Pascual Muñoz
2003-Dec-22 18:38 UTC
[Samba] User validation in domain different than workgroup
Hello all, First of all, I'm really a newbie in Samba. I can manage to setup the Samba server in security = user, and now I'm trying to do a more complicated thing. I wish the Samba server to be our domain master in group COMOPT, that is workgroup = COMPOPT. I do not want to have Linux user accounts for the users, but rather to validate them using another domain server, whose domain is UPVNET, and then map all the connections to the shares to a single Linux user for all of them. I'm a little bit confused, because it seems I must use security = domain and winbind, but then workgroup should be UPVNET rather than COMOPT, that is the one I want. Sorry in advance for this little mess. Maybe I'm asking something that makes no sense. Can any one help me? Thanks in advance. Pascual.
Sean Kennedy
2003-Dec-22 19:04 UTC
[Samba] User validation in domain different than workgroup
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'm not entirely sure I understand. You want your users to be validated against the UPVNET domain controller, right? How does COMOPT come into then? Is COMOPT the domain root, and UPVNET a branch ( or subforest, or whatever they call it )? From Samba's perspective, it shouldn't matter the relationship: Point samba to UPVNET as the DC, and let the win2k boxes work themselves out. Please let me know if I got what you want wrong. Pascual Mu?oz wrote:> Hello all, > > First of all, I'm really a newbie in Samba. I can manage to setup the > Samba server in security = user, and now I'm trying to do a more > complicated thing. > > I wish the Samba server to be our domain master in group COMOPT, that > is workgroup = COMPOPT. I do not want to have Linux user accounts for > the users, but rather to validate them using another domain server, > whose domain is UPVNET, and then map all the connections to the shares > to a single Linux user for all of them. > > I'm a little bit confused, because it seems I must use security = > domain and winbind, but then workgroup should be UPVNET rather than > COMOPT, that is the one I want. > > Sorry in advance for this little mess. Maybe I'm asking something that > makes no sense. Can any one help me? > > Thanks in advance. > > Pascual. >- -- Sean Kennedy PGP public key: http://tpno.org/keys/0xFC1C377F.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1-nr1 (Windows 2000) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD4DBQE/5z9xIjyA6vwcN38RAnPOAJQPCHtvRM2qHZk4tpwLwWNQUeRjAJ9GSbzX 0ZeKGMX9V0L2ePLSYOQ0wA==TziP -----END PGP SIGNATURE-----
John H Terpstra
2003-Dec-22 19:41 UTC
[Samba] User validation in domain different than workgroup
Pascual, You need to use Samba-3.0.1, and then use Interdomain Trusts. See Samba-HOWTO chapter on that. http://www.samba.org/samba/docs/Samba-HOWTO-Collection.pdf - John T. On Mon, 22 Dec 2003, [ISO-8859-1] Pascual Muñoz wrote:> Hello all, > > First of all, I'm really a newbie in Samba. I can manage to setup the Samba > server in security = user, and now I'm trying to do a more complicated thing. > > I wish the Samba server to be our domain master in group COMOPT, that is > workgroup = COMPOPT. I do not want to have Linux user accounts for the users, > but rather to validate them using another domain server, whose domain is UPVNET, > and then map all the connections to the shares to a single Linux user for all of > them. > > I'm a little bit confused, because it seems I must use security = domain and > winbind, but then workgroup should be UPVNET rather than COMOPT, that is the one > I want. > > Sorry in advance for this little mess. Maybe I'm asking something that makes no > sense. Can any one help me? > > Thanks in advance. > > Pascual. > >-- John H Terpstra Email: jht@samba.org