ckeding
Goto Top

Windows 7 Samba Domänen beitritt klappt nicht, mit Ubuntu, Samba u. Zimbra

Hallo zusammen,

ich versuche seit Tagen mich an einer Samba3 Domäne anzumelden, mit der Fehlermeldung: "Ein an das System angeschlossene Gerät funktioniert nicht"

Server: Ubuntu (14.04) mit Samba (4.1.6) und Zimbra (8.6) für das LDAP.
Client: Windows 7 Prof. SP1

Zu Testzwecken ist die Windows Firewall auf dem Client deaktiviert.
Der Server hat keine Firewall Regeln und befindet sich im selben Netzwerk.


Beide sind über das Netzwerk untereinander anpingbar über die IP und DNS.

Im LDAP (Zimbra) wird der Maschinen Account erstellt.
dn: uid=PC-TEST$,ou=machines,dc=mailserver-test,dc=xxx,dc=de
control: 1.2.840.113556.1.4.805 false
changetype: delete

#!RESULT OK
#!CONNECTION ldap://mailserver-test.xxx.de:389
#!DATE 2015-08-11T13:14:06.723
dn: uid=xxx-test$,ou=machines,dc=mailserver-test,dc=xxx,dc=de
control: 1.2.840.113556.1.4.805 false
changetype: delete

Sowie der lokale Account `getent passwd`
pc-test$:x:1002:1000:machine account,,,:/home/pc-test$:/bin/false

Samba Konfiguration
        interfaces = lo eth0
        workgroup = 
        netbios name = 
        os level = 33
        preferred master = yes
        server string = %h server (Samba, Ubuntu)
        wins support = yes
        dns proxy = no
        name resolve order = wins bcast hosts
        log file = /var/log/samba/%I.log
        log level = 3
        max log size = 1000
        syslog only = no
        syslog = 0
        panic action = /usr/share/samba/panic-action %d
        security = user
        encrypt passwords = true
        ldap passwd sync = yes
        passdb backend = ldapsam:ldap://xxx:389/
        ldap admin dn = "uid=zimbra,cn=admins,cn=zimbra"
        ldap suffix = dc=mailserver-test,dc=xxx,dc=de
        ldap group suffix = ou=groups
        ldap user suffix = ou=people
        ldap machine suffix = ou=machines
        obey pam restrictions = no
        passwd program = /usr/bin/passwd %u
        passwd chat = *Enter\snew\sUNIX\spassword:* %n\n *Retype\snew\sUNIX\spassword:* %n\n *password\supdated\ssuccessfully* .
        domain logons = yes
        logon path = \\%L\profiles\%U\%a
        logon home = \\%L\%U
        logon drive = P:
        add user script = /usr/sbin/adduser --quiet --disabled-password --gecos "" %u
        add machine script = /usr/sbin/adduser -n -g machines -c Machine -d /var/lib/nobody -s /bin/false %u
        socket options = TCP_NODELAY
        domain master = yes
        local master = yes
        ldap ssl = Off
        client ldap sasl wrapping = sign


Samba Log vom Beitrittsversuch in die Domäne
[2015/08/11 15:39:58.863080,  3] ../source3/smbd/smb2_negprot.c:243(smbd_smb2_request_process_negprot)
  Selected protocol SMB2_FF
[2015/08/11 15:39:58.864700,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'gssapi_spnego' registered
[2015/08/11 15:39:58.864790,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'gssapi_krb5' registered
[2015/08/11 15:39:58.864842,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'gssapi_krb5_sasl' registered
[2015/08/11 15:39:58.864887,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'schannel' registered
[2015/08/11 15:39:58.864937,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'spnego' registered
[2015/08/11 15:39:58.865006,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'ntlmssp' registered
[2015/08/11 15:39:58.865076,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'krb5' registered
[2015/08/11 15:39:58.865129,  3] ../auth/gensec/gensec_start.c:870(gensec_register)
  GENSEC backend 'fake_gssapi_krb5' registered
[2015/08/11 15:39:58.865565,  3] ../source3/smbd/negprot.c:671(reply_negprot)
  Selected protocol SMB 2.???
[2015/08/11 15:39:58.865963,  3] ../source3/smbd/smb2_negprot.c:243(smbd_smb2_request_process_negprot)
  Selected protocol SMB2_10
[2015/08/11 15:39:58.868538,  3] ../auth/ntlmssp/ntlmssp_util.c:34(debug_ntlmssp_flags)
  Got NTLMSSP neg_flags=0xe2088297
[2015/08/11 15:39:58.869619,  3] ../auth/ntlmssp/ntlmssp_server.c:358(ntlmssp_server_preauth)
  Got user=[xxx] domain=[xxx-TEST] workstation=[PC-TEST] len1=24 len2=300
[2015/08/11 15:39:58.869694,  3] ../source3/param/loadparm.c:4838(lp_load_ex)
  lp_load_ex: refreshing parameters
[2015/08/11 15:39:58.869779,  3] ../source3/param/loadparm.c:750(init_globals)
  Initialising global parameters
[2015/08/11 15:39:58.869896,  3] ../lib/util/params.c:550(pm_process)
  params.c:pm_process() - Processing configuration file "/etc/samba/smb.conf"
[2015/08/11 15:39:58.869968,  3] ../source3/param/loadparm.c:3564(do_section)
  Processing section "[global]"
[2015/08/11 15:39:58.870251,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[profiles]"
[2015/08/11 15:39:58.870374,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[homes]"
[2015/08/11 15:39:58.870454,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[netlogon]"
[2015/08/11 15:39:58.870555,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[arbaro]"
[2015/08/11 15:39:58.870686,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[banken]"
[2015/08/11 15:39:58.870801,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[digitalisierung]"
[2015/08/11 15:39:58.870894,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[dokumentationen]"
[2015/08/11 15:39:58.870980,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[gesamt]"
[2015/08/11 15:39:58.871066,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[xxx]"
[2015/08/11 15:39:58.871151,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[nuernberger]"
[2015/08/11 15:39:58.871255,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[servicecenter]"
[2015/08/11 15:39:58.871349,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[vorlagenxxx]"
[2015/08/11 15:39:58.871439,  2] ../source3/param/loadparm.c:3581(do_section)
  Processing section "[vorlagenpdf]"
[2015/08/11 15:39:58.871537,  3] ../source3/param/loadparm.c:1773(lp_add_ipc)
  adding IPC service
[2015/08/11 15:39:58.871654,  3] ../source3/auth/auth.c:177(auth_check_ntlm_password)
  check_ntlm_password:  Checking password for unmapped user [xxxPDC1-TEST]\[xxx]@[PC-TEST] with the new password interface
[2015/08/11 15:39:58.871744,  3] ../source3/auth/auth.c:180(auth_check_ntlm_password)
  check_ntlm_password:  mapped user is: [xxxPDC1-TEST]\[xxx]@[PC-TEST]
[2015/08/11 15:39:58.871986,  2] ../source3/lib/smbldap.c:794(smbldap_open_connection)
  smbldap_open_connection: connection opened
[2015/08/11 15:39:58.872722,  3] ../source3/lib/smbldap.c:1013(smbldap_connect_system)
  ldap_connect_system: successful connection to the LDAP server
[2015/08/11 15:39:58.873223,  2] ../source3/passdb/pdb_ldap.c:524(init_sam_from_ldap)
  init_sam_from_ldap: Entry found for user: xxx
[2015/08/11 15:39:58.875274,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.877040,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.878534,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.878928,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10001
[2015/08/11 15:39:58.879041,  3] ../source3/auth/auth.c:226(auth_check_ntlm_password)
  check_ntlm_password: sam authentication for user [xxx] succeeded
[2015/08/11 15:39:58.879135,  2] ../source3/auth/auth.c:278(auth_check_ntlm_password)
  check_ntlm_password:  authentication for user [xxx] -> [xxx] -> [xxx] succeeded
[2015/08/11 15:39:58.879237,  3] ../auth/ntlmssp/ntlmssp_sign.c:547(ntlmssp_sign_init)
  NTLMSSP Sign/Seal - Initialising with flags:
[2015/08/11 15:39:58.879306,  3] ../auth/ntlmssp/ntlmssp_util.c:34(debug_ntlmssp_flags)
  Got NTLMSSP neg_flags=0xe2088215
[2015/08/11 15:39:58.882402,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.884042,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.884722,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10002
[2015/08/11 15:39:58.885363,  2] ../source3/passdb/pdb_ldap.c:2311(init_group_from_ldap)
  init_group_from_ldap: Entry found for group: 10001
[2015/08/11 15:39:58.887306,  3] ../source3/smbd/password.c:144(register_homes_share)
  Adding homes service for user 'xxx' using home directory: '/home/xxx'
[2015/08/11 15:39:58.887574,  3] ../source3/param/loadparm.c:1725(lp_add_home)
  adding home's share [xxx] for user 'xxx' at '/home/xxx'
[2015/08/11 15:39:58.888766,  3] ../source3/lib/access.c:338(allow_access)
  Allowed connection from 192.168.11.30 (192.168.11.30)
[2015/08/11 15:39:58.889036,  3] ../source3/smbd/service.c:612(make_connection_snum)
  Connect path is '/tmp' for service [IPC$]
[2015/08/11 15:39:58.889296,  3] ../source3/smbd/vfs.c:113(vfs_init_default)
  Initialising default vfs hooks
[2015/08/11 15:39:58.889460,  3] ../source3/smbd/vfs.c:139(vfs_init_custom)
  Initialising custom vfs hooks from [/[Default VFS]/]
[2015/08/11 15:39:58.889677,  3] ../source3/smbd/service.c:856(make_connection_snum)
  pc-test (ipv4:192.168.11.30:49479) connect to service IPC$ initially as user xxx (uid=10010, gid=10002) (pid 13948)
[2015/08/11 15:39:58.899300,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: lsarpc -> lsarpc rpc service
[2015/08/11 15:39:58.899415,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \lsarpc
[2015/08/11 15:39:58.899505,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: lsarpc -> lsarpc rpc service
[2015/08/11 15:39:58.900276,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 28
[2015/08/11 15:39:58.901124,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_OPENPOLICY2
[2015/08/11 15:39:58.901358,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1112
[2015/08/11 15:39:58.902148,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY2
[2015/08/11 15:39:58.902295,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 32
[2015/08/11 15:39:58.903342,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY
[2015/08/11 15:39:58.903514,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 168
[2015/08/11 15:39:58.904306,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_CLOSE
[2015/08/11 15:39:58.904444,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 28
[2015/08/11 15:39:59.240305,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: lsarpc -> lsarpc rpc service
[2015/08/11 15:39:59.240461,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \lsarpc
[2015/08/11 15:39:59.240550,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: lsarpc -> lsarpc rpc service
[2015/08/11 15:39:59.241248,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 28
[2015/08/11 15:39:59.242084,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_OPENPOLICY2
[2015/08/11 15:39:59.242228,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1112
[2015/08/11 15:39:59.242986,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY2
[2015/08/11 15:39:59.243116,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 32
[2015/08/11 15:39:59.244081,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY
[2015/08/11 15:39:59.244218,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 168
[2015/08/11 15:39:59.245000,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: LSA_CLOSE
[2015/08/11 15:39:59.245129,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 28
[2015/08/11 15:39:59.249758,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: samr -> samr rpc service
[2015/08/11 15:39:59.249870,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \samr
[2015/08/11 15:39:59.249957,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: samr -> samr rpc service
[2015/08/11 15:39:59.250708,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.251505,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CONNECT5
[2015/08/11 15:39:59.251686,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1042
[2015/08/11 15:39:59.252345,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_ENUMDOMAINS
[2015/08/11 15:39:59.252511,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 90
[2015/08/11 15:39:59.253321,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_LOOKUPDOMAIN
[2015/08/11 15:39:59.253462,  2] ../source3/rpc_server/samr/srv_samr_nt.c:4004(_samr_LookupDomain)
  Returning domain sid for domain xxxPDC1-TEST -> S-1-5-21-4220448075-2189648771-2097191391
[2015/08/11 15:39:59.253600,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 94
[2015/08/11 15:39:59.254371,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_OPENDOMAIN
[2015/08/11 15:39:59.254555,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1042
[2015/08/11 15:39:59.255374,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CREATEUSER2
[2015/08/11 15:39:59.256003,  2] ../source3/passdb/pdb_ldap.c:524(init_sam_from_ldap)
  init_sam_from_ldap: Entry found for user: PC-TEST$
[2015/08/11 15:39:59.258209,  3] ../source3/passdb/lookup_sid.c:1560(get_primary_group_sid)
  Forcing Primary Group to 'Domain Users' for PC-TEST$
[2015/08/11 15:39:59.259533,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.260299,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CLOSE
[2015/08/11 15:39:59.260407,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.261172,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CLOSE
[2015/08/11 15:39:59.261290,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.264384,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: samr -> samr rpc service
[2015/08/11 15:39:59.264716,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \samr
[2015/08/11 15:39:59.264979,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: samr -> samr rpc service
[2015/08/11 15:39:59.266022,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.266912,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CONNECT5
[2015/08/11 15:39:59.267174,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1042
[2015/08/11 15:39:59.268103,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_OPENDOMAIN
[2015/08/11 15:39:59.268331,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1042
[2015/08/11 15:39:59.269230,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_LOOKUPNAMES
[2015/08/11 15:39:59.269861,  2] ../source3/passdb/pdb_ldap.c:524(init_sam_from_ldap)
  init_sam_from_ldap: Entry found for user: PC-TEST$
[2015/08/11 15:39:59.271639,  3] ../source3/passdb/lookup_sid.c:1560(get_primary_group_sid)
  Forcing Primary Group to 'Domain Users' for PC-TEST$
[2015/08/11 15:39:59.272848,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 38
[2015/08/11 15:39:59.273643,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_OPENUSER
[2015/08/11 15:39:59.275304,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 1274
[2015/08/11 15:39:59.276161,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_QUERYUSERINFO
[2015/08/11 15:39:59.277933,  3] ../source3/rpc_server/samr/srv_samr_nt.c:2947(_samr_QueryUserInfo)
  User:[PC-TEST$]
[2015/08/11 15:39:59.278089,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 882
[2015/08/11 15:39:59.278870,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_GETUSERPWINFO
[2015/08/11 15:39:59.281566,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.282660,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_SETUSERINFO2
[2015/08/11 15:39:59.285390,  2] ../source3/passdb/pdb_ldap.c:1139(init_ldap_from_sam)
  init_ldap_from_sam: Setting entry for user: PC-TEST$
[2015/08/11 15:39:59.285962,  2] ../source3/passdb/pdb_ldap.c:1936(ldapsam_update_sam_account)
  ldapsam_update_sam_account: successfully modified uid = PC-TEST$ in the LDAP database
[2015/08/11 15:39:59.286198,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.287077,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CLOSE
[2015/08/11 15:39:59.287207,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.287973,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CLOSE
[2015/08/11 15:39:59.288169,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.289069,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: SAMR_CLOSE
[2015/08/11 15:39:59.289352,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 26
[2015/08/11 15:39:59.302991,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.303069,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \netlogon
[2015/08/11 15:39:59.303131,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.303725,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 30
[2015/08/11 15:39:59.304286,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: NETR_DSRENUMERATEDOMAINTRUSTS
[2015/08/11 15:39:59.304386,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 34
[2015/08/11 15:39:59.307033,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.307105,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \netlogon
[2015/08/11 15:39:59.307156,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.307763,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 30
[2015/08/11 15:39:59.308309,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: NETR_DSRENUMERATEDOMAINTRUSTS
[2015/08/11 15:39:59.308394,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 34
[2015/08/11 15:39:59.311020,  3] ../source3/rpc_server/srv_pipe.c:693(api_pipe_bind_req)
  api_pipe_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.311088,  3] ../source3/rpc_server/srv_pipe.c:342(check_bind_req)
  check_bind_req for \netlogon
[2015/08/11 15:39:59.311137,  3] ../source3/rpc_server/srv_pipe.c:349(check_bind_req)
  check_bind_req: netlogon -> netlogon rpc service
[2015/08/11 15:39:59.311720,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 30
[2015/08/11 15:39:59.312238,  3] ../source3/rpc_server/srv_pipe.c:1371(api_rpcTNP)
  api_rpcTNP: rpc command: NETR_NETRENUMERATETRUSTEDDOMAINS
[2015/08/11 15:39:59.312800,  3] ../source3/rpc_server/srv_pipe_hnd.c:122(free_pipe_context)
  free_pipe_context: destroying talloc pool of size 2168
[2015/08/11 15:40:14.010122,  3] ../source3/smbd/service.c:1130(close_cnum)
  pc-test (ipv4:192.168.11.30:49479) closed connection to service IPC$
[2015/08/11 15:40:14.011010,  3] ../source3/smbd/server_exit.c:212(exit_server_common)
  Server exit (NT_STATUS_CONNECTION_RESET)


Ich goolge mich seit min. 3 Tagen durch das Internet und finde keine passende Lösung, evtl. bin ich einfach auch unfähig oder es ist zu warm dafür face-smile
Bitte helft mir und danke für eure Mühe.

Gruß
Chris

Content-Key: 279878

Url: https://administrator.de/contentid/279878

Printed on: April 16, 2024 at 21:04 o'clock

Member: Chonta
Chonta Aug 11, 2015 at 14:11:42 (UTC)
Goto Top
Hallo,

komische Konstruktion..
Samba 4 = Active Directory (wenn man es denn will ) und Samba3 = NT Domäne.

Warum einen Ldap über Zimbra anstelle eines nahezuvollwertigen AD über Samba4? Zimbra kann man doch auch ans Ad hängen ode nicht?
Was genau geht nicht?

Kannst Du auf dem Samba Freigaben erstellen und mit dem Zimbrabenutzern darauf zugreifen?
Wenn ja geht doch alles.

Windows7++ in einer NT-Domäne sollte deine Googlesuche lauten, die Fallstricke sind ähnlich.

Gruß

Chonta
Member: ckeding
ckeding Aug 11, 2015 at 14:20:55 (UTC)
Goto Top
Samba4 hab ich doch gar nicht face-smile

In dem ganzen Konstrukt geht es um um ein Upgrade von Ubuntu8.04 32bit mit Zimbra 7.2 als Mailserver/Fileserver/ NT Domäne auf ein Ubuntu 14.04 64bit mit Zimbra 8.6. als Mailserver/Fileserver/ NT Domäne

Es müssen alle Profile nach dem Upgrade noch funktionieren daher versuche ich das alles so zu Upgraden wie es war.

Mail funktioniert, die Freigaben auch aber eben nicht das beitreten in die Domäne mit einem neuen PC.

Ich werde mal danach Googeln was du vorgeschlagen hast...
Member: Chonta
Chonta Aug 11, 2015 at 14:32:27 (UTC)
Goto Top
Zitat von @ckeding:

Samba4 hab ich doch gar nicht face-smile

Äh Doch

Server: Ubuntu (14.04) mit Samba (4.1.6) und Zimbra (8.6) für das LDAP.
Client: Windows 7 Prof. SP1

Ubuntu 14.04 Samba (4.1.6) ist einfdeutig Samba4
Samba 4 kann, muss aber nicht als DC verwendet werden.
Wenn Du was vorhandenes migrieren musst ok dann ist das ersmal so einfacher.
Aber später lohnt der AD Umstieg allemal.

Mail funktioniert, die Freigaben auch aber eben nicht das beitreten in die Domäne mit einem neuen PC.
Ich werde mal danach Googeln was du vorgeschlagen hast...

Sind die alten Rechner alles Win7 oder XP? Wenn Win7 musste bei denen auch was beachtet werden damit die da landen.


