[Samba] FW: Cannot access domain member from trusted domain user

Stephen Brandli steve at brandli.com
Mon Feb 17 19:02:46 UTC 2025


Ah.  I don't know how you guys get your heads around this stuff.

	Steve

-----Original Message-----
From: samba <samba-bounces at lists.samba.org> On Behalf Of Rowland Penny via samba
Sent: Monday, February 17, 2025 12:49 AM
To: samba at lists.samba.org
Cc: Rowland Penny <rpenny at samba.org>
Subject: Re: [Samba] FW: Cannot access domain member from trusted domain user

On Mon, 17 Feb 2025 03:09:45 +0000
Stephen Brandli via samba <samba at lists.samba.org> wrote:

> More: users on the BRANDLILAW domain can access the share, but it's 
> incredibly slow.  In addition, smbd logs these errors repeatedly:
> 
> Feb 16 18:49:06 roberts smbd[136]:   check_account: Failed to convert
> SID S-1-5-21-2136821272-1111453333-1140905514-1601 to a UID
> (dom_user[BRANDLILAW\admin-fh$]) Feb 16 18:49:06 roberts smbd[136]:
> [2025/02/16 18:49:06.365450,  0]
> source3/auth/auth_util.c:1945(check_account)
> 
> admin-fh is a machine name, not a user name.
> 

That one I can answer.

In AD a computer is a user with an extra objectclass, so if you want to stop that log message, give the computer a uidNumber.

Rowland

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba



More information about the samba mailing list