You need security=domain instead of security=server. You will also need to create a machine account in Server Manager on your NT Domain Controller, and join the Samba server to the NT Domain using:
smbpasswd -j NT -r PDC
I also suggest using winbindd instead of managing a smbusers file for UNIX-to-NT username mappings, in case you aren't already. Winbindd is configured adding two UID & GID ranges in smb.conf, and modifying /etc/nsswitch.conf to allow the 'passwd' & 'group' databases to also be read from the NT DC and act as though the NT users were local to the Linux machine. Works like a dream.
|