[Samba] joining machines into a samba domain

manuel.piessnegger at straumann.com manuel.piessnegger at straumann.com
Fri Nov 7 15:05:20 GMT 2003





Hello,

I'm testing samba3 to shutdown our existing NT4 Domain.
OS=UL1
Samba3
OpenLdap as backend
All users and machine account are in a ldap backend (posix & samba).
We will create the account manually into ldap before we went to a windows
client (W2kPro) and join them manually into the domain.

Witch users can join machines to the domain from a windows client directly?
At the moment just the "ldap admin dn = cn=root,dc=xy,dc=com" user can join
machines to the domain.
When I try to do this with an other account, who has the ACL rights from
LDAP to write into, and is also member of the Group "DomainAdmin"
(SID-xxxx-512), I become the error message "LoginFailure: unknown user or
bad password" on the windows client.

What are nessesary skills for a useraccount to join machines into a samba3
domain? Is it really just the PDC ldap admin dn , who has enough rights to
do that?


Regards

Manuel Piessnegger




More information about the samba mailing list