<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cifs authentication question. in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839374#M273063</link>
    <description>I have no idea if it's a Windows problem.&lt;BR /&gt;&lt;BR /&gt;Has anyone else had this?&lt;BR /&gt;&lt;BR /&gt;Here are the conf files in case anyone spots the obvious.&lt;BR /&gt;&lt;BR /&gt;*kerberos&lt;BR /&gt;&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = HUFUK.COM&lt;BR /&gt;default_tkt_enctypes = DES-CBC-CRC&lt;BR /&gt;default_tgs_enctypes = DES-CBC-CRC&lt;BR /&gt;ccache_type = 2&lt;BR /&gt;[realms]&lt;BR /&gt;HUFUK.COM = {&lt;BR /&gt;kdc = apdc.hufuk.com:88&lt;BR /&gt;admin_server = apdc.hufuk.com&lt;BR /&gt;}&lt;BR /&gt;[domain realm]&lt;BR /&gt;.COM = HUFUK.COM&lt;BR /&gt;[logging]&lt;BR /&gt;kdc = FILE:/var/log/krb5dc.log&lt;BR /&gt;admin_server = FILE:/var/logkadmin.log&lt;BR /&gt;default = FILE:/var/log/krb5lib.log&lt;BR /&gt;&lt;BR /&gt;smb.conf.&lt;BR /&gt;&lt;BR /&gt;# Global parameters&lt;BR /&gt;[global]&lt;BR /&gt;workgroup = HUFUK&lt;BR /&gt;realm = HUFUK.COM&lt;BR /&gt;server string = Huferpu1 Samba Server&lt;BR /&gt;security = ADS&lt;BR /&gt;password server = apdc.hufuk.com&lt;BR /&gt;syslog = 0&lt;BR /&gt;log file = /var/opt/samba/log.%m&lt;BR /&gt;max log size = 1000&lt;BR /&gt;preferred master = No&lt;BR /&gt;domain master = No&lt;BR /&gt;idmap uid = 10000-20000&lt;BR /&gt;idmap gid = 10000-20000&lt;BR /&gt;winbind enable local accounts = Yes&lt;BR /&gt;winbind use default domain = Yes&lt;BR /&gt;valid users = cjohnson aflavell&lt;BR /&gt;read only = No&lt;BR /&gt;hosts allow = 192.0.0.0/255.255.0.0&lt;BR /&gt;short preserve case = No&lt;BR /&gt;dos filetime resolution = Yes&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# ./net ads join -U cjohnson%mypass&lt;BR /&gt;Using short domain name -- HUFUK&lt;BR /&gt;Joined 'HUFERPU1' to realm 'HUFUK.COM&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;Very short and sweet, nothing special going on.&lt;BR /&gt;&lt;BR /&gt;I really could do with some suggestions people?&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Chris</description>
    <pubDate>Wed, 09 Aug 2006 01:48:22 GMT</pubDate>
    <dc:creator>Chris Johnson_11</dc:creator>
    <dc:date>2006-08-09T01:48:22Z</dc:date>
    <item>
      <title>Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839372#M273061</link>
      <description>Hi everyone.&lt;BR /&gt;&lt;BR /&gt;I have a slight problem understanding how ADS security works.&lt;BR /&gt;&lt;BR /&gt;I have the latest version of CIFS / Kerberos and LDAP/UX&lt;BR /&gt;&lt;BR /&gt;I have installed samba correctly as far as I can see.&lt;BR /&gt;&lt;BR /&gt;smb.conf / kinit / krb5.conf / net ads join etc all work correctly as far as I can see.&lt;BR /&gt;&lt;BR /&gt;However, when I use syncsmbpasswd &lt;BR /&gt;/var/opt/samba/private/smbpasswd does indeed get populated from the windows 2003 PDC but all state similar to the following:-&lt;BR /&gt;&lt;BR /&gt;AFLAVELL$:10244:NOPASSWORDXXXXXXXXXXXXXXXXXXXXX:NO PASSWORDXXXXXXXXXXXXXXXXXXXXX[NU         ]:LCT-00000000:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I admit it has taken me a while to get this far so backtracking would be difficult. As far as I understand, running syncsmbpasswd should pull all users and passwords from the Windows domain controller. Is this correct?&lt;BR /&gt;&lt;BR /&gt;All shares do not work at all at present. Any user immediately is greeted with a password prompt.&lt;BR /&gt;&lt;BR /&gt;I will post all configs if needed but I am sure this is a simple step I have missed.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 08 Aug 2006 09:32:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839372#M273061</guid>
      <dc:creator>Chris Johnson_11</dc:creator>
      <dc:date>2006-08-08T09:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839373#M273062</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;My understanding is that syncsmbpasswd should do as you expect.&lt;BR /&gt;&lt;BR /&gt;You seem to be having a problem with the way one of the users is configured in ADS. This looks like a Windows issue. &lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 08 Aug 2006 09:42:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839373#M273062</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-08-08T09:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839374#M273063</link>
      <description>I have no idea if it's a Windows problem.&lt;BR /&gt;&lt;BR /&gt;Has anyone else had this?&lt;BR /&gt;&lt;BR /&gt;Here are the conf files in case anyone spots the obvious.&lt;BR /&gt;&lt;BR /&gt;*kerberos&lt;BR /&gt;&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = HUFUK.COM&lt;BR /&gt;default_tkt_enctypes = DES-CBC-CRC&lt;BR /&gt;default_tgs_enctypes = DES-CBC-CRC&lt;BR /&gt;ccache_type = 2&lt;BR /&gt;[realms]&lt;BR /&gt;HUFUK.COM = {&lt;BR /&gt;kdc = apdc.hufuk.com:88&lt;BR /&gt;admin_server = apdc.hufuk.com&lt;BR /&gt;}&lt;BR /&gt;[domain realm]&lt;BR /&gt;.COM = HUFUK.COM&lt;BR /&gt;[logging]&lt;BR /&gt;kdc = FILE:/var/log/krb5dc.log&lt;BR /&gt;admin_server = FILE:/var/logkadmin.log&lt;BR /&gt;default = FILE:/var/log/krb5lib.log&lt;BR /&gt;&lt;BR /&gt;smb.conf.&lt;BR /&gt;&lt;BR /&gt;# Global parameters&lt;BR /&gt;[global]&lt;BR /&gt;workgroup = HUFUK&lt;BR /&gt;realm = HUFUK.COM&lt;BR /&gt;server string = Huferpu1 Samba Server&lt;BR /&gt;security = ADS&lt;BR /&gt;password server = apdc.hufuk.com&lt;BR /&gt;syslog = 0&lt;BR /&gt;log file = /var/opt/samba/log.%m&lt;BR /&gt;max log size = 1000&lt;BR /&gt;preferred master = No&lt;BR /&gt;domain master = No&lt;BR /&gt;idmap uid = 10000-20000&lt;BR /&gt;idmap gid = 10000-20000&lt;BR /&gt;winbind enable local accounts = Yes&lt;BR /&gt;winbind use default domain = Yes&lt;BR /&gt;valid users = cjohnson aflavell&lt;BR /&gt;read only = No&lt;BR /&gt;hosts allow = 192.0.0.0/255.255.0.0&lt;BR /&gt;short preserve case = No&lt;BR /&gt;dos filetime resolution = Yes&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# ./net ads join -U cjohnson%mypass&lt;BR /&gt;Using short domain name -- HUFUK&lt;BR /&gt;Joined 'HUFERPU1' to realm 'HUFUK.COM&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;Very short and sweet, nothing special going on.&lt;BR /&gt;&lt;BR /&gt;I really could do with some suggestions people?&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Chris</description>
      <pubDate>Wed, 09 Aug 2006 01:48:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839374#M273063</guid>
      <dc:creator>Chris Johnson_11</dc:creator>
      <dc:date>2006-08-09T01:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839375#M273064</link>
      <description>Hi Chris,&lt;BR /&gt;&lt;BR /&gt;Did you change the "authenticationLevel" parameter to kerberos (instead of ntlm) in the /etc/opt/cifsclient/cifsclient.cfg file?&lt;BR /&gt;&lt;BR /&gt;An xtra question: is your ADS the 2003 R2 version with the RF2307 scheme implemented or do you use the MS SFU scheme extensions?&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Aug 2006 02:54:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839375#M273064</guid>
      <dc:creator>TEC-HP</dc:creator>
      <dc:date>2006-08-09T02:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839376#M273065</link>
      <description>Hi Chris,&lt;BR /&gt;&lt;BR /&gt;Now we may be getting somewhere. I didnt even know that cifsclient.cfg existed. I didn't see a reference to that in the admin guide.&lt;BR /&gt;&lt;BR /&gt;The authentication is set to ntlm. Is this correct?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Chris</description>
      <pubDate>Thu, 10 Aug 2006 02:06:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839376#M273065</guid>
      <dc:creator>Chris Johnson_11</dc:creator>
      <dc:date>2006-08-10T02:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839377#M273066</link>
      <description>Chris&lt;BR /&gt;&lt;BR /&gt;I'm just checking the possibilities at this moment. I haven't a working environment aither at this point. But if you want to use kerberos authentication: thenyou need to change parameter to kerberos instead of NTLM (check also your PAM config). Anyway: I'm currently following this guide:&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B8724-90067/ch03.html?btnNext=next%A0%BB" target="_blank"&gt;http://docs.hp.com/en/B8724-90067/ch03.html?btnNext=next%A0%BB&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'm currently at this point:&lt;BR /&gt;#kinit &lt;ACCOUNT&gt;&lt;BR /&gt;...&lt;BR /&gt;#/opt/cifsclient/bin/cifsgettkt -s af0002&lt;BR /&gt;cifsgettkt: acquired service ticket for server af0002&lt;BR /&gt;default cache: FILE:/tmp/krb5cc_809_833&lt;BR /&gt;ticket data:&lt;BR /&gt;  client name:    id075213&lt;BR /&gt;  client realm:   BGC.NET&lt;BR /&gt;  server name:    af0002&lt;BR /&gt;  server realm:   BGC.NET&lt;BR /&gt;  authtime:       Thu Aug 10 09:39:50 2006&lt;BR /&gt;  starttime:      Thu Aug 10 09:39:50 2006&lt;BR /&gt;  endtime:        Thu Aug 10 19:39:50 2006&lt;BR /&gt;  ticket length:  1725 bytes&lt;BR /&gt;&lt;BR /&gt;so far so good, but when:&lt;BR /&gt;&lt;BR /&gt;#cifsmount  //af0002/id075213$ /home/id075213 -U id075213&lt;BR /&gt;Remote user id075213's password:&lt;BR /&gt;Logging in User: Unknown error class 999&lt;BR /&gt;...&lt;BR /&gt;will keep you informed if progress is made&lt;BR /&gt;&lt;BR /&gt;&lt;/ACCOUNT&gt;</description>
      <pubDate>Thu, 10 Aug 2006 02:55:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839377#M273066</guid>
      <dc:creator>TEC-HP</dc:creator>
      <dc:date>2006-08-10T02:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839378#M273067</link>
      <description>&lt;!--!*#--&gt;Chris, I have been going through the same process for a few weeks.  Today I have successfuly configured my HP-UX 11i server with SAMBA and AD and was able to sync up with the AD server using the command -  /opt/samba/bin/syncsmbpasswd &lt;BR /&gt;I used Winbind for this. &lt;BR /&gt;HERE ARE MY STEPS -&lt;BR /&gt;Do you have the current Patches neede and the following product installed -&lt;BR /&gt;# swlist -l product |grep -i CIFS&lt;BR /&gt;  CIFS-Client           A.02.02        CIFS Client    &lt;BR /&gt;  CIFS-Development      A.02.02.01     HP CIFS Server Source Code Files &lt;BR /&gt;  CIFS-Server           A.02.02.01     HP CIFS Server (Samba) File and Print Services &lt;BR /&gt;# swlist -l product |grep -i ldap&lt;BR /&gt;  LdapUxClient          B.04.00.02     LDAP-UX Client Services &lt;BR /&gt;  NisLdapServer         B.04.00.02     The NIS/LDAP Gateway (ypldapd) &lt;BR /&gt;# swlist -l product |grep -i pam&lt;BR /&gt;  PAM-Kerberos          B.11.11.14     PAM-Kerberos Version 1.24 &lt;BR /&gt;  PAM-NTLM              A.02.02        HP NTLM Pluggable Authentication Module &lt;BR /&gt;  PHCO_27064            1.0            libpam cumulative patch &lt;BR /&gt;  PHCO_34214            1.0            libpam_unix cumulative patch &lt;BR /&gt;&lt;BR /&gt;make sure that you have the NTP server running.  I used my AD server as the NTP server. &lt;BR /&gt;Add these lines to your pam.conf file for each grouping -&lt;BR /&gt;# ADDED BY MTG 9/8/06&lt;BR /&gt;login    auth required    /usr/lib/security/libpam_updbe.1&lt;BR /&gt;login    auth sufficient  /usr/lib/security/libpam_krb5.1 forwardable renewable=5d10h&lt;BR /&gt;login    auth required    /usr/lib/security/libpam_unix.1 try_first_pass&lt;BR /&gt;# END ADD&lt;BR /&gt;make sure that you change the file permissions back to 444.&lt;BR /&gt;Make sure that these lines are in your smb.conf file -&lt;BR /&gt;security = ADS&lt;BR /&gt;realm = YourREALM.COM&lt;BR /&gt;        encrypt passwords = Yes&lt;BR /&gt;        allow trusted domains = No&lt;BR /&gt;        password server = MyADServer *&lt;BR /&gt;        domain master = no&lt;BR /&gt;        syslog = 0&lt;BR /&gt;        log file = /var/opt/samba/log.%m&lt;BR /&gt;        max log size = 1000&lt;BR /&gt;        server signing = auto&lt;BR /&gt;        client use spnego = No&lt;BR /&gt;        announce version = 3.2&lt;BR /&gt;        name resolve order = wins host lmhosts bcast&lt;BR /&gt;        wins server = yes&lt;BR /&gt;        wins server = 10.1.2.34&lt;BR /&gt;        ldap ssl = no&lt;BR /&gt;        idmap uid = 16777216-33554431&lt;BR /&gt;        idmap gid = 16777216-33554431&lt;BR /&gt;&lt;BR /&gt;Make sure that /etc/services is correct with the following entries:&lt;BR /&gt;&lt;BR /&gt;Services changes&lt;BR /&gt;# Kerberos (Project Athena/MIT) services&lt;BR /&gt;#&lt;BR /&gt;# ADD BELOW MTG 09/08/2006 FOR AD/CIFS&lt;BR /&gt;# PAM Kerberos services&lt;BR /&gt;#&lt;BR /&gt;kerberos     88/udp   kdc  # Kerberos V5 kdc&lt;BR /&gt;kerberos     88/tcp   kdc  # Kerberos V5 kdc&lt;BR /&gt;klogin       543/tcp       # Kerberos rlogin -kfall&lt;BR /&gt;kshell       544/tcp  cmd  # Kerberos remote&lt;BR /&gt; shell&lt;BR /&gt;kerberos-adm 749/tcp       # Kerberos 5 admin/changepw&lt;BR /&gt;kerberos-adm 749/udp       # Kerberos 5 admin/changepw&lt;BR /&gt;krb5_prop    754/tcp       # Kerberos slave propagation&lt;BR /&gt;kerberos-adm 464/udp       # Kerberos Password Change protocol&lt;BR /&gt;kerberos-cpw  464/tcp       # Kerberos Password Change protocol&lt;BR /&gt;#&lt;BR /&gt;# END PAM Kerberos services&lt;BR /&gt;swat      901/tcp       # SAMBA Web-based Admin Tool&lt;BR /&gt;Make these changes to the nsswitch.conf file.&lt;BR /&gt;# cat /etc/nsswitch.conf&lt;BR /&gt;#&lt;BR /&gt;# /etc/nsswitch.files:&lt;BR /&gt;#&lt;BR /&gt;# @(#)B.11.11_LR&lt;BR /&gt;#&lt;BR /&gt;# An example file that could be copied over to /etc/nsswitch.conf; it&lt;BR /&gt;# does not use any name services.