PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : Samba als PDC



rthill
13.11.01, 18:58
Hi,

ich habe ein Problem mit meinem Domain Logon, wenn ich von Windows 2000 aus einloggen will.

hier mal meine smb.conf:# Global parameters
[global]
coding system =
client code page = 850
code page directory = /etc/codepages
workgroup = LRB.DOM
netbios name = LRB.DOM
netbios aliases =
netbios scope =
server string = netlogon Server
interfaces =
bind interfaces only = No
security = USER
encrypt passwords = Yes
update encrypted = No
allow trusted domains = Yes
hosts equiv =
min passwd length = 3
map to guest = Never
null passwords = No
obey pam restrictions = No
password server =
smb passwd file = /etc/samba/smbpasswd
root directory =
pam password change = No
passwd program = /usr/bin/passwd
passwd chat = *new*password* %n\n *new*password* %n\n *changed*
passwd chat debug = No
username map = /etc/samba/smbusers
password level = 4
username level = 4
unix password sync = No
restrict anonymous = No
lanman auth = Yes
use rhosts = No
log level = 0
syslog = 1
syslog only = No
log file = /var/log/samba/log.%m
max log size = 500
timestamp logs = Yes
debug hires timestamp = No
debug pid = No
debug uid = No
protocol = NT1
large readwrite = No
max protocol = NT1
min protocol = CORE
read bmpx = No
read raw = Yes
write raw = Yes
nt smb support = Yes
nt pipe support = Yes
nt acl support = Yes
announce version = 4.5
announce as = NT
max mux = 50
max xmit = 65535
name resolve order = lmhosts host wins bcast
max packet = 65535
max ttl = 259200
max wins ttl = 518400
min wins ttl = 21600
time server = No
change notify timeout = 60
deadtime = 0
getwd cache = Yes
keepalive = 300
lpq cache time = 10
max smbd processes = 0
max disk size = 0
max open files = 10000
read size = 16384
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
stat cache size = 50
total print jobs = 0
load printers = Yes
printcap name = /etc/printcap
enumports command =
addprinter command =
deleteprinter command =
show add printer wizard = Yes
os2 driver map =
strip dot = No
character set =
mangled stack = 50
stat cache = Yes
domain admin group =
domain guest group =
machine password timeout = 604800
add user script =
delete user script =
logon script =
logon path = \\%N\%U\profile
logon drive =
logon home = \\%N\%U
domain logons = Yes
os level = 65
lm announce = Auto
lm interval = 60
preferred master = True
local master = Yes
domain master = True
browse list = Yes
enhanced browsing = Yes
dns proxy = Yes
wins proxy = No
wins server =
wins support = Yes
wins hook =
kernel oplocks = Yes
oplock break wait time = 0
add share command =
change share command =
delete share command =
config file =
preload =
lock dir = /var/lock/samba
utmp directory =
wtmp directory =
utmp = No
default service =
message command =
dfree command =
valid chars =
remote announce =
remote browse sync =
socket address = 0.0.0.0
homedir map = auto.home
time offset = 0
NIS homedir = No
source environment =
panic action =
hide local users = No
host msdfs = No
winbind uid =
winbind gid =
template homedir = /home/%D/%U
template shell = /bin/false
winbind separator = winbind cache time = 15
winbind cache time = 15
comment =
path =
alternate permissions = No
username =
guest account = nobody
invalid users =
valid users =
admin users =
read list =
write list =
printer admin =
force user =
force group =
read only = Yes
create mask = 0744
force create mode = 00
security mask = -1
force security mode = -1
directory mask = 0755
force directory mode = 00
directory security mask = -1
force directory security mode = -1
inherit permissions = No
guest only = No
guest ok = No
only user = No
hosts allow =
hosts deny =
status = Yes
max connections = 0
min print space = 0
strict sync = No
sync always = No
write cache size = 0
max print jobs = 1000
printable = No
postscript = No
printing = bsd
print command = lpr -r -P%p %s
lpq command = lpq -P%p
lprm command = lprm -P%p %j
lppause command =
lpresume command =
queuepause command =
queueresume command =
printer name =
printer driver =
printer driver file = /etc/printers.def
printer driver location =
default case = lower
case sensitive = No
preserve case = Yes
short preserve case = Yes
mangle case = No
mangling char = ~
hide dot files = Yes
hide unreadable = No
delete veto files = No
veto files =
hide files =
veto oplock files =
map system = No
map hidden = No
map archive = Yes
mangled names = Yes
mangled map =
browseable = Yes
blocking locks = Yes
fake oplocks = No
locking = Yes
oplocks = Yes
level2 oplocks = Yes
oplock contention limit = 2
posix locking = Yes
strict locking = No
share modes = Yes
copy =
include =
exec =
preexec close = No
postexec =
root preexec =
root preexec close = No
root postexec =
available = Yes
volume =
fstype = NTFS
set directory = No
wide links = Yes
follow symlinks = Yes
dont descend =
magic script =
magic output =
delete readonly = No
dos filemode = No
dos filetimes = No
dos filetime resolution = No
fake directory create times = No
vfs object =
vfs options =
msdfs root = No

[netlogon]
comment = Domain Logon Service
path = /home/netlogon
browseable = No

[homes]
comment = Home Directories
browseable = No

[Public]
comment = Public Stuff
path = /usr/local/public
read only = No
create mask = 0777

[Profiles]
comment = profiles
path = /usr/local/samba/profiles
read only = No



Dies läuft auf einem RedHat 7.0
Vielen Dank für weitere Hilfe.

SmackTV
13.11.01, 20:50
Hi,

Erst einmal zwei allgemeine Fragen (das hat mir nämlich als Information gefehlt): Welche Samba Version nutzt du? Und welches Servicepack läuft auf deinem Win2k?

Hier nun warum diese Frage!!!

Solltest du Win2k mit SP2 laufen lassen kannst du einen Domain-Logon mit Samba Versionen unter 2.2.1 vergessen. Hast du 'nen Win2k mit kein SP oder SP1 sollte es auch ab Samba 2.2.0 funzen.

MFG, SmackTV

Shadow18
13.11.01, 20:54
Ich habe Samba und SP 2 win 2000 bei mir sagt er auch immer fehler geht es mit SP1? Unter win 95 kommt der Fehler Ungültiger Parmeter

-caretaker-
14.11.01, 16:50
Hi Du,
kenn Dich zwar nicht, aber ich habe SuSE 7.3, Win2k SP2 .... und es läuft :-)
habs heute morgen um 3.00 Uhr hingekriegt.

------------------hier meine smb.conf----------------------

# Samba config file created using SWAT
# from 0.0.0.0 (0.0.0.0)
# Date: 2001/11/14 17:42:15

# Global parameters
[global]
coding system =
client code page = 850
code page directory = /usr/local/samba/lib/codepages
workgroup = STOLLIS
netbios name = SERVER-1 (PDC)
netbios aliases =
netbios scope =
server string = Samba-Server - %R - %m
interfaces =
bind interfaces only = No
security = USER
encrypt passwords = Yes
update encrypted = No
allow trusted domains = Yes
hosts equiv =
min passwd length = 3
map to guest = Never
null passwords = No
obey pam restrictions = No
password server =
smb passwd file = /usr/local/samba/private/smbpasswd
root directory =
pam password change = No
passwd program =
passwd chat = *new*password* %n\n *new*password* %n\n *changed*
passwd chat debug = Yes
username map = /etc/samba/user.map
password level = 8
username level = 8
unix password sync = Yes
restrict anonymous = No
lanman auth = Yes
use rhosts = No
log level = 5
syslog = 1
syslog only = No
log file = //var/log/sambalog.%m-%I
max log size = 2000
timestamp logs = Yes
debug hires timestamp = No
debug pid = No
debug uid = Yes
protocol = NT1
large readwrite = No
max protocol = NT1
min protocol = CORE
read bmpx = No
read raw = Yes
write raw = Yes
nt smb support = Yes
nt pipe support = Yes
announce version = 4.5
announce as = NT
max mux = 50
max xmit = 65535
name resolve order = lmhosts host wins bcast
max packet = 65535
max ttl = 86400
max wins ttl = 518400
min wins ttl = 21600
time server = Yes
change notify timeout = 60
deadtime = 0
getwd cache = Yes
keepalive = 300
lpq cache time = 10
max smbd processes = 0
max disk size = 1000000
max open files = 10000
read size = 32768
socket options = TCP_NODELAY SO_KEEPALIVE SO_BROADCAST IPTOS_LOWDELAY
stat cache size = 50
use mmap = Yes
total print jobs = 0
load printers = No
printcap name = /etc/printcap
disable spoolss = No
enumports command =
addprinter command =
deleteprinter command =
show add printer wizard = Yes
os2 driver map =
strip dot = No
character set = ISO8859-1
mangled stack = 100
stat cache = Yes
domain admin group = @root,@admin
domain guest group =
machine password timeout = 604800
add user script =
delete user script =
logon script = scripts\%U.bat
logon path = \\server-1\Netlogon\%U
logon drive = Y:
logon home = \\server-1\profiles\%m\%U
domain logons = Yes
os level = 255
lm announce = Auto
lm interval = 60
preferred master = True
local master = Yes
domain master = True
browse list = Yes
enhanced browsing = Yes
dns proxy = Yes
wins proxy = Yes
wins server =
wins support = Yes
wins hook =
kernel oplocks = Yes
oplock break wait time = 0
add share command =
change share command =
delete share command =
config file =
preload =
lock dir = /usr/local/samba/var/locks
default service =
message command =
dfree command = df -h
valid chars =
remote announce =
remote browse sync =
socket address = 0.0.0.0
homedir map =
time offset = 0
NIS homedir = No
source environment =
panic action = reboot
hide local users = No
host msdfs = No
winbind uid =
winbind gid =
template homedir = /home/%D/%U
template shell = /bin/false
winbind separator = \
winbind cache time = 15
winbind enum users = Yes
winbind enum groups = Yes
comment =
path =
alternate permissions = Yes
username = root,dennis,miriam,eric
guest account = nobody
invalid users = nobody,guest,gast,anonymous
valid users = @users,@ftpvalid,@root
admin users = dennis,administrator,root
read list = @users,@ftpvalid,@root
write list = @ftpvalid,@root
printer admin =
force user =
force group =
read only = Yes
create mask = 0744
force create mode = 00
security mask = 0777
force security mode = 00
directory mask = 0755
force directory mode = 00
directory security mask = 0777
force directory security mode = 00
inherit permissions = No
guest only = No
guest ok = Yes
only user = No
hosts allow =
hosts deny = 192.168.1.
status = Yes
nt acl support = Yes
max connections = 0
min print space = 0
strict allocate = No
strict sync = No
sync always = No
write cache size = 0
max print jobs = 1000
printable = No
postscript = No
printing = cups
print command = lpr -r -P%p %s
lpq command = lpq -P%p
lprm command = lprm -P%p %j
lppause command =
lpresume command = lp -i %p-%j -H resume
queuepause command = disable %p
queueresume command = enable %p
printer name = hpdj815c-raw
use client driver = No
printer driver =
printer driver file = /usr/local/samba/lib/printers.def
printer driver location =
default case = lower
case sensitive = No
preserve case = Yes
short preserve case = Yes
mangle case = No
mangling char = ~
hide dot files = Yes
hide unreadable = No
delete veto files = No
veto files =
hide files =
veto oplock files =
map system = Yes
map hidden = Yes
map archive = Yes
mangled names = Yes
mangled map =
browseable = Yes
blocking locks = Yes
fake oplocks = No
locking = Yes
oplocks = Yes
level2 oplocks = Yes
oplock contention limit = 2
posix locking = Yes
strict locking = No
copy =
include =
exec =
preexec close = No
postexec =
root preexec =
root preexec close = No
root postexec =
available = Yes
volume =
fstype = NTFS
set directory = No
wide links = Yes
follow symlinks = Yes
dont descend =
magic script =
magic output =
delete readonly = No
dos filemode = No
dos filetimes = No
dos filetime resolution = No
fake directory create times = No
vfs object =
vfs options =
msdfs root = No

[homes]
comment = Heimatverzeichnis
path = /hdb1-dtla/public
admin users = dennis,nb3400,administrator
write list = @users,@ftpvalid
read only = No
directory mask = 0750
max connections = 10
browseable = No

[public]
comment = Public %m - %I
path = /hdb1-dtla/public
admin users = dennis,nb3400,administrator
read only = No
directory mask = 0750
max connections = 10

[non-public]
comment = non-public %m - %I
path = /hdc1-ic35l040/non_public
read list = @ftpvalid
read only = No
create mask = 0770
force create mode = 0770
force directory mode = 0770
guest ok = No
max connections = 10
browseable = No

[root]
comment = ROOT
path = //
valid users = dennis
read list = @ftpvalid
read only = No
create mask = 0700
directory mask = 0700
guest ok = No
hosts allow = 172.22.0.
hosts deny = 192.168.
max connections = 2
browseable = No

[Eric Privat]
comment = eric-secure %m - %I
path = /hdb1-dtla/eric-secure
username = eric
guest account =
valid users = eric
read list = @ftpvalid
read only = No
create mask = 0700
security mask = 0700
directory mask = 0700
directory security mask = 0700
guest ok = No
only user = Yes
max connections = 2

[Dennis Privat]
comment = dennis-secure %m - %I
path = /hdb1-dtla/dennis-secure
username = dennis
guest account =
valid users = dennis
read list = @ftpvalid
read only = No
create mask = 0700
directory mask = 0700
guest ok = No
only user = Yes
max connections = 2

[backup]
comment = Backup %m - %I
path = /hdc1-ic35l040/backup
username = dennis,miriam,eric
guest account =
valid users = dennis,miriam,eric
read list = @ftpvalid
read only = No
create mask = 0770
directory mask = 0770
guest ok = No
only user = Yes
max connections = 3

[netlogon]
comment = Netlogon
path = /netlogon
guest account =
invalid users =
valid users = @machines,@users,@ftpvalid
admin users = dennis,root,administrator
read list =
write list =
create mask = 0760
security mask = 0740
directory mask = 0760
guest ok = No
max connections = 4

[profiles]
comment = profiles
path = /home/profiles
username = root,dennis,miriam,eric,administrator
invalid users = nobody,guest,gast,anonymous,@nogroup
valid users = @users,@ftpvalid,@root,@machines
read only = No
create mask = 0600
nt acl support = No
browseable = No

----------------------------ende---------------------------

ich empfehle auf jedenfall die Maschinenkonten - wenn zuviel rumprobiert wurde - zu löschen und neu anzulegen. Vergesst Null-Password für Maschinen-Konten nicht.
und wenn ihr mit "smbpasswd -a user" den user anlegt, sollte man ihn auch enablen.
:)


irgendwie hab ich das problem dass die Profile der einzelnen User sich immer gegenseitig überschreiben. Was ich bräuchte wär ein Befehl oder ähnliches damit samba praktisch im Verzeichnis "\\server-1\home\profiles\athlon900" auf jedenfall noch userordner anlegt. Am besten Automatisch. Samba sieht ja schliesslich welcher User sich in diesem Moment einloggt.

ich denke "passwd program" oder "add user script" wäre der richtige Ansatz... bloss was schreib ich rein?

Das 2. Problem dass ich habe ist, dass der Server nicht mehr in der Netzwerkumgebung auftaucht... :(

Kann jemand helfen?

-caretaker-
14.11.01, 16:52
bin grad fett beschäftigt.

Wärt Ihr so nett und würdet ne carbon-copy an folgende mail-addi schicken?


dennis@linuxrulez.dynu.com

Vielen Dank

SmackTV
15.11.01, 20:40
Hi,

es hatte sich bei mir ein kleiner Wortunreim eingeschlichen. Sorry. Was ich meinte war, das aller Versionen vor 2.2.1 Probleme mit dem SP2 haben...

MFG, SmackTV

-caretaker-
02.12.01, 13:37
Hi @ll.

Ich werde zwar von Samba in die Domäne aufgenommen,
wenn ich mich im W2k aber abmelde und in der Liste "den PDC" auswähle,
sagt dieser dass er kein computerkonto gefunden hat oder das passwort falsch ist.

- ich werde in die domäne aufgenommen
- kann mich dort aber nicht anmelden...


hääääää?


weis da jemand was?:confused:

mikrobi
24.03.02, 16:13
Hallo caretaker,

in deiner smb.conf steht
path = /home/profiles

probiers doch mal damit path = /home/profiles/%U
und dann sollten sich Benutzerprofile nicht mehr überschreiben :-).
Bei Dir steht das unter logon home nicht unter profiles. Logon Home ist aber nicht das Nutzerprofile sondern das Homeverzeichnis des Users. Oder hab ich da was übersehen?

ralf - isi
25.03.02, 20:24
hi

ist nur ein versuch allen antwort zu geben. (kann nicht alles im kopf behalten - alzheimer lässt grüssen):
profile ablegen auf dem samba-server mit:
logon path = \\%N\profiles\%U\profile (nur als beispiel)
so wird kein profil überschrieben.
domäne login bracht:
- username in passwd und smbpasswd
- maschinen-account in passwd mit $ am schluss (ohne passwort)
- maschinen-account in smbpasswd eröffnen und -m nicht vergessen

logo - rechte richtig gesetzt in den freigaben die samba zu verfügung stellen sollte.

am besten samba-version 2.2.2 oder 2.2.3a einsetzen
welche fragen hab ich nun wieder vergessen?! *grübel

gruss ralf

ps habe auch mail :)