[Samba] Samba 4.10.7 + freeradius 3.0.17 +ntlm_auth - Debian buster

Rowland penny rpenny at samba.org
Fri Aug 30 11:54:11 UTC 2019

On 30/08/2019 12:32, Christian Naumer via samba wrote:
> Am 30.08.19 um 13:09 schrieb L.P.H. van Belle via samba:
>> Now Christian, this failes for me.
>> radtest -t mschap 'NTDOM\username" 'passwd' localhost 0 testing
>> ( MS-CHAP-Error = "\000E=691 R=1 C=58f41f1a946ac94a V=2")
>> So my question here is, are the username at REALM logins also working for you.
>> And are you using in smb.conf :  winbind use default domain = yes
> username at REALM does not work. However we do not use this.
> And as it runs on the DC "winbind use default domain = yes " is the default.

No, 'winbind use default domain = no' is the default on a DC and you 
cannot change it.


More information about the samba mailing list