[Samba] FW: Cannot access domain member from trusted domain user
Stephen Brandli
steve at brandli.com
Mon Feb 17 19:02:46 UTC 2025
Ah. I don't know how you guys get your heads around this stuff.
Steve
-----Original Message-----
From: samba <samba-bounces at lists.samba.org> On Behalf Of Rowland Penny via samba
Sent: Monday, February 17, 2025 12:49 AM
To: samba at lists.samba.org
Cc: Rowland Penny <rpenny at samba.org>
Subject: Re: [Samba] FW: Cannot access domain member from trusted domain user
On Mon, 17 Feb 2025 03:09:45 +0000
Stephen Brandli via samba <samba at lists.samba.org> wrote:
> More: users on the BRANDLILAW domain can access the share, but it's
> incredibly slow. In addition, smbd logs these errors repeatedly:
>
> Feb 16 18:49:06 roberts smbd[136]: check_account: Failed to convert
> SID S-1-5-21-2136821272-1111453333-1140905514-1601 to a UID
> (dom_user[BRANDLILAW\admin-fh$]) Feb 16 18:49:06 roberts smbd[136]:
> [2025/02/16 18:49:06.365450, 0]
> source3/auth/auth_util.c:1945(check_account)
>
> admin-fh is a machine name, not a user name.
>
That one I can answer.
In AD a computer is a user with an extra objectclass, so if you want to stop that log message, give the computer a uidNumber.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
More information about the samba
mailing list