Displaying 20 results from an estimated 478 matches for "sambantpassword".
2011 May 02
3
Issue providing seamless migrtion (3.0.24 to 3.5.6) - sambaNTPassword mystery
...hen I provide my machine account the same SID in ldap using:
#pdbedit machine_account$ -U S-1-5-21-720590779-4203916555-4014520812-11343
The result is [2], and I can't log with it. Logs tell me something like
"Workstation machine_account$ doesn't have a password"... Indeed, no
sambaNTPassword here !
2. I want to manually provide sambaNTPassword. Here, no samba command
(pdbedit, smpasswd) provides me a way to do it, the only way I found is
to adding it directly into LDAP (ldapadd or mod,...) [3].
As we could pedict, it doesn't work (log as root). Since
"sambaNTPassword"...
2005 Dec 12
1
sambaNTPassword does NOT write to master LDAP when machines auto change the values
We have SuSE SLES9 servers with LDAP master/slave replication (24
replications/BDC's)
All working fine -joining domain etc.
The problem I am having is PC's at remote sites (BDC) with a local
replica (OpenLDAP) periodically change the
sambaNTPassword/sambaLMPassword on there own and write to the local LDAP
server and do NOT follow the referral to the master.
I have written scripts to force the sambaNTPassword attribute to be
re-synchronised but the attribute becomes a different value - at a
variable timeframe.
Further investigation suggests t...
2005 Nov 17
0
Replication errors with LDAP and problems with NT machines
...elysion.lan:389
time: 1132047279.0
dn: uid=eurydice$,ou=Computers,dc=elysion,dc=lan
changetype: modify
delete: sambaPwdCanChange
sambaPwdCanChange: 1132045192
-
add: sambaPwdCanChange
sambaPwdCanChange: 1132047279
-
delete: sambaLMPassword
sambaLMPassword: 60F9BE525098FB3917306D272A9441BB
-
delete: sambaNTPassword
sambaNTPassword: 82ABE317EDABC40E2D3DF00A4E8C76AF
-
add: sambaNTPassword
sambaNTPassword: BD4E5B924259E25B210B39F6F2AB3A27
-
delete: sambaPwdLastSet
sambaPwdLastSet: 1132045192
-
add: sambaPwdLastSet
sambaPwdLastSet: 1132047279
-
replace: entryCSN
entryCSN: 20051115093439Z#000001#00#000000
-
replac...
2013 Feb 27
4
Samba authentication against 389 DS
...entos 6 with 389 DS. Everything is working, I can
authenticate my users against it etc.
Now I am trying to make Samba authenticate against the LDAP by
following http://directory.fedoraproject.org/wiki/Howto:Samba
However, it seems that Samba does not read the 'password' value, but
'sambaNTPassword'. I wrote in 389-DS mailing list and they said, that
there is no way to make Samba read the 'password'. So I must end with
two password (Samba and "normal" one). I can not sync them, since crypt
algorithms are different and I can not just copy/paste the password to
sambaNT...
2009 Jan 02
5
How workstation get authenticated in DC
...kstation lost the trust relationship with the domain controller. The solution is to re-join the workstation to the domain, but I do not know why workstation lost the trust relationship.
When I re-join the workstation to domain, I find that the workstation LDAP entry change/add the attribute sambaNTPassword. Therefore, would you please instruct which script is called to modify the attribute sambaNTPassword when I add a workstation to domain? I also want to know how PC make authentication at DC, where PC stores its password (used to authenticate itself during authentication).
You explanation...
2007 Aug 13
0
ldap passwd sync on 3.0.25a
...odify
replace: userPassword
userPassword:: e1NTSEF9UFZSZk1zcTNoRlFuYWhGMzRWN1BZWE5BU3U0MHNVTWo=
-
replace: sambaPwdMustChange
sambaPwdMustChange: 1218542837
-
replace: sambaPwdLastSet
sambaPwdLastSet: 1187006837
-
replace: sambaLMPassword
sambaLMPassword: 8d16f4badd1da493aad3b435b51404ee
-
replace: sambaNTPassword
sambaNTPassword: b39a61f16a4e11fa80580241f1d4aae8
-
replace: pwdChangedTime
pwdChangedTime: 20070813120717Z
-
replace: entryCSN
entryCSN: 20070813120717Z#000000#00#000000
-
replace: modifiersName
modifiersName: cn=sambamgr,ou=Managers,o=stars
-
replace: modifyTimestamp
modifyTimestamp: 200708131207...
2008 Dec 09
0
Issue with SambaNTPassword not replicating
...ing error
[2008/12/09 12:02:30, 0] rpc_server/srv_netlog_nt.c:_net_auth_2(478)
_net_auth2: creds_server_check failed. Rejecting auth request from
client XXXX machine account XXXX$
Comparing the LDAP records on the PDC and the BDC for system XXXX I see
that the following fields are different
sambaNTPassword: 64AF0BD8913B5BD2F6B92201B2AFD071
sambaPwdLastSet: 1226922777
on the PDC and BDC LDAP servers. It looks like the PDC has a newer
sambaNTPassword than the BDC which would seem to explain the domain
authentication problems.
I'm wondering why only the sambaNTPassword field is not getting
repl...
2012 Jul 31
1
Samba+LDAP: Minimal permissions for sambaLMPassword/sambaNTPassword attributes?
Hi,
what are the minimum permissions for the attributes
sambaLMPassword/sambaNTPassword for the the LDAP administrator account
so that Samba is just enabled to use it for authentication with
ldapsam backend.
It seems like auth is not enough, is this true?!
Thanks,
Arokux
2010 Jun 28
3
Password policies in the LDAP server
...to update password
==> /var/log/dirsrv/slapd-pruebas/audit <==
time: 20100628122637
dn: uid=10000001s,XXXXXXXXXXXXX
changetype: modify
delete: sambaLMPassword
sambaLMPassword: 0182BD0BD4444BF836077A718CCDF409
-
add: sambaLMPassword
sambaLMPassword: 39EAD569B79C7EA2C2265B23734E0DAC
-
delete: sambaNTPassword
sambaNTPassword: 259745CB123A52AA2E693AAACCA2DB52
-
add: sambaNTPassword
sambaNTPassword: 8EC60ADEA316D957D1CF532C5841758D
-
delete: sambaPwdLastSet
sambaPwdLastSet: 1277720109
-
add: sambaPwdLastSet
sambaPwdLastSet: 1277720798
-
replace: modifiersname
modifiersname: uid=adminsamba,XXXXXXXXXXX
-
re...
2003 Oct 22
2
Samba 3.0 + LDAP userPassword -> sambaNTPassword manual sync?
First, the software:
Samba 3.0.0
OpenLDAP 2.0.27
nssldap / pam_ldap
Redhat 9
This may be more of a question for the OpenLDAP mailing list.. but does
anyone know of a method (perhaps using slappasswd?) to hand-sync userPassword
attributes to sambaNTPassword attributes?
Deploying Samba 3.0 as pdc pretty soon, used Migration Tools on the mail
server soon, and I'd really like to be able to tell people to log in using
their mail credentials, as opposed to a generic password that they might
not ever change, resulting in the ever-unfun activity of trac...
2008 Apr 22
1
Convert ssha password to sambaNTpassword?
Is it possible to take a SSHA password from an ldif and create a proper
sambaNTpassword from it? Here's the scenario: the ldap servers in our
organization do not have the samba schema installed and the likelihood
of that happening is slim. I still want to provide clients with as
close to a single sign on solution as possible and I can get an ldif of
the accounts I need. Ho...
2012 Nov 30
5
Samba file server using ldap backend without AD or PDC?
Hi all,
I've been using samba for a few years now on a couple of file servers with a
tdbsam backend for our user accounts. We use openldap for the vast majority
of our identity management, so I would love to be able to tie into this. We
recently started using sambaNTPassword in openldap for radius
authentication, so this is populated for most of our users now.
>From reading through some of the documentation though, I'm a bit confused as
to how this would be implemented. We don't currently have Active Directory
and don't have any samba PDC/BDCs set up...
2005 Sep 09
0
sambaLMPassowrd and sambaNTPassword
Hi all,
I have plan to upgrade samba 3.0.2 to current release, aparently some
work must be done on the user entries on LDAP since the samba.schema has
change.
While do some changes, I want to remove sambaLMPassword attribute so I
don't need to maintain it in sync with sambaNTPassword.
Will I break something if I remove this attribute?
--
--beast
2005 Feb 01
3
LDAP help!
Hey list,
Right now I have Samba+LDAP working (like a charm acctually) I just
have one issue. Right now Samba is authenticating the user against
the sambaLMPassword and/or the sambaNTPassword attributes.
I would rather it authenticated against the userPassword attribute
like my unix boxes and mail servers do. Is samba capable of doing
this? Otherwise I have to maintain two seperate passwords for each
user.
Thanks
Regards,
Daniel
2006 Mar 09
1
changing password on samba bdc
...tr=uid uidNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn displayName sambaHomeDrive sambaHomePath sambaLogonScript sambaProfilePath description sambaUserWorkstations sambaSID sambaPrimaryGroupSID sambaLMPassword sambaNTPassword sambaDomainName objectClass sambaAcctFlags sambaMungedDial sambaBadPasswordCount sambaBadPasswordTime sambaPasswordHistory modifyTimestamp sambaLogonHours modifyTimestamp
conn=327 op=2 SEARCH RESULT tag=101 err=0 nentries=1 text=
#
#conn=328 is made via nss_ldap
#
conn=328 fd=27 ACCEPT from PATH=...
2009 Sep 23
1
After migrating users to ldap, passwords still stored in passdb.tdb
...ed running "pdbedit -e ldapsam:ldap://ldap1.mydomain.com " -
but that didn't seem to work.
Used "pdbedit -L -w" to dump the NT account info to a text file
Ran some custom perl scripts to read that file and update
add/modify samba attributes (including sambaLMPassword,
sambaNTPassword, objectClass=NTUser, sambaSID) to my ldap accounts.
The SambaSID value for the LDAP account was copied from the
output of "wbinfo -n username"
Set the ldap admin passwd with "smbpasswd -w thepassword"
Changed smb.conf to use ldap as the backend
smb.conf includes...
2005 Jun 07
1
Problems with userPassword when it's base64 encoded
...6/07 19:27:45, 0] libsmb/smbencrypt.c:decode_pw_buffer(540)
decode_pw_buffer: check that 'encrypt passwords = yes'
-- cut here --
And a dialog from Windows that says:
"The User name or old password is incorrect. Letters in passwords must
be typed using the correct case."
The SambaNTPassword and SambaLMPassword entries change, but the
userPassword entry does not.
I'm using the ldap passwd sync = Yes option in my smb.conf since the
LDAP server is used for Linux authentication as well as Samba
authentication.
However, if I use the smbldap-passwd utility everything works like a ch...
2011 Oct 13
3
Samba, OpenLDAP and Passwords
...ou=Groups
ldap password sync = yes
I have defined the admin password with the smbpasswd utility, and everything
is working.
If I want that a LDAP user uses Samba, I have to use again the smbpasswd
utility for adding him to the samba users and defining a new password that
will be the LDAP attribute SambaNTPassword (and the new password overwrites
the LDAP userPassword, thanks to the "ldap password sync = yes" directive in
smb.conf).
If I want to permit that a user can change his LDAP userPassword and align
it to the SambaNTPassword, I have seen that I can do it by using the
smbk5pwd overlay and pam...
2020 May 15
2
Problems with groups, minimum gidnumber?
On Fri, 15 May 2020, Rowland penny via samba wrote:
> On 15/05/2020 16:33, Harald Hannelius wrote:
>> If there's a way to copy the sambaNTPassword password-hash from the LDAP
>> for the Samba 3 DC with samba-tool I would have loved to find that
>> information long ago :)
> Why do you need the sambaNTPassword ?
So the users would have the same password. I don't have time to wait for our
IDM to change the passwords one by...
2008 Feb 12
3
ldap passwd sync not working
...true!
NT and LM passwords are changed but unixPassword isn't.
Look at this openldap.log lines:
Feb 12 07:50:28 apolo slapd[22826]: conn=698021 op=40 MOD
dn="uid=teste,ou=Users,dc=domain"
Feb 12 07:50:28 apolo slapd[22826]: conn=698021 op=40 MOD
attr=sambaLMPassword sambaLMPassword sambaNTPassword sambaNTPassword
sambaPwdLastSet sambaPwdLastSet
See?
My smb.conf have this ldap related options:
passdb backend = ldapsam:ldap://apolo.domain
idmap backend = ldapsam:ldap://apolo.domain
ldap suffix = dc=domain
ldap admin dn = cn=root,dc=domain
ldap ssl = start_tls
ldap group suffix = ou=Groups
l...