when i run the command:
smbclient -L
london@ablecreation.com -N
(on the samba machine) it says:
Unknown parameter encountered: "netbios"
Ignoring unknown parameter "netbios"
Connection to
london@ablecreation.com failed
this according to you is improper configuration, so how do i fix this?
I want you to understand that this is not just a samba set up. its a winbind integrated environment. authentication of all the LAN workstations are intended to take place in the ADS which is in a w2k3 server. files configured are:
Krb5-workstation
Krb5-libs
Pam_krb5
Samba-commons
Samba
NTP
And below are the changes in these files:
(1)krb5.conf:
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = ABLECREATION.COM
dns_lookup_realm = true
dns_lookup_kdc = true
[realms]
ABLECREATION.COM = {
kdc = w2k3dc.ablecreation.com:88
admin_server = w2k3dc.ablecreation.com:749
default_domain = ablecreation.com
}
[domain_realm]
.ablecreation.com = ABLECREATION.COM
ablecreation.com = ABLECREATION.COM
[kdc]
profile = /var/kerberos/krb5kdc/kdc.conf
[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
(2)nsswitch.conf:
passwd: files winbind
shadow: files winbind
group: files winbind
protocols: files winbind
services: files winbind
netgroup: files winbind
automount: files winbind
(3)system-auth (in /etc/pam.d directory):
auth required /lib/security/$ISA/pam_env.so
auth sufficient /lib/security/$ISA/pam_unix.so likeauth nullok
auth sufficient /lib/security/$ISA/pam_krb5.so use_first_pass
auth sufficient /lib/security/$ISA/pam_winbind.so use_first_pass
auth required /lib/security/$ISA/pam_deny.so
account required /lib/security/$ISA/pam_unix.so broken_shadow
account sufficient /lib/security/$ISA/pam_succeed_if.so uid < 100 quiet
account [default=bad success=ok user_unknown=ignore] /lib/security/$ISA/pam_krb5.so
account [default=bad success=ok user_unknown=ignore] /lib/security/$ISA/pam_winbind.so
account required /lib/security/$ISA/pam_permit.so
account requisite /lib/security/$ISA/pam_succeed_if.so user ingroup unix
password requisite /lib/security/$ISA/pam_cracklib.so retry=3
password sufficient /lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
password sufficient /lib/security/$ISA/pam_krb5.so use_authtok
password sufficient /lib/security/$ISA/pam_winbind.so use_authtok
password required /lib/security/$ISA/pam_deny.so
session required /lib/security/$ISA/pam_limits.so
session required /lib/security/$ISA/pam_unix.so
session optional /lib/security/$ISA/pam_mkhomedir.so skel=etc/skel/ umask=0027
session optional /lib/security/$ISA/pam_krb5.so
(4)smb.conf:
[global]
workgroup = ABLECREATION
netbios name = London
server string = Samba Server
security = ads
realm = ABLECREATION.COM
encrypt passwords = yes
smb passwd file = /etc/samba/smbpasswd
allow trusted domains = yes
unix password sync = Yes
passwd program = /usr/bin/passwd %u
passwd chat = *New*password* %n\n *Retype*new*password* %n\n
*passwd:*all*authentication*tokens*updated*successfully*
pam password change = yes
obey pam restrictions = yes
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
dns proxy = no
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
winbind use default domain = yes
winbind separator = #
winbind enum users = yes
winbind enum groups = yes
template shell=/bin/bash
template homedir = /home/%U
Is anything wrong in any of these fileds?