[Samba] Can't reset password from windows 2000, or from the samba pdc. Error from samba pdc: machine rejected the password change: Error was : RAP86: The specified password is invalid.

big toe bigtoeage21 at yahoo.com
Wed May 19 19:33:41 GMT 2004

I have a samba pdc running 3.0.4.  I have users
logging into the profile server and wanting to change
there password.  However when they try to change the
password it asks them for the old and new password but
says they do not have permission to change the
password.  I can change the password for them when I
log into the pdc as root but when I try to do it as
user it gives the error:

machine rejected the password change: Error
was : RAP86: The specified password is invalid.

Looking at the log file for that machine the error
messages are as follows:

[2004/05/19 08:46:36, 0]
  PAM: UNKNOWN PAM ERROR (19) for User: tony
[2004/05/19 08:46:36, 2]
  smb_pam_error_handler: PAM: Password Change Failed :
Conversation error
[2004/05/19 08:46:36, 0]
  smb_pam_passchange: PAM: Password Change Failed for
user tony!

My redhat 9.0 box is running samba 3.0.4 and the
workstations are all windows 2000 pro boxes.  I have
looked in google and no one seems to know the cause or
solution to this problem.  Here is my smb.conf file:


   ;basic server settings
   workgroup = workgroup
   netbios name = name
   server string = Samba PDC running %v
   socket options = TCP_NODELAY SO_RCVBUF=8192

   ;PDC and master browser settings
   os level = 64
   preferred master = yes
   local master = yes
   domain master = yes
   wins support = yes
   domain logons = yes

   ;security and logging settings
   security = user
   encrypt passwords = yes
   log file = /var/log/samba/log.%m
   log level = 2
   max log size = 50
   hosts allow =

   add user script = /usr/sbin/useradd -d /dev/null -g
machines -s /bin/false -M %u

   ;sync UNIX passwords
   smb passwd file = /etc/samba/smbpasswd
#   pam password change = yes
   unix password sync = yes
   passwd program = /usr/bin/passwd %u
   passwd chat = *New*UNIX*password* %n\n
*ReType*new*UNIX*password* %n\n
   passwd chat debug = yes

Any help on this would be very appreciative!!!  Thanks
in advance.



