Solved

Connecting Windows 7 to Ubuntu / Samba as PDC

Posted on 2013-06-18
9
974 Views
Last Modified: 2013-06-26
I have a network consisting of 12 Windows 7 Professional 64-bit machines and one 64-bit Ubuntu/Samba 3 server configured as a PDC using roaming profiles.

I can join the domain windows XP professional and login using any user from the domain, but when I try using Windows 7 professional 64-bit it will join the domain but after a reboot it says that the trust relationship between the workstation and the server failed and will not login with any user except the local account.

I tried changing the two registry entries listed at samba.org for windows 7, but I still get the same results.   My samba version is 3.6.15

Anyone know the trick to making this work
0
Comment
Question by:Rolling_Tech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
9 Comments
 
LVL 17

Accepted Solution

by:
lruiz52 earned 500 total points
ID: 39258156
check the link below, see if it fixes your problem.

http://praxis.edoceo.com/howto/samba3-windows7
0
 

Author Comment

by:Rolling_Tech
ID: 39258251
I followed the directions there and tried leaving and rejoining the domain, but I still get

"the trust relationship between the workstation and the primary domain controller failed"
0
 
LVL 17

Expert Comment

by:lruiz52
ID: 39258289
Have you tried disabling the windows firewall to test?
0
Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

 

Author Comment

by:Rolling_Tech
ID: 39258391
I tried disabling the firewall on all connections then rebooted.  

At login I got the same message:
"the trust relationship between the workstation and the primary domain controller failed"
0
 
LVL 17

Expert Comment

by:lruiz52
ID: 39258601
0
 

Author Comment

by:Rolling_Tech
ID: 39260345
Tried #9 same results can't login to any domain account.
0
 
LVL 19

Expert Comment

by:jools
ID: 39261917
Are the machine accounts created ok?
0
 

Author Comment

by:Rolling_Tech
ID: 39264282
When I join the domain it creates the machine accounts just fine, but for some reason it doesn't trust them.after a reboot.
0
 

Author Comment

by:Rolling_Tech
ID: 39275763
I finally got past this problem using this registry script:

Windows Registry Editor Version 5.00

; Win7/Samba 3.4.x - Workstation Share
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\lanmanserver\parameters]
"AutoShareWks"=dword:00000001

; Win7/Samba 3.4.x - Compat
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\lanmanworkstation\parameters]
"DNSNameResolutionRequired"=dword:00000000
"DomainCompatibilityMode"=dword:00000001
; AllowPlain ....
; RequireSecuritySignature"=dword:00000000

; Win7/Samba 3.4.x - Compat
; http://us.generation-nt.com/answer/samba-rejecting-auth-request-client-xxx-machine-account-win7-help-206090182.html#206092242
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\netlogon\parameters]
"DisablePasswordChange"=dword:00000001
"RequireSignOrSeal"=dword:00000001
"RequireStrongKey"=dword:00000001

;Turn off last user logged in stuff.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000001

;Disable the security center stuff annoyances
; [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc]
; "Start"=dword:00000003

; Speedup settings
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
"SlowLinkDetectEnabled"=dword:00000000
"DeleteRoamingCache"=dword:00000001
"WaitForNetwork"=dword:00000000
"CompatibleRUPSecurity"=dword:00000001

; Can drive you nuts
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=dword:00000000
"LocalAccountTokenFilterPolicy"=dword:00000001

;Stupid keys that make the windows 7 sysprep crap out.
[HKEY_LOCAL_MACHINE\SYSTEM\Setup]
"RestartSetup"=dword:00000000
"SetupType"=dword:00000000
"SystemSetupInProgress"=dword:00000000
"SetupPhase"=dword:00000000
"CmdLine"=""
"OOBEInProgress"=dword:00000000

_________________________________________________________________________________________________

And then setting "RequireSignOrSeal"=dword:00000000

_________________________________________________________________________________________________
For some reason though it did not map my H:\ drive to home directory, although I can access all the shares without issue.
0

Featured Post

How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up Secure Ubuntu server on VMware 1.      Insert the Ubuntu Server distribution CD or attach the ISO of the CD which is in the “Datastore”. Note that it is important to install the x64 edition on servers, not the X86 editions. 2.      Power on th…
Batch, VBS, and scripts in general are incredibly useful for repetitive tasks.  Some tasks can take a while to complete and it can be annoying to check back only to discover that your script finished 5 minutes ago.  Some scripts may complete nearly …
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question