[Samba] Domain authentification problem with LDAP
daniel_tousignant at travelcom.com
Fri Mar 17 20:08:04 GMT 2006
The objectclass sambaSAMAccount and subsequent fields have been
created. We are using the standard perl script tools that are installed
the mandriva 2006 distro (samba 3.0.13 and openldap 2.3.6).
What I really do not understand is that if I put a user in the standard
group "Domain Admins" (gid=512), the user is able to logon to the domain,
when it is in the "Domain Users" group (gid=513). What is the big
difference for Samba
between the two's ? Can it be an ACL problems ?
"James Taylor" <jtaylor at laszlosystems.com> a écrit:
>The LDAP users you have created (including the machines) need to have the
>objectclass: sambaSAMAccount and the subsequent fields. What are your
>add scripts and machine add scripts you are using. Also, I have found
>the IDEALX tools have an error in the smbldap-useradd script which
>that when you use the add machine switch the sambaSAMAccount information
>not added to the LDAP database. I do have a copy of this modified file if
>you need it. Otherwise if you can edit the script yourself.
>From: samba-bounces+jtaylor=laszlosystems.com at lists.samba.org
>[mailto:samba-bounces+jtaylor=laszlosystems.com at lists.samba.org] On Behalf
>Of Daniel Tousignant
>Sent: Friday, March 17, 2006 9:11 AM
>To: samba at lists.samba.org
>Subject: [Samba] Domain authentification problem with LDAP
>We use samba 3.0.13 and openldap 2.3.6
>Members of the ldap group "Domain Admins" are working fine, but
>members of the group "Domain Users" can not login to the domain,
>and do not have access to the shares. Also, we are unable to join
>a windows xp workstation to the domain.
>Can anyone give me a hint where to start looking ...
>To unsubscribe from this list go to the following URL and read the
Courriel : daniel_tousignant at travelcom.com
Telephone : (514) 286-8515 poste 3326
More information about the samba