[Samba] samba3.0.22 - "net setlocalsid" with no effect

Douglas VanLeuven roamdad at sonic.net
Wed Mar 26 18:15:27 GMT 2008


Friedrich Strohmaier wrote:
> Hi all,
> 
> Really no one with a glue, what steps I could go??

I can't tell what you're trying to do from what you've described.
It looks like you set the local machine sid and it worked.
The local machine sid will be different than the domain sid.
A profile based on the local machine sid won't be a roaming profile it 
will be a local profile.

> 
> Friedrich Strohmaier schrieb:
> 
> [..]
> 
>> root# net setlocalsid SID_WANTED
>> root#
>>
>> root# net getlocalsid
>> SID for domain DOMAIN is: SID_WANTED
>>
>> Result:
>> Client with Roamingprofile based on SID_WANTED is not able to connect
>> to DOMAIN but has access to shares.
>>
>> OOOoops!

If the local user name and password are the same as the domain name and 
password, depending on the security model, it's an old trick to allow 
access to shares in a workgroup without being a domain member.  Which is 
sort of what you describe.

>>
>> More Tests found here:
>> http://us3.samba.org/samba/docs/man/Samba-HOWTO-Collection/NetCommand.html#netmisc1
>>
>> root# net rpc info
>> Domain Name: DOMAIN
>> Domain SID: SID_NOT_WANTED
>> Sequence number: 1206493306
>> Num users: 37
>> Num domain groups: 0
>> Num local groups: 0

I would think zero groups with 37 users is a hint to a problem.

Regards, Doug


More information about the samba mailing list