[Samba] Vista SP1, Server 2008 joining NT4/Samba Domain

Stefan Oberwahrenbrock oberwahrenbrock at transdata.net
Tue Jun 17 10:07:18 GMT 2008


It seems, that Vista SP1 and Server 2008 cannot join an NT4/Samba-domain. 
Vista once could join before SP1, if one did some modifications to the 
system (LAN Manager authentication level, Encryption of secure channel). 
But these workarounds do not seem to work with SP1 anymore.

Microsoft points out that joining NT4-domains with  Vista SP1 and Server 
2008 is not supported/tested (Article ID 940268, 

To my knowledge Samba 3.0.x - acting as an PDC/BDC - basically provides 
NT4-domain functions/services. We tried to join Vista SP1 and Server 2008 
to a Microsoft NT4-domain (PDC running NT4.0 SP6a) as well as to a Samba-
domain (Samba 3.0.24 [Debian] with LDAP Backend slpapd 2.3.30 [Debian]). 
Both tries failed, symptoms as mentioned in der MS articel. Other systems 
(2000, XP, 2003) join without problems.

Conclusion: As Vista SP1 and Server 2008 do not "cooperate" with NT4-
domains, you cannot join these systems in Samba 3.0.x domains, which 
basically "emulate" NT4-domains.

Can someone confirm the conclusion/scenario or confute it by providing 
empiric values of working samba domains containing Vista SP1 and Server 
2008 sytems? The latter ist more appreciated ... ;-)


More information about the samba mailing list