[Samba] user can't shut down windows clients?
geza at kzsdabas.sulinet.hu
Mon Mar 15 07:58:54 GMT 2004
-----BEGIN PGP SIGNED MESSAGE-----
| dear sir,
| i have create a few users of the nobody group on my samba server.
| in my samba config, i listed root account as the domain admin group.
| when i logon to samba server, my root account can shutdown my windows
| client, can disconnect to domain ect etc...
| but when i logon as a user of the nobody group. i can't shutdown the
| windows client! the shutdown fucntion is not there anymore!
| i don't want to list restricted my users as domain admin group.
| is there any way to get around is problem?
| thank Q!
Supposing that your group mapping is correct, something like this:
System Operators (S-1-5-32-549) -> daemon
Replicators (S-1-5-32-552) -> disk
Guests (S-1-5-32-546) -> nogroup
Power Users (S-1-5-32-547) -> wheel
Domain Users (S-1-5-21-4109351342-2997801466-301355879-513) -> users
Print Operators (S-1-5-32-550) -> lp
Administrators (S-1-5-32-544) -> root
Domain Admins (S-1-5-21-4109351342-2997801466-301355879-512) -> adm
Domain Guests (S-1-5-21-4109351342-2997801466-301355879-514) -> nogroup
Account Operators (S-1-5-32-548) -> adm
Backup Operators (S-1-5-32-551) -> daemon
Users (S-1-5-32-545) -> users
where S-1-5-21-4109351342-2997801466-301355879 is my test domains domain
Your problem is Windows Policy related. Depending on your Windows OS
version it could be the domain policy file in your Netlogon share for
Win 9x/ME and NT4 (you should know about this if you were setting up
your Samba server ;-) ) More probably you suffer from a Windows 2000/XP
"feature", called (I think) Local Policy. Probably you should go to each
Windows box and fire up the mmc plugin for managing that policies.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
-----END PGP SIGNATURE-----
More information about the samba