M. D. Parker
2006-Jul-12 05:13 UTC
[Samba] Problem using 2.0.23 client in a domain with a Samba 2.0.20c PDC.
I have a samba PDC running 2.0.20c I installed Samba 2.0.23 on a client joined to the domain. With this combination, when I attempt to connect to a share on this client from any host even the localhost results in the following: $ smbclient //localhost/atest -U auser Password: Domain=[DOMAIN] OS=[Unix] Server=[Samba 3.0.23-SerNet-RedHat] tree connect failed: NT_STATUS_ACCESS_DENIED Windows clients will similarly NOT connect. This situation does not happen on other NON-2.0.23 clients containing shares. I have traced the problem to the line in the smb.conf file that I have been using for years: [atest] . . "valid users = auser" . . If I remove this line, I get connected to the share, however, of course I lose any username protection. I have tried using write list = or even admin users = ... All to no avail. The log file indicates seems to recoginze my id but then finally at the end gets some type of deny message: [2006/07/11 15:38:34, 2] lib/access.c:check_access(324) Allowed connection from (127.0.0.1) [2006/07/11 15:39:37, 2] auth/auth.c:check_ntlm_password(309) check_ntlm_password: authentication for user [auser] -> [auser] -> [auser] succeeded [2006/07/11 15:39:37, 2] lib/access.c:check_access(324) Allowed connection from (10.10.32.200) [2006/07/11 15:39:37, 2] lib/access.c:check_access(324) Allowed connection from (10.10.32.200) [2006/07/11 15:39:37, 2] smbd/service.c:make_connection_snum(571) user 'auser' (from session setup) not permitted to access this share (atest) I have had this problem on all the "RC" versions of 2.0.23 and thought that this was something that would probably be fixed at release time. Wrong assumption. Got a fix or a workaround for this problem? I really need this to work before being able to upgrade to this revision. ========================================= M. D. Parker Systems Administrator General Atomics / Electromagnetic Systems +1 858 455 2877 mike.parker@ga.com
Gerald (Jerry) Carter
2006-Jul-12 11:27 UTC
[Samba] Problem using 2.0.23 client in a domain with a Samba 2.0.20c PDC.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 M. D. Parker wrote:> I have a samba PDC running 2.0.20c > > I installed Samba 2.0.23 on a client joined to the domain. > > With this combination, when I attempt to connect to a > share on this client from any host even the localhost > results in the following: > > $ smbclient //localhost/atest -U auser > Password: > Domain=[DOMAIN] OS=[Unix] Server=[Samba 3.0.23-SerNet-RedHat] > tree connect failed: NT_STATUS_ACCESS_DENIED > > Windows clients will similarly NOT connect. > > This situation does not happen on other NON-2.0.23 > clients containing shares. I have traced the problem to the > line in the smb.conf file that I have been using for years: > > [atest] > . > "valid users = auser" > . > > If I remove this line, I get connected to the share, > however, of course I lose any username protection. I > have tried using write list = or even admin > users = ... All to no avail. > > The log file indicates seems to recognize my id but > then finally at the end gets some type of deny message: >...> user 'auser' (from session setup) not permitted to access > this share (atest) > > I have had this problem on all the "RC" versions of > 2.0.23 and thought that this was something that would > probably be fixed at release time. Wrong assumption.Arggg!!!! *why* didn't you report it? Please send me your full smb.conf and a full level 10 debug log from smbd off list. cheers, jerry ====================================================================Samba ------- http://www.samba.org Centeris ----------- http://www.centeris.com "What man is a man who does not make the world better?" --Balian -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org iD8DBQFEtNxuIR7qMdg1EfYRAvvcAJ9Q6fGuOlfWPsLADKYH1Z8hcjd+UACg6bjr LiJn6vnqPzm+koseSO1TgTY=E4CU -----END PGP SIGNATURE-----
Gerald (Jerry) Carter
2006-Jul-13 18:57 UTC
[Samba] Problem using 3.0.23 client in a domain with a Samba 3.0.20c PDC.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 M. D. Parker wrote:> No I really mean DOMAIN\user = userI guess that makes sense... clever. Hmmm.... jerry -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org iD8DBQFEtpeSIR7qMdg1EfYRAiCEAJ9XWpVyeKVl9GGmfdDvnOwNOypo4wCgyU0o Bylxpe/OjRJY1pgEavxY0eQ=+Q4H -----END PGP SIGNATURE-----
M. D. Parker
2006-Jul-14 05:20 UTC
[Samba] Problem using 3.0.23 client in a domain with a Samba 3.0.20c PDC.
No I really mean DOMAIN\user = user BTW, the patch provided to me works successfully. ========================================= M. D. Parker Systems Administrator General Atomics / Electromagnetic Systems +1 858 455 2877 mike.parker@ga.com -----Original Message----- From: Gerald (Jerry) Carter [mailto:jerry@samba.org] Sent: Thursday, July 13, 2006 8:39 AM To: mike.parker@GA.com Cc: Volker.Lendecke@SerNet.DE; samba@lists.samba.org; samba-technical@samba.org Subject: Re: [Samba] Problem using 3.0.23 client in a domain with a Samba 3.0.20c PDC. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 M. D. Parker wrote:> Just for the record, I did find a workaround that seemed to work > after looking at the debug files a little more closely. > > In the smbusers file (mapping account names to local names), I put in > the line > > DOMAIN\user = userDo you mean user = DOMAIN\user ? We did code up for that case. Volker has a new fix that he will be sending out shortly. cheers, jerry ====================================================================Samba ------- http://www.samba.org Centeris ----------- http://www.centeris.com "What man is a man who does not make the world better?" --Balian -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org iD8DBQFEtmj5IR7qMdg1EfYRAlTxAJ9RQnfdGymjybJIQaIgNqRPYXEzAgCgoDUG 7o3ur4ieSpjs3V5UOY+r+zY=TTYH -----END PGP SIGNATURE-----
Reasonably Related Threads
- FW: Problem using 3.0.23 client in a domain with a Samba 3.0.20c PDC. -- REVISED I am using V3.x.x
- Format
- samba-tool ou create "OU=del-ou, dc=atest, dc=com" fails with /var/lib/samba/private/sam.ldb: No such file or directory
- Rename folder bug dovecot-1.0RC6 ?
- Two Problems while trying to aggregate a dataframe