RES: RES: [Samba] Re: Winbind broken after 2.2.8 upgrade

Andrew Bartlett abartlet at samba.org
Fri Mar 28 06:22:23 GMT 2003


On Fri, 2003-03-28 at 09:46, FRANCO wrote:
> I did it more then 12 times...
> 
> I have a lot of problems with winbind and NEVER I did receive a answer...
> Sorry if I have a poore english:

There are a number of documents on 'how to get questions answered'
around on the net.  In particular, just repeating the question, or
complaining that your question isn't answered just gets people
frustrated.  Instead, show that you have tried to solve the problem
yourself.

For example, if you have downgraded back to 2.2.7, and the problem 'went
away', then this needs to be made clear.  If you didn't, how can you
claim it's a bug in 2.2.8?

> I hve 3 installations with problems... I never saw this I think that Im not
> a god SAMBA Administrator but I did read all the doc.... I dont have any
> troubles with other soft, but with samba ehehehehehe

Samba is a complex peice of software.  It's interactions with (often
separately maintained) Windows DCs is particularly complex.

If it doesn't occur on all your DCs, then you should look at what is
different.  This information should be present when you contact the
list.

> I did send e-mails to the lis in :
> 
> 11/3. 12/3, 16/3, 18/3, 19, 20, 25, 27 with the same questions.... If you
> want, please check it and will see if Im joking... Im 42 years old.
> 
> 
> 
> FIRST INSTALATION:
> 
> Can yoiu help m?
> 
> [root at firewall /etc]# smbpasswd -j surson -r cleo -U Administrator
> Password:
> Joined domain SURSON.
> [root at firewall /etc]#
> 
> 
> [root at firewall /etc]# smbclient //firewall/PUBLICO -UAdministrator added
> interface ip=192.168.1.1 bcast=192.168.1.255 nmask=255.255.255.0 Got a
> positive name query response from 192.168.1.2 ( 192.168.1.1 )
> Password:
> session setup failed: NT_STATUS_LOGON_FAILURE
> 
> When I try \\firewall\PUBLICO in the NT I receive a BOX to type USER and
> PASSWD
> 
> Joe log.cleo
> 
> [2003/03/25 04:38:27, 0]
> smbd/password.c:connect_to_domain_password_server(1307)
>   connect_to_domain_password_server: machine CLEO rejected the tconX on the
> IPC$ share. Error was : NT_STATUS_ACCESS_DENIED. [2003/03/25 04:38:27, 0]
> smbd/password.c:domain_client_validate(1554)
>   domain_client_validate: Domain password server not available. [2003/03/25

This looks like an issue with your PDC, not with Samba.

Your PDC is has 'restrict anonymous = 2' set.  The two options are to
set a username for Samba to use (wbinfo -Auser%pass), or to disable it. 

However, setting this only really works for Samba 3.0 - for 2.2 you
really can't run with this set. 

If you already have a username/pw set (by wbinfo -A), then I would
suspect that you have SMB signing required, on a 'fixed' DC (MS did not
used to enforce this).

Andrew Bartlett

-- 
Andrew Bartlett                                 abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba/attachments/20030328/cb75723f/attachment.bin


More information about the samba mailing list