[Samba] Samba 2.2.8 and domain logons

Buchan Milne bgmilne at cae.co.za
Mon Sep 1 13:42:35 GMT 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> Message: 3
> Date: Sun, 31 Aug 2003 21:54:20 +0530
> From: Govindarajan <govindarajan at hotpop.com>
> Subject: [Samba] Samba 2.2.8 and domain logons
> To: samba at lists.samba.org
> Message-ID: <200308312154.20686.govindarajan at hotpop.com>
> Content-Type: text/plain;  charset="us-ascii"
>
> Hi all,
> 	We have around 15 computers (win2k+sp4) and a Linux samba
server(mandrake).
> Samba is configured for domain logons. I have included the "domain admin
> group" parameter in smb.conf and the group is called "admin". Till
yesterday
> things were OK, everyone was able to login to the domain. Today, out
of the
> blue, domain logins are not happening. Log files do not give a clue as to
> what's happening.
>
> The windows clients throw out an error message saying "Unable to load
your
> roaming profile.... logging in with your local profile". Does this
mean that
> authentication is going OK and that only the roaming profile is not being
> loaded?

You can check by looking at the LOGONSERVER variable in Windows, start a
command prompt, and type (C:\> indicated the prompt):

C:\>echo %LOGONSERVER%

If it is the name of the local machine, chances are you are having name
resolution issues, and the only reason your users can log in is cached
credentials. The easiest way to overcome this is to run a WINS server on
your domain controller (if you don't yet), and tell your Windows
machines where the DC is via DHCP.

 I checked the perminssions on the profile folders and everything
> seems to be OK. Where do I need to look? I'll be glad if someone could
point
> me in the right direction.
>

You might want to turn logging up (ex 'log level = 3' in smb.conf), and
see if the clients actually authenticate or not

> If any further information is needed to troubleshoot this issue please
let me
> know. Also, I'll email the smb.conf in a day as I am at home right
now. BTW I
> followed the procedure as described in the IBM samba document.

IIRC the IBM document gives a worse configuration in the end than the
default /etc/samba/smb.conf if you read it through once and uncomment
all the relevany domain controller options according to the comments.

Also, please see the documents at:
http://mandrake.vmlinuz.ca/bin/view/Main/SambaDomainController

Regards,
Buchan

- --
|--------------Another happy Mandrake Club member--------------|
Buchan Milne                Mechanical Engineer, Network Manager
Cellphone * Work            +27 82 472 2231 * +27 21 8828820x202
Stellenbosch Automotive Engineering         http://www.cae.co.za
GPG Key                   http://ranger.dnsalias.com/bgmilne.asc
1024D/60D204A7 2919 E232 5610 A038 87B1 72D6 AC92 BA50 60D2 04A7
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE/U0zKrJK6UGDSBKcRAuhWAJ4zbHI4/3Nf5kDDb9SSY58z4Ugo6wCfaS3v
y2xogRdZVp3zw8Cp7WVQ7aY=
=4cRy
-----END PGP SIGNATURE-----

*****************************************************************
Please click on http://www.cae.co.za/disclaimer.htm to read our
e-mail disclaimer or send an e-mail to info at cae.co.za for a copy.
*****************************************************************



More information about the samba mailing list