<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenVMS CIFS 1.1 problem in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289873#M57094</link>
    <description>Did you report this to HP?&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 20 Oct 2008 08:31:40 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2008-10-20T08:31:40Z</dc:date>
    <item>
      <title>OpenVMS CIFS 1.1 problem</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289872#M57093</link>
      <description>Everyone,&lt;BR /&gt;&lt;BR /&gt;I installed CIFS for OpenVMS 1.1 on an AlphaServer ES40 runing OpenVMS V8.3 (with the latest OS Patches and CRTL Updates as of October 10, 2008) with TCP/IP Service for OpenVMS V5.6 ECO2. In an attempt to configure CIFS I performed the following steps:&lt;BR /&gt;&lt;BR /&gt;1.) Using the AUTHORIZE Utility, copy the System Manager account to a new CIFS Administration&lt;BR /&gt;   account, create the OpenvMS resource identifiers corresponding to the Windows predefined&lt;BR /&gt;   Local and Domain groups (Administrators [L], Domain Admins, Domain Users, Domain Guests) and copy the SAMBA$TMPLT&lt;BR /&gt;   account to a new machine account corresponding to the the domain controller:&lt;BR /&gt;   &lt;BR /&gt;   $ SET DEFAULT SYS$SYSTEM:&lt;BR /&gt;   $ RUN AUTHORIZE&lt;BR /&gt;   UAF&amp;gt; COPY /FLAGS=(NODISUSER,PWDMIX)/DEVICE=SAMBA$ROOT:/DIRECTORY=[BIN]/LGICMD=SAMBA$DEFINE_COMMANDS.COM/UIC=[1,0]/PASSWORD="CIFSTest" SYSTEM CIFSADMIN&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$ADMINISTRATORS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$USERS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$GUESTS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$POWER_USERS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$ACCOUNT_OPERATORS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$SERVER_OPERATORS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$PRINT_OPERATORS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$BACKUP_OPERATORS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$DOMAIN_ADMINS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$DOMAIN_USERS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$DOMAIN_GUESTS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$DOMAIN_COMPUTERS&lt;BR /&gt;   UAF&amp;gt; ADD/IDENTIFIER/ATTRIBUTE=RESOURCE CIFS$DOMAIN_CONTROLLERS&lt;BR /&gt;   UAF&amp;gt; GRANT/IDENTIFIER CIFS$ADMINISTRATORS CIFSADMIN&lt;BR /&gt;   UAF&amp;gt; COPY/FLAGS=DISUSER/UIC=[360,100]/PASSWORD=srvr1/nopwdlifetime SAMBA$TMPLT &lt;PDC-NETBIOS-NAME&gt;$&lt;BR /&gt;   UAF&amp;gt; EXIT&lt;BR /&gt;&lt;BR /&gt;2.) Add the following to the global section of the SAMBA$ROOT:[LIB]SMB.CONF file:&lt;BR /&gt;&lt;BR /&gt;   workgroup = &lt;YOUR domain="" name=""&gt;&lt;BR /&gt;   username map = /samba$root/lib/username.map&lt;BR /&gt;   admin users = cifsadmin&lt;BR /&gt;   domain logons = Yes&lt;BR /&gt;   os level = 65&lt;BR /&gt;   preferred master = Yes&lt;BR /&gt;   domain master = Yes&lt;BR /&gt;   &lt;BR /&gt;3.) Add the username mapping entry for the Windows Domain Administrator account name to the &lt;BR /&gt;   SAMBA$ROOT:[LIB]username.map file:&lt;BR /&gt;   &lt;BR /&gt;   CIFSADMIN= &lt;YOUR domain="" name=""&gt;\Administrator&lt;BR /&gt;&lt;BR /&gt;4.) Start CIFS:&lt;BR /&gt;&lt;BR /&gt;   $ @SYS$STARTUP:SAMBA$STARTUP.COM&lt;BR /&gt;&lt;BR /&gt;5.) Define the local CIFS Administrator account to the CIFS user database:&lt;BR /&gt;&lt;BR /&gt;   $ @SAMBA$ROOT:[BIN]SAMBA$DEFINE_COMMANDS.COM&lt;BR /&gt;   $!&lt;BR /&gt;   $! Create the host's CIFS Administration account in the&lt;BR /&gt;   $! CIFS Authentication database.&lt;BR /&gt;   $!&lt;BR /&gt;   $ PDBEDIT "-v" "-d0" "-a" CIFSADMIN "-U" 500&lt;BR /&gt;   new password:CIFSAdmin&lt;BR /&gt;   retype new password:CIFSAdmin&lt;BR /&gt;                       VMS  username:        cifsadmin&lt;BR /&gt;   NT username:&lt;BR /&gt;   Account Flags:        [U          ]&lt;BR /&gt;   User SID:             S-1-5-21-3047386565-4175223335-2173056391-500&lt;BR /&gt;   Primary Group SID:    S-1-5-21-3047386565-4175223335-2173056391-513&lt;BR /&gt;   Full Name:&lt;BR /&gt;   Home Directory:       \\srvr1\cifsadmin&lt;BR /&gt;   HomeDir Drive:&lt;BR /&gt;   Logon Script:&lt;BR /&gt;   Profile Path:         \\srvr1\cifsadmin\profile&lt;BR /&gt;   Domain:               ROBERTSON&lt;BR /&gt;   Account desc:&lt;BR /&gt;   Workstations:&lt;BR /&gt;   Munged dial:&lt;BR /&gt;   Logon time:           0&lt;BR /&gt;   Logoff time:          Sun, 07 Feb 2106 01:28:15 EST&lt;BR /&gt;   Kickoff time:         Sun, 07 Feb 2106 01:28:15 EST&lt;BR /&gt;   Password last set:    Wed, 09 Jul 2008 10:49:12 EDT&lt;BR /&gt;   Password can change:  Wed, 09 Jul 2008 10:49:12 EDT&lt;BR /&gt;   Password must change: Sun, 07 Feb 2106 01:28:15 EST&lt;BR /&gt;   Last bad password   : 0&lt;BR /&gt;   Bad password count  : 0&lt;BR /&gt;   Logon hours         : FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF&lt;BR /&gt;&lt;BR /&gt;6.) Add the Windows predefined Local and Domain groups corresponding to following&lt;BR /&gt;   Well Known SID group mappings and add the CIFS administration account to the Local&lt;BR /&gt;   Administrators group:&lt;BR /&gt;   &lt;BR /&gt;   Group Type        Windows Group Name         Windows Well Known SID&lt;BR /&gt;   ----------        ------------------         -----------------------&lt;BR /&gt;     Local           Administrators             S-1-5-32-544&lt;BR /&gt;     Local           Users                      S-1-5-32-545&lt;BR /&gt;     Local           Guests                     S-1-5-32-546&lt;BR /&gt;     Local           Power Users                S-1-5-32-547&lt;BR /&gt;     Local           Account Operators          S-1-5-32-548&lt;BR /&gt;     Local           Server Operators           S-1-5-32-549&lt;BR /&gt;     Local           Print Operators            S-1-5-32-550&lt;BR /&gt;     Local           Backup Operators           S-1-5-32-551&lt;BR /&gt;     Domain          Domain Admins              S-1-5-&lt;DOMAIN id=""&gt;-512&lt;BR /&gt;     Domain          Domain Users               S-1-5-&lt;DOMAIN id=""&gt;-513&lt;BR /&gt;     Domain          Domain Guests              S-1-5-&lt;DOMAIN id=""&gt;-514&lt;BR /&gt;     Domain          Domain Computers           S-1-5-&lt;DOMAIN id=""&gt;-515&lt;BR /&gt;     Domain          Domain Controllers         S-1-5-&lt;DOMAIN id=""&gt;-516&lt;BR /&gt;&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-544 TYPE=L NTGROUP="Administrators" UNIXGROUP=CIFS$ADMINISTRATORS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-545 TYPE=L NTGROUP="Users" UNIXGROUP=CIFS$USERS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-546 TYPE=L NTGROUP="Guests" UNIXGROUP=CIFS$GUESTS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-547 TYPE=L NTGROUP="Power Users" UNIXGROUP=CIFS$POWER_USERS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-548 TYPE=L NTGROUP="Account Operators" UNIXGROUP=CIFS$ACCOUNT_OPERATORS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-549 TYPE=L NTGROUP="Server Operators" UNIXGROUP=CIFS$SERVER_OPERATORS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-550 TYPE=L NTGROUP="Print Operators" UNIXGROUP=CIFS$PRINT_OPERATORS&lt;BR /&gt;   $ NET GROUPMAP ADD SID=S-1-5-32-551 TYPE=L NTGROUP="Backup Operators" UNIXGROUP=CIFS$BACKUP_OPERATORS&lt;BR /&gt;   $ NET GROUPMAP ADD RID=512 TYPE=D NTGROUP="Domain Admins" UNIXGROUP=CIFS$DOMAIN_ADMINS&lt;BR /&gt;   $ NET RPC RIGHTS GRANT "&lt;DOMAIN-NAME&gt;\Domain Admins" "SeMachineAccountPrivilege" "SeTakeOwnershipPrivilege" "SeBackupPrivilege" "SeRestorePrivilege" "SeRemoteShutdownPrivilege" "SePrintOperatorPrivilege" "SeAddUsersPrivilege" "SeDiskOperatorPrivilege" "-U" "cifsadmin%CIFSAdmin"&lt;BR /&gt;   $ NET RPC RIGHTS GRANT "Domain Admins" "SeMachineAccountPrivilege" "SeTakeOwnershipPrivilege" "SeBackupPrivilege" "SeRestorePrivilege" "SeRemoteShutdownPrivilege" "SePrintOperatorPrivilege" "SeAddUsersPrivilege" "SeDiskOperatorPrivilege" "-U" "cifsadmin%CIFSAdmin"&lt;BR /&gt;   $ NET GROUPMAP ADD RID=513 TYPE=D NTGROUP="Domain Users" UNIXGROUP=CIFS$DOMAIN_USERS&lt;BR /&gt;   $ NET GROUPMAP ADD RID=514 TYPE=D NTGROUP="Domain Guests" UNIXGROUP=CIFS$DOMAIN_GUESTS&lt;BR /&gt;   $ NET GROUPMAP ADD RID=515 TYPE=D NTGROUP="Domain Computers" UNIXGROUP=CIFS$DOMAIN_COMPUTERS&lt;BR /&gt;   $ NET GROUPMAP ADD RID=516 TYPE=D NTGROUP="Domain Controllers" UNIXGROUP=CIFS$DOMAIN_CONTROLLERS&lt;BR /&gt;   $ NET RPC GROUP ADDMEM "Administrators" "cifsadmin" "-U" "cifsadmin%CIFSAdmin"&lt;BR /&gt;&lt;BR /&gt;7.) Create the Domain controller's own machine trust account and Add &lt;BR /&gt;   the Domain controller to its own domain and record the Domain SID:&lt;BR /&gt;&lt;BR /&gt;   $ PDBEDIT "-a" "-m" "-u" &lt;PDC-NETBIOS-NAME&gt;&lt;BR /&gt;   $ NET RPC JOIN PDC "-S" &lt;PDC-NETBIOS-NAME&gt; "-U" "cifsadmin%CIFSAdmin"&lt;BR /&gt;   $ DEFINE SYS$OUTPUT SAMBA$ROOT:[LIB]ROBERTSON_DOMAIN_SID.TXT&lt;BR /&gt;   $ NET GETLOCALSID&lt;BR /&gt;   $ DEASSIGN SYS$OUTPUT&lt;BR /&gt;&lt;BR /&gt;8.) Initialize the required members for the well known groups:&lt;BR /&gt;   $ net rpc group addmem "Administrators" "Domain Admins" "-U" "cifsadmin%CIFSTest"&lt;BR /&gt;   $ net rpc group addmem "Users" "Domain Users" "-U" "cifsadmin%CIFSTest"&lt;BR /&gt;   $ net rpc group addmem "Domain Users" "cifsadmin" "-U" "cifsadmin%CIFSTest"&lt;BR /&gt;   &lt;BR /&gt;&lt;BR /&gt;All of this proceeded without incident until the very last item where I attempted to add the cifsadmin user to the Domain group "Domain Users" where the following message was returned:&lt;BR /&gt;&lt;BR /&gt;Could not add cifsadmin to Domain Users: NT_STATUS_ACCESS_DENIED&lt;BR /&gt;&lt;BR /&gt;After a little experimentation, it became apparent that attempting to modify the memberships of any of the created Domain groups resulted in this same message. Does anybody have any wisdom on what the problem might be? From the Documentation I read on the SAMBA web site this should work.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for any assistance.&lt;BR /&gt;&lt;BR /&gt;Eric&lt;/PDC-NETBIOS-NAME&gt;&lt;/PDC-NETBIOS-NAME&gt;&lt;/DOMAIN-NAME&gt;&lt;/DOMAIN&gt;&lt;/DOMAIN&gt;&lt;/DOMAIN&gt;&lt;/DOMAIN&gt;&lt;/DOMAIN&gt;&lt;/YOUR&gt;&lt;/YOUR&gt;&lt;/PDC-NETBIOS-NAME&gt;</description>
      <pubDate>Sun, 19 Oct 2008 14:17:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289872#M57093</guid>
      <dc:creator>Eric W. Robertson</dc:creator>
      <dc:date>2008-10-19T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVMS CIFS 1.1 problem</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289873#M57094</link>
      <description>Did you report this to HP?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Oct 2008 08:31:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289873#M57094</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2008-10-20T08:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVMS CIFS 1.1 problem</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289874#M57095</link>
      <description>&amp;gt; Did you report this to HP?&lt;BR /&gt;&lt;BR /&gt;That's not an option for a number of people.&lt;BR /&gt;&lt;BR /&gt;In spite of having update support, HP aren't interested in hearing about any problems we experience.&lt;BR /&gt;&lt;BR /&gt;Whilst I'm not expecting my problems fixed for free, I find this disappointing.</description>
      <pubDate>Mon, 20 Oct 2008 08:39:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289874#M57095</guid>
      <dc:creator>Mark Iline</dc:creator>
      <dc:date>2008-10-20T08:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVMS CIFS 1.1 problem</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289875#M57096</link>
      <description>Fill in the form at &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/network/fb_cifs.html" target="_blank"&gt;http://h71000.www7.hp.com/network/fb_cifs.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Oct 2008 09:15:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289875#M57096</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2008-10-20T09:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVMS CIFS 1.1 problem</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289876#M57097</link>
      <description>FYI :-&lt;BR /&gt;&lt;BR /&gt;DELTA_ROB$$ @SAMBA$DEFINE_COMMANDS.COM&lt;BR /&gt;DELTA_ROB$$ addshare&lt;BR /&gt;%DCL-W-ACTIMAGE, error activating image SAMBA$ROOT:[BIN.ALPHA]SAMBA$ADDSHARE.EXE;&lt;BR /&gt;-CLI-E-IMAGEFNF, image file not found $1$DGA150:[SYS0.SYSCOMMON.SAMBA.][BIN.ALPHA]SAMBA$ADDSHARE.EXE;&lt;BR /&gt;DELTA_ROB$$ &lt;BR /&gt;</description>
      <pubDate>Tue, 21 Oct 2008 09:00:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/openvms-cifs-1-1-problem/m-p/4289876#M57097</guid>
      <dc:creator>Robert Atkinson</dc:creator>
      <dc:date>2008-10-21T09:00:17Z</dc:date>
    </item>
  </channel>
</rss>