&lt;BR /&gt;#&lt;BR /&gt;# MTG Commented 2 lines below and &lt;BR /&gt;# ADDED 9/14/2006 for SAMBA/WINBIND/AD&lt;BR /&gt;#passwd:       files&lt;BR /&gt;#group:        files&lt;BR /&gt;&lt;BR /&gt;passwd:     files winbind&lt;BR /&gt;shadow:     files&lt;BR /&gt;group:      files winbind&lt;BR /&gt;# END MTG 9/14/2006&lt;BR /&gt;&lt;BR /&gt;host: files [NOTFOUND=continue] dns&lt;BR /&gt;services:     files&lt;BR /&gt;networks:     files&lt;BR /&gt;protocols:    files&lt;BR /&gt;rpc:          files&lt;BR /&gt;publickey:    files&lt;BR /&gt;netgroup:     files&lt;BR /&gt;automount:    files&lt;BR /&gt;aliases:      files&lt;BR /&gt;ipnodes : dns files&lt;BR /&gt;&lt;BR /&gt;Create or Change the krb5.conf file like Unix server below â  &lt;BR /&gt;# cat krb5.conf&lt;BR /&gt;# Kerberos Configuration #&lt;BR /&gt;# #&lt;BR /&gt;# This krb5.conf file is intended as an example only. #&lt;BR /&gt;# See krb5.conf(4) for more details. #&lt;BR /&gt;#&lt;BR /&gt;# Please verify that you have created the directory /var/log.#&lt;BR /&gt;# #&lt;BR /&gt;# Replace MYREALM.XYZ.COM with your kerberos Realm. #&lt;BR /&gt;# Replace adsdc.myrealm.xyz.com with your Windows ADS DC full#&lt;BR /&gt;# domain name. #&lt;BR /&gt;# MyREALM and my AD server are the same #&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = MyREALM.COM&lt;BR /&gt;# MTG ADDED 9/11/2006 &lt;BR /&gt;dns_lookup_realm = true&lt;BR /&gt;dns_lookup_kdc = true&lt;BR /&gt;# END ADD&lt;BR /&gt;default_tkt_enctypes = DES-CBC-MD5&lt;BR /&gt;default_tgs_enctypes = DES-CBC-MD5&lt;BR /&gt;ccache_type = 2&lt;BR /&gt;[realms]&lt;BR /&gt;MyREALM.COM = {&lt;BR /&gt;kdc = MY-ADserver.mydomain.com:88&lt;BR /&gt;admin_server = MY-ADserver.mydomain.com&lt;BR /&gt;}&lt;BR /&gt;[domain_realm]&lt;BR /&gt;.COM = MyDomain.COM&lt;BR /&gt;[logging]&lt;BR /&gt;kdc = FILE:/var/log/krb5kdc.log&lt;BR /&gt;admin_server = FILE:/var/log/kadmin.log&lt;BR /&gt;default = FILE:/var/log/krb5lib.log&lt;BR /&gt;&lt;BR /&gt;THIS REGISTERS AND CREATES THE KRB5 KEYTAB FILE ON THE UNIX SERVER-&lt;BR /&gt;# ktutil&lt;BR /&gt;ktutil:  rkt /Dump/AD-Keypass/unixMyUnixserver.keytab&lt;BR /&gt;ktutil:  wkt /etc/krb5.keytab&lt;BR /&gt;ktutil:  quit&lt;BR /&gt;&lt;BR /&gt;NOW USE KLIST TO SEE THAT THE KEY TAB FILE IS REGISTERED -&lt;BR /&gt;# klist -k&lt;BR /&gt;Keytab name: FILE:/etc/krb5.keytab&lt;BR /&gt;KVNO Principal&lt;BR /&gt;---- --------------------------------------------------------------------------&lt;BR /&gt;   3 host/MyUnixServer.MyDomain.com@MyREALM.COM&lt;BR /&gt;&lt;BR /&gt;VALIDATE THE PAM and KERBEROS FILEs WITH THE FOLLOWING COMMAND -&lt;BR /&gt;# pamkrbval -v    --&amp;gt; Re-validate the PAM-KRB setup&lt;BR /&gt; ** LOOK FOR ERRORS OR WARNINGS **&lt;BR /&gt;&lt;BR /&gt; NOW JOIN THE AD ENVIRONMENT -&lt;BR /&gt;# /opt/samba/bin/net ads join -U Intrepid&lt;BR /&gt;       'MyUnixServer' 's password:  %AD0nxrrE1d_0&lt;BR /&gt;&lt;BR /&gt;[2006/09/08 15:04:13, 0] libads/ldap.c:ads_add_machine_acct(1404)&lt;BR /&gt;  ads_add_machine_acct: Host account for MyUnixServer already exists - modifying old account&lt;BR /&gt;Using short domain name -- MyDomain&lt;BR /&gt;Joined 'MyUnixServer' to realm 'MyDomain/MyREALM.COM'&lt;BR /&gt;&lt;BR /&gt;How to Un-Join or LEAVE the AD Server -&lt;BR /&gt;# /opt/samba/bin/net ads leave&lt;BR /&gt;Removed ' MyUnixServer ' from realm 'DVWF.COM'&lt;BR /&gt;&lt;BR /&gt;Stop and start the services.&lt;BR /&gt;I did this through SAMBA/SWAT http://{MyUnixServer}:901&lt;BR /&gt;&lt;BR /&gt;stop smbd, nmbd, and wins&lt;BR /&gt;start smbs, nmbd, and wins&lt;BR /&gt;&lt;BR /&gt;Now Sync up with AD&lt;BR /&gt;# /opt/samba/bin/syncsmbpasswd &lt;BR /&gt;Backing up your /var/opt/samba/private/smbpasswd file to /var/opt/samba/private/smbpasswd.backup&lt;BR /&gt;Adding MyREALM\_dv to smbpasswd file.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I hope that this will help you.  I wish I found something like this when I was searching.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Mike&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Sep 2006 16:25:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839378#M273067</guid>
