[Samba] Samba LDAP replication weirdness...

2005-03-22 Thread Mccrory, Kevin B
I have the PDC/BDC with a master slave LDAP directory set up and
operating. 

One problem is that I've only been able to get the LDAP Master/Slave
replication working if I use Manager as the binddn for the replication.
I'm using the IDEALX smbldap tools. If I use another user I get a ERROR:
Insufficient access: no write access to entry error and a .rej file is
created. 

Each entry shows modifiersName: cn=Manager,dc=mphqcops,dc=opmg,dc=local
for all the change entries. Isn't this supposed to match the binddn
entry from the slapd.conf file 



Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba-3 By Example correction...

2005-03-21 Thread Mccrory, Kevin B
Chapter 7, Section 7.3 Step 3 needs a correction:

The step has users create an admin-accts.ldif file.

As currently written the userpaddword: not24get should be userPassword
with the P capitalized. Failure to have this causes a replication error:
access denied since the password for updateuser is never loaded. 

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


RE: [Samba] PDC Samba 3+LDAP

2005-03-18 Thread Mccrory, Kevin B
Domain:   ARZUR-NT 
   ^
   | 
There's your problem. Get rid of the - in the domain name. Windows
machines can't handle anything other than alpha-numerics in the Domain
name. 


Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf
Of [EMAIL PROTECTED]
Sent: Friday, March 18, 2005 11:14 AM
To: samba@lists.samba.org
Subject: [Samba] PDC Samba 3+LDAP


Hello all,

I've some problem with my new Samba / Ldap PDC :
I cannot join the Domain from Windows (XP) computers

Okay, all configuration seem to be okay on the serveur, I can create 
Users,Computers for samba (and unix)
I put here some config file, if someone can help me, I'm on since 5 
days, it's my first PDC so I use the tutorial from Idealx
(smbldap-howto)

getent passwd give me local and ldap account (here are the LDAP account)
... Administrateur:x:0:512:Netbios Domain
Administrator:/root:/sbin/nologin
nobody:x:999:514:nobody:/dev/null:/sbin/nologin
bdupuis:x:1005:512:Benjamin
Dupuis:/home/data1/samba/bdupuis:/sbin/nologin
POIL-BAREBONE$:x:1008:515:Computer:/dev/null:/sbin/nologin

POIL-BAREBONE is a computer is it normal smbldap-tools add me a $ to 
computer's name?

pdbedit -Lv give me samba accout (here is just the Administrator):

Unix username:Administrateur
NT username:  Administrateur
Account Flags:[U  ]
User SID: S-1-5-21-3150904180-1303617548-1471141863-1000
Primary Group SID:S-1-5-21-1911238739-97561441-2706018148-512
Full Name:Administrateur
Home Directory:   \\PDC-SMB3\homes\Administrator
HomeDir Drive:X:
Logon Script: logon.bat
Profile Path: \\PDC-SMB3\profiles\Administrator\
Domain:   ARZUR-NT
Account desc:
Workstations:
Munged dial: 
Logon time:   0
Logoff time:  Tue, 19 Jan 2038 04:14:07 GMT
Kickoff time: Tue, 19 Jan 2038 04:14:07 GMT
Password last set:Fri, 18 Mar 2005 16:15:41 GMT
Password can change:  0
Password must change: Sat, 25 Jun 2005 17:15:41 GMT
Last bad password   : 0
Bad password count  : 0
Logon hours : FF
init_sam_from_ldap: Entry found for user: nobody

Now when I try to join the domain From windows XP,
I enter username : bdupuis
password: toto
domain name : ARZUR-NT

computer name : POIL-BAREBONE (I try POIL-BAREBONE$ also)

User name: Administrateur
password: toto
domain name : ARZUR-NT

and I have an error

Log on Samba :
[2005/03/18 17:08:34, 2] lib/smbldap.c:smbldap_open_connection(692)
  smbldap_open_connection: connection opened
[2005/03/18 17:08:34, 2] passdb/pdb_ldap.c:init_sam_from_ldap(518)
  init_sam_from_ldap: Entry found for user: Administrateur [2005/03/18
17:08:34, 2] passdb/pdb_ldap.c:init_group_from_ldap(2057)
  init_group_from_ldap: Entry found for group: 512
[2005/03/18 17:08:34, 2] auth/auth.c:check_ntlm_password(305)
  check_ntlm_password:  authentication for user [Administrateur] - 
[Administrateur] - [Administrateur] succeeded
[2005/03/18 17:08:34, 2] smbd/server.c:exit_server(575)
  Closing connections

Log on LDAP :
Mar 18 17:08:50 mastok slapd[5569]: conn=131 fd=8 ACCEPT from 
IP=127.0.0.1:33002 (IP=0.0.0.0:389)
Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=0 BIND 
dn=cn=samba,ou=DSA,dc=arzur,dc=local method=128
Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=0 BIND 
dn=cn=samba,ou=DSA,dc=ARZUR,dc=LOCAL mech=SIMPLE ssf=0
Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=0 RESULT tag=97 err=0
text= Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=1 SRCH 
base=dc=arzur,dc=local scope=2 deref=0 
filter=((uid=arzur)(objectClass=sambaSamAccount))
Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=1 SRCH attr=uid 
uidNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange 
sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn 
displayName sambaHomeDrive sambaHomePath sambaLogonScript 
sambaProfilePath description sambaUserWorkstations sambaSID 
sambaPrimaryGroupSID sambaLMPassword sambaNTPassword sambaDomainName 
objectClass sambaAcctFlags sambaMungedDial sambaBadPasswordCount 
sambaBadPasswordTime sambaPasswordHistory modifyTimestamp 
sambaLogonHours modifyTimestamp
Mar 18 17:08:50 mastok slapd[5569]: conn=131 op=1 SEARCH RESULT tag=101 
err=0 nentries=0 text=
Mar 18 17:09:00 mastok slapd[5569]: conn=131 fd=8 closed
Mar 18 17:09:01 mastok slapd[5569]: conn=132 fd=8 ACCEPT from 
IP=127.0.0.1:33004 (IP=0.0.0.0:389)
Mar 18 17:09:01 mastok slapd[5569]: conn=132 op=0 BIND 
dn=cn=samba,ou=DSA,dc=arzur,dc=local method=128
Mar 18 17:09:01 mastok slapd[5569]: conn=132 op=0 BIND 
dn=cn=samba,ou=DSA,dc=ARZUR,dc=LOCAL mech=SIMPLE ssf=0
Mar 18 17:09:01 mastok slapd[5569]: conn=132 op=0 RESULT tag=97 

RE: [Samba] PDC Samba 3+LDAP

2005-03-18 Thread Mccrory, Kevin B
I have had issues with joining windows servers to domains that have a -
in the Domain Name. I ran into the same problem when I was creating an
Active Directory Domain and used a - as in opmg-cops.opmg-eds.local.  I
had nothing but problems. Changed the domain name to
opmgcops.opmg-eds.local and it worked fine. 

When building the Samba PDC/BDC to replace AD I again used a -. The
Linux BDC could join the domain but my Windows 2000 and XP machines were
getting rejected. Took the - out and they joined fine. 

My rule of thumb (which I violated this past week) is not to use special
characters in the Windows Domain name. It has caused  me problems in the
past. 

If its working for you, fantastic. My experience has been to the
contrary. If you're just building things, it should be a fairly easy
task to change the name. 

Cheers.



Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: Prakash Velayutham [mailto:[EMAIL PROTECTED] 
Sent: Friday, March 18, 2005 4:11 PM
To: Mccrory, Kevin B
Cc: [EMAIL PROTECTED]; samba@lists.samba.org
Subject: Re: [Samba] PDC Samba 3+LDAP


Hi,

Are you sure about this? Here is my pdbedit -Lv output. Looks like 
Windows does accept '-' in the domain name. My windows clients join the 
domain just fine, and the users do login to the PDC without any hitches.

Unix username:
NT username: 
Account Flags:[U  ]
User SID: S-1-5-21-709429014-924526411-3950163471-15102
Primary Group SID:S-1-5-21-709429014-924526411-3950163471-513
Full Name:X X - Network User
Home Directory:   \\MCPILDAP1\homes\winprofile
HomeDir Drive:Z:
Logon Script: scripts\logon.bat
Profile Path: \\MCPILDAP1\homes\winprofile
Domain:   CMC-NT
Account desc:
Workstations:
Munged dial:
Logon time:   0
Logoff time:  Mon, 18 Jan 2038 22:14:07 GMT
Kickoff time: Mon, 18 Jan 2038 22:14:07 GMT
Password last set:Tue, 08 Mar 2005 17:05:12 GMT
Password can change:  Tue, 08 Mar 2005 17:05:12 GMT
Password must change: Mon, 18 Jan 2038 22:14:07 GMT
Last bad password   : 0
Bad password count  : 0
Logon hours : FF

Prakash

Mccrory, Kevin B wrote:

Domain:   ARZUR-NT 
   ^
   |
There's your problem. Get rid of the - in the domain name. Windows
machines can't handle anything other than alpha-numerics in the Domain
name. 


Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf 
Of [EMAIL PROTECTED]
Sent: Friday, March 18, 2005 11:14 AM
To: samba@lists.samba.org
Subject: [Samba] PDC Samba 3+LDAP


Hello all,

I've some problem with my new Samba / Ldap PDC :
I cannot join the Domain from Windows (XP) computers

Okay, all configuration seem to be okay on the serveur, I can create
Users,Computers for samba (and unix)
I put here some config file, if someone can help me, I'm on since 5 
days, it's my first PDC so I use the tutorial from Idealx
(smbldap-howto)

getent passwd give me local and ldap account (here are the LDAP 
account) ... Administrateur:x:0:512:Netbios Domain 
Administrator:/root:/sbin/nologin
nobody:x:999:514:nobody:/dev/null:/sbin/nologin
bdupuis:x:1005:512:Benjamin 
Dupuis:/home/data1/samba/bdupuis:/sbin/nologin
POIL-BAREBONE$:x:1008:515:Computer:/dev/null:/sbin/nologin

POIL-BAREBONE is a computer is it normal smbldap-tools add me a $ to
computer's name?

pdbedit -Lv give me samba accout (here is just the Administrator):

Unix username:Administrateur
NT username:  Administrateur
Account Flags:[U  ]
User SID: S-1-5-21-3150904180-1303617548-1471141863-1000
Primary Group SID:S-1-5-21-1911238739-97561441-2706018148-512
Full Name:Administrateur
Home Directory:   \\PDC-SMB3\homes\Administrator
HomeDir Drive:X:
Logon Script: logon.bat
Profile Path: \\PDC-SMB3\profiles\Administrator\
Domain:   ARZUR-NT
Account desc:
Workstations:
Munged dial: 
Logon time:   0
Logoff time:  Tue, 19 Jan 2038 04:14:07 GMT
Kickoff time: Tue, 19 Jan 2038 04:14:07 GMT
Password last set:Fri, 18 Mar 2005 16:15:41 GMT
Password can change:  0
Password must change: Sat, 25 Jun 2005 17:15:41 GMT
Last bad password   : 0
Bad password count  : 0
Logon hours : FF
init_sam_from_ldap: Entry found for user: nobody

Now when I try to join the domain From windows XP,
I enter username : bdupuis
password: toto
domain

RE: [Samba] Problem joining a Samba 3 domain - DC can't be contac ted

2005-03-16 Thread Mccrory, Kevin B
Change the domain name to sambadomain. Having the - in the name prevents the
windows machines from joining. I ran into the same problem here. 

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: fatima riadi [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, March 16, 2005 12:28 PM
To: Mccrory, Kevin B; samba@lists.samba.org
Subject: RE: [Samba] Problem joining a Samba 3 domain - DC can't be contac
ted


My domain name is SAMBA-DOMAIN, I can't join it from a
win 2003 machine. Now, if I try to join it from a XP
machine, I am asked to enter a username and password
for a user allowed to join the domain, however, the
info I enter is not accepted!!!

Any idea please?

Thank you

Note: to manage joining my samba domain from a xp
machine, I had to change a registry key.

--- Mccrory, Kevin B [EMAIL PROTECTED] wrote:
 What is your domain name? If you have special
 characters in the domain name
 the workstations won't join properly. The domain
 name should be all one
 word.
 
 Kevin B. McCrory
 Network Engineer - COPS
 US Government Solutions
 13600 EDS Drive
 Mail stop:  A4S-B21
 Herndon, VA 20171
 * phone: +01-703-733-3255
 * mailto:[EMAIL PROTECTED]
 * AKO mailto:[EMAIL PROTECTED]
 
 
 
 -Original Message-
 From:
 [EMAIL PROTECTED]

[mailto:[EMAIL PROTECTED]
 On Behalf Of
 fatima riadi
 Sent: Wednesday, March 16, 2005 11:59 AM
 To: samba@lists.samba.org
 Subject: [Samba] Problem joining a Samba 3 domain -
 DC can't be contacted
 
 
 Dear all,
 
 I configured samba 3.0.11 as PDC with openLDAP.
 
 Wehen I try to join my samba domain from a windows
 machine (XP or 2003) I get this error message a
 domain controller for the domain my_samba_domain
 could not be contacted.
 
 Do have any idea of what is hapening?
 
 Just for reference: I do not have a dns server.
 
 Regards.
 
 
   
 
   
   
 Découvrez nos promotions exclusives destination de
 la Tunisie, du Maroc,
 des Baléares et la Rép. Dominicaine sur Yahoo!
 Voyages :
 http://fr.travel.yahoo.com/promotions/mar14.html
 --
 To unsubscribe from this list go to the following
 URL and read the
 instructions: 
 https://lists.samba.org/mailman/listinfo/samba
 






Découvrez nos promotions exclusives destination de la Tunisie, du Maroc,
des Baléares et la Rép. Dominicaine sur Yahoo! Voyages :
http://fr.travel.yahoo.com/promotions/mar14.html
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


RE: [Samba] W2K Server and Workstation can't join SMB/LDAP domain

2005-03-15 Thread Mccrory, Kevin B
I found the error. MS Windows Domain names can't have special characters in
them. I forgot about that little wrinkle. Changed Domain
mphq-cops.opmg.local to mphqcops.opmg.local and everything is working fine.

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
Mccrory, Kevin B
Sent: Monday, March 14, 2005 6:02 PM
To: samba@lists.samba.org
Subject: [Samba] W2K Server and Workstation can't join SMB/LDAP domain


I have a SMB Domain set up with a PDC and BDC. The BDC is joined to the PDC
domain fine and shows up in the LDAP directory. 
I can add and delete users to the LDAP directory. I can use the user
accounts to access the Linux boxes. My W2K boxes see the domain and domain
servers when browsing. I can access the shared drive on the PDC.

I cannot join the Windows servers to the domain. I get an error that the
domain mphq-cops can't be located. I've run an nbtstat that shows the domain
name listed and its resolving to the correct IP address. In fact I turned
off the BDC for a while so that there would only be one DC in the mix in
case my config was wrong.  The W2K machines showed the domain with the PDC
IP address. When I turned the BDC back on nbstat showed the domain name
resolving to the BDC ip address which is what I would expect would happen.

I've tried adding the workstation accounts manually using smbldap-useradd -w
. The machine name correctly appears when I do a ldapsearch -x -b however
using getent group does not show the machine names in the Domain Computers
group. Is this normal?

I've checked and rechecked the Administrator account and made sure the
password is correct for the account. 

Not sure where to go from here... Some pointers on what to look at would be
greatly appreciated...

Thanks

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Changing SMB Administrator account name

2005-03-14 Thread Mccrory, Kevin B
How do you change the Administrator account name for Samba/LDAP? On all of
our Windows machines we change the default Administrator account name to
something else. I want to do that for the Samba/LDAP PDC so that all the
machines are in sync. 

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] W2K Server and Workstation can't join SMB/LDAP domain

2005-03-14 Thread Mccrory, Kevin B
I have a SMB Domain set up with a PDC and BDC. The BDC is joined to the PDC
domain fine and shows up in the LDAP directory. 
I can add and delete users to the LDAP directory. I can use the user
accounts to access the Linux boxes. My W2K boxes see the domain and domain
servers when browsing. I can access the shared drive on the PDC.

I cannot join the Windows servers to the domain. I get an error that the
domain mphq-cops can't be located. I've run an nbtstat that shows the domain
name listed and its resolving to the correct IP address. In fact I turned
off the BDC for a while so that there would only be one DC in the mix in
case my config was wrong.  The W2K machines showed the domain with the PDC
IP address. When I turned the BDC back on nbstat showed the domain name
resolving to the BDC ip address which is what I would expect would happen.

I've tried adding the workstation accounts manually using smbldap-useradd -w
. The machine name correctly appears when I do a ldapsearch -x -b however
using getent group does not show the machine names in the Domain Computers
group. Is this normal?

I've checked and rechecked the Administrator account and made sure the
password is correct for the account. 

Not sure where to go from here... Some pointers on what to look at would be
greatly appreciated...

Thanks

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] LDAP items that might help for How-to

2005-03-10 Thread Mccrory, Kevin B
Might want to include the following command in LDAP config incase LDAP
doesn't start.

slapd -u ldap -g ldap -d -1

This command pointed out that I hadn't copied my samba.schema to the
/etc/openldap/schema directory. Might want to put that in the doc before you
start LDAP. A newbie like me might pass over that little detail while
following the instructions...

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Chapter 6: Making Users Happy...

2005-03-09 Thread Mccrory, Kevin B
Not sure if this is the place to post this butI'm just going through the
process of installing Samba and LDAP using the current version of Chapter 6:
Making Users Happy
(http://us4.samba.org/samba/docs/man/Samba-Guide/happy.html#id2557011
http://us4.samba.org/samba/docs/man/Samba-Guide/happy.html#id2557011 )

I found one error in the Install and Configure Idealx smbldap-tools
Scripts...Item 4. Should read Change to the /etc/smbldap-tools/ directory,
then edit the /etc/smbldap-tools/smbldap_conf.pm instead of CHange to the
/opt/IDEALX/sbin/ directory then edit the /opt/IDEALX/sbin/smbldap_conf.pm
.





Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Samba as PDC and BDC on the same network.

2005-03-02 Thread Mccrory, Kevin B
This is the way it should be working. The BDC handles authentication
requests for the domain unless it becomes overloaded at which time the PDC
steps in to take over. 
Refer to Chapter 4 section 4.2 of the Official Samba-3 HOWTO and Reference
Guide that explains Domain Control.

Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED]
* AKO mailto:[EMAIL PROTECTED]



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
Clement DIEBOLD
Sent: Wednesday, March 02, 2005 8:14 AM
To: samba@lists.samba.org
Subject: [Samba] Samba as PDC and BDC on the same network.


I have recently configured two servers to be controlers of my domain. The
first one is the PDC and is configured like :
   domain master = yes
   prefered master = yes
   local master = yes
   domain logons = yes
   security = user
   os level = 99

And the second, the BDC like :
   domain master = no
   prefered master = no
   local master = no
   domain logons = yes
   security = user
   password server = PDC BDC
   os level = 40

When the two servers are started, i see in the logs :
DOMAIN(1) current master browser = PDC
BDC 40009a03 (BDC)
PDC 400c9b0b (PDC)

but my clients (windows 2000 and XP) are authenticated by the BDC.

I don't unterstand why it's working like this !! The PDC becomes the 
master if I set the domain logons option to no.

Thanks.

-- 
Clément DIEBOLD
Service Informatique
LMARC Université de Franche-Comté
24, chemin de l'Epitaphe
25000 Besançon
Tel : 03 81 66 60 53
Fax : 03 81 66 67 00
--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Simple PDC/BDC with LDAP config

2005-02-25 Thread Mccrory, Kevin B
I want to be able to use Samba to manage a Windows cluster account for
failing over two Windows clusters. 

This is a small system, 8 web servers with two DB clusters along with a
couple of other servers handling backup and management functions. I run DNS
services on the firewall for the internal machines.  The AD DNS is only for
the clusters. All the machines are Domain members for single Sign on but
this is a nice to have. The developers don't even use it to access the web
pages. I have an Windows 2003 AD set up but the issue is that the
implementation didn't go right so replication isn't working. Its also
massive overkill for what I need. I want to simplify the whole mess.

The PDC/BDC configuration is to ensure that the cluster always has the
ability to access the domain account for failover along with a minimum of 4
DB servers configured in two clusters.  

All of the docs go into configurations that support many users, logon
profiles, shared drives off the server, etc. 
I plan on using LDAP to provide replication of machine accounts and the
Cluster Account between the two DCs.  
Can I bypass using DNS and just use /etc/hosts with all other requests going
to the firewall DNS? 
My question is what is the minimum that I need to have to support the Domain
Cluster login account? 







Kevin B. McCrory
Network Engineer - COPS
US Government Solutions
13600 EDS Drive
Mail stop:  A4S-B21
Herndon, VA 20171
* phone: +01-703-733-3255
* mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 
* AKO mailto:[EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba