-   Linux - Server (
-   -   ldap password sync with samba and unix user account (

macpraveen 04-21-2010 10:06 PM

ldap password sync with samba and unix user account
I setup openldap and samba on 9.10. The ubuntu desktop client gets authenticated successfully with the server.

But when I do a passwd on the client, only the ldap passwd is getting changed but not in the samba and the unix user account.

My smb.conf

  passdb backend = ldapsam:ldap://
  ldap suffix = dc=example,dc=local
  ldap user suffix = ou=People
  ldap group suffix = ou=Groups
  ldap admin dn = cn=admin,dc=example,dc=local
  ldap ssl = no
  ldap passwd sync = yes

  add machine script = sudo /usr/sbin/smbldap-useradd -t 0 -w "%u"

  obey pam restrictions = yes

  unix password sync = no

  passwd program = /usr/bin/passwd %u
  passwd chat = *Enter\snew\s*\spassword:* %n\n *Retype\snew\s*\spassword:* %n\n *password\supdated\ssuccessfully* .

  pam password change = yes

When I do a passwd, I get,

Enter login(LDAP) password:
New password:
Re-enter new password:
LDAP password information changed for username
passwd: password updated successfully

But only the ldap password is getting changed and not in the samba and unix user account.

I tried
unix password sync = yes
but same result.

Am I missing something?


macpraveen 04-22-2010 02:44 AM

can some one pls help me out on this?

Blue_Ice 04-22-2010 02:52 AM

This is pretty logical as you are only changing the ldap password with passwd. Passwd doesn't read the samba configuration.
Try to use smbpasswd, that will probably work.

macpraveen 04-22-2010 04:44 AM

Tried with smbpasswd and unix passwd sync yes (in smb.conf) still the same result. But when I type smbpasswd from the terminal (on server) the password is getting changed for both samba and unix account. Do I need to change the passwd chat script in smb.conf?

Where I can see the logs for these password changes? /var/log/samba/log* does not seem to have logged any password changes.

Any ideas?

Blue_Ice 04-22-2010 10:55 AM

I think you have too many references in your config and I am not sure if they can overrule each other.

All times are GMT -5. The time now is 04:28 AM.