Two-way Trust relationship between Samba 3 and AD 2008 R2

Posted by Romain on Server Fault See other posts from Server Fault or by Romain
Published on 2012-12-16T22:32:22Z Indexed on 2012/12/16 23:05 UTC
Read the original article Hit count: 759

Did somebody already make a two-way trust relationship between Samba 3 and AD ?

  • I've got Samba 3.5 domain (ES02) controller and AD 2008 R2 domain (ES01) controller.

  • Trust domain seems to be ok:

Trusted domains list:

ES01 S-1-5-21-1816646249-803782145-3669927669

Trusting domains list:

ES01 S-1-5-21-1816646249-803782145-3669927669

  • I can login AD domain workstation with a Samba user account and access to AD domain workstation shares from Samba workstation with Samba user account.

  • BUT, when I try to access to Samba domain workstation shares from AD domain workstation with AD account (test), I've got this:

[2012/12/16 23:00:26.146090, 5] auth/auth.c:268(check_ntlm_password) check_ntlm_password: winbind authentication for user [test] FAILED with error NT_STATUS_NO_SUCH_USER [2012/12/16 23:00:26.146123, 2] auth/auth.c:314(check_ntlm_password) check_ntlm_password: Authentication for user [test] -> [test] FAILED with error NT_STATUS_NO_SUCH_USER

  • When I try to access samba share with the Administrator account that I create on both side with same password, I've got this:

[2012/12/16 22:57:22.701841, 1] rpc_server/srv_pipe_hnd.c:1602(serverinfo_to_SamInfo_base)
_netr_LogonSamLogon: user ES01\Administrator has user sid S-1-5-21-1816646249-803782145-3669927669-500 but group sid S-1-5-21-3405883886-2425668597-4100599511-513. The conflicting domain portions are not supported for NETLOGON calls

  • I don't know if winbind is working because of this:

wbinfo -u

root 
nobody
smb3user 
administrator
  • "wbinfo -u" should list all local and trusted users, no ?

Any fresh idea would be appreciated, I've been reading all the Internet for 1 week...

Regards,

© Server Fault or respective owner

Related posts about active-directory

Related posts about samba

  • Unable to connect to Samba printer

    as seen on Ask Ubuntu - Search for 'Ask Ubuntu'
    I have a headless Ubuntu 12.04 server for files and printers. It shares files via Samba just fine. However, the HP PSC-750xi connected to the server via USB is not accessible from my Ubuntu 12.04 laptop. I can browse for it in the Printing control panel, but any attempt to authenticate my ID to the… >>> More

  • Samba folder is gone

    as seen on Ask Ubuntu - Search for 'Ask Ubuntu'
    I seem to have some issues sharing folders from my Ubuntu 12.04 machine to a Win7 machine. After playing around with the settings, I decided to revert to Samba's original setting by reinstalling it: sudo apt-get purge samba sudo rm -rf /etc/samba/ /etc/default/samba sudo apt-get install samba just… >>> More

  • Samba on OS X 10.6.4

    as seen on Server Fault - Search for 'Server Fault'
    I just updated from 10.6.3 to 10.6.4, and now my Samba shares won't mount and won't allow access into the directories. In the logs, I've started to get the following errors, any idea what might have gone wrong? 2010/06/25 15:54:27, 0, pid=13848] /SourceCache/samba/samba-235.4/samba/source/passdb/secrets… >>> More

  • OpenLDAP and Samba, can't log onto Samba share from Windows

    as seen on Server Fault - Search for 'Server Fault'
    The former jackass IT-guy that I'm taking over for had a Samba share setup on a Fedora server that uses our OpenLDAP server to authenticate users who want to log in from Windows. We recently added a new employee and I jumped through the LDAP hoops to add them to the system. However, I can't seem… >>> More

  • Windows 7 Samba issue

    as seen on Server Fault - Search for 'Server Fault'
    We have a strange samba issue affecting only one user. Our samba setup is as follow : Red Hat Enterprise Linux Server release 5.4 (Tikanga) - Samba Server Samba version 3.0.33-3.14.el5 - Samba version Domain Controller WIN2008R2 Standard -… >>> More