- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Samba (CIFS) and winbind in ADS
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 07:08 AM
10-31-2005 07:08 AM
Samba (CIFS) and winbind in ADS
Here is my smb.conf:
# Global parameters
[global]
workgroup = HDQ
realm = HDQ.USS.COM
netbios name = DEV12
server string = Samba Server
security = ADS
syslog = 0
log file = /var/opt/samba/log.%m
max log size = 1000
wins server = 170.191.250.20
ldap ssl = no
idmap uid = 15000-15005
idmap gid = 15000-15005
winbind enum users = No
winbind enum groups = No
read only = No
short preserve case = No
dos filetime resolution = Yes
I have /etc/nsswitch.conf setup to use winbind:
passwd: files winbind
group: files winbind
Not sure what else I may have missed. Does CIFS know to look for libnss_winbind.so in /opt/samba/lib, or do I need to create a link to it somewhere?
Any ideas of things to check would be greatly appreciated.
Thanks in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 07:11 AM
10-31-2005 07:11 AM
Re: Samba (CIFS) and winbind in ADS
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=949365
It might help you out on the steps.
Rgds...Geoff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 07:13 AM
10-31-2005 07:13 AM
Re: Samba (CIFS) and winbind in ADS
Kerberos version? Widows 2003 server needs a patch to authenticate client versions below version 5.
\
http://www.interopsystems.com/tools/forum/fb.aspx?go=prev&m=7071&viewType=tm
http://us2.samba.org/samba/ftp/slides/ad-integration.pdf
http://docs.hp.com/en/B8725-90062/ch01s02.html
Hope these help.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 08:23 AM
10-31-2005 08:23 AM
Re: Samba (CIFS) and winbind in ADS
I know this sounds ...... simplistic, but did you start winbind? If yes, then check the winbind log file: /var/opt/samba/log.winbind
Also, if you are unsure about Kerberos, email me and I can provide you with a Kerberos setup and troubleshooting whitepaper that I wrote. But it's 54Mb (!! - lots of screenshots).
eric.roseme@hp.com.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-01-2005 01:40 AM
11-01-2005 01:40 AM
Re: Samba (CIFS) and winbind in ADS
#swlist | grep LDAP
J4269AA B.03.30.02 LDAP-UX Integration
#swlist | grep CIFS
B8725AA A.02.01.02 HP CIFS Server
I don't have the full client version of Kerberos installed. Just the config files and binaries that were installed with the OS. Do I need to install all of the Kerberos libraries?
Thanks for all of the suggestions. I can try them now that the Windows admin is back.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-01-2005 02:20 AM
11-01-2005 02:20 AM
Re: Samba (CIFS) and winbind in ADS
# swlist |grep -i ker
KRB5CLIENT C.1.3.5.01 Kerberos V5 Client Version 1.3.5.01
Like I said above - just follow my steps in my last post in this thread:
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=949365
Rgds...Geoff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 01:28 AM
11-02-2005 01:28 AM
Re: Samba (CIFS) and winbind in ADS
#/opt/samba/bin/wbinfo --domain HDQ -u
WINBIND_LOOKUPNAME failed for user(HDQ\LORAIN$)
WINBIND_LOOKUPNAME failed for user(HDQ\NATIONALSTEEL$)
WINBIND_LOOKUPNAME failed for user(HDQ\DAS2018)
Any ideas?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 02:09 AM
11-02-2005 02:09 AM
Re: Samba (CIFS) and winbind in ADS
Rgds...Geoff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 02:24 AM
11-02-2005 02:24 AM
Re: Samba (CIFS) and winbind in ADS
Here is the output in a log in /var/opt/samba, the log is my PC name:
#tail -10 log.psc-l601319
[2005/11/02 10:19:29, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
Failed to verify incoming ticket!
[2005/11/02 10:19:50, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
Failed to verify incoming ticket!
[2005/11/02 10:19:50, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
Failed to verify incoming ticket!
[2005/11/02 10:19:55, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
Failed to verify incoming ticket!
[2005/11/02 10:19:55, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
Failed to verify incoming ticket!
Here is the smb.conf with the share:
# Global parameters
[global]
workgroup = HDQ
realm = HDQ.USS.COM
netbios name = DEV12
server string = Samba Server
security = ADS
syslog = 0
log file = /var/opt/samba/log.%m
max log size = 1000
wins server = 170.191.250.20
ldap ssl = no
idmap uid = 15000-15005
idmap gid = 15000-15005
winbind enum users = No
winbind enum groups = No
read only = No
short preserve case = No
dos filetime resolution = Yes
[homes]
comment = Home Directories
browseable = No
[tmp]
comment = Temporary file space
path = /tmp
[drsdev]
comment = Development DRS Share
path = /drsdev
valid users = HDQ\phi8254, HDQ\wj109t2
I am trying to come in as HDQ\wj109t2. It just keeps prompting for the ID and password over and over.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 03:03 AM
11-02-2005 03:03 AM
Re: Samba (CIFS) and winbind in ADS
ads_secrets_verify_ticket: enc type [3] decrypted message !
[3] is MD5. If you are not getting that, then your config is wrong, and the bad-password popup is the symptom. I have just about every known config problem in the whitepaper I mentioned above.
Eric Roseme
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 05:05 AM
11-02-2005 05:05 AM
Re: Samba (CIFS) and winbind in ADS
Is there somewhere that I can download the white paper or can you just email it to me?
I would like to take a look through it to see if kerberos is the problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-02-2005 07:59 AM
11-02-2005 07:59 AM