[Samba] Problem joining SAMBA domain with LDAP from 2K/XP

Alexei Monastyrnyi alexeim at orcsoftware.com
Thu Sep 9 17:13:20 GMT 2004

Hi All.

Sorry for the possible off-topic.

I have SAMBA 3.0.6 + OpenLDAP 2.2.15.
OpenLDAP backend has a UNIX stuff and was initialized with a help of 
smbldap-tools 0.8.5 for SAMBA stuff.
There is user Administrator with all necessary SAMBA objects in LDAP DB, 
with uid 0 and gid 512 (SAMBA group Domain Admins).
It has passwords both in LDAP and in SAMBA secrets.tdb.
In smb.conf there is an "add machine script" and "add user script"
        add user script = /usr/local/sbin/smbldap-useradd -m %u
        add machine script = /usr/local/sbin/smbldap-useradd -w %u

When I try to join 2k/XP box to SAMBA domain it says "The user name 
could not be found".

Log from LDAP server shows that during joining machine account is added 
(with POSIX stuff) but no attempt to add SAMBA stuff.

Log from SAMBA shows that user administrator is authenticated 
successfully and domain SID is returned, no error messages...

The weird thing is that it worked before...

Ami hints would be appreciated.


