[Samba] Re: NTLM Problems

Ian Barnes ian at opteqint.net
Wed Nov 2 07:27:43 GMT 2005


Hi,

Even if the client doesn't support Kerberos should I leave that option
enabled in smb.conf?

Attached are the log files, maybe they can help.

Cheers
Ian

-----Original Message-----
From: Andrew Bartlett [mailto:abartlet at samba.org] 
Sent: 02 November 2005 07:03 AM
To: Ian Barnes
Cc: samba at lists.samba.org
Subject: RE: [Samba] Re: NTLM Problems

On Wed, 2005-11-02 at 06:54 +0200, Ian Barnes wrote:
> Okay, ill remove the realm line if its not in use. I only fill it in if im
> using Kerberos? Or should it be filled in at all times?

You should be using kerberos.  I strongly suggest running
'security=ads'.

> Any idea as to why I could be "falling out" of the domain? Its strange and
> only seems to be our unit that is doing this. All other machines that log
> onto the domain don't have this problem.

See if there are clues in the DC-side event log.

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net


More information about the samba mailing list