[Samba] Problems with SAMBA as PDC and Windows XP SP2 as client

2007-06-20 Thread Personal Técnico

Hi!!

We are trying to configure a Debian Linux Server as Samba Server (Domain 
Controller) and a Windows XP (with Service Pack 2) as client. We have 
configured Windows into the Samba Domain (in other words, we have been 
able to agregate the machine into the domain), but when we restart 
Windows and try to login with a samba user (from linux server) 
(selecting the Domain), we received a message telling us that the domain 
is blocked or not available.


We send you our smb.conf file. Linux Samba Server is running in a Debian 
Etch, with version 3.0.24-6etch4


Thanks for you help!!
[global]
dos charset = CP850
unix charset = UTF-8
display charset = LOCALE
workgroup = DOMAIN_NAME
realm = 
netbios name = MACHINE_NAME
netbios aliases = 
netbios scope = 
server string = %h server
interfaces = eth1
bind interfaces only = Yes
security = USER
auth methods = 
encrypt passwords = Yes
update encrypted = No
client schannel = Auto
server schannel = Auto
allow trusted domains = Yes
map to guest = Never
null passwords = No
obey pam restrictions = Yes
password server = *
smb passwd file = /etc/samba/smbpasswd
private dir = /etc/samba
passdb backend = smbpasswd:/etc/samba/smbpasswd
algorithmic rid base = 1000
root directory = 
guest account = nobody
enable privileges = Yes
pam password change = No
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\sUNIX\spassword:* %n\n 
*Retype\snew\sUNIX\spassword:* %n\n *password\supdated\ssuccessfully* .
passwd chat debug = No
passwd chat timeout = 2
check password script = 
username map = /etc/samba/smbusers
password level = 0
username level = 0
unix password sync = No
restrict anonymous = 0
lanman auth = Yes
ntlm auth = Yes
client NTLMv2 auth = No
client lanman auth = Yes
client plaintext auth = Yes
preload modules = 
use kerberos keytab = No
log level = 0
syslog = 0
syslog only = No
log file = /var/log/samba/log.%m
max log size = 1000
debug timestamp = Yes
debug hires timestamp = No
debug pid = No
debug uid = No
enable core files = Yes
smb ports = 445 139
large readwrite = Yes
max protocol = NT1
min protocol = CORE
read bmpx = No
read raw = Yes
write raw = Yes
disable netbios = No
reset on zero vc = No
acl compatibility = auto
defer sharing violations = Yes
nt pipe support = Yes
nt status support = Yes
announce version = 4.9
announce as = NT
max mux = 50
max xmit = 16644
name resolve order = lmhosts wins host bcast
max ttl = 259200
max wins ttl = 518400
min wins ttl = 21600
time server = No
unix extensions = Yes
use spnego = Yes
client signing = auto
server signing = No
client use spnego = Yes
enable asu support = No
svcctl list = 
deadtime = 0
getwd cache = Yes
keepalive = 300
kernel change notify = Yes
fam change notify = Yes
lpq cache time = 30
max smbd processes = 0
paranoid server security = Yes
max disk size = 0
max open files = 1
open files database hash size = 10007
socket options = TCP_NODELAY
use mmap = Yes
hostname lookups = No
name cache timeout = 660
load printers = No
printcap cache time = 750
printcap name = 
cups server = 
iprint server = 
disable spoolss = No
addport command = 
enumports command = 
addprinter command = 
deleteprinter command = 
show add printer wizard = Yes
os2 driver map = 
mangling method = hash2
mangle prefix = 1
max stat cache size = 0
stat cache = Yes
machine password timeout = 604800
add user script = 
rename user script = 
delete user script = 
add group script = 
delete group script = 
add user to group script = 
delete user from group script = 
set primary group script = 
add machine script = 
shutdown script = 
abort shutdown script = 
username map script = 
logon script = 
logon path = \\%N\%U\profile
logon drive = 
logon home = \\%N\%U
domain logons = Yes
os level = 64
lm announce = Auto
lm interval = 60
preferred master = Yes
local master = Yes
domain master = Yes
browse list = Yes
enhanced 

Re: [Samba] Problems with SAMBA as PDC and Windows XP SP2 as client

2007-06-20 Thread Personal Técnico

John Drescher escribió:

Is this preventing the user from logging on or loading their profile?


profile acls = No

If it is loading their profile I believe this may be your problem as I
had the same problem a few months ago. Set that to yes. The reason for
this is that WinXPSP2 checks the credentials of the profile match the
user and rejects the profile when it does not match.

John
We have changed this parameter to Yes, but we continue with the same 
problems.
Logfile shows the following message: smbd/service.c: 
make_connection_snum(849) Can't become connected user!




--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba