Hello all, I have samba+ldap configured, one workstation win2k in the domain. I'm trying logging in the domain, but this error return: samba-2.2.8a openldap-server-2.0.27-8 [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_open_connection(217) ldap_open_connection: connection opened [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:ldap_connect_system(316) ldap_connect_system: Binding to ldap server as "cn=root,o=domain,c=br" [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_connect_system(331) ldap_connect_system: succesful connection to the LDAP server [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_search_one_user(343) ldap_search_one_user: searching for:[(&(uid=nobody)(objectclass=sambaAccount))] [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:pdb_getsampwnam(940) LDAP search "(&(uid=nobody)(objectclass=sambaAccount))" returned 0 entries. [2003/09/25 15:51:30, 1] smbd/password.c:pass_check_smb(545) Couldn't find user 'nobody' in passdb. [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_open_connection(217) ldap_open_connection: connection opened [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:ldap_connect_system(316) ldap_connect_system: Binding to ldap server as "cn=root,o=domain,c=br" [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_connect_system(331) ldap_connect_system: succesful connection to the LDAP server [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_search_one_user(343) ldap_search_one_user: searching for:[(&(uid=nobody)(objectclass=sambaAccount))] [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:pdb_getsampwnam(940) LDAP search "(&(uid=nobody)(objectclass=sambaAccount))" returned 0 entries. [2003/09/25 15:51:30, 1] smbd/password.c:pass_check_smb(545) Couldn't find user 'nobody' in passdb. [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_open_connection(217) ldap_open_connection: connection opened [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:ldap_connect_system(316) ldap_connect_system: Binding to ldap server as "cn=root,o=domain,c=br" [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_connect_system(331) ldap_connect_system: succesful connection to the LDAP server [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_search_one_user(343) ldap_search_one_user: searching for:[(&(uid=nobody)(objectclass=sambaAccount))] [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:pdb_getsampwnam(940) LDAP search "(&(uid=nobody)(objectclass=sambaAccount))" returned 0 entries. [2003/09/25 15:51:30, 1] smbd/password.c:pass_check_smb(545) Couldn't find user 'nobody' in passdb. [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_open_connection(217) ldap_open_connection: connection opened [2003/09/25 15:51:30, 0] passdb/pdb_ldap.c:ldap_connect_system(316) ldap_connect_system: Binding to ldap server as "cn=root,o=domain,c=br" [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_connect_system(331) ldap_connect_system: succesful connection to the LDAP server [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:ldap_search_one_user(343) ldap_search_one_user: searching for:[(&(uid=labwin$)(objectclass=sambaAccount))] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [uid] = [labwin$] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:init_sam_from_ldap(576) Entry found for user: labwin$ [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [pwdLastSet] = [1064505031] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [logonTime] = [0] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [logoffTime] = [0] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [kickoffTime] = [0] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [pwdCanChange] = [0] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [pwdMustChange] = [0] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [cn] = [LABWIN$] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(435) get_single_attribute: [homeDrive] = [<does not exist>] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(435) get_single_attribute: [smbHome] = [<does not exist>] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(435) get_single_attribute: [scriptPath] = [<does not exist>] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(435) get_single_attribute: [profilePath] = [<does not exist>] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [description] = [Computer] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(435) get_single_attribute: [userWorkstations] = [<does not exist>] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [rid] = [3000] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [primaryGroupID] = [2001] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [lmPassword] = [C1363FB322CB1FF209E4386DEE362670] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [ntPassword] = [C24F7A17A441FD171FB9871365C30B17] [2003/09/25 15:51:30, 2] passdb/pdb_ldap.c:get_single_attribute(441) get_single_attribute: [acctFlags] = [[W ]] [2003/09/25 15:52:38, 2] smbd/server.c:exit_server(511) Closing connections My smb.conf [global] workgroup = INTRANET netbios name = PDC-SERVER server string = LDAP server running SAMBA #domain admin group = musb @"Domain Admins" ## LDAP ldap suffix = o=domain,c=br ldap admin dn = cn=root,o=domain,c=br ldap port = 389 ldap server = xxx.xxx.xxx.xxx ldap ssl = No add user script = /usr/local/sbin/smbldap-useradd.pl -w %u guest account = nobody character set = iso8859-1 log file = /usr/local/samba/var/log.%m log level = 2 max log size = 50 security = user socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192 local master = yes os level = 90 domain master = yes preferred master = yes null passwords = Yes encrypt passwords = yes passwd program =/usr/local/sbin/smbldap-passwd.pl -o %u unix password sync = yes passwd chat = *new*password* %n\n *new*password* %n\n *successfully* domain logons = yes logon path = \\%L\profiles\%u logon home = \\%L\%U logon drive = Z: wins support = Yes [homes] comment = Home Directories browseable = no writable = yes valid users = %S readonly = No create mask = 0664 directory mask = 0775 [netlogon] ; comment = Network Logon Service path = /usr/local/samba/lib/netlogon read only = yes # write list = ntadmin locking = no guest ok = yes ; writable = no ; share modes = no [profiles] path = /usr/local/samba/profiles read only = no create mask = 0600 directory mask = 0700 writable = yes ; browseable = no ; guest ok = yes My /etc/openldap/slapd.conf # $OpenLDAP: pkg/ldap/servers/slapd/slapd.conf,v 1.8.8.7 2001/09/27 20:00:31 kurt Exp $ # # See slapd.conf(5) for details on configuration options. # This file should NOT be world readable. # include /etc/openldap/schema/core.schema include /etc/openldap/schema/cosine.schema include /etc/openldap/schema/inetorgperson.schema include /etc/openldap/schema/nis.schema include /etc/openldap/schema/redhat/rfc822-MailMember.schema include /etc/openldap/schema/redhat/autofs.schema include /etc/openldap/schema/redhat/kerberosobject.schema include /etc/openldap/schema/courier.schema include /etc/openldap/schema/qmail.schema include /etc/openldap/schema/samba.schema # Define global ACLs to disable default read access. # Do not enable referrals until AFTER you have a working directory # service AND an understanding of referrals. #referral ldap://root.openldap.org #pidfile //var/run/slapd.pid #argsfile //var/run/slapd.args # Create a replication log in /var/lib/ldap for use by slurpd. #replogfile /var/lib/ldap/master-slapd.replog # Load dynamic backend modules: # modulepath /usr/sbin/openldap # moduleload back_ldap.la # moduleload back_ldbm.la # moduleload back_passwd.la # moduleload back_shell.la # # The next three lines allow use of TLS for connections using a dummy test # certificate, but you should generate a proper certificate by changing to # /usr/share/ssl/certs, running "make slapd.pem", and fixing permissions on # slapd.pem so that the ldap user or group can read it. # TLSCertificateFile /usr/share/ssl/certs/slapd.pem # TLSCertificateKeyFile /usr/share/ssl/certs/slapd.pem # TLSCACertificateFile /usr/share/ssl/certs/ca-bundle.crt # # Sample Access Control # Allow read access of root DSE # Allow self write access # Allow authenticated users read access # Allow anonymous users to authenticate # #access to dn="" by * read #access to dn=".*,o=domain,c=br" attr=userPassword # by self write #access to * # by users read # by anonymous auth # # if no access controls are present, the default is: # Allow read by all # # rootdn can always write! access to attr=userPassword by self write by anonymous auth by dn.base="cn=root,o=domain,c=br" write by * none access to attr=lmPassword by self write by anonymous auth by dn.base="cn=root,o=domain,c=br" write by * none access to attr=ntPassword by self write by anonymous auth by dn.base="cn=root,o=domain,c=br" write by * none access to * by self write by dn.base="cn=root,o=domain,c=br" write by * read ####################################################################### # ldbm database definitions ####################################################################### database ldbm suffix "o=domain,c=br" #suffix "o=My Organization Name,c=US" rootdn "cn=root,o=domain,c=br" #rootdn "cn=Manager,o=My Organization Name,c=US" # Cleartext passwords, especially for the rootdn, should # be avoided. See slappasswd(8) and slapd.conf(5) for details. # Use of strong authentication encouraged. rootpw {SSHA}5y658hVH9FHiaEr4/E73lCMaUMThwZ5H # rootpw {crypt}ijFYNcSNctg52 # The database directory MUST exist prior to running slapd AND # should only be accessible by the slapd/tools. Mode 700 recommended. directory /var/lib/ldap # Indices to maintain index objectClass,uid,uidNumber,gidNumber,memberUid eq index cn,mail,surname,givenname eq,subinitial # Replicas to which we should propagate changes #replica host=ldap-1.example.com:389 tls=yes # bindmethod=sasl saslmech=GSSAPI # authcId=host/ldap-master.example.com@EXAMPLE.COM Thanks Very Much! -- + -------------------------------------------------------- | Fernando Ribeiro | Linux User 273768 | Tel.: 55+61+92860361 | ICQ. 175630330 | Death to the mouse! Death to the graph! | Death to the closed standards! Death the patents! | Powered by VIm, MUTT + --------------------------------------------------------