LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-08-2004, 08:40 AM   #1
Nuclear_Kitten
LQ Newbie
 
Registered: Dec 2002
Location: Wolves, Uk
Distribution: SuSE 9.1 Professional, Morphix
Posts: 12

Rep: Reputation: 0
Samba Locked Down


i'm sorry if this has been sorted before, and if it has please direct me to the posts, but i've been searching for this for hours,


i decided that the accounts department needed a new file server, so having a copy of suse lying around, i built one for them. now i've got samba set up and connected to our Windows 2k (small business server) PDC, kerberos is working fine and from the linux box i can view all the other shares, but for some reason Samba refused to let me authenticate.

when i try to view samba from my XP box i get this (using both domain name, netbios name and ip address)

Code:
Z:\>net view \\LINUX\
System error 5  has occured

Access is denied
and if i use smbclient i get this
Code:
linux:/root/ # smbclient -k -L \\LINUX\
session setup failed: NT_STATUS_LOGON_FAILURE
if i don't use my kerberos ticket, i get asked for a password.. i tried both roots password and the PDC administrators password and i got a failure for both.

if i try to connect through network neighbourhood i get the same thing again, no way of authenticating..

here's my smb.conf dump

Code:
# Samba config file created using SWAT
# from 127.0.0.1 (127.0.0.1)
# Date: 2004/09/08 14:16:39

# Global parameters
[global]
	workgroup = DOM
	realm = DOMAIN.LOCAL
	netbios name = LINUX
	server string = Samba Server
	security = ADS
	auth methods = winbindd
	password server = 192.168.0.1
	local master = No
	ldap suffix = dc=DOMAIN,dc=LOCAL
	idmap uid = 10000-20000
	idmap gid = 10000-20000
	template shell = /bin/bash
	winbind separator = +
	hosts allow = 192.168.0.

[homes]
	comment = Home Directories
	valid users = %S
	read only = No
	create mask = 0640
	directory mask = 0750
	browseable = No

[share]
	comment = accounts
	path = /ashare
	read only = No
	guest ok = Yes
	hosts allow = 192.168.0.
	profile acls = Yes
	map acl inherit = Yes
if you need any more info just let me know

any help would be greatly appreciated
 
Old 09-08-2004, 09:59 AM   #2
Nuclear_Kitten
LQ Newbie
 
Registered: Dec 2002
Location: Wolves, Uk
Distribution: SuSE 9.1 Professional, Morphix
Posts: 12

Original Poster
Rep: Reputation: 0
i searched through my logs and tail log.smbd gives me this
Code:
[2004/09/08 15:55:36, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
  Failed to verify incoming ticket!
i can't figure out why it won't verify the ticket.. even tho' the PDC will

[edit] just upgraded samba, to no avail.. this is getting on my nerves now.. surley sharing should be simple?

Last edited by Nuclear_Kitten; 09-08-2004 at 10:49 AM.
 
Old 09-08-2004, 01:25 PM   #3
kryo_king
LQ Newbie
 
Registered: Sep 2004
Posts: 3

Rep: Reputation: 0
Question

The Biggest problem lies with your windows server! Microsoft small business server only supports 1 server!!!

This is one of the biggest limitations of sbs! Your samba server is theroetically the equivalent of an NT4 BDC, which cannot be connected to and SBS Domain!

There may be the usual Linux hacks to get round this but in my experience it is not possible!

Sorry to be the bearer of bad news!
 
Old 09-09-2004, 02:51 AM   #4
Nuclear_Kitten
LQ Newbie
 
Registered: Dec 2002
Location: Wolves, Uk
Distribution: SuSE 9.1 Professional, Morphix
Posts: 12

Original Poster
Rep: Reputation: 0
oooooooooooohhhhhhhhhhhhhhhhhhhhhhhhhhhhh
that makes sense now then , so i'd be better off just using simple file/print sharing on there..

i'll have to get them to add themselves on the server and do that then
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
samba-share "Directory Locked" Xstack Linux - Software 1 03-20-2005 07:22 PM
Locked out of SU... wiskic10_4 Linux - Newbie 6 12-03-2004 06:49 PM
(DNS change) + (samba) = locked out BrianWGray Linux - Networking 2 08-01-2004 12:05 AM
Locked out of RH 9 carmoda Linux - Security 3 12-16-2003 09:44 AM
locked out of X VioLaToR Linux - Newbie 15 11-12-2002 04:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration