Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 12th July 2005, 10:42 PM
penguinman Offline
Registered User
 
Join Date: Jul 2005
Location: Nottingham, London, Salisbury
Age: 28
Posts: 1
Logging onto a domain with windbindd

I have set up a Fedora Core 2 box as a WinNT PDC using Samba 3.0.14a. The set up seems to work fine for Windoze machines, as I have managed to add my WinXP computer to the domain with relatively few problems. However, despite a huge amount of effort I can't get my other Fedora 2 box to log onto the server using winbind. I successfully joined it to the domain, but it will only allow the domain's root user to log on over the network. No other domain users are authenticated, and Fedora tells me that an incorrect username/password were entered when I trying logging on as a domain user other than root.

Samba seems to be working fine on both PCs and I can use the wbinfo command to get various details such as domain users and groups.

My smb.conf file on the samba client is:

----

[global]

workgroup = NETWORK
server string = Samba %v Server (Fedora Core 2)
security = domain
encrypt passwords = true
password server = *
printcap name = /etc/printcap
log file = /var/log/samba/%m.log
max log size = 50
socket options = TCP_NODELAY SO_SNDBUF=8192 SO_RCVBUF=8192
os level = 18
local master = no
dns proxy = no
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431

# Winbind Settings

winbind uid = 10000-20000
winbind gid = 10000-20000
template shell = /bin/bash
winbind separator = /
winbind use default domain = no
template homedir = /home/%U
winbind enum users = yes
winbind enum groups = yes

[homes]
comment = Home Directories
browseable = no
writeable = yes

[printers]
comment = All Printers
path = /var/spool/samba
browseable = no
# Set public = yes to allow user 'guest account' to print
printable = yes

----

The pam.d login file is:

----

#%PAM-1.0
auth required pam_securetty.so
auth required pam_stack.so service=system-auth
auth required pam_nologin.so
#auth sufficient pam_winbind.so
#auth sufficient pam_unix.so use_first_pass
account required pam_stack.so service=system-auth
password required pam_stack.so service=system-auth
session required pam_selinux.so multiple
session required pam_stack.so service=system-auth
session optional pam_console.so
session required pam_mkhomedir.so skel=/etc/skel/ umask=0077

----

And pam.d system-auth:

----

#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth required /lib/security/$ISA/pam_env.so
auth sufficient /lib/security/$ISA/pam_unix.so likeauth nullok
auth sufficient /lib/security/$ISA/pam_winbind.so use_first_pass
auth required /lib/security/$ISA/pam_deny.so

account sufficient /lib/security/$ISA/pam_succeed_if.so uid < 100
account required /lib/security/$ISA/pam_unix.so
account [default=bad success=ok user_unknown=ignore] /lib/security/$ISA/pam_winbind.so

password requisite /lib/security/$ISA/pam_cracklib.so retry=3
password sufficient /lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
password sufficient /lib/security/$ISA/pam_winbind.so use_authtok
password required /lib/security/$ISA/pam_deny.so

session required /lib/security/$ISA/pam_limits.so
session required /lib/security/$ISA/pam_unix.so

----

Anyone got any ideas? This is really bugging me. I've checked and double checked everything, but knowing me I've made some glaringly obvious stupid mistake somewhere...

Thanks in advance
Reply With Quote
  #2  
Old 12th July 2005, 11:07 PM
MrC Offline
Registered User
 
Join Date: Jul 2005
Posts: 31
Hi..
Igot on stage further than this but no quite there I can get a user to logon (form Core 4 client) but errors bring up the GUI (no local rights).. I used LDAP on the server (to share user info) and smbldap-tools to configure it.. Then on the client I used authconfig... (see my other post for more info)...

Sorry not a total answer but it might help
Reply With Quote
Reply

Tags
domain, logging, windbindd

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Domain Controller: Primary Domain Controller vuthy Servers & Networking 4 18th March 2008 04:20 AM
sendmail Sender address rejected: Domain Sender address rejected: Domain not found) grosminet Servers & Networking 1 21st October 2006 12:44 AM
passwd: can't get local yp domain: Local domain name not set powah Security and Privacy 0 26th May 2006 01:31 PM
FC4 stop logging after Webmin installed ( bandwidth logging ) simonxyz EOL (End Of Life) Versions 0 15th November 2005 10:48 AM
Logging into domain during bootup mihunt Servers & Networking 1 12th October 2005 04:09 AM


Current GMT-time: 21:17 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat