[Samba] FW: Cannot access domain member from trusted domain user

Rowland Penny rpenny at samba.org
Mon Feb 17 08:48:40 UTC 2025


On Mon, 17 Feb 2025 03:09:45 +0000
Stephen Brandli via samba <samba at lists.samba.org> wrote:

> More: users on the BRANDLILAW domain can access the share, but it's
> incredibly slow.  In addition, smbd logs these errors repeatedly:
> 
> Feb 16 18:49:06 roberts smbd[136]:   check_account: Failed to convert
> SID S-1-5-21-2136821272-1111453333-1140905514-1601 to a UID
> (dom_user[BRANDLILAW\admin-fh$]) Feb 16 18:49:06 roberts smbd[136]:
> [2025/02/16 18:49:06.365450,  0]
> source3/auth/auth_util.c:1945(check_account)
> 
> admin-fh is a machine name, not a user name.
> 

That one I can answer.

In AD a computer is a user with an extra objectclass, so if you want to
stop that log message, give the computer a uidNumber.

Rowland



More information about the samba mailing list