[Samba] Not able to join Debian 10 to AD using winbind

Rowland Penny rpenny at samba.org
Fri Oct 15 11:21:32 UTC 2021


On Fri, 2021-10-15 at 16:45 +0530, Sac Isilia wrote:
> Hi Rowland,
> 
> But my account is created in media domain. Also i tried looking to id
> users in emea-media domain and it also didn't work.
> 

The last time I heard, you were using a smb.conf similar to this:

[global]
    workgroup = EMEA-MEDIA
    realm = EMEA.MEDIA.GLOBAL.LOC
    security = ADS

    dedicated keytab file = /etc/krb5.keytab
    kerberos method = secrets and keytab

    winbind offline logon = yes
    winbind refresh tickets = yes
    winbind use default domain = yes
    template shell = /bin/bash
    restrict anonymous = 2
    domain master = no
    local master = no
    preferred master = no

    idmap config * : backend = autorid
    idmap config * : range = 10000-9999999

    dns proxy = no
    # user Administrator workaround, without it you are unable to set
privileges
    username map = /etc/samba/user.map

    vfs objects = acl_xattr
    map acl inherit = Yes

    log file = /var/log/samba/log.%m
    max log size = 1000
    syslog = 0
    panic action = /usr/share/samba/panic-action %d
    obey pam restrictions = yes
    usershare allow guests = yes

If that isn't your smb.conf, please post your current smb.conf

Rowland





More information about the samba mailing list