[Samba] Samba 4.6.5-Debian, authentication on a mix workgroup+domain

Rowland Penny rpenny at samba.org
Mon Jul 31 07:22:40 UTC 2017

On Mon, 31 Jul 2017 00:29:31 +0200
Marc-Henri Pamiseux via samba <samba at lists.samba.org> wrote:

> Hi Rowland,
> Sorry if i did not post smb.conf again, just because nothing really
> change since my post from 25/07/2017 14:52.
> I have add "ntlm auth = yes" for testing.

There are things in that smb.conf I would remove, but none that have
anything to do with your problem.

I think your problem is down to sheer stupidity, who thought it was a
good idea to have an an AD domain and a workgroup with the
same NetBIOS domain name ?

Not that any of this will stop your problem, your workgroup users are
NOT in the AD NetBIOS domain (MYDOMAIN) and so they will be mapped into
the '*' domain and winbindd needs to know who they are, so they get
asked for the NetBIOS domain they are in, windows does this as well.

You could try adding 'map untrusted to domain', this may help, I am
unsure though, mainly because I have never been daft enough to use the
same NetBIOS domain twice on the same network.

Can I also point that I (and probably everybody else) cannot remember
all the smb.conf files that get posted on here ;-)


More information about the samba mailing list