Review your favorite Linux distribution.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 03-01-2005, 10:58 AM   #1
Registered: Oct 2004
Location: Canada
Distribution: Ubuntu
Posts: 330

Rep: Reputation: 30
Domain Admins not Local ADmins - Samba 3.0.7


I have succesfully setup a Samba server as a Domain Controller. I have about 7 users. Wow!

I have three Windows XP machines that logon to the domain. Now with Windows XP there is this thing called group policy editor, how to I make policies and apply to them to everyone on the network?

Secondly, I have a user called "admin" which is really root in linux. This user has domain admin priviliges (it can create/edit/delete users using NT User Manager). But what I want in addition is for this user to have local admin privileges, so I can modify the file system, hardware etc....



I tried to map it to a group:
net groupmap modify ntgroup="Domain Admins" unixgroup=ntadmins
net groupmap modify ntgroup="Domain Users" unixgroup=users
net groupmap modify ntgroup="Domain Guests" unixgroup=nobody
net groupmap modify ntgroup="Administrators" unixgroup=ntadmins
Old 03-01-2005, 11:51 AM   #2
Registered: Oct 2004
Location: Canada
Distribution: Ubuntu
Posts: 330

Original Poster
Rep: Reputation: 30
Some more information:

Windows XP reports that in properties of the Administrators group:

david (renamed administrator account)

Lublink\Domain Admins (S-1-5-21-4128833642-285588081-677358102-512)

Some output from Linux Commands (note that superman is renamed root account)
web:~ # net groupmap list

System Operators (S-1-5-32-549) -> -1
Domain Guests (S-1-5-21-4128833642-285588081-677358102-514) -> nobody
Replicators (S-1-5-32-552) -> -1
Guests (S-1-5-32-546) -> -1
Power Users (S-1-5-32-547) -> -1
Print Operators (S-1-5-32-550) -> -1
Administrators (S-1-5-32-544) -> ntadmins
Domain Admins (S-1-5-21-4128833642-285588081-677358102-512) -> ntadmins
Account Operators (S-1-5-32-548) -> -1
Domain Users (S-1-5-21-4128833642-285588081-677358102-513) -> users
Backup Operators (S-1-5-32-551) -> -1
Users (S-1-5-32-545) -> -1

web:~ # net rpc group MEMBERS "Domain Admins"

web:~ # cat /etc/group | tail -1
Old 03-01-2005, 12:05 PM   #3
Registered: Oct 2004
Location: Canada
Distribution: Ubuntu
Posts: 330

Original Poster
Rep: Reputation: 30
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\superman>net user admin /domain
The request will be processed at a domain controller for domain LUBLINK.

User name superman
Full Name root
User's comment
Country code 000 (System Default)
Account active Yes
Account expires Never

Password last set 2/24/2005 4:27 PM
Password expires Never
Password changeable 2/24/2005 4:27 PM
Password required Yes
User may change password Yes

Workstations allowed All
Logon script scripts\logon.bat
User profile \\pdc\Profiles\superman
Home directory \\pdc\superman
Last logon Never

Logon hours allowed All

Local Group Memberships
Global Group memberships *Domain Admins
The command completed successfully.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
To the admins: chris318 Slackware 8 03-02-2005 09:42 PM
Contact with school-net admins wanted, for migrating discussion. pingu Linux - General 1 02-08-2005 12:52 PM
Easy way to setup admins to create/maintain users jimdaworm Linux - Networking 6 10-04-2004 03:43 AM
Joining a machine from another domain to my linux samba domain acummins Linux - Networking 0 09-13-2003 08:07 AM
for all Slack admins... zeky Linux - Distributions 2 08-25-2002 12:02 PM > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:50 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration