-   Linux - Server (
-   -   Whay I can't join WinXP to Samba PDC LDAP domain? (

meksyk13 11-06-2008 03:11 AM

Whay I can't join WinXP to Samba PDC LDAP domain?
I have problem with joining Windows XP Pro to the Samba domain.

workgroup = SOEG.PL
netbios name = SOEG
interfaces = lo, eth0
bind interfaces only = Yes
map to guest = Bad User
obey pam restrictions = Yes
passdb backend = ldapsam:ldap://
passwd program = /usr/local/sbin/smbldap-passwd -u %u
passwd chat = "Changing password for*\nNew password*" %n\n "*Retype new password*" %n\n"
username map = /etc/samba/smbusers
unix password sync = Yes
client NTLMv2 auth = Yes
log level = 5
log file = /var/log/samba/%m.log
time server = Yes
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
printcap name = cups
add user script = /usr/local/sbin/smbldap-useradd -m %u
delete user script = /usr/local/sbin/smbldap-userdel %u
add group script = /usr/local/sbin/smbldap-groupadd -p %g
delete group script = /usr/local/sbin/smbldap-groupdel %g
add user to group script = /usr/local/sbin/smbldap-groupmod -m %g %u
delete user from group script = /usr/local/sbin/smbldap-groupmod -x %g %u
set primary group script = /usr/local/sbin/smbldap-usermod -g %g %u
add machine script = /usr/local/sbin/smbldap-useradd -w -i %u
logon script = scripts\logon.bat
logon path = \\%L\profiles\%U
logon drive = H:
logon home = \\%L\%U
domain logons = Yes
os level = 255
preferred master = Yes
domain master = Yes
wins support = Yes
ldap admin dn = cn=manager,dc=soeg,dc=pl
ldap group suffix = ou=Groups
ldap idmap suffix = ou=Users
ldap machine suffix = ou=Computers
ldap passwd sync = Yes
ldap suffix = dc=soeg,dc=pl
ldap ssl = no
ldap user suffix = ou=Users
idmap uid = 10000-20000
idmap gid = 10000-20000
create mask = 0640
directory mask = 0750
nt acl support = No
cups options = raw
dont descend = /proc,/dev,/etc,/lib,/lost+found,/initrd

comment = Home Directories
valid users = %S, %D%w%S
read only = No
inherit acls = Yes
browseable = No

comment = Network Profiles Service
path = /home/samba/profiles
valid users = %U, "Domain Admins"
force user = %U
read only = No
create mask = 0600
directory mask = 0700
guest ok = Yes
profile acls = Yes
store dos attributes = Yes
browseable = No

comment = NetLogon Scripts
path = /home/samba/netlogon
inherit acls = Yes
browseable = No

comment = Public
path = /home/public
read only = No
inherit acls = Yes

comment = Temporary file space
path = /tmp
read only = No
guest ok = Yes

----end smb.conf----
I sucessfull populate ldap by script smbldap-populate.
/usr/local/sbin/smbldap-populate -u 10000 -g 15000
Populating LDAP directory for domain SOEG.PL (S-1-5-21-4082334872-2015609457-1420611726)
(using builtin directory structure)

entry dc=soeg,dc=pl already exist.
adding new entry: ou=Users,dc=soeg,dc=pl
adding new entry: ou=Groups,dc=soeg,dc=pl
adding new entry: ou=Computers,dc=soeg,dc=pl
adding new entry: ou=Idmap,dc=soeg,dc=pl
adding new entry: uid=Administrator,ou=Users,dc=soeg,dc=pl
adding new entry: uid=nobody,ou=Users,dc=soeg,dc=pl
adding new entry: cn=Domain Admins,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Domain Users,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Domain Guests,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Domain Computers,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Administrators,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Account Operators,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Print Operators,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Backup Operators,ou=Groups,dc=soeg,dc=pl
adding new entry: cn=Replicators,ou=Groups,dc=soeg,dc=pl
adding new entry: sambaDomainName=SOEG.PL,dc=soeg,dc=pl

Please provide a password for the domain Administrator:

DNS and dig. is my dns server.

dig -t any

; <<>> DiG 9.4.2-P1 <<>> -t any
; (1 server found)
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28950
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 1


;; ANSWER SECTION: 600 IN SRV 0 100 389



;; Query time: 0 msec
;; WHEN: Thu Nov 6 09:48:00 2008
;; MSG SIZE rcvd: 115

< 1ms. ok.
Here is the errors when I try to join domain.
"Domain not exists or can not be contacted."

There aren't any error in smbd.log or nmb.log localmessage.log etc.
OS OpenSuSe 11
Where is the bug?

bnkelley 08-26-2014 08:50 AM

Can't join Samba LDAP AD DC domain
I am having a similar issue with Windows 7 workstations. I did not see any replies to this message. Do they still exist here?

New2Linux2 08-26-2014 07:49 PM

bnkelley, this is one of the faux pas' of using a forum like LQ. The original post was made over 5 years ago. The odds of that person using the same version of samba that you are attempting to use are exceedingly slim. Because that person did not receive a reply at that time, it means that there wasn't anybody available at that time that was familiar with samba enough to address his/her issue.

Close to 6 years later there are going to be more people available that are familiar with samba, but not necessarily with an older version. The latest version of samba available (samba4) includes Active Directory Domain Controller functionality that was not included 5 years ago. Also, most of the settings in the OPs smb.conf have been deprecated in the latest version and are not needed.

Your best option is to start a new thread with the following info:
-Distro and version used
-Samba version
-Samba source (repositories/built from source/3rd party pre-configured package available from whom?)
-Contents of your smb.conf file
-Link to any tutorials or instructions that you have already followed to try and get it working on your own
-Any other tweaks, changes, mods that you have implemented, why you implemented them and where you got them from.

Give us the info and we can figure it out collectively. Re-open a 5-6 year old post and your just beating a dead horse that failed to get the attention it needed when it was posted.

Welcome to LQ. I hope we can help get you running.

tombelcher7 08-29-2014 07:34 AM

This might be more specific to Samba 4 and may not address the issue but have you set the DNS address for the Client to point at the PDC Emulator / Domain Controller? Otherwise I think it might come up with such issues????

All times are GMT -5. The time now is 09:47 AM.