LinuxQuestions.org
View the Most Wanted LQ Wiki articles.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 01-15-2013, 06:42 AM   #1
nandon
LQ Newbie
 
Registered: Jan 2013
Posts: 3

Rep: Reputation: Disabled
Users in Domain Admin group (512) don't have admin rights on windows machine


Hi everyone,

My Problem is the following:
Users in the Domain Admins group (512) seem not to authenticate at local windows machines with admin rights.

Distribution: CentOS
Kernel: 2.6.18-308.20.1.el5
Systeme: OpenLDAP slapd 2.3.43, Samba version 3.5.10-0.110.el5_8

# net groupmap list
Domain Admins (S-1-5-21-3285246029-973205485-3622274768-512) -> samba_domain_admins
Domain Users (S-1-5-21-3285246029-973205485-3622274768-513) -> samba_domain_users
Domain Guests (S-1-5-21-3285246029-973205485-3622274768-514) -> samba_domain_guests
Domain Computers (S-1-5-21-3285246029-973205485-3622274768-515) -> samba_domain_computers
Administrators (S-1-5-21-3285246029-973205485-3622274768-544) -> samba_administrator
Account Operators (S-1-5-21-3285246029-973205485-3622274768-548) -> samba_account_operators
Print Operators (S-1-5-21-3285246029-973205485-3622274768-550) -> samba_print_operators
Backup Operators (S-1-5-21-3285246029-973205485-3622274768-551) -> samba_backup_operators
Replicators (S-1-5-21-3285246029-973205485-3622274768-552) -> samba_replicators

Additionally here are some screenshots from our Apache Directory Browser with the user accounts backup and root and the group Domain Admins.
backup
root
samba_domain_admins

If you need further confuration, please ask me.
I would be really happy if we could solve this issue.

Last edited by nandon; 01-15-2013 at 06:53 AM.
 
Old 01-17-2013, 09:31 AM   #2
nandon
LQ Newbie
 
Registered: Jan 2013
Posts: 3

Original Poster
Rep: Reputation: Disabled
has anybody an idea how this issue could be solved?
 
Old 01-21-2013, 07:24 AM   #3
nandon
LQ Newbie
 
Registered: Jan 2013
Posts: 3

Original Poster
Rep: Reputation: Disabled
It seems that this is an synchronization issue.
When I add some ldap-user to the Domain Admins group, a few days later I can login with this user and he is domain admin at a local machine.
But when I remove the user again from Domain Admins then the user still stays domain admin.

Something is still wrong with the system.
Please, if anybody has an idea how this synchronization works please tell me.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 7 local admin rights using a samba 3 domain controller Jacem84 Linux - Server 1 07-24-2010 12:14 AM
LINUX SAMBA SERVER - Temporary domain admin rights for network windows client user. jcdole Linux - Server 0 01-07-2008 02:44 PM
How do I give windows domain users local admin rights - WINBIND basilwt Linux - Networking 1 03-16-2007 11:53 PM
wlassistant says I don't have admin rights hrp2171 Ubuntu 0 12-06-2006 11:20 AM
Samba domain: admin rights problem on XP hitotito Linux - Networking 2 04-26-2005 04:27 PM


All times are GMT -5. The time now is 11:23 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration