1. Change the server from PDC to Single Server and back again. In a
way I've tried that by removing the /etc/smb.conf and /var/samba.
2. Set the password of the directory administrator a couple of times
and then it should work. Tried that but it didn't work for me.
At this mailing list in August 2005:
3. A tip from Michael Bartosh: /usr/bin/opendirectorypdbconfig -c
set_authenticator -r admin-name -p xxxxx -n /LDAPv3/127.0.0.1
Tried it, but didn't work.
At the moment I believe it may be the file
/var/db/samba/secrets.tdb
since I didn't delete it when I reconfigured Samba. I was also
surprised that the SID of the Samba domain didn't change when I
reconfigured Samba.
My question is then: Is it safe to rename this file and and then
start Samba again? Or will the domain loose it SID and I have to add
all the Win clients again? But if I run the command:
sudo net getlocalsid [DOMAIN]
before the renaming and then run the command:
net setlocalsid SID
after. Will this procedure do it?
Regards,
Lars-Gunnar Persson
On 22. aug. 2006, at 14.24, Lars-Gunnar Persson wrote:
I tried now to create a new user [winadmin] with all privileges and
tried to add a Win 2k computer but I got the same error.
I also tried to create a group "Domain Admins" and add the new
admin account to this group. Checked that the user was a member of
the group with the command:
net user info |winadmin]
and got back the result
Domain Admins
I also updated the group mapping for "Domain Admins", to be sure
that the group is a Domain group and not a local group, with the
command
net groupmap modify ntgroup="Domain Admins"
unixgroup=domainadmins type=domain
Tested the Win client again, but it still didn't work.
Thank you for your reply!
Lars-Gunnar Persson
On 22. aug. 2006, at 13.51, email@hidden wrote:
I would create a new domain admin account that will allow you to
add machines to the domain. Experience tells me this is a
privilege issue with the admin account.
On Tuesday, August 22, 2006, at 06:07AM, Lars-Gunnar Persson <lars-
email@hidden> wrote:
I'm not able to add Win clients to my domain anymore. I receive an
error on the PC (2000 or XP):
"The following error occurred attempting to join the domain
"[DOMAIN]":
Logon failure: unknown user name or password."
But I am able to log on to the server when accessing shares and
printers. This error message only appears when joining the domain.
And on the Mac OS X 10.4.7 server I get the following in my
log.smbd:
where DOMAIN is my domain name and tmpadmin is a user account with
all privileges.
I've been googling (oops, I'm not sure I can say that :-)) and
reading all the documentation I could find, but without any luck.
What's strange is that when the server was installed I was able to
add a lot of clients. Then I've probably done something wrong and
now
I'm getting into trouble. So, what have I been doing?
Editing /etc/smb.conf
* Adding the line: logon home = \\[FILESERVER]\%U
* Removing the line: #logon path = \\%N\profiles\%u
Adding a group mapping with the command net
net groupmap add ntgroup="Domain Admins" unixgroup="admin"
type=domain
net groupmap cleanup
but also reverted back to default group mappings.
Reconfigured the Windows service by removing /var/samba and /etc/
smb.conf. Didn't help.
Editing /etc/openldap/slapd.conf:
* Adding a schema from ldapuserdata ( a Squirrelmail plug-in) but
has removed this schema now.
Are there other services/configuration files I have to look at?
Do you have ANY tips? This is starting to get urgent for me now!
Regards,
Lars-Gunnar Persson
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/macos-x-server/groveton%
40mac.com
This email sent to email@hidden
Lars-Gunnar Persson
Nansen Environmental and Remote Sensing Center
Thormøhlensgt. 47, N-5006 BERGEN, NORWAY
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/macos-x-server/lars-
email@hidden