<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Samba to prevent multiple logins? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519086#M219580</link>
    <description>Every time I set up a user, I create a unix account for them, and create an NT account for them.  NT for Windows file and print sharing, Unix for email and a unix database.&lt;BR /&gt;&lt;BR /&gt;So users log in to the Windows network, which gives them access to NT file shares, an NT home directory, and Windows shared printers.&lt;BR /&gt;&lt;BR /&gt;They use Eudora etc. to POP in to the Unix box for email.&lt;BR /&gt;&lt;BR /&gt;Then, to access our primary database, they open a terminal emulator, and log in to unix to run the DB.&lt;BR /&gt;&lt;BR /&gt;Can I use Samba to prevent having to maintain two sets of accounts, and so they don't need to login twice?&lt;BR /&gt;&lt;BR /&gt;i.e. set them up in Unix but not NT?&lt;BR /&gt;&lt;BR /&gt;And, once authenticated there, can the Unix box be in the same domain such that the NT shares are available to them without logging in again?&lt;BR /&gt;&lt;BR /&gt;The O'Reilly Samba book says I can avoid NT CALs, is that true, or do I avoid CALs by sharing everything from unix disks?&lt;BR /&gt;&lt;BR /&gt;If someone could touch on these points I'd appreciate it.&lt;BR /&gt;</description>
    <pubDate>Wed, 06 Apr 2005 09:07:30 GMT</pubDate>
    <dc:creator>Fred Martin_1</dc:creator>
    <dc:date>2005-04-06T09:07:30Z</dc:date>
    <item>
      <title>Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519086#M219580</link>
      <description>Every time I set up a user, I create a unix account for them, and create an NT account for them.  NT for Windows file and print sharing, Unix for email and a unix database.&lt;BR /&gt;&lt;BR /&gt;So users log in to the Windows network, which gives them access to NT file shares, an NT home directory, and Windows shared printers.&lt;BR /&gt;&lt;BR /&gt;They use Eudora etc. to POP in to the Unix box for email.&lt;BR /&gt;&lt;BR /&gt;Then, to access our primary database, they open a terminal emulator, and log in to unix to run the DB.&lt;BR /&gt;&lt;BR /&gt;Can I use Samba to prevent having to maintain two sets of accounts, and so they don't need to login twice?&lt;BR /&gt;&lt;BR /&gt;i.e. set them up in Unix but not NT?&lt;BR /&gt;&lt;BR /&gt;And, once authenticated there, can the Unix box be in the same domain such that the NT shares are available to them without logging in again?&lt;BR /&gt;&lt;BR /&gt;The O'Reilly Samba book says I can avoid NT CALs, is that true, or do I avoid CALs by sharing everything from unix disks?&lt;BR /&gt;&lt;BR /&gt;If someone could touch on these points I'd appreciate it.&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Apr 2005 09:07:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519086#M219580</guid>
      <dc:creator>Fred Martin_1</dc:creator>
      <dc:date>2005-04-06T09:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519087#M219581</link>
      <description>The latest versions of Samba can authenticate users from both a Microsoft domain or Active Directory. See:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://bob.rasey.net/archives/000137.html" target="_blank"&gt;http://bob.rasey.net/archives/000137.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.go-getters.com/index.php?p=26" target="_blank"&gt;http://www.go-getters.com/index.php?p=26&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html" target="_blank"&gt;http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;These sites should be enough to get you started.</description>
      <pubDate>Thu, 07 Apr 2005 07:11:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519087#M219581</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2005-04-07T07:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519088#M219582</link>
      <description>Depending upon, how you have configured the smb.conf, you can authenticate users from wiondow$ PDC. Check the setting for security in global section.&lt;BR /&gt;&lt;BR /&gt;For details on this setting, read sabba book.&lt;BR /&gt;&lt;A href="http://www.oreilly.com/openbook" target="_blank"&gt;http://www.oreilly.com/openbook&lt;/A&gt;</description>
      <pubDate>Thu, 07 Apr 2005 07:23:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519088#M219582</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2005-04-07T07:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519089#M219583</link>
      <description>Best to authenticate on Windows...&lt;BR /&gt;&lt;BR /&gt;Here's the samba how to collection:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/" target="_blank"&gt;http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Use HP's cif server though:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B8725AA" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B8725AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You need winbind running as well (add to /etc/nsswitch.conf:&lt;BR /&gt;&lt;BR /&gt;passwd:       files winbind&lt;BR /&gt;group:        files winbind&lt;BR /&gt;hosts:        files [NOTFOUND=CONTINUE] dns&lt;BR /&gt;&lt;BR /&gt;You can make the samba server join the NT domain - you need someone with admin priviliges and password:&lt;BR /&gt;&lt;BR /&gt;/opt/samba/bin/net rpc join -U administrator&lt;BR /&gt;&lt;BR /&gt;Main things to put in smb.conf:&lt;BR /&gt;&lt;BR /&gt;        workgroup = YOURNTDOMAIN&lt;BR /&gt;        security = DOMAIN&lt;BR /&gt;        password server = YOURNTDC1, YOURNTDC2&lt;BR /&gt;&lt;BR /&gt;        winbind separator = +&lt;BR /&gt;        winbind enum users = No&lt;BR /&gt;        winbind enum groups = No&lt;BR /&gt;        valid users = $YOURNTDOMAIN+AGROUP, bb, oracle, YOURNTDOMAIN+somentuserid&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;An example share:&lt;BR /&gt;&lt;BR /&gt;[homes]&lt;BR /&gt;        comment = Home Directories&lt;BR /&gt;        path = /home/%U&lt;BR /&gt;        valid users = YOURNTDOMAIN+somentuserid, YOURNTDOMAIN+somentuserid2, bb, oracle&lt;BR /&gt;        browseable = No&lt;BR /&gt;&lt;BR /&gt;NOTE: as of Samba 3 something...browsing is OFF by default - if you want browsing - then you have to add the IPC$ share:&lt;BR /&gt;&lt;BR /&gt;[IPC$]&lt;BR /&gt;        hosts allow = 192.168.2.0/24 127.0.0.1&lt;BR /&gt;        hosts deny = 0.0.0.0/0&lt;BR /&gt;        valid users = bb, YOURNTDOMAIN+somentuserid, YOURNTDOMAIN+somentuserid2&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Apr 2005 08:35:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519089#M219583</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2005-04-07T08:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519090#M219584</link>
      <description>Thanks folks, I'm reading more of the O'Reilly text and getting some answers there.  I'll also review your links.&lt;BR /&gt;&lt;BR /&gt;I was hoping though that I could use the unix box as the 'master' i.e. set up accounts there, then have the unix box act as the PDC for windows, letting Windows users authenticate from the unix box.&lt;BR /&gt;&lt;BR /&gt;This because they need to have a unix account for email anyway.&lt;BR /&gt;&lt;BR /&gt;Is it just harder to configure with unix as the PDC, or is it somewhat broken when done that way?&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Apr 2005 08:07:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519090#M219584</guid>
      <dc:creator>Fred Martin_1</dc:creator>
      <dc:date>2005-04-08T08:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519091#M219585</link>
      <description>You can use Unix as PDC - I do that @ home with my Linux box.&lt;BR /&gt;&lt;BR /&gt;As far as I remember - you need  Unix account for each as well as setting up the smbpasswd for NT id's.&lt;BR /&gt;&lt;BR /&gt;There are a lot of How to's - heres one:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.hughesjr.com/content/view/24/2/Site_News" target="_blank"&gt;http://www.hughesjr.com/content/view/24/2/Site_News&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Rgds...Goeff</description>
      <pubDate>Fri, 08 Apr 2005 08:32:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519091#M219585</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2005-04-08T08:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519092#M219586</link>
      <description>Accckk.  So I have to set up the account twice anyway?  I was hoping to avoid that.&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Apr 2005 08:35:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519092#M219586</guid>
      <dc:creator>Fred Martin_1</dc:creator>
      <dc:date>2005-04-08T08:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519093#M219587</link>
      <description>Yes - 2 accounts - the unix one can be nologin - or false...but you need an Unix uid for each NT user.&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Apr 2005 08:51:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519093#M219587</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2005-04-08T08:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Samba to prevent multiple logins?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519094#M219588</link>
      <description>But the Windows account is set up on the unix box in an smbpasswd file, is it not?  Could it be automated, in that every time I add or remove a user in SAM for unix, a script fires off to create the smb account for windows?&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Apr 2005 09:04:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/samba-to-prevent-multiple-logins/m-p/3519094#M219588</guid>
      <dc:creator>Fred Martin_1</dc:creator>
      <dc:date>2005-04-08T09:04:42Z</dc:date>
    </item>
  </channel>
</rss>

