Rowland penny via samba ha scritto il 25/08/20 alle 12:21:> [...] > Try adding 'nltm auth = yes' to the smb.conf, it defaulted to 'no' at 4.5.0thanks Rowland I have tried to change ntlm auth to yes but AD users continue to have problems connecting to the shares... Piviul
On 25/08/2020 12:05, Piviul via samba wrote:> Rowland penny via samba ha scritto il 25/08/20 alle 12:21: >> [...] >> Try adding 'nltm auth = yes' to the smb.conf, it defaulted to 'no' at >> 4.5.0 > thanks Rowland I have tried to change ntlm auth to yes but AD users > continue to have problems connecting to the shares... > > Piviul >Even though your users may have the same username in AD as in the NT4-style domain, they are different users, so a few thoughts. You have 'map to guest = bad user', so I take it you must have 'guest ok = yes' set in the shares (you haven't shown us the shares), so try changing 'bad user' to 'bad password'. The only other thing I can think of at the moment is to remove 'winbind use default domain = yes' Rowland
Mandi! Rowland penny via samba In chel di` si favelave...> Even though your users may have the same username in AD as in the NT4-style > domain, they are different users, so a few thoughts. You have 'map to guest > = bad user', so I take it you must have 'guest ok = yes' set in the shares > (you haven't shown us the shares), so try changing 'bad user' to 'bad > password'.Interesting. But my server had 'map to guest = Bad User', and worked. Anyway, it is worth a try...> The only other thing I can think of at the moment is to remove > 'winbind use default domain = yes'It was a try, i think in NT mode don't bother at all. Paolo, if possible: a) your client OS is Win10 or Win7? I don't remember if you have specified it. If possible, use Win7. If not, make sure ti have smb1 enabled, but also this: - https://support.microsoft.com/en-gb/help/4046019/guest-access-in-smb2-disabled-by-default-in-windows-10-and-windows-ser b) you have tried to mount shares using IP and not names? EG, try please: net use g: \\1.2.3.4\share /persistent:yes c) follow the hint by Louis, eg try to explicit the login in domainful way: net use g: \\server.fqdn.tld\share /persistent:yes /user:NT4DOM\%username% (i think that this WILL HAVE to work!) If possible, for every try enable log (samba and windows) and post result. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia'' http://www.lanostrafamiglia.it/ Polo FVG - Via della Bont?, 7 - 33078 - San Vito al Tagliamento (PN) marco.gaiarin(at)lanostrafamiglia.it t +39-0434-842711 f +39-0434-842797 Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA! http://www.lanostrafamiglia.it/index.php/it/sostienici/5x1000 (cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)
I've send this message yesterday but I've not received it from samba at lists.samba.org: I try to send it again... Piviul -------- Messaggio Inoltrato -------- Oggetto: Re: [Samba] accessing foreign AD users to NT domain Data: Tue, 25 Aug 2020 13:05:35 +0200 Mittente: Piviul <piviul at riminilug.it> A: samba at lists.samba.org Rowland penny via samba ha scritto il 25/08/20 alle 12:21:> [...] > Try adding 'nltm auth = yes' to the smb.conf, it defaulted to 'no' at 4.5.0thanks Rowland I have tried to change "ntlm auth" to "yes" but AD users continue to have problems connecting to the shares... Piviul
Rowland penny
2020-Aug-26 07:49 UTC
[Samba] Fwd: Re: accessing foreign AD users to NT domain
On 26/08/2020 08:07, Piviul via samba wrote:> I've send this message yesterday but I've not received it from > samba at lists.samba.org: I try to send it again... > > Piviul > > -------- Messaggio Inoltrato -------- > Oggetto: Re: [Samba] accessing foreign AD users to NT domain > Data: Tue, 25 Aug 2020 13:05:35 +0200 > Mittente: Piviul <piviul at riminilug.it> > A: samba at lists.samba.org > > Rowland penny via samba ha scritto il 25/08/20 alle 12:21: >> [...] >> Try adding 'nltm auth = yes' to the smb.conf, it defaulted to 'no' at >> 4.5.0 > thanks Rowland I have tried to change "ntlm auth" to "yes" but AD > users continue to have problems connecting to the shares... > > Piviul >And I replied: [quote] Even though your users may have the same username in AD as in the NT4-style domain, they are different users, so a few thoughts. You have 'map to guest = bad user', so I take it you must have 'guest ok = yes' set in the shares (you haven't shown us the shares), so try changing 'bad user' to 'bad password'. The only other thing I can think of at the moment is to remove 'winbind use default domain = yes' [/quote] It looks like something at your end is blocking posts from the samba list, have you looked in your SPAM box etc ? Rowland
Rowland penny via samba ha scritto il 25/08/20 alle 18:20:> [...] > Even though your users may have the same username in AD as in the > NT4-style domain, they are different users, so a few thoughts. You have > 'map to guest = bad user', so I take it you must have 'guest ok = yes' > set in the shares (you haven't shown us the shares),in effect there is no guest ok = yes in shares...> so try changing > 'bad user' to 'bad password'. The only other thing I can think of at the > moment is to remove 'winbind use default domain = yes'done, changed "map to guest" to "bad password" but nothing changed... :( Piviul