search for: sambantpassword

Displaying 20 results from an estimated 478 matches for "sambantpassword".

2011 May 02
3
Issue providing seamless migrtion (3.0.24 to 3.5.6) - sambaNTPassword mystery
...hen I provide my machine account the same SID in ldap using: #pdbedit machine_account$ -U S-1-5-21-720590779-4203916555-4014520812-11343 The result is [2], and I can't log with it. Logs tell me something like "Workstation machine_account$ doesn't have a password"... Indeed, no sambaNTPassword here ! 2. I want to manually provide sambaNTPassword. Here, no samba command (pdbedit, smpasswd) provides me a way to do it, the only way I found is to adding it directly into LDAP (ldapadd or mod,...) [3]. As we could pedict, it doesn't work (log as root). Since "sambaNTPassword&quot...
2005 Dec 12
1
sambaNTPassword does NOT write to master LDAP when machines auto change the values
We have SuSE SLES9 servers with LDAP master/slave replication (24 replications/BDC's) All working fine -joining domain etc. The problem I am having is PC's at remote sites (BDC) with a local replica (OpenLDAP) periodically change the sambaNTPassword/sambaLMPassword on there own and write to the local LDAP server and do NOT follow the referral to the master. I have written scripts to force the sambaNTPassword attribute to be re-synchronised but the attribute becomes a different value - at a variable timeframe. Further investigation suggests t...
2005 Nov 17
0
Replication errors with LDAP and problems with NT machines
...elysion.lan:389 time: 1132047279.0 dn: uid=eurydice$,ou=Computers,dc=elysion,dc=lan changetype: modify delete: sambaPwdCanChange sambaPwdCanChange: 1132045192 - add: sambaPwdCanChange sambaPwdCanChange: 1132047279 - delete: sambaLMPassword sambaLMPassword: 60F9BE525098FB3917306D272A9441BB - delete: sambaNTPassword sambaNTPassword: 82ABE317EDABC40E2D3DF00A4E8C76AF - add: sambaNTPassword sambaNTPassword: BD4E5B924259E25B210B39F6F2AB3A27 - delete: sambaPwdLastSet sambaPwdLastSet: 1132045192 - add: sambaPwdLastSet sambaPwdLastSet: 1132047279 - replace: entryCSN entryCSN: 20051115093439Z#000001#00#000000 - replac...
2013 Feb 27
4
Samba authentication against 389 DS
...entos 6 with 389 DS. Everything is working, I can authenticate my users against it etc. Now I am trying to make Samba authenticate against the LDAP by following http://directory.fedoraproject.org/wiki/Howto:Samba However, it seems that Samba does not read the 'password' value, but 'sambaNTPassword'. I wrote in 389-DS mailing list and they said, that there is no way to make Samba read the 'password'. So I must end with two password (Samba and "normal" one). I can not sync them, since crypt algorithms are different and I can not just copy/paste the password to sambaNT...
2009 Jan 02
5
How workstation get authenticated in DC
...kstation lost the trust relationship with the domain controller. The solution is to re-join the workstation to the domain, but I do not know why workstation lost the trust relationship. When I re-join the workstation to domain, I find that the workstation LDAP entry change/add the attribute sambaNTPassword. Therefore, would you please instruct which script is called to modify the attribute sambaNTPassword when I add a workstation to domain? I also want to know how PC make authentication at DC, where PC stores its password (used to authenticate itself during authentication). You explanation...
2007 Aug 13
0
ldap passwd sync on 3.0.25a
...odify replace: userPassword userPassword:: e1NTSEF9UFZSZk1zcTNoRlFuYWhGMzRWN1BZWE5BU3U0MHNVTWo= - replace: sambaPwdMustChange sambaPwdMustChange: 1218542837 - replace: sambaPwdLastSet sambaPwdLastSet: 1187006837 - replace: sambaLMPassword sambaLMPassword: 8d16f4badd1da493aad3b435b51404ee - replace: sambaNTPassword sambaNTPassword: b39a61f16a4e11fa80580241f1d4aae8 - replace: pwdChangedTime pwdChangedTime: 20070813120717Z - replace: entryCSN entryCSN: 20070813120717Z#000000#00#000000 - replace: modifiersName modifiersName: cn=sambamgr,ou=Managers,o=stars - replace: modifyTimestamp modifyTimestamp: 200708131207...
2008 Dec 09
0
Issue with SambaNTPassword not replicating
...ing error [2008/12/09 12:02:30, 0] rpc_server/srv_netlog_nt.c:_net_auth_2(478) _net_auth2: creds_server_check failed. Rejecting auth request from client XXXX machine account XXXX$ Comparing the LDAP records on the PDC and the BDC for system XXXX I see that the following fields are different sambaNTPassword: 64AF0BD8913B5BD2F6B92201B2AFD071 sambaPwdLastSet: 1226922777 on the PDC and BDC LDAP servers. It looks like the PDC has a newer sambaNTPassword than the BDC which would seem to explain the domain authentication problems. I'm wondering why only the sambaNTPassword field is not getting repl...
2012 Jul 31
1
Samba+LDAP: Minimal permissions for sambaLMPassword/sambaNTPassword attributes?
Hi, what are the minimum permissions for the attributes sambaLMPassword/sambaNTPassword for the the LDAP administrator account so that Samba is just enabled to use it for authentication with ldapsam backend. It seems like auth is not enough, is this true?! Thanks, Arokux
2010 Jun 28
3
Password policies in the LDAP server
...to update password ==> /var/log/dirsrv/slapd-pruebas/audit <== time: 20100628122637 dn: uid=10000001s,XXXXXXXXXXXXX changetype: modify delete: sambaLMPassword sambaLMPassword: 0182BD0BD4444BF836077A718CCDF409 - add: sambaLMPassword sambaLMPassword: 39EAD569B79C7EA2C2265B23734E0DAC - delete: sambaNTPassword sambaNTPassword: 259745CB123A52AA2E693AAACCA2DB52 - add: sambaNTPassword sambaNTPassword: 8EC60ADEA316D957D1CF532C5841758D - delete: sambaPwdLastSet sambaPwdLastSet: 1277720109 - add: sambaPwdLastSet sambaPwdLastSet: 1277720798 - replace: modifiersname modifiersname: uid=adminsamba,XXXXXXXXXXX - re...
2003 Oct 22
2
Samba 3.0 + LDAP userPassword -> sambaNTPassword manual sync?
First, the software: Samba 3.0.0 OpenLDAP 2.0.27 nssldap / pam_ldap Redhat 9 This may be more of a question for the OpenLDAP mailing list.. but does anyone know of a method (perhaps using slappasswd?) to hand-sync userPassword attributes to sambaNTPassword attributes? Deploying Samba 3.0 as pdc pretty soon, used Migration Tools on the mail server soon, and I'd really like to be able to tell people to log in using their mail credentials, as opposed to a generic password that they might not ever change, resulting in the ever-unfun activity of trac...
2008 Apr 22
1
Convert ssha password to sambaNTpassword?
Is it possible to take a SSHA password from an ldif and create a proper sambaNTpassword from it? Here's the scenario: the ldap servers in our organization do not have the samba schema installed and the likelihood of that happening is slim. I still want to provide clients with as close to a single sign on solution as possible and I can get an ldif of the accounts I need. Ho...
2012 Nov 30
5
Samba file server using ldap backend without AD or PDC?
Hi all, I've been using samba for a few years now on a couple of file servers with a tdbsam backend for our user accounts. We use openldap for the vast majority of our identity management, so I would love to be able to tie into this. We recently started using sambaNTPassword in openldap for radius authentication, so this is populated for most of our users now. >From reading through some of the documentation though, I'm a bit confused as to how this would be implemented. We don't currently have Active Directory and don't have any samba PDC/BDCs set up...
2005 Sep 09
0
sambaLMPassowrd and sambaNTPassword
Hi all, I have plan to upgrade samba 3.0.2 to current release, aparently some work must be done on the user entries on LDAP since the samba.schema has change. While do some changes, I want to remove sambaLMPassword attribute so I don't need to maintain it in sync with sambaNTPassword. Will I break something if I remove this attribute? -- --beast
2005 Feb 01
3
LDAP help!
Hey list, Right now I have Samba+LDAP working (like a charm acctually) I just have one issue. Right now Samba is authenticating the user against the sambaLMPassword and/or the sambaNTPassword attributes. I would rather it authenticated against the userPassword attribute like my unix boxes and mail servers do. Is samba capable of doing this? Otherwise I have to maintain two seperate passwords for each user. Thanks Regards, Daniel
2006 Mar 09
1
changing password on samba bdc
...tr=uid uidNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn displayName sambaHomeDrive sambaHomePath sambaLogonScript sambaProfilePath description sambaUserWorkstations sambaSID sambaPrimaryGroupSID sambaLMPassword sambaNTPassword sambaDomainName objectClass sambaAcctFlags sambaMungedDial sambaBadPasswordCount sambaBadPasswordTime sambaPasswordHistory modifyTimestamp sambaLogonHours modifyTimestamp conn=327 op=2 SEARCH RESULT tag=101 err=0 nentries=1 text= # #conn=328 is made via nss_ldap # conn=328 fd=27 ACCEPT from PATH=...
2009 Sep 23
1
After migrating users to ldap, passwords still stored in passdb.tdb
...ed running "pdbedit -e ldapsam:ldap://ldap1.mydomain.com " - but that didn't seem to work. Used "pdbedit -L -w" to dump the NT account info to a text file Ran some custom perl scripts to read that file and update add/modify samba attributes (including sambaLMPassword, sambaNTPassword, objectClass=NTUser, sambaSID) to my ldap accounts. The SambaSID value for the LDAP account was copied from the output of "wbinfo -n username" Set the ldap admin passwd with "smbpasswd -w thepassword" Changed smb.conf to use ldap as the backend smb.conf includes...
2005 Jun 07
1
Problems with userPassword when it's base64 encoded
...6/07 19:27:45, 0] libsmb/smbencrypt.c:decode_pw_buffer(540) decode_pw_buffer: check that 'encrypt passwords = yes' -- cut here -- And a dialog from Windows that says: "The User name or old password is incorrect. Letters in passwords must be typed using the correct case." The SambaNTPassword and SambaLMPassword entries change, but the userPassword entry does not. I'm using the ldap passwd sync = Yes option in my smb.conf since the LDAP server is used for Linux authentication as well as Samba authentication. However, if I use the smbldap-passwd utility everything works like a ch...
2011 Oct 13
3
Samba, OpenLDAP and Passwords
...ou=Groups ldap password sync = yes I have defined the admin password with the smbpasswd utility, and everything is working. If I want that a LDAP user uses Samba, I have to use again the smbpasswd utility for adding him to the samba users and defining a new password that will be the LDAP attribute SambaNTPassword (and the new password overwrites the LDAP userPassword, thanks to the "ldap password sync = yes" directive in smb.conf). If I want to permit that a user can change his LDAP userPassword and align it to the SambaNTPassword, I have seen that I can do it by using the smbk5pwd overlay and pam...
2020 May 15
2
Problems with groups, minimum gidnumber?
On Fri, 15 May 2020, Rowland penny via samba wrote: > On 15/05/2020 16:33, Harald Hannelius wrote: >> If there's a way to copy the sambaNTPassword password-hash from the LDAP >> for the Samba 3 DC with samba-tool I would have loved to find that >> information long ago :) > Why do you need the sambaNTPassword ? So the users would have the same password. I don't have time to wait for our IDM to change the passwords one by...
2008 Feb 12
3
ldap passwd sync not working
...true! NT and LM passwords are changed but unixPassword isn't. Look at this openldap.log lines: Feb 12 07:50:28 apolo slapd[22826]: conn=698021 op=40 MOD dn="uid=teste,ou=Users,dc=domain" Feb 12 07:50:28 apolo slapd[22826]: conn=698021 op=40 MOD attr=sambaLMPassword sambaLMPassword sambaNTPassword sambaNTPassword sambaPwdLastSet sambaPwdLastSet See? My smb.conf have this ldap related options: passdb backend = ldapsam:ldap://apolo.domain idmap backend = ldapsam:ldap://apolo.domain ldap suffix = dc=domain ldap admin dn = cn=root,dc=domain ldap ssl = start_tls ldap group suffix = ou=Groups l...