Displaying 20 results from an estimated 700 matches similar to: "Getting users and groups through winbind on FreeBSD"
2008 Nov 19
0
File sharing is ok, but new ADS user validation is not ok
We have Samba 3.2.4 on two SLES 10 (one is SP1, the other SP2 64bit)
machines. Both are member servers in our ADS, which was over the past
month given some additional DCs, new IPs for all DCs, and upgraded to
Windows 2008 (from win2003). The krb5.conf and nsswitch.conf files on
the two machines are identical; the smb.conf files are *nearly*
identical in their common section; the filewall rules
2006 Apr 26
1
Bad Password
Everyone,
I am going nuts trying to figure this problem out. I have
successfully joined a SUSE 10 server to our domain and configured samba
for ADS authentication. This exact setup works on all my other servers.
On this one, I keep getting access denied when entering my domain
password despite the fact that I have tried it literally dozens of
times. I am 100% confident I am
2007 May 18
1
3.0.25 Winbind high CPU usage
I just upgraded from 3.0.23d to 3.0.25 and I'm noticing that winbind is
chewing up a lot of CPU usage.
There are always 2 winbindd processes and one uses about 80% cpu and the
other use 15% cpu.
When I run a tcpdump and look at the traffic going to/from the domain
controller winbindd is connected to, there is a constant flow of
traffic.
Here is the winbind setup from my smb.conf file:
2005 Dec 09
1
Limit user authentification into Winbind ?
Hi
i see on my log, two informations :
1- Into my log, i see a very big quantity of :
[19391]: lookupname ECTPP/root
[2005/12/09 14:28:46, 3]
nsswitch/winbindd_async.c:winbindd_dual_lookupname(695)
[19391]: lookupname ECTPP/root
[2005/12/09 14:28:46, 3]
nsswitch/winbindd_async.c:winbindd_dual_lookupname(695)
10x per s .... 600x/minutes .. it's very very big no ?
It's possible
2007 Oct 26
0
Pre-3.023d-Bug in ACL-handling reappears in 3.026a
# wbinfo -Y S-1-5-11
Could not convert sid S-1-5-11 to gid
# wbinfo -Y S-1-5-13
Could not convert sid S-1-5-13 to gid
(S-1-5-11 are the Authenticated Users, S-1-5-13 are the Terminal Server
Users.)
This bug was finally solved in release 3.023d.
Now it is back again.
How can I get this working?
I'm using idmap/tdb - would another idmap-module solve this issue?
The winbind log looks like
2007 Apr 18
1
winbindd/mod_auth_ntlm_winbind.so fail to use workstation credentials (NTLM+SPNEGO)
Hallo,
We protect linux/apache server with mod_auth_ntlm_winbind.so to
authenticate users with their domain accounts. The server is joined into
windows domain (Windows 2003 Server). Apache/mod_auth_ntlm_winbind.so is
configured for NTLM+SPNEGO authentication. So far users can login when
providing valid credentials.
Users login into their windows workstation (Windows XP SP2 IE/Firefox)
with
2009 Nov 17
1
Samba trusts, mapping issue, and pam crap domain
I am running Samba ver 3.0.37 on Solaris 10 (sparc) as a PDC with LDAP for
the backend for both samba and unix accounts. Assume the samba SMBPDC is
called "PDC."
I have also set up a trust with an Windows domain- lets call it
WINDOMAIN- (the PDC for the Windows domain is Win 2003 but is in mixed mode
for backwards compat.) The SAMBA domain trusts the WINDOWS domain, not not
vice
2008 Sep 02
1
Winbind 3.2.3 error with trusted domains
With Samba on Debian Lenny joined to a Server 2003 Native domain that has two incoming non-transitive trusts (users in my domain can authenticate to the foreign domains, but their users cannot authenticate to us) winbind is taking a very long time to authenticate or list users the first time it is used after starting. Winbind blocks for four to five minutes, and anything that touches winbind will
2008 Feb 19
0
idmap_ad and multiple domians
Has anyone else gotten samba functioning with idmap_ad and multiple domains?
In our environment we have a domain with two child domains. There is one child
domain for students, and another for faculty staff. Our servers are joined to
the student domain, but need to be able to enumerate users in the staff domain.
When attempting to lookup a user (wbinfo -i 'NAU\car3') that only exists
2007 Nov 05
0
Samba 3.0.26a, windows 2k3 r2 SFU, problems with auth/nss
Dear samba list,
For some time we've had servers connecting to a w2k3 r2 server via
ADS setup. Wins was working fine and users were able to authenticate.
Recently we've added a GFS like system. This required getting the
UID/GID's unified. Suggestions were made on the samba IRC channel to
install SFU on the PDC. I'm receiving some very strange output.
Usernames/pwd have
2009 Mar 21
1
Windows server 2003 SP2, SFU 3.5 and Samba 3.0.28
Hello list users,
I have been struggling with this combination in the subject field couple
of days now, so I decided to ask for some advice here. Hopefully someone
can point me to a right direction. The ultimate goal for me is to
authenticate users using AD, so that the UID/GID values configured for
users with SFU would also be in use in all our Linux machines. My
understanding is that using
2012 Mar 15
0
winbindd requests failing with NT_STATUS_PIPE_BROKEN
Hi Samba experts,
I am currently investigating an issue with a bigger winbindd
installation which causes all following winbindd requests to fail until
winbindd is restarted. We use a slightly patched version of winbindd
based on Samba 3.5.8. In the used setup the winbindd is joined to an AD
domain and is quite busy with answering winbindd requests of type
PAM_AUTH_CRAP, LOOKUPNAME, GETUSERSIDS,
2010 Jan 21
0
Samba/Winbind 3.4.4 on AIX 5.3 TL 10 does not retrieve ANY User's Secondary Groups
Hi folks !
Has someone any idea on this issue on AIX 5.3 TL 10 with winbind ?
I'm really stuck now ...
I think everything is working pretty well with WINBIND and AD 2k3 ,
but not my most important point : I absolutely need the Secondary groups of
each AD user which get connected to the AIX to use this filter with sudo...
I only get Primary Group (which is by default "Domain Users"
2008 Dec 26
0
Samba PDC, LDAP, IDMAP backend not working
Please help. I've been searching for days, trying nearly everything I can find that seems relevant, but I can't get this working.
I am able to create users, login to Windows systems joined to the SAMBA domain as those users, but filesystem ACLs on Windows Domain Member Servers do not work which I suspect is due to my IDMAP OU is empty.
wbinfo -u returns "Error looking up domain
2005 Sep 22
0
STATUS_BUFFER_OVERFLOW
FC4 with Samba 3.20
Win 2003 AD Domain, no SP1 yet
wbinfo --authenticate=dom+domtest%password yields the following
could not open handle to NETLOGON pipe (error: STATUS_BUFFER_OVERFLOW)
NTLM CRAP authentication for user [dom]\[domtest] returned STATUS_BUFFER_OVERFLOW (PAM: 4)
challenge/response password authentication failed
Could not authenticate user dom+domtest with challenge/response
from
2006 May 30
0
Samba 3.0.22 w2k3 ad+sfu working but ls shows only uidNumber and not uid
Hi Guys,
i have a problem getting id mapping to work as it should. My setup is as
follows:
Samba 3.0.22 on Debian Sarge 3.1 . I 've got SFU 3.5 installed on a W2K3
DC with SP1. I 'm using winbindd in "idmap proxy only" mode. Here 's my
generic smb.conf:
workgroup = METADS
realm = META.XXX.XX "it 's not the real realm, of course !"
security = ADS
2003 Apr 09
0
One user with a problem accessing shares
I have a RedHat 8 box configured as a Samba server using winbind (version
2.2.7 installed from RedHat's rpms.) The server successfully joined my
Win2K domain. Everything works great. Users can log in to the RedHat
server via ssh using their AD accounts. Users can connect to the shares
from their windows machines. All except one. I have one account that has
problems. If I restart
2006 Feb 16
1
kerberos error when users in trusted win2k domain try to browse samba server
I have users from Domain A trying to browse a domain member samba server in
Domain B. Domain A and Domain B are both Windows 2k domains. Domain B has
a one way trust to A. A users can browse Domain B Windows server with no
problem so I no the trust is fine. Samba version is 3.0.21b on RH Linux ES
3.
The winbindd log is giving me the following error:
[2006/02/16 08:28:50, 0]
2005 Jul 22
1
winbind lookup errors
Hello Samba folks,
I have recently begun seeing some disturbing behavior from winbind.
Winbind will fail to look up users and groups. Examples:
The machine is configured to use winbind as a nss module.
"getent passwd <username>" will yield no results.
"wbinfo -n <username>" will yield "Could not lookup name <username>"
"wbinfo -g"
2006 Oct 09
0
wbinfo -r returns only 16 groups (sometimes)
Something we noticed after upgrading from 3.0.14a to 3.0.20 and still a
problem with 3.0.23c on Solaris 9 Sparc. Windows 2003 server running
Active Directory. The examples below are all with 3.0.23c downloaded
last week and compiled from source using gcc 3.3.something. 3.0.14a
works perfectly using the same smb.conf.
We use Samba to do proxy authentication for squid using ntlm_auth and
group