Bluehost.com Web Hosting $6.95

Re: [Samba] OK,I'm In Trouble

This is a discussion on Re: [Samba] OK,I'm In Trouble within the Samba forums, part of the Networking and Network Related category; Greeting Yang, Surely the simpless way to to this is to export your DIT (or a section of DIT) in ...


Go Back   Usenet Forums > Networking and Network Related > Samba

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-16-2006
Cybionet
 
Posts: n/a
Default Re: [Samba] OK,I'm In Trouble

Greeting Yang,

Surely the simpless way to to this is to export your DIT (or a section
of DIT) in a LDIF format file. Make a find/replace of the mismatch SID
in the LDIF file. Delete your DIT (or the section) in LDAP Directory and
reimport the 'new one'. Be sure to have a backup of the original DIT.

I have made the same mistake with phpldapadmin, when I have forgot to
change the domain SID in the configuration. I have a samba PDC with a
domain SID and populate my LDAP with samba user with another domain SID lol.

Robert

>>Hi Everyone,
>>I've been getting this error when trying to login from an XP box to a Samba
>>3 + LDAP PDC, but failed.
>>
>>[2006/03/15 17:48:12, 1] rpc_server/srv_netlog_nt.c:_net_sam_logon(766)
>> _net_sam_logon: user Domain\user has user sid
>>S-1-5-21-3570476861-1302945835-1904156257-3004
>> but group sid S-1-5-21-790863915-1833833965-864709722-513.
>> The conflicting domain portions are not supported for NETLOGON calls
>>
>>I did some research and found this is due to SID mismatch as it is shown
>>with the user sid and group sid
>>
>>net getlocalsid on the dc shows S-1-5-21-3570476861-1302945835-1904156257
>>and net getlocalsid DOMAIN shows S-1-5-21-3570476861-1302945835-1904156257
>>as well.
>>
>>but, net groupmap list shows
>>
>>Domain Admins (S-1-5-21-790863915-1833833965-864709722-512) -> Domain Admins
>>Domain Users (S-1-5-21-790863915-1833833965-864709722-513) -> Domain Users
>>Domain Guests (S-1-5-21-790863915-1833833965-864709722-514) -> Domain Guests
>>Domain Computers (S-1-5-21-790863915-1833833965-864709722-515) -> Domain
>>Computers
>>Administrators (S-1-5-32-544) -> Administrators
>>Account Operators (S-1-5-32-548) -> Account Operators
>>Print Operators (S-1-5-32-550) -> Print Operators
>>Backup Operators (S-1-5-32-551) -> Backup Operators
>>Replicators (S-1-5-32-552) -> Replicators
>>systems (S-1-5-21-3570476861-1302945835-1904156257-3003) -> systems
>>development (S-1-5-21-3570476861-1302945835-1904156257-3005) -> development
>>analytics (S-1-5-21-3570476861-1302945835-1904156257-3007) -> analytics
>>
>>and most of my user/machine accounts have sids like this
>>S-1-5-21-790863915-1833833965-864709722-xxxx.
>>but the smbldap.conf says the sid is set to
>>SID="S-1-5-21-3570476861-1302945835-1904156257"
>>
>>then according to LDAP
>>dn: sambaDomainName=Domain,dc=Domain,dc=com
>>sambaSID: S-1-5-21-3570476861-1302945835-1904156257
>>
>>so this is a certified bloody mess, my question is, does this mean I have to
>>change every instance of sid that's
>>S-1-5-21-790863915-1833833965-864709722-xxxx in LDAP? what's a good way of
>>doing this?
>>
>>Many thanks!
>>
>>- Yang
>>
>>smb.conf & slapd.conf attached
>>
>>


--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 08:15 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0