LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 12-22-2008, 09:43 PM   #1
jax8
Member
 
Registered: Feb 2004
Location: Australia
Distribution: Ubuntu, Fedora 10
Posts: 632

Rep: Reputation: 31
SAMBA and LDAP - net getlocalsid shows error NT_STATUS_UNSUCCESSFUL


{SOLVED}
Look here - https://help.ubuntu.com/8.10/serverg...-configuration




I have been following the tutorial here http://ubuntuforums.org/showthread.php?t=640760&page=34

I have been getting the following error when I run the
Code:
net getlocalsid
command.

Code:
myuser@mycomputer:/etc/samba$ sudo net getlocalsid
[2008/12/23 10:35:05,  0] lib/smbldap_util.c:smbldap_search_domain_info(310)
  smbldap_search_domain_info: Adding domain info for MYDOMAIN failed with NT_STATUS_UNSUCCESSFUL
SID for domain MYDOMAIN is: S-1-5-21-1153465165-1443174390-2997034973
Here is the section of my smb.conf file that is causing the trouble.


Code:
#######################################################################
#COPY AND PASTE THE FOLLOWING UNDERNEATH "OBEY PAM RESTRICTIONS = NO"
#######################################################################
#
#	Begin: Custom LDAP Entries
#
ldap admin dn = cn=admin,dc=myserver,dc=mydomain,dc=co,dc=th
ldap suffix = dc=myserver,dc=mydomain,dc=co,dc=th
ldap group suffix = ou=Groups
ldap user suffix = ou=Users
ldap machine suffix = ou=Computers
ldap idmap suffix = ou=Users
; Do ldap passwd sync
ldap passwd sync = Yes
passwd program = /usr/sbin/smbldap-passwd %u
passwd chat = *New*password* %n\n *Retype*new*password* %n\n *all*authentication*tokens*updated*
add user script = /usr/sbin/smbldap-useradd -m "%u"
ldap delete dn = Yes
delete user script = /usr/sbin/smbldap-userdel "%u"
add machine script = /usr/sbin/smbldap-useradd -w "%u"
add group script = /usr/sbin/smbldap-groupadd -p "%g"
delete group script = /usr/sbin/smbldap-groupdel "%g"
add user to group script = /usr/sbin/smbldap-groupmod -m "%u" "%g"
delete user from group script = /usr/sbin/smbldap-groupmod -x "%u" "%g"
set primary group script = /usr/sbin/smbldap-usermod -g "%g" "%u"
domain logons = yes
#
#	End: Custom LDAP Entries
#
#####################################################
#STOP COPYING HERE!
#####################################################
When I change the line that reads
Code:
ldap suffix = dc=myserver,dc=mydomain,dc=co,dc=th
to
Code:
ldap suffix =
I no longer get this error. Does any one know why this is????

Thanks


------------------------------------------------------------

ALSO

When I run
Code:
 smbldap-populate -u 30000 -g 30000
I get the following error regardless of if I get the above error or not.

Code:
entry dc=myserver,dc=mydomain,dc=co,dc=th already exist. 
entry ou=Users,dc=myserver,dc=mydomain,dc=co,dc=th already exist. 
entry ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th already exist. 
entry ou=Computers,dc=myserver,dc=mydomain,dc=co,dc=th already exist. 
entry ou=Idmap,dc=myserver,dc=mydomain,dc=co,dc=th already exist. 
adding new entry: uid=root,ou=Users,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #4 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 55.
adding new entry: uid=nobody,ou=Users,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #4 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 83.
adding new entry: cn=Domain Admins,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 95.
adding new entry: cn=Domain Users,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 106.
adding new entry: cn=Domain Guests,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 117.
adding new entry: cn=Domain Computers,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 128.
adding new entry: cn=Administrators,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=thh
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 173.
adding new entry: cn=Account Operators,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 195.
adding new entry: cn=Print Operators,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 206.
adding new entry: cn=Backup Operators,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 217.
adding new entry: cn=Replicators,ou=Groups,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: objectClass: value #2 invalid per syntax at /usr/sbin/smbldap-populate line 499, <GEN1> line 228.
adding new entry: sambaDomainName=EPSRV,dc=myserver,dc=mydomain,dc=co,dc=th
failed to add entry: invalid DN at /usr/sbin/smbldap-populate line 499, <GEN1> line 236.

Please provide a password for the domain root: 
/usr/sbin/smbldap-passwd: user root doesn't exist

Last edited by jax8; 12-23-2008 at 01:50 AM.
 
Old 06-06-2009, 02:35 PM   #2
linx win
Member
 
Registered: Jan 2004
Posts: 390

Rep: Reputation: 31
Hello

Would you please explain how you did solve this issue based on this thread:
https://help.ubuntu.com/8.10/serverg...-configuration

I tried to follow the TLS section, but slapd would not start if I select TLS.
 
Old 01-20-2011, 07:50 AM   #3
archtoad6
Senior Member
 
Registered: Oct 2004
Location: Houston, TX (usa)
Distribution: MEPIS, Debian, Knoppix,
Posts: 4,727
Blog Entries: 15

Rep: Reputation: 231Reputation: 231Reputation: 231
1. That link is now broken:
Quote:
The requested URL /8.10/serverguide/C/openldap-server.html was not found on this server.

2. Would anyone who can, try to help here:
http://www.linuxquestions.org/questi...pulate-857300/
TIA.


FWIW, both posters have fairly recent LQ activity.

Last edited by archtoad6; 01-20-2011 at 07:52 AM.
 
Old 06-17-2013, 02:35 PM   #4
micho1978
LQ Newbie
 
Registered: Jul 2009
Posts: 2

Rep: Reputation: 0
Smile Re : SAMBA and LDAP - net getlocalsid shows error NT_STATUS_UNSUCCESSFUL Reply

Hi,
This is works for me very fine. Indeed some ldap version I guest need some parameters.

For suffix by example : ldap suffix = dc=domain,dc=com will not work
You can specify the name of the machine (hostname) : mypc.domain.com

So the new suffix will be : ldap suffix = dc=mypc,dc=domain,dc=com => It works

If you have also TLS error just add : ldap ssl = off in smb.conf

Thanks Hope it helps you.
 
  


Reply

Tags
slapd


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
while i open net beans it shows tis error vidhyaprakash85 Linux - Software 3 11-21-2008 12:38 PM
SMBLDAP-TOOLS SAMBA LDAP . Problem when filling ldap. jcdole Linux - Server 0 06-07-2008 11:41 AM
samba-ldap pdc server error candri Linux - Server 0 09-13-2007 08:47 AM
error in xp login in debian etch + samba +ldap xcore_on Linux - Networking 1 06-01-2007 08:31 AM
net getlocalsid error rulirahm Linux - Networking 1 09-15-2005 05:30 PM


All times are GMT -5. The time now is 01:23 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration