[Samba] pam_unix failing after pam_winbind when Samba is running in Standalone Server mode

Rowland Penny rpenny at samba.org
Fri Aug 4 14:39:35 UTC 2023

On 04/08/2023 15:28, Jöran Malek via samba wrote:
> Hi,
> I'm trying to get PAM to authenticate against a local install of
> Samba, using the Standalone server mode.
> Environment information:
> - Debian 12
> - Samba version: 4.17.9
> Following packages are installed:
> - samba
> - libpam-winbind
> - libnss-winbind
> I added a user to passwd using
>> adduser --no-create-home --disabled-password --ingroup users jmalek
> Then registered that user in Sambas tdb:
>> pdbedit -a -u jmalek
> Confirmed the password, and continued:
> pdbedit -L
> jmalek:1000:
> Now, nsswitch.conf is configured to use winbind for passwd and group.

Sorry, but I don't think that is ever going to work, you do not use 
winbind on a standalone server, it is meant for use in a domain and 
requires much more configuration.

> I'm basically encountering the same issue that Brian Campbell
> encountered in 2014:
> https://bugzilla.samba.org/show_bug.cgi?id=10669#c12
> but can't find a resolution to this (I do see, that the mentioned
> patch is - albeit modified - still in Samba sources).

Perhaps if you were to explain just what you are trying to achieve, we 
may be able to come up with a workaround.


More information about the samba mailing list