Samba en AD two way trust

Pagina: 1
Acties:

  • metalant
  • Registratie: November 1999
  • Laatst online: 13-01 20:11
Ik probeer een trust te bouwen tussen een AD W2K3 R2 server en een Redhat server met Samba 3.0.14a.

Bij de trust establish krijg ik de volgende foutmelding:

[root@SOLTEC13 root]# net -d 3 -I 192.168.1.250 rpc trustdom establish VSWW
[2006/08/01 16:45:03, 3] param/loadparm.c:lp_load(3907)
lp_load: refreshing parameters
[2006/08/01 16:45:03, 3] param/loadparm.c:init_globals(1321)
Initialising global parameters
[2006/08/01 16:45:03, 3] param/params.c:pm_process(573)
params.c:pm_process() - Processing configuration file "/etc/samba/smb.conf"
[2006/08/01 16:45:03, 3] param/loadparm.c:do_section(3409)
Processing section "[global]"
[2006/08/01 16:45:03, 1] param/loadparm.c:lp_do_parameter(3149)
WARNING: The "min password length" option is deprecated
[2006/08/01 16:45:03, 1] param/loadparm.c:lp_do_parameter(3149)
WARNING: The "enable rid algorithm" option is deprecated
[2006/08/01 16:45:03, 1] param/loadparm.c:lp_do_parameter(3149)
WARNING: The "only user" option is deprecated
[2006/08/01 16:45:03, 1] param/loadparm.c:lp_do_parameter(3149)
WARNING: The "write cache size" option is deprecated
[2006/08/01 16:45:03, 1] param/loadparm.c:lp_do_parameter(3149)
WARNING: The "mangled map" option is deprecated
[2006/08/01 16:45:03, 3] param/loadparm.c:handle_copy(2834)
Copying service from service
[2006/08/01 16:45:03, 0] param/loadparm.c:handle_copy(2846)
Unable to copy service - source not found:
[2006/08/01 16:45:03, 2] param/loadparm.c:handle_include(2813)
Can't find include file
[2006/08/01 16:45:03, 2] lib/interface.c:add_interface(81)
added interface ip=192.168.1.11 bcast=192.168.255.255 nmask=255.255.0.0
Password: XXXXXXXX
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_start_connection(1406)
Connecting to host=NLVS0001
[2006/08/01 16:45:44, 3] lib/util_sock.c:open_socket_out(752)
Connecting to 192.168.1.250 at port 445
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(708)
Doing spnego session setup (blob length=108)
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(733)
got OID=1 2 840 48018 1 2 2
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(733)
got OID=1 2 840 113554 1 2 2
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(733)
got OID=1 2 840 113554 1 2 2 3
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(733)
got OID=1 3 6 1 4 1 311 2 2 10
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup_spnego(740)
got principal=nlvs0001$@VSWW.LOCAL
[2006/08/01 16:45:44, 3] libsmb/ntlmssp.c:ntlmssp_client_challenge(869)
Got challenge flags:
[2006/08/01 16:45:44, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(62)
Got NTLMSSP neg_flags=0x62890215
[2006/08/01 16:45:44, 3] libsmb/ntlmssp.c:ntlmssp_client_challenge(891)
NTLMSSP: Set final flags:
[2006/08/01 16:45:44, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(62)
Got NTLMSSP neg_flags=0x60080215
[2006/08/01 16:45:44, 3] libsmb/ntlmssp_sign.c:ntlmssp_sign_init(319)
NTLMSSP Sign/Seal - Initialising with flags:
[2006/08/01 16:45:44, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(62)
Got NTLMSSP neg_flags=0x60080215
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_session_setup(861)
SPNEGO login failed: No logon interdomain trust account
[2006/08/01 16:45:44, 1] libsmb/cliconnect.c:cli_full_connection(1494)
failed session setup with NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT
Could not connect to server NLVS0001
[2006/08/01 16:45:44, 3] libsmb/cliconnect.c:cli_start_connection(1406)
Connecting to host=NLVS0001
[2006/08/01 16:45:44, 3] lib/util_sock.c:open_socket_out(752)
Connecting to 192.168.1.250 at port 445
[2006/08/01 16:45:44, 0] rpc_client/cli_pipe.c:cli_nt_session_open(1450)
cli_nt_session_open: cli_nt_create failed on pipe \wkssvc to machine NLVS0001. Error was NT_STATUS_ACCESS_DENIED
[2006/08/01 16:45:44, 0] utils/net_rpc.c:rpc_trustdom_establish(4672)
Couldn't not initialise wkssvc pipe
[2006/08/01 16:45:44, 2] utils/net.c:main(897)
return code = -1

Ik heb gezocht in Google, maar krijg het niet voor elkaar.
Heeft iemand een hint?

  • Z-Dragon
  • Registratie: December 2002
  • Laatst online: 14:42
Graag je smb.conf en de output van testparm.

^ Wat hij zegt.


  • metalant
  • Registratie: November 1999
  • Laatst online: 13-01 20:11
Ik heb het nu anders ingericht, met heimdal kerberos.
Daarmee kwam ik al iets verder.

Maandag ben ik weer on-site, dan zal ik de smb.conf en testparm output posten.

  • metalant
  • Registratie: November 1999
  • Laatst online: 13-01 20:11
Na aanpassingen in de krb5.conf werkt het nu prima. kinit doet het niet (commando niet gevonden op server), maar een net ads join gaat wel goed. Gebriukers uit AD kunnen nu athenticeren op de SAMBA server.

Via windbindd moet ik de gebruikers en groepen nog mappen, voorlopig gebruik ik voor de rechten nog de passwd en group files om de id's uit te halen.