<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Integrate windows Active Directory and Samba in Ubuntu</title>
	<atom:link href="http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html</link>
	<description>Ubuntu Linux Tutorials,Howtos,Tips &#38; News &#124; Oneiric,Natty,Maverick</description>
	<lastBuildDate>Mon, 06 Feb 2012 15:40:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Domain</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-34306</link>
		<dc:creator>Domain</dc:creator>
		<pubDate>Fri, 11 Jun 2010 13:50:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-34306</guid>
		<description>Will give this a try, thanks again for sharing this great tutorial.=) cheers!</description>
		<content:encoded><![CDATA[<p>Will give this a try, thanks again for sharing this great tutorial.=) cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antoine</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-27532</link>
		<dc:creator>Antoine</dc:creator>
		<pubDate>Tue, 13 Apr 2010 10:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-27532</guid>
		<description>You can add 

obey pam restrictions = yes

in smb.conf. If you use this, the home directory is created by pam when a user connect to his home directory shared with samba

Sorry for my english.</description>
		<content:encoded><![CDATA[<p>You can add </p>
<p>obey pam restrictions = yes</p>
<p>in smb.conf. If you use this, the home directory is created by pam when a user connect to his home directory shared with samba</p>
<p>Sorry for my english.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-26386</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 25 Mar 2010 16:23:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-26386</guid>
		<description>@Amanibhavam

Thankyou i have corrected the problem</description>
		<content:encoded><![CDATA[<p>@Amanibhavam</p>
<p>Thankyou i have corrected the problem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amanibhavam</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-26382</link>
		<dc:creator>Amanibhavam</dc:creator>
		<pubDate>Thu, 25 Mar 2010 16:14:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-26382</guid>
		<description>In the nsswitch.conf edits there&#039;s a linebreak problem.  Instead of

passwd:  compat
winbindgroup: compat winbind

It should read

passwd:  compat winbind
group:   compat winbind

most of the login incorrect problems reported by the commenters are likely to be caused by this edit problem.</description>
		<content:encoded><![CDATA[<p>In the nsswitch.conf edits there&#8217;s a linebreak problem.  Instead of</p>
<p>passwd:  compat<br />
winbindgroup: compat winbind</p>
<p>It should read</p>
<p>passwd:  compat winbind<br />
group:   compat winbind</p>
<p>most of the login incorrect problems reported by the commenters are likely to be caused by this edit problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johnny</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-21155</link>
		<dc:creator>Johnny</dc:creator>
		<pubDate>Fri, 22 Jan 2010 16:19:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-21155</guid>
		<description>What is the best way to implement ADS/Samba intergration?</description>
		<content:encoded><![CDATA[<p>What is the best way to implement ADS/Samba intergration?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ricardo</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-14218</link>
		<dc:creator>Ricardo</dc:creator>
		<pubDate>Mon, 12 Oct 2009 22:01:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-14218</guid>
		<description>Thank You!!!, this guide is very simple and usefull, i was trying many days validate samba in W2k8, until found this guide</description>
		<content:encoded><![CDATA[<p>Thank You!!!, this guide is very simple and usefull, i was trying many days validate samba in W2k8, until found this guide</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Directory</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-5827</link>
		<dc:creator>Directory</dc:creator>
		<pubDate>Thu, 05 Feb 2009 16:14:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-5827</guid>
		<description>Very informative article, which I found quite useful.  Cheers ,Jay</description>
		<content:encoded><![CDATA[<p>Very informative article, which I found quite useful.  Cheers ,Jay</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken Leja</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-5351</link>
		<dc:creator>Ken Leja</dc:creator>
		<pubDate>Mon, 12 Jan 2009 06:08:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-5351</guid>
		<description>#  Ken Leja Says: Your comment is awaiting moderation.
January 12th, 2009 at 6:00 am

I was getting the following errors in auth.log and could not login as administrator without getting an error on login “User not known to the underlying authentication module”
auth.log:
Jan 11 22:33:44 myserver login[5180]: pam_winbind(login:auth): getting password (0×00000000)
Jan 11 22:33:44 myserver login[5180]: pam_winbind(login:auth): user ‘ADMINISTRATOR’ granted access
Jan 11 22:33:44 myserver login[5180]: pam_unix(login:account): could not identify user (from getpwnam(administrator))
Jan 11 22:33:44 myserver login[5180]: User not known to the underlying authentication module

This turned out to be an issue with nsswitch.conf so I tweaked it as follows after reading the following HOWTO http://localhost:901/swat/help/Samba3-HOWTO/FastStart.html in SWAT. Change the following lines as shown.

nsswitch.conf:
passwd:         compat winbind
group:          compat winbind
hosts:          files dns wins winbind

My appologies I pasted the wrong text in the previous post.</description>
		<content:encoded><![CDATA[<p>#  Ken Leja Says: Your comment is awaiting moderation.<br />
January 12th, 2009 at 6:00 am</p>
<p>I was getting the following errors in auth.log and could not login as administrator without getting an error on login “User not known to the underlying authentication module”<br />
auth.log:<br />
Jan 11 22:33:44 myserver login[5180]: pam_winbind(login:auth): getting password (0×00000000)<br />
Jan 11 22:33:44 myserver login[5180]: pam_winbind(login:auth): user ‘ADMINISTRATOR’ granted access<br />
Jan 11 22:33:44 myserver login[5180]: pam_unix(login:account): could not identify user (from getpwnam(administrator))<br />
Jan 11 22:33:44 myserver login[5180]: User not known to the underlying authentication module</p>
<p>This turned out to be an issue with nsswitch.conf so I tweaked it as follows after reading the following HOWTO <a href="http://localhost:901/swat/help/Samba3-HOWTO/FastStart.html" rel="nofollow">http://localhost:901/swat/help/Samba3-HOWTO/FastStart.html</a> in SWAT. Change the following lines as shown.</p>
<p>nsswitch.conf:<br />
passwd:         compat winbind<br />
group:          compat winbind<br />
hosts:          files dns wins winbind</p>
<p>My appologies I pasted the wrong text in the previous post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4746</link>
		<dc:creator>Craig</dc:creator>
		<pubDate>Sat, 20 Dec 2008 13:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4746</guid>
		<description>Hi Everyone,

I picked up an issue when using Likewise-open and the above how-to to get my Samba shares to use ADS integration. It kept on prompting for a password and the ADS usernames did not work!

I am currently running child domains on Server 2003 R2 platform. This changes the ADS schema and the &#039;net ads join ....&#039; command does not allow you to join the domain.

If you used Likewise-open to join the domain. Please use this tutorial:

www.likewisesoftware.com/resources/user_documentation/Likewise-Samba-Guide.pdf

You do not need to change the krb5.conf, nsswith.conf or the PAM authentication config files at all!

I hope this saves someone from the late nights I went through to find it.

Regards,

Craig</description>
		<content:encoded><![CDATA[<p>Hi Everyone,</p>
<p>I picked up an issue when using Likewise-open and the above how-to to get my Samba shares to use ADS integration. It kept on prompting for a password and the ADS usernames did not work!</p>
<p>I am currently running child domains on Server 2003 R2 platform. This changes the ADS schema and the &#8216;net ads join &#8230;.&#8217; command does not allow you to join the domain.</p>
<p>If you used Likewise-open to join the domain. Please use this tutorial:</p>
<p><a href="http://www.likewisesoftware.com/resources/user_documentation/Likewise-Samba-Guide.pdf" rel="nofollow">http://www.likewisesoftware.com/resources/user_documentation/Likewise-Samba-Guide.pdf</a></p>
<p>You do not need to change the krb5.conf, nsswith.conf or the PAM authentication config files at all!</p>
<p>I hope this saves someone from the late nights I went through to find it.</p>
<p>Regards,</p>
<p>Craig</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: STAARTech</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4744</link>
		<dc:creator>STAARTech</dc:creator>
		<pubDate>Thu, 11 Dec 2008 01:05:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4744</guid>
		<description>I followed the procedure, rebooted the server.

I try and log in as a user and get the message that my password will expire in 9 days (which is correct, my AD password is due to expire).
I click on OK and then get a message: &quot;Incorrect User name or password, letter must be typed in the correct case&quot;
and am back at login.

But I did, AD authenticated, so why am I being blocked?</description>
		<content:encoded><![CDATA[<p>I followed the procedure, rebooted the server.</p>
<p>I try and log in as a user and get the message that my password will expire in 9 days (which is correct, my AD password is due to expire).<br />
I click on OK and then get a message: &#8220;Incorrect User name or password, letter must be typed in the correct case&#8221;<br />
and am back at login.</p>
<p>But I did, AD authenticated, so why am I being blocked?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fr33d0m</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4743</link>
		<dc:creator>Fr33d0m</dc:creator>
		<pubDate>Fri, 05 Dec 2008 23:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4743</guid>
		<description>To answer my question above, you do indeed need to use your local domain name where DOMAIN.INTERNAL is listed.  But I can confirm that something after the krb5.conf edits above breaks login for me.  I cp&#039;d every file to a .orig file first so it was easy to revert.</description>
		<content:encoded><![CDATA[<p>To answer my question above, you do indeed need to use your local domain name where DOMAIN.INTERNAL is listed.  But I can confirm that something after the krb5.conf edits above breaks login for me.  I cp&#8217;d every file to a .orig file first so it was easy to revert.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fr33d0m</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4745</link>
		<dc:creator>Fr33d0m</dc:creator>
		<pubDate>Thu, 04 Dec 2008 22:32:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4745</guid>
		<description>A little clarity may be in order here.

As I see it since you only once say to change something you typed:

&lt;blockquote&gt;Note:- replace ug01 netbios name with your own&lt;/blockquote&gt;

That indicates to me that everything else is entered verbatim.  For example instead of entering my own domain information where you have DOMAIN.INTERNAL, I enter DOMAIN.INTERNAL.

This seems wrong to me.  I don&#039;t honestