?
Solved

Samba setup on Suse 9.2 with Windows 2003 Domain Controller

Posted on 2005-03-17
3
Medium Priority
?
358 Views
Last Modified: 2013-11-30
Hi Guys,

I am going mad I cannot for the life of me get samba to work and it apppears that swat is NOT included with suse 9.2!

I am trying to get samba to talk to my Windows Domain and use the Windows active Directory to authenticate. this for some reason is not happening. can anyone help.
I would prefer to do this without swat, but I maybe being a bit purist!  However I feel I do not learn otherwise.  Can someone give some step by step help.

0
Comment
Question by:sifenwick
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 2

Accepted Solution

by:
this213 earned 1000 total points
ID: 13573164
Samba always has issues talking to Windows based PDC's. If it's possible (it isn't always), you'd do better to have the Linux box act as the PDC and drop the AD alltogether (seriously).

If you have to use the Win2k AD, you're going to need the following:
In the first place, you need samba v 3.0 or better with kerberos and LDAP
You can find your samba version with:
smbclient | grep Version

To check for ldap:
rpm -qa | grep ldap-devel
and, finally, the kerboros development libraries
rpm -qa | grep krb
this last should return at least 3 packages: krb5-devel, krb5-libs and krb5-workstation

If you don't have any of these... well, go get them and install them. I'm not going to get into setting up LDAP since I don't know your layout. The file that you want for Kerberos is /etc/krb5.conf - keep in mind that everything in that file is CaSe sensitive. It should be fairly self explanitory.

Also, if the clock time on the Linux machine is more than 5 minutes off from the time on the windows machine no ticket information will work. There are three wys to deal with this:
  1. Have the Linux server act as a network time server, with the windows machine as a client
  2. Have the windows machine act as a time server for the linux client
  3. Make both systems pull the time from the same 3rd server ( some are listed here - http://ntp.isc.org/bin/view/Servers/NTPPoolServers )

Once you've gotten to this point, you can try:
/usr/kerberos/bin/kinit user@DOMAIN.COM
replacing *user* with a real user and DOMAIN.COM with a real domain (which must be UPPERCASE). If things are working, you'll be prompted for a password. If you enter the correct password, you'll come back to a bash shell, if not, you'll be presented with:
"kinit(v5): Preauthentication failed while getting initial credentials"
or some such.

 Back to Samba. In your smb.conf:
----8<-----
realm = DOMAIN.COM
ads server = 123.123.123.123
security = ADS
encrypt passwords = yes
----8<-----
To Explain further:
DOMAIN.COM - must be the domain name
ads server - should be the resolvable name or IP of the Win2k server (IP address removed the possibility of DNS failure)
security - ADS for Active Directory Service
lastly, passwords must be encrypted.

To add the linux computer to the AD, you need to log into the AD and add it as a user with such privledges, so:
/usr/kerberos/bin/kinit administrator@DOMAIN.COM
then enter your password, then:
/usr/local/samba/bin/net ads join

you should see something like:
Joined 'LINUX_MACHINE_NAME' to realm 'DOMAIN.COM'

To verify this worked, go to the win2k machine and open Active Directory->Users and Computers and look for your linux machine to be listed there.

Once again though, I'd dump the Win2k AD if you're able to do so and just use strictly samba for everything.

THIS
0

Featured Post

Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This program is used to assist in finding and resolving common problems with wireless connections.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Suggested Courses

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question