> > > > rejected the tconX on
> > > > the IPC$ share. Error was :
> > NT_STATUS_ACCESS_DENIED.
> > > >
> > > > This is the message I receive with 2.0.10 when I
> > try
> > > > to join the domain:
> > > >
> > > > modify_trust_password: machine SERVER rejected
> > the
> > > > tconX on the IPC$ share.
> > > > Error was : ERRDOS - ERRnoaccess.
> > > > 2002/09/09 10:45:34 :
> > change_trust_account_password:
> > > > Failed to change
> > > > password for domain DOMAIN.
> > > > Unable to join domain DOMAIN.
> > > >
> > > > Of course, the machine account is fresh and new
> > on
> > > > each attempt.  It's
> > > > deleted, and the server rebooted before it is
> > > > re-added.  I've also tried
> > > > never before used machine account names with the
> > > > same result.  I've read on
> > > > a couple of different sites that M$ added some
> > new
> > > > RPC calls via W2K SP2
> > > > which were not supported by pre 2.2 Samba.
> > However
> > > > what is it that I am
> > > > running into with the 2.2.x versions?
> > > >
> > > > Any thoughts, suggestions or questions are
> > welcome
> > > > and
> > > > appreciated.  Obviously I could roll back to a
> > > > working configuration from
> > > > my tape backups, however I am not one who's mind
> > > > lends it's self well to
> > > > going backwards and "just getting it working."
> > > >
> > > > Thank you all for your time and suggestions.
> > > >
> > > > Aaron
> > > >
> > > >
> > > > --
> > > > To unsubscribe from this list go to the
> > following
> > > > URL and read the
> > > > instructions:
> > >http://lists.samba.org/mailman/listinfo/samba
> > >
> > >
> > >__________________________________________________
> > >Do You Yahoo!?
> > >Yahoo! Finance - Get real-time stock quotes
> > >http://finance.yahoo.com
> > >--
> > >To unsubscribe from this list go to the following
> > URL and read the
> > >instructions:
> > http://lists.samba.org/mailman/listinfo/samba
> >
>=== message truncated ===
>
>
>__________________________________________________
>Do You Yahoo!?
>Yahoo! Finance - Get real-time stock quotes
>http://finance.yahoo.com
>--
>To unsubscribe from this list go to the following URL and read the
>instructions:  http://lists.samba.org/mailman/listinfo/samba




More information about the samba mailing list