[Samba] Re: Trusting and trusted domain (home mapping) problem

Adrian Chow achow at uwcsea.edu.sg
Fri Nov 5 05:23:49 GMT 2004


You are right... I need winbind... this log is when it does not have... 
trying to emulate what you are doing..

adrian


Igor Belyi wrote:
> 
> Adrian Chow wrote:
> 
>> Hi Igor,
>>
>> Got some logs from the Domain_A_PDC on the domain_A_XP when domain_B 
>> user (grade2) logs into domain_B on domain_A_XP.
>>
>>
>>
>> [2004/11/05 11:18:45, 3] auth/auth.c:check_ntlm_password(219)
>>   check_ntlm_password:  Checking password for unmapped user 
>> [UWCSTU]\[grade2]@[ADMINWS3] with the new password interface
>> [2004/11/05 11:18:45, 3] auth/auth.c:check_ntlm_password(222)
>>   check_ntlm_password:  mapped user is: [UWCSTU]\[grade2]@[ADMINWS3]
>> [2004/11/05 11:18:45, 3] smbd/sec_ctx.c:push_sec_ctx(256)
>>   push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1
>> [2004/11/05 11:18:45, 3] smbd/uid.c:push_conn_ctx(365)
>>   push_conn_ctx(100) : conn_ctx_stack_ndx = 0
>> [2004/11/05 11:18:45, 3] smbd/sec_ctx.c:set_sec_ctx(288)
>>   setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
>> [2004/11/05 11:18:45, 3] smbd/sec_ctx.c:pop_sec_ctx(386)
>>   pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0
>> [2004/11/05 11:18:45, 3] libsmb/namequery_dc.c:rpc_dc_name(145)
>>   rpc_dc_name: Returning DC GLOIN (172.16.7.227) for domain UWCSTU
>> [2004/11/05 11:18:45, 3] libsmb/cliconnect.c:cli_start_connection(1376)
>>   Connecting to host=GLOIN
>> [2004/11/05 11:18:45, 3] lib/util_sock.c:open_socket_out(752)
>>   Connecting to 172.16.7.227 at port 445
>> [2004/11/05 11:18:46, 3] auth/auth_util.c:make_server_info_info3(1114)
>>   User grade2 does not exist, trying to add it
>> [2004/11/05 11:18:46, 0] auth/auth_util.c:make_server_info_info3(1122)
>>   make_server_info_info3: pdb_init_sam failed!
>> [2004/11/05 11:18:46, 3] smbd/sec_ctx.c:push_sec_ctx(256)
>>   push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1
>> [2004/11/05 11:18:46, 3] smbd/uid.c:push_conn_ctx(365)
>>   push_conn_ctx(100) : conn_ctx_stack_ndx = 0
>>
>>
>> Cannot understand why going to GLOIN (Domain_B_PDC) will not get 
>> grade2 (domain_B_user) user and trying to add it!!??
>>
>> Any ideas?  Thanks.
>>
>> adrian
>>
> Was this is for the case with winbind in the /etc/nsswitch.conf or 
> without it? As I've described in my previouse message - I was wrong - 
> you do need winbind in /etc/nsswitch.conf for things to work.
> 
> I'd suggest to increase log level to 5 - there could be more helpful 
> information.
> 
> Igor
> 


More information about the samba mailing list