      <dc:creator>Michael Gildersleeve</dc:creator>
      <dc:date>2006-09-14T16:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839379#M273068</link>
      <description>Hi Michael,&lt;BR /&gt;&lt;BR /&gt;Now THAT is the sort of superb, concise answer to a fairly difficult problem everyone needs.&lt;BR /&gt;&lt;BR /&gt;Well done sir and I hope future threads point to this.&lt;BR /&gt;&lt;BR /&gt;Very nice.</description>
      <pubDate>Fri, 15 Sep 2006 01:51:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839379#M273068</guid>
      <dc:creator>Chris Johnson_11</dc:creator>
      <dc:date>2006-09-15T01:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839380#M273069</link>
      <description>In my last reply I have an incorrect pam.conf file which will cause logins to prompt several times before allowing access.  I have a correction for this and an apology for not noticing this prior to my post.  Sorry to all and here is the correction -&lt;BR /&gt;cat /etc/pam.conf&lt;BR /&gt;# cat pam.conf&lt;BR /&gt;#&lt;BR /&gt;# PAM Configuration&lt;BR /&gt;#&lt;BR /&gt;# Account Management&lt;BR /&gt;#&lt;BR /&gt;dtaction  account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;dtlogin account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;ftp     account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;login   account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;su      account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;OTHER   account  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;#&lt;BR /&gt;# Authentication Management&lt;BR /&gt;#&lt;BR /&gt;dtaction  auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;dtlogin   auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;ftp       auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;# login   auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;su        auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;OTHER     auth  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;# ADDED BY MTG 9/8/06&lt;BR /&gt;login    auth required    /usr/lib/security/libpam_updbe.1&lt;BR /&gt;login    auth sufficient  /usr/lib/security/libpam_krb5.1 forwardable renewable=5d10h&lt;BR /&gt;login    auth required    /usr/lib/security/libpam_unix.1 try_first_pass&lt;BR /&gt;# END ADD&lt;BR /&gt;#&lt;BR /&gt;# Password Management&lt;BR /&gt;#&lt;BR /&gt;dtaction  password  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;dtlogin   password  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;login     password  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;# passwd          password  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;OTHER     password  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;# ADDED BY MTG 9/8/06&lt;BR /&gt;passwd    password  required  /usr/lib/security/libpam_updbe.1&lt;BR /&gt;passwd    password  required  /usr/lib/security/libpam_ntlm.1&lt;BR /&gt;passwd    password  required  /usr/lib/security/libpam_unix.1 try_first_pass&lt;BR /&gt;# END ADD&lt;BR /&gt;#&lt;BR /&gt;# Session Management&lt;BR /&gt;#&lt;BR /&gt;dtaction        session  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;dtlogin         session  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;login           session  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;OTHER           session  required  /usr/lib/security/libpam_unix.1  &lt;BR /&gt;# ADDED BY MTG 9/8/06&lt;BR /&gt;login           session  required  /usr/lib/security/libpam_updbe.1 &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 25 Sep 2006 11:44:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839380#M273069</guid>
      <dc:creator>Michael Gildersleeve</dc:creator>
      <dc:date>2006-09-25T11:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839381#M273070</link>
      <description>Please post smb config file.&lt;BR /&gt;&lt;BR /&gt;To authenticate from the windoze side you must have winbind daemon running.</description>
      <pubDate>Mon, 25 Sep 2006 11:47:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839381#M273070</guid>
      <dc:creator>Nobody's Hero</dc:creator>
      <dc:date>2006-09-25T11:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs authentication question.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839382#M273071</link>
      <description>Sure, here is my smb.conf file -&lt;BR /&gt;# cat opt/samba/smb.conf&lt;BR /&gt;# Samba config file created using SWAT&lt;BR /&gt;# from 10.1.9.5 (10.1.9.5)&lt;BR /&gt;# Date: 2006/09/22 15:06:47&lt;BR /&gt;&lt;BR /&gt;# Global parameters&lt;BR /&gt;[global]&lt;BR /&gt;        workgroup = FLOWER&lt;BR /&gt;        realm = FLOWER.COM&lt;BR /&gt;        server string = MyServerName&lt;BR /&gt;        security = ADS&lt;BR /&gt;        allow trusted domains = No&lt;BR /&gt;        password server = MYADserver *&lt;BR /&gt;        log file = /var/opt/samba/log.%m&lt;BR /&gt;        max log size = 1000&lt;BR /&gt;        announce version = 3.2&lt;BR /&gt;        name resolve order = wins host lmhosts bcast&lt;BR /&gt;        server signing = auto&lt;BR /&gt;        client use spnego = No&lt;BR /&gt;        domain master = No&lt;BR /&gt;        wins server = 10.1.2.34&lt;BR /&gt;        ldap ssl = no&lt;BR /&gt;        idmap uid = 16777216-33554431&lt;BR /&gt;        idmap gid = 16777216-33554431&lt;BR /&gt;        read only = No&lt;BR /&gt;        create mask = 0766&lt;BR /&gt;        directory mask = 0777&lt;BR /&gt;        short preserve case = No&lt;BR /&gt;        dos filetime resolution = Yes&lt;BR /&gt;&lt;BR /&gt;[homes]&lt;BR /&gt;        comment = Home Directories&lt;BR /&gt;        browseable = No&lt;BR /&gt;&lt;BR /&gt;[tmp]&lt;BR /&gt;        path = /tmp&lt;BR /&gt;&lt;BR /&gt;[Dump]&lt;BR /&gt;        path = /Dump&lt;BR /&gt;        guest ok = Yes&lt;BR /&gt;&lt;BR /&gt;[Labels]&lt;BR /&gt;        comment = Label dump&lt;BR /&gt;        path = /Dump/Labels&lt;BR /&gt;        guest ok = Yes&lt;BR /&gt;&lt;BR /&gt;[Code]&lt;BR /&gt;        path = /LANShare/Code&lt;BR /&gt;        write list = MyNTID-here&lt;BR /&gt;        read only = Yes&lt;BR /&gt;        guest ok = Yes&lt;BR /&gt;&lt;BR /&gt;[AppServ]&lt;BR /&gt;        path = /LANShare/Code/appserv&lt;BR /&gt;        guest ok = Yes&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[Import]&lt;BR /&gt;        path = /Dump/Import&lt;BR /&gt;        guest ok = Yes&lt;BR /&gt;&lt;BR /&gt;Hope that this will help you.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Mike</description>
      <pubDate>Mon, 25 Sep 2006 13:54:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-authentication-question/m-p/3839382#M273071</guid>
      <dc:creator>Michael Gildersleeve</dc:creator>
      <dc:date>2006-09-25T13:54:04Z</dc:date>
    </item>
  </channel>
</rss>

