[Samba] pulling userinfo from trusted domain RE-POST

Christopher Welsh cpwe at deakin.edu.au
Tue Jun 21 14:26:28 GMT 2005

Sorry to repeat this but I had no answers. Anyone up for a chat about 
this. More info:

wbinfo -m returns nothing
wbinfo -t , wbinfo -u wbinfo -g returns users for the primary (Staff 
Domain, but not the student domain). I'm sure I had it returning info 
from both primary and secondary domains when the servers were windows 
2000 servers earlier this year, So I believe winbind should be able to 
do the job.

Oh, I have fixed the clock skew issue, but that did nothing to help.


I'm trying to pull user info from a student domain.

I can pull a user's info from a primary domain ok, but not from the
domain (student) that trusts the primary domain.

Lets say the primary is staff and secondary is student.
Student trusts staff, but staff does not trust student.

/usr/bin/net ads search "(&(objectCategory=person)
(sAMAccountName=foo))" -P -I

The command tries to pull out the users ldap account info. I'm
interested in seeing if the user's account is locked or not. (514 or 512)

It works on the staff domain for staff users, so I know the syntax is ok.

Any way of doing this?  Error back is clock skew, I will check the
server times tomorrow.

I'm using Mandrake linux 10.1
samba v3.0.2a
ADS server 2003K SP1
ADS and kerberos mode.

Is there a simple samba command that will lock or unlock a user's account.


More information about the samba mailing list