<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Using Samba in Linux-AD Integration</title>
	<atom:link href="http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:13:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Rajsekhar</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-51778</link>
		<dc:creator>Rajsekhar</dc:creator>
		<pubDate>Mon, 03 Oct 2011 06:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-51778</guid>
		<description>Thanks Slowe for your imm response.

I&#039;m hoping the same from last 2 weeks that any readers will give me a +ve response but the same as you .

But i never lost the hope .....

waiting for the person who can help me ...

and thanks for moderating my post...</description>
		<content:encoded><![CDATA[<p>Thanks Slowe for your imm response.</p>
<p>I&#8217;m hoping the same from last 2 weeks that any readers will give me a +ve response but the same as you .</p>
<p>But i never lost the hope &#8230;..</p>
<p>waiting for the person who can help me &#8230;</p>
<p>and thanks for moderating my post&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-51761</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Fri, 30 Sep 2011 17:20:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-51761</guid>
		<description>Rajsekhar, I really can&#039;t help you---I didn&#039;t do very much testing with Winbind, and the testing that I did do was almost 5 years ago. Perhaps another reader can help.

Good luck to you!</description>
		<content:encoded><![CDATA[<p>Rajsekhar, I really can&#8217;t help you&#8212;I didn&#8217;t do very much testing with Winbind, and the testing that I did do was almost 5 years ago. Perhaps another reader can help.</p>
<p>Good luck to you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rajsekhar</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-51748</link>
		<dc:creator>Rajsekhar</dc:creator>
		<pubDate>Thu, 29 Sep 2011 10:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-51748</guid>
		<description>and when i change the permissions other than &quot;750&quot; the winbind service is going to dead state but the pid is still reserved.

please help me ....

Thanks for help ...... in advance.... please help me ....</description>
		<content:encoded><![CDATA[<p>and when i change the permissions other than &#8220;750&#8243; the winbind service is going to dead state but the pid is still reserved.</p>
<p>please help me &#8230;.</p>
<p>Thanks for help &#8230;&#8230; in advance&#8230;. please help me &#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rajsekhar</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-51747</link>
		<dc:creator>Rajsekhar</dc:creator>
		<pubDate>Thu, 29 Sep 2011 10:23:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-51747</guid>
		<description>Help Required Please!!!!

 I have winbind, samba,HTTPS,appserver, everything is in running mode.

I did all the configurations as above and also some other config changes specified in some other parts of web. 

The command &quot;net rpc join -U Administrator&quot; joined fine.
 But when given &quot;wbinfo -u&quot; the users in the local machine are showed up not the DC machines user.
 But the linux machine is showing up in the DC machine under computers added.

i&#039;m getting the SSO pop-up asking for the username and password.
But when i give the credentials &quot;Internal server Error&quot; is coming .


When i see the error_log of IBMHTTPS it is saying 



[2011/09/28 18:32:30, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63)
  Got NTLMSSP neg_flags=0xa2088207
[2011/09/28 18:32:38, 3] libsmb/ntlmssp.c:ntlmssp_server_auth(739)
  Got user=[administrator] domain=[] workstation=[SIMPRO359] len1=24 len2=24
[2011/09/28 18:32:38, 0] utils/ntlm_auth.c:winbind_pw_check(515)
  Login for user []\[administrator]@[SIMPRO359] failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/cache/samba/winbindd_privileged are set correctly.]
[Wed Sep 28 18:32:38 2011] [error] [client 172.18.2.153] (20014)Internal error: ntlm_auth reports Broken Helper: BH NT_STATUS_ACCESS_DENIED, referer: http://msi-vmpl3cord10:81/
[2011/09/28 18:32:38, 0] utils/ntlm_auth.c:manage_squid_ntlmssp_request(776)
  NTLMSSP BH: NT_STATUS_ACCESS_DENIED


Can any one please help me it&#039;s already 2 weeks over my dead line... please ......</description>
		<content:encoded><![CDATA[<p>Help Required Please!!!!</p>
<p> I have winbind, samba,HTTPS,appserver, everything is in running mode.</p>
<p>I did all the configurations as above and also some other config changes specified in some other parts of web. </p>
<p>The command &#8220;net rpc join -U Administrator&#8221; joined fine.<br />
 But when given &#8220;wbinfo -u&#8221; the users in the local machine are showed up not the DC machines user.<br />
 But the linux machine is showing up in the DC machine under computers added.</p>
<p>i&#8217;m getting the SSO pop-up asking for the username and password.<br />
But when i give the credentials &#8220;Internal server Error&#8221; is coming .</p>
<p>When i see the error_log of IBMHTTPS it is saying </p>
<p>[2011/09/28 18:32:30, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63)<br />
  Got NTLMSSP neg_flags=0xa2088207<br />
[2011/09/28 18:32:38, 3] libsmb/ntlmssp.c:ntlmssp_server_auth(739)<br />
  Got user=[administrator] domain=[] workstation=[SIMPRO359] len1=24 len2=24<br />
[2011/09/28 18:32:38, 0] utils/ntlm_auth.c:winbind_pw_check(515)<br />
  Login for user []\[administrator]@[SIMPRO359] failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/cache/samba/winbindd_privileged are set correctly.]<br />
[Wed Sep 28 18:32:38 2011] [error] [client 172.18.2.153] (20014)Internal error: ntlm_auth reports Broken Helper: BH NT_STATUS_ACCESS_DENIED, referer: <a href="http://msi-vmpl3cord10:81/" rel="nofollow">http://msi-vmpl3cord10:81/</a><br />
[2011/09/28 18:32:38, 0] utils/ntlm_auth.c:manage_squid_ntlmssp_request(776)<br />
  NTLMSSP BH: NT_STATUS_ACCESS_DENIED</p>
<p>Can any one please help me it&#8217;s already 2 weeks over my dead line&#8230; please &#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-48657</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 17 Jun 2010 11:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-48657</guid>
		<description>Request help !

i have an linux open suse version 11.1 and trying to join in an Win 2003 R2 server...
but at i&#039;ve got the following error in BASH

(net join -W krafft.local -I 192.168.2.1 -U Administrator%passwrd)

[2010/06/17 15:44:12,  0] utils/net_rpc_join.c:net_rpc_join_newstyle(393)
Error in domain join verification (credential setup failed): NT_STATUS_INVALID_COMPUTER_NAME
Unable to join domain

____________________________________________________________
winbindd running
nsbd running
smb running
SAMBA version (smbclient -V) = 3.2.4-5.2-1985-SUSE-CODE11

any suggestions?</description>
		<content:encoded><![CDATA[<p>Request help !</p>
<p>i have an linux open suse version 11.1 and trying to join in an Win 2003 R2 server&#8230;<br />
but at i&#8217;ve got the following error in BASH</p>
<p>(net join -W krafft.local -I 192.168.2.1 -U Administrator%passwrd)</p>
<p>[2010/06/17 15:44:12,  0] utils/net_rpc_join.c:net_rpc_join_newstyle(393)<br />
Error in domain join verification (credential setup failed): NT_STATUS_INVALID_COMPUTER_NAME<br />
Unable to join domain</p>
<p>____________________________________________________________<br />
winbindd running<br />
nsbd running<br />
smb running<br />
SAMBA version (smbclient -V) = 3.2.4-5.2-1985-SUSE-CODE11</p>
<p>any suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guoping</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-47638</link>
		<dc:creator>guoping</dc:creator>
		<pubDate>Fri, 05 Mar 2010 15:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-47638</guid>
		<description>The paramter &#039;use kerberos keytab = true&#039; did not work on my RHEL client.

[root@ ]# net ads join -U Administrator
[2010/03/05 15:06:50,  0] param/loadparm.c:7444(lp_do_parameter)
  Ignoring unknown parameter &quot;use kerberos keytab&quot;
Enter Administrator&#039;s password:
Using short domain name -- ADTEST
Joined &#039;WODAO2&#039; to realm &#039;adtest.corp.net&#039;
No DNS domain configured for wodao2. Unable to perform DNS Update.
DNS update failed!

Here is testparm output (unknown parameter):

[root@wodao2 pam.d]# testparm
Load smb config files from /etc/samba/smb.conf
Unknown parameter encountered: &quot;use kerberos keytab&quot;
Ignoring unknown parameter &quot;use kerberos keytab&quot;
Loaded services file OK.</description>
		<content:encoded><![CDATA[<p>The paramter &#8216;use kerberos keytab = true&#8217; did not work on my RHEL client.</p>
<p>[root@ ]# net ads join -U Administrator<br />
[2010/03/05 15:06:50,  0] param/loadparm.c:7444(lp_do_parameter)<br />
  Ignoring unknown parameter &#8220;use kerberos keytab&#8221;<br />
Enter Administrator&#8217;s password:<br />
Using short domain name &#8212; ADTEST<br />
Joined &#8216;WODAO2&#8242; to realm &#8216;adtest.corp.net&#8217;<br />
No DNS domain configured for wodao2. Unable to perform DNS Update.<br />
DNS update failed!</p>
<p>Here is testparm output (unknown parameter):</p>
<p>[root@wodao2 pam.d]# testparm<br />
Load smb config files from /etc/samba/smb.conf<br />
Unknown parameter encountered: &#8220;use kerberos keytab&#8221;<br />
Ignoring unknown parameter &#8220;use kerberos keytab&#8221;<br />
Loaded services file OK.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JohnJ</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-42593</link>
		<dc:creator>JohnJ</dc:creator>
		<pubDate>Wed, 03 Dec 2008 22:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-42593</guid>
		<description>Win2k3 and Win2k3 R2 do not appear to support the service principal credentials as you would expect.

A samba net ads join will create a keytab, will populate it with SPNs, will create an AD computer account, and will populate the serviceprincipalnames field for it -- however, I have not found a mechanism by which they are directly usable.

IE: kinit -kt /etc/krb5.keytab host/hostname.myfqdn should work, but with SPNs it fails.

What apparently needs to be done, and what ktpass does, is to map the userprincipalname under the account, but unfortunately AD only supports one userprincipalname per user account.

You can create a valid keytab entru by doing net ads join and using the createupn field accordingly, it would seem.</description>
		<content:encoded><![CDATA[<p>Win2k3 and Win2k3 R2 do not appear to support the service principal credentials as you would expect.</p>
<p>A samba net ads join will create a keytab, will populate it with SPNs, will create an AD computer account, and will populate the serviceprincipalnames field for it &#8212; however, I have not found a mechanism by which they are directly usable.</p>
<p>IE: kinit -kt /etc/krb5.keytab host/hostname.myfqdn should work, but with SPNs it fails.</p>
<p>What apparently needs to be done, and what ktpass does, is to map the userprincipalname under the account, but unfortunately AD only supports one userprincipalname per user account.</p>
<p>You can create a valid keytab entru by doing net ads join and using the createupn field accordingly, it would seem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Drew</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-36615</link>
		<dc:creator>Drew</dc:creator>
		<pubDate>Wed, 26 Mar 2008 20:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-36615</guid>
		<description>What&#039;s up guys... I&#039;ve got a quick question (hopefully). I&#039;ve got samba up and running and joined the ad domain and all that business. 

The issue i&#039;m having is when I log on to my shared drive &#039;MyShare&#039; it works fine but i see it creates a directory for me called drew (ad domain name)... i&#039;ve tried to log in but can&#039;t. But I can log into the regular samba share..any ideas?</description>
		<content:encoded><![CDATA[<p>What&#8217;s up guys&#8230; I&#8217;ve got a quick question (hopefully). I&#8217;ve got samba up and running and joined the ad domain and all that business. </p>
<p>The issue i&#8217;m having is when I log on to my shared drive &#8216;MyShare&#8217; it works fine but i see it creates a directory for me called drew (ad domain name)&#8230; i&#8217;ve tried to log in but can&#8217;t. But I can log into the regular samba share..any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor Meghesan</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-35085</link>
		<dc:creator>Victor Meghesan</dc:creator>
		<pubDate>Wed, 16 Jan 2008 04:28:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-35085</guid>
		<description>Hi Arthur,

More important that the disto version you&#039;re running is the Samba version, you can find this using for ex. net -V

You should first check that you can reach the domain CG.DC.FOR.ad.corp.com by using for ex. ping IP.ADDR.OF.CG.DC.FOR.ad.corp.com, if you will use -I, or that you can resolve and reach the host DNS.NAME.OF.CG.DC.FOR.ad.corp.com, if you will use -S, for ex. host/nslookup/dig DNS.NAME.OF.CG.DC.FOR.ad.corp.com and ping DNS.NAME.OF.CG.DC.FOR.ad.corp.com

you can find the list of SRV&#039;s using AD DNS and query for SRV records of type _ldap._tcp.gc._msdcs.

Also if something is not working, restart by first deleting from AD the incomplete entry for the Samba machine and don&#039;t use -S with IP, use -S name or use -I IP, or use -I IP and -S name in the net cmd</description>
		<content:encoded><![CDATA[<p>Hi Arthur,</p>
<p>More important that the disto version you&#8217;re running is the Samba version, you can find this using for ex. net -V</p>
<p>You should first check that you can reach the domain CG.DC.FOR.ad.corp.com by using for ex. ping IP.ADDR.OF.CG.DC.FOR.ad.corp.com, if you will use -I, or that you can resolve and reach the host DNS.NAME.OF.CG.DC.FOR.ad.corp.com, if you will use -S, for ex. host/nslookup/dig DNS.NAME.OF.CG.DC.FOR.ad.corp.com and ping DNS.NAME.OF.CG.DC.FOR.ad.corp.com</p>
<p>you can find the list of SRV&#8217;s using AD DNS and query for SRV records of type _ldap._tcp.gc._msdcs.</p>
<p>Also if something is not working, restart by first deleting from AD the incomplete entry for the Samba machine and don&#8217;t use -S with IP, use -S name or use -I IP, or use -I IP and -S name in the net cmd</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arthur</title>
		<link>http://blog.scottlowe.org/2006/12/19/using-samba-in-linux-ad-integration/comment-page-1/#comment-34955</link>
		<dc:creator>Arthur</dc:creator>
		<pubDate>Sat, 05 Jan 2008 23:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=389#comment-34955</guid>
		<description>Help !!

I&#039;m have OpenSuse 10.3 and im trying to join it to a Win2k ADS. When i try to net join -S IP.ADDR -U administrator%password i get: utils/net_rpc_join.c:net_rpc_join_newstyle(350)
Error in domain join verification (credential setup failed): NT_STATUS_INVALID_COMPUTER_NAME Unable to join domain COMBI.  The strange thing is I get computerobject in the ADS. I have the same configuration as your previous articles. Kerberos is working fine.

any ideas??</description>
		<content:encoded><![CDATA[<p>Help !!</p>
<p>I&#8217;m have OpenSuse 10.3 and im trying to join it to a Win2k ADS. When i try to net join -S IP.ADDR -U administrator%password i get: utils/net_rpc_join.c:net_rpc_join_newstyle(350)<br />
Error in domain join verification (credential setup failed): NT_STATUS_INVALID_COMPUTER_NAME Unable to join domain COMBI.  The strange thing is I get computerobject in the ADS. I have the same configuration as your previous articles. Kerberos is working fine.</p>
<p>any ideas??</p>
]]></content:encoded>
	</item>
</channel>
</rss>

