LinuxQuestions.org
Latest LQ Deal: Linux Power User Bundle
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 07-09-2013, 09:00 AM   #1
Krampus
LQ Newbie
 
Registered: Jul 2013
Posts: 1

Rep: Reputation: Disabled
Running Samba/Winbind with two domains


First: I'm not a Linux administrator, and I don't know what I don't know (if you know what I mean).

We have this server here at work, named FAXSERVER, running the Red Hat Enterprise Linux ES release 3 (Taroon Update 8) distro, along with Samba version 3.0.9-1.3E.12. The directory /home/faxes/ is shared out to our domain via Samba/Winbind.

This is primarily a Windows network. Windows domain controller, etc. I'm on this primary domain (DOMAIN1). And there is another domain. It's a trusted domain (DOMAIN2). I want users authenticating to DOMAIN2 to be able to access /home/faxes/ on this server as well. I can't seem to be able to make it happen.

Here's what I've (clumsily) tried so far:

SAMBA:

The permissions for /home/faxes/ are as follows: drwxrwsr-x 57 uucp 10001 4096 Jul 24 2012 faxes. Looks like everyone has read/execute permission, and the file owner and members of the file's group additionally have write permission.

There are currently three Samba users set up, according to /etc/samba/smbusers: root (mapped to 'administrator' and 'admin'), nobody (mapped to 'guest', 'pcguest', and 'smbguest'), and mike (mapped to 'mike').

The Samba configuration (location: /etc/samba/smb.conf) for /faxes/ is currently as follows:
comment = FAX faxes
path=/home/faxes
writable = yes
printable = no
public = yes
guest ok = yes
create mask = 0665
Prior to me looking into it, the "guest ok" flag was set to no. I changed it to "yes" (since "public=yes" seems to make this redundant) and restarted the Samba service (service smb restart). It doesn't appear that this resolved the issue, but I wanted to try it.

WINBIND:

The 'wbinfo -g' command gives me a list of all user groups, but they're all under DOMAIN1\*. There are no DOMAIN2\* groups listed.

The 'wbinfo -m' command gives me a list of all trusted domains: FAXSERVER, BUILTIN, and DOMAIN2. So DOMAIN2 is trusted by FAXSERVER.

I'm also able to query both DOMAIN1 and DOMAIN2 from FAXSERVER:

[root@faxserver home]# wbinfo -D DOMAIN1
Name : DOMAIN1
Alt_Name : DOMAINNAME.COM
SID : S-1-3-59-7490224-282867100-4786781930
Active Directory : Yes
Native : Yes
Primary : Yes
Sequence : 62852289
[root@faxserver home]# wbinfo -D DOMAIN2
Name : DOMAIN2
Alt_Name : acrometis.com
SID : S-1-5-21-3827589627-1874523873-1381929582
Active Directory : No
Native : No
Primary : No
Sequence : -1
IN SUMMARY:

I don't really know what I'm doing. This is likely self-evident. Is it a matter of changing the "Active Directory" flag under DOMAIN2 from "No" to "Yes"? If so, how would I go about doing that?

Or is this an impossible task, and I'll just end up chasing my tail?
 
Old 07-10-2013, 06:39 PM   #2
Ser Olmy
Senior Member
 
Registered: Jan 2012
Distribution: Slackware
Posts: 2,404

Rep: Reputation: Disabled
It seems your Samba server is communicating properly with the DOMAIN1 domain, and is even able to see the trust. But none of that really matters, since it seems no users from either domain have any explicit rights on the share or the /home/faxes directory (unless getfacl /home/faxes returns something interesting).

Do you get any error messages when you try to access the share from a Windows computer in DOMAIN2? Does net view \\faxserver show the shares on the server? Does dir \\faxserver\sharename return an error message?

Any error messages in the Samba logs when you attempt to access the share?

Are you mapping unknown users or bad passwords to Guest in Samba?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba/Winbind issue - Can't get user and group info from sub domains thesunlover Linux - Networking 0 04-09-2013 06:44 PM
Multiple domains in LDAP and 1 samba server for all domains, what to do? xnomad Linux - Server 1 11-14-2008 10:12 AM
Samba + Winbind + AD Thakowbbery Linux - Networking 6 06-28-2007 02:49 AM
Samba + Winbind velu.net Linux - Software 3 11-07-2006 01:24 AM
samba with winbind kaasi Red Hat 2 10-26-2003 03:48 PM


All times are GMT -5. The time now is 05:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration