Re: RES: RES: [Samba] Re: Winbind broken after 2.2.8 upgrade

2003-03-27 Thread Andrew Bartlett
On Fri, 2003-03-28 at 09:46, FRANCO wrote:
> I did it more then 12 times...
> 
> I have a lot of problems with winbind and NEVER I did receive a answer...
> Sorry if I have a poore english:

There are a number of documents on 'how to get questions answered'
around on the net.  In particular, just repeating the question, or
complaining that your question isn't answered just gets people
frustrated.  Instead, show that you have tried to solve the problem
yourself.

For example, if you have downgraded back to 2.2.7, and the problem 'went
away', then this needs to be made clear.  If you didn't, how can you
claim it's a bug in 2.2.8?

> I hve 3 installations with problems... I never saw this I think that Im not
> a god SAMBA Administrator but I did read all the doc I dont have any
> troubles with other soft, but with samba ehehehehehe

Samba is a complex peice of software.  It's interactions with (often
separately maintained) Windows DCs is particularly complex.

If it doesn't occur on all your DCs, then you should look at what is
different.  This information should be present when you contact the
list.

> I did send e-mails to the lis in :
> 
> 11/3. 12/3, 16/3, 18/3, 19, 20, 25, 27 with the same questions If you
> want, please check it and will see if Im joking... Im 42 years old.
> 
> 
> 
> FIRST INSTALATION:
> 
> Can yoiu help m?
> 
> [EMAIL PROTECTED] /etc]# smbpasswd -j surson -r cleo -U Administrator
> Password:
> Joined domain SURSON.
> [EMAIL PROTECTED] /etc]#
> 
> 
> [EMAIL PROTECTED] /etc]# smbclient //firewall/PUBLICO -UAdministrator added
> interface ip=192.168.1.1 bcast=192.168.1.255 nmask=255.255.255.0 Got a
> positive name query response from 192.168.1.2 ( 192.168.1.1 )
> Password:
> session setup failed: NT_STATUS_LOGON_FAILURE
> 
> When I try \\firewall\PUBLICO in the NT I receive a BOX to type USER and
> PASSWD
> 
> Joe log.cleo
> 
> [2003/03/25 04:38:27, 0]
> smbd/password.c:connect_to_domain_password_server(1307)
>   connect_to_domain_password_server: machine CLEO rejected the tconX on the
> IPC$ share. Error was : NT_STATUS_ACCESS_DENIED. [2003/03/25 04:38:27, 0]
> smbd/password.c:domain_client_validate(1554)
>   domain_client_validate: Domain password server not available. [2003/03/25

This looks like an issue with your PDC, not with Samba.

Your PDC is has 'restrict anonymous = 2' set.  The two options are to
set a username for Samba to use (wbinfo -Auser%pass), or to disable it. 

However, setting this only really works for Samba 3.0 - for 2.2 you
really can't run with this set. 

If you already have a username/pw set (by wbinfo -A), then I would
suspect that you have SMB signing required, on a 'fixed' DC (MS did not
used to enforce this).

Andrew Bartlett

-- 
Andrew Bartlett [EMAIL PROTECTED]
Manager, Authentication Subsystems, Samba Team  [EMAIL PROTECTED]
Student Network Administrator, Hawker College   [EMAIL PROTECTED]
http://samba.org http://build.samba.org http://hawkerc.net


signature.asc
Description: This is a digitally signed message part
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RES: RES: [Samba] Re: Winbind broken after 2.2.8 upgrade

2003-03-27 Thread FRANCO
I did it more then 12 times...

I have a lot of problems with winbind and NEVER I did receive a answer...
Sorry if I have a poore english:

I hve 3 installations with problems... I never saw this I think that Im not
a god SAMBA Administrator but I did read all the doc I dont have any
troubles with other soft, but with samba ehehehehehe

I did send e-mails to the lis in :

11/3. 12/3, 16/3, 18/3, 19, 20, 25, 27 with the same questions If you
want, please check it and will see if Im joking... Im 42 years old.



FIRST INSTALATION:

Can yoiu help m?

[EMAIL PROTECTED] /etc]# smbpasswd -j surson -r cleo -U Administrator
Password:
Joined domain SURSON.
[EMAIL PROTECTED] /etc]#


[EMAIL PROTECTED] /etc]# smbclient //firewall/PUBLICO -UAdministrator added
interface ip=192.168.1.1 bcast=192.168.1.255 nmask=255.255.255.0 Got a
positive name query response from 192.168.1.2 ( 192.168.1.1 )
Password:
session setup failed: NT_STATUS_LOGON_FAILURE

When I try \\firewall\PUBLICO in the NT I receive a BOX to type USER and
PASSWD

Joe log.cleo

[2003/03/25 04:38:27, 0]
smbd/password.c:connect_to_domain_password_server(1307)
  connect_to_domain_password_server: machine CLEO rejected the tconX on the
IPC$ share. Error was : NT_STATUS_ACCESS_DENIED. [2003/03/25 04:38:27, 0]
smbd/password.c:domain_client_validate(1554)
  domain_client_validate: Domain password server not available. [2003/03/25
04:38:27, 1] smbd/password.c:pass_check_smb(555)
  Couldn't find user 'surson+administrator' in passdb. [2003/03/25 04:38:27,
1] smbd/password.c:pass_check_smb(555)
  Couldn't find user 'surson+administrator' in passdb. [2003/03/25 04:38:27,
1] smbd/reply.c:reply_sesssetup_and_X(988)
  Rejecting user 'surson+administrator': authentication failed [2003/03/25
04:38:27, 0] smbd/password.c:connect_to_domain_password_server(1307)
  connect_to_domain_password_server: machine CLEO rejected the tconX on the
IPC$ share. Error was : NT_STATUS_ACCESS_DENIED. [2003/03/25 04:38:27, 0]
smbd/password.c:domain_client_validate(1554)
  domain_client_validate: Domain password server not available.


Joe.firewall

IW   log.firewall
Row 1Col 14:57F1 for help
[2003/03/25 04:37:32, 0]
smbd/password.c:connect_to_domain_password_server(1307)
  connect_to_domain_password_server: machine CLEO rejected the tconX on the
IPC$ share. Error was : NT_STATUS_ACCESS_DENIED. [2003/03/25 04:37:32, 0]
smbd/password.c:domain_client_validate(1554)
  domain_client_validate: Domain password server not available. [2003/03/25
04:37:32, 1] smbd/password.c:pass_check_smb(555)
  Couldn't find user 'surson+administrator' in passdb. [2003/03/25 04:37:32,
1] smbd/password.c:pass_check_smb(555)
  Couldn't find user 'surson+administrator' in passdb. [2003/03/25 04:37:32,
1] smbd/reply.c:reply_sesssetup_and_X(988)
  Rejecting user 'surson+administrator': authentication failed

Etc/smbusers

# Unix_name = SMB_name1 SMB_name2 ...
root = administrator admin
nobody = guest pcguest smbguest

Etc/smbpasswd

root:0:CHANGED BY ME:[UX
]:LCT-3E7AEA06:
Administrator:1CHANGED BY
MEe:[UX
]:LCT-3E7FED90:
catena:500:CHANGED BY
ME:[UX ]:LCT-3



Etc/passwd

Administrator:x:10032:10033::/home/Administrator:/dev/null
danilo:x:10033:10033::/home/danilo:/dev/null

Etc/pwdb.conf

#
# This is the configuration file for the pwdb library
#

user:
unix+shadow
nis+unix+shadow

group:
unix+shadow
nis+unix+shadow



etc/Pam.d/samba 

auth   required/lib/security/pam_unix.so nullok shadow
accountrequired/lib/security/pam_unix.so

#authrequired/lib/security/pam_securetty.so
#authrequired/lib/security/pam_nologin.so
#authsufficient  /lib/security/pam_winbind.so
#authrequired/lib/security/pam_pwdb.so use_first_pass shadow
#account required/lib/security/pam_winbind.so





SMB.conf
[global]
workgroup = SURSON
server string = Server FIREWALL usando  Samba
interfaces = 192.168.1.1/24
bind interfaces only = Yes
security = DOMAIN
encrypt passwords = Yes
password server = cleo
password level = 8
username level = 8
log level = 1
log file = /var/log/samba/log.%m
max log size = 50
name resolve order = wins hosts lmhosts bcast
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
os level = 0
preferred master = False
local master = No
domain master = False
wins server = 192.168.1.2
winbind uid = 1-2
winbind gid = 1-2
template homedir = /home/winnt/%D/%U
template shell = /bin/bash
winbind separator = +
winbind cache time = 10
hosts allow = 192.168.1. 192.168.2. 127.
printing = lprng

[homes]
comme