[Samba] Problems after changing security = domain to security = ads

Hamish lists at subvs.co.uk
Mon Jun 6 16:56:15 GMT 2005

On Monday 06 June 2005 13:22, Hamish wrote:
> Hello all
> I have a samba domain member authenticating to a w2k3 server, after
> installing SP1, there were problems, and a solution I found was to change
> to security = ads. This seemed to work fine, but today no-one can get their
> home drives, and some people are denied access to shares where the
> permissions on the files are rwx for the user.
> I did not change anything other than the security line in smb.conf and
> rejoined the domain with `net ads join -U administrator` (this was
> successful)
> I find this in the samba log when users try to connect:
> [2005/06/06 13:16:17, 2] smbd/sesssetup.c:setup_new_vc_session(608)
>   setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all
> old resources.
> [2005/06/06 13:16:17, 1] smbd/sesssetup.c:reply_spnego_kerberos(173)
>   Failed to verify incoming ticket!
> I can do `kinit Administrator at MY.DOMAIN.NET` and it returns no errors (but
> no success either - if I put in a wrong password, it gives an error though,
> so i guess this is ok)
> Anyone have any ideas? or can I change back to security = domain with some
> other fix?
> Thanks,
> H
PS I joined a test server (suse 9.2, Version 3.0.15pre2-0.1-SUSE) to the 
domain with security = ads, and it seems to be fine (homes work as expected). 
I did not test group membership problems - is there a fix for this in this 
version? (sorry bad phrasing)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.samba.org/archive/samba/attachments/20050606/49296320/attachment.bin

More information about the samba mailing list