- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Samba 3.X Domain Member (old Style) - How to Perio...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-31-2008 05:24 AM
тАО03-31-2008 05:24 AM
My Samba 3.X services on HP-UX 11.11 are domain members (SECURITY = DOMAIN, old style, joined via "net rpc oldjoin"). Our Windows Domain Admins aer asking if there is a way for these Samba nodes to periodically "reset" their "machine accounts" on the domain. It seems our domain has a policy for a "machine account" to expire/get-flagged after 90 days.
Thanks!
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-31-2008 06:32 AM
тАО03-31-2008 06:32 AM
Re: Samba 3.X Domain Member (old Style) - How to Periodically refresh Machine Account?
The Windows Domain administrators should handle the reset themselves. The machine accounts reside in the windows domain and that is what they are talking about
They need to let you know, because if you have the same accounts on HP-UX and are mapping the id's your systems could be thrown out of the domain by the windows admins doing their reset.
This is particularly fun with Kerberos, where the kinit command will suddenly fail if the windows machine account for the system is updated.
Strictly speaking machine accounts are not needed on the Unix side. They are created by the net join when the Unix system joins the domain.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-31-2008 09:05 AM
тАО03-31-2008 09:05 AM
Solution- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-31-2008 09:11 AM
тАО03-31-2008 09:11 AM
Re: Samba 3.X Domain Member (old Style) - How to Periodically refresh Machine Account?
Thanks.. I was just actually about to mention that the "net" man pages do mention that option. There is also however a "CHANGESECRETPW":
CHANGESECRETPW
This command allows the Samba machine account password to be set from
an external application to a machine account password that has already
been stored in Active Directory. DO NOT USE this command unless you
know exactly what you are doing. The use of this command requires that
the force flag (-f) be used also. There will be NO command prompt.
Whatever information is piped into stdin, either by typing at the com-
mand line or otherwise, will be stored as the literal machine pass-
word. Do NOT use this without care and attention as it will overwrite
a legitimate machine password without warning. YOU HAVE BEEN WARNED.
Can I actually script this "NET RPC CHANGETRUSTPW" thingy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-31-2008 09:51 AM
тАО03-31-2008 09:51 AM