Gruß

Chonta
Member: ckeding
ckeding Aug 12, 2015 at 08:51:51 (UTC)
Goto Top
Die Rechner sind alles Win7.

Dort habe ich jetzt unter "secpol.msc" die Option...
Lokale Richtlinien -> Sicherheitsoptionen -> Microsoft-Netzwerk (Client): Unverschlüsseltes Kennwort an SMB-Server von Drittanbietern senden = aktiviert

Hat aber leider auch nicht geholfen.
Member: Chonta
Chonta Aug 12, 2015 at 09:27:34 (UTC)
Goto Top
Member: ckeding
ckeding Aug 12, 2015 at 09:58:52 (UTC)
Goto Top
Danke für den Tipp

Habe die Registry geprüft, dort waren die geforderten Optionen bereits gesetzt.

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManWorkstation\Parameters]

"DomainCompatibilityMode"=dword:00000001
"DNSNameResolutionRequired"=dword:00000000

Zudem habe ich noch den Eintrag für "secpol.msc" kontroliert.

Lokale Richtlinien -> Sicherheitsoptionen -> Domänenmitglied: Starker Sitzungsschlüssel erforderlich (Windows 2000 oder höher) = Deaktiviert

Rechner mal neu gestartet, brachte aber leider auch nicht die Lösung.
Bis auf diese blöde Windows Fehlermeldung sehe ich auch keine in den Server Logs, das ist echt zum Haare raufen :/
Auch in der Ereignisslogs ist nix zu finden.
Member: ckeding
ckeding Aug 12, 2015 updated at 10:16:11 (UTC)
Goto Top
Ich habe mal versucht den PC am alten Server anzumelden. Dort funktioniert es ohne Probleme.
Kann also nicht mehr am PC selbst liegen.

Was müsste denn noch passieren, wenn der Client PC im LDAP angelegt wurde und auch der Maschinen Account lokal erstellt wurde?
Im Samba Log passiert ja dann auch nichts mehr.

Muss ich evtl. noch etwas machen wegen Umstellung von Samba3 auf Samba4?
Ich hatte hier lediglich die smb.conf vom alten Server kopiert und `smbpasswd -w XXXX` eingerichtet
Member: Chonta
Chonta Aug 12, 2015 at 10:19:09 (UTC)
Goto Top
Es ist komisch, das alle deine alten Rechner laufen mit dem Samba4 Server und LDAP...
Ist die Konfig denn bei beiden geleich?
Du kannst ja natürlich auch Samba 3.6.6 installieren oder Du nutzt die Gunst der Stunde und machst eine Vollmigration auf AD und Zimbra über AD.

Was für eine Meldung kommt denn und was ist i m Systemlog/Anwendungslog vom Win7 zu sehen?
Wenn der Beitrit des Rechners beom alten Server geht, muss dem neune ja was fehlen.

Gruß

Chonta
Member: ckeding
ckeding Aug 12, 2015, updated at Apr 18, 2023 at 11:57:01 (UTC)
Goto Top
Die Konfig ist dieselbe bis auf den LDAP Zugriff, der hat sich ein klein wenig geändert (Port und IP).
Laut Samba Log funktioniert das aber und ich sehe den neuen Eintrag im LDAP, in der Maschinen Gruppe.

Beim anmelden bekomme ich im Windows die Fehlermeldung: "Ein an das System angeschlossene Gerät funktioniert nicht"

Im System/Anwendungslog ist gar nichts zu diesen Zeiten zu sehen.

Nur im Sicherheitslog ist ein Eintrag...


Dieses Ereignis wird bei einem Anmeldeversuch durch einen Prozess generiert, wenn ausdrücklich die Anmeldeinformationen des Kontos angegeben werden. Dies ist normalerweise der Fall in Batch-Konfigurationen, z. B. bei geplanten Aufgaben oder wenn der Befehl "runas" verwendet wird.
Member: Chonta
Chonta Aug 12, 2015 at 10:30:12 (UTC)
Goto Top
Was sagt testparm in Bezug auf deine Sambaconfig?