Hello all,
I repost this mail with a new subject line because on
the original one ("Unable to join domain from WNT4")
i've got no respnse.
version is 3.0.23d (the same happens with 3.0.21c )
running as a PDC
OS: Linux 2.6.11.4-21.14-smp, (from SuSE 9.3) on dual Opterons.
After upgrading from 3.0.11 to 3.0.23d, all Windows-NT4-sp6
machines were no longer DOMAIN-members - WinXP or Win2000
members work as usual. Trying to get
the WNT4 machines back into the domain gave about this message
( translated from german text ) on the NT4-Machines:
"To change or to add an account in the domain is not possible.
The assigned account informations do not give you enough privileges
to create or change an account."
A part of the logs:
[2006/11/30 15:00:47, 2] smbd/sesssetup.c:setup_new_vc_session(799)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close
all old resources.
[2006/11/30 15:00:47, 2] auth/auth.c:check_ntlm_password(309)
check_ntlm_password: authentication for user [smbadmin] -> [smbadmin]
-> [smbadmin] succeeded
[2006/11/30 15:00:47, 2] smbd/reply.c:reply_tcon_and_X(711)
Serving IPC$ as a Dfs root
[2006/11/30 15:00:47, 0] rpc_parse/parse_prs.c:prs_mem_get(559)
prs_mem_get: reading data of size 2 would overrun buffer by 1 bytes.
[2006/11/30 15:00:47, 0] rpc_server/srv_samr.c:api_samr_set_userinfo(848)
api_samr_set_userinfo: Unable to unmarshall SAMR_Q_SET_USERINFO.
[2006/11/30 15:00:47, 0] rpc_server/srv_pipe.c:api_rpcTNP(2287)
api_rpcTNP: samr: SAMR_SET_USERINFO failed.
Whats happening here ??
A snippet from "pdbedit -Lv -u smbadmin"
---------------
Unix username: smbadmin
NT username:
Account Flags: [U ]
User SID: S-1-5-21-1042923542-3040449016-515553985-512
Primary Group SID: S-1-5-21-1042923542-3040449016-515553985-513
Full Name: Samba Server Sys Admin
Home Directory: \\umv8\smbadmin
HomeDir Drive:
Logon Script:
Profile Path: \\umv8\Profiles\smbadmin
Domain: PHYSIOCHEM
---------------
A snippet from "net rpc rights list accounts"
---
S-1-5-21-1042923542-3040449016-515553985-512
SeMachineAccountPrivilege
SeRemoteShutdownPrivilege
SePrintOperatorPrivilege
SeAddUsersPrivilege
SeDiskOperatorPrivilege
-----
Greetings, Manfred