SUSE 9.1 joinn windows NT 4.0 domain
I'm trying to get a SUSE 9.1 workstation to join my windows domain, using logins from my windows domains. this might be foolish, or it might be something better attempted with xandrOS, but here's what i've encountered so far:
users from my domain show up in the login box, but when i attempt to login with those users, i get a box that says "xsession: login for domain\user is disabled" and has an "okay" button. i found this thread: http://lists.suse.com/archive/suse-l...-Dec/1633.html and i made those changes. now i can log in fine, but when KDE attempts to start up i get three errors: /home/usr/.DCOPserver_k2node-16__0 check to see if your DCOPserver is running "Will not save configuration Configuration file "/home/usr/.kde/share/config/kwinrc" not writable Configuration file "/home/usr/.kde/share/config/kdeglobals" not writable Please contact your system admin." $HOME is not writable in theory, chown -R youruser:yourgroup /home/usr/.kde should fix that, but since these are domain users, they have no local files, and i can't change permissions to those users, since they don't exist locally. the reason i'm trying to do this is so that the users won't have to repeatedly authenticate when they want to browse network resources. if there's a better way to do this, that would be useful, too. |
update
ok.. i was able to do
chown -R DOMAIN\user:DOMAIN\group /home/group/usr/.kde which fixed the errors inside of .kde also, in /etc/pam.d/login template homedir=/home/%D+%U should have been template homedir=/home/%D/%U but i still get "could not read network connection list ... please check that .DCOPserver is running" |
Your issue revolves around domain user and group mapping. You have to explictly map your NT users to linux users(same with groups) instead of just chowning the individual directories. NT domain ids are really weird strings(S-1-2-000-...) that obviously linux doesn't understand. Go look in samba documentation for "domain group maps" and "domain user maps".
|
Quote:
p.s. that's the most obnoxious signature i've ever seen |
The sig comes from before LQ had an affero button. Thanks for noticing, I removed it...
|
All times are GMT -5. The time now is 12:53 PM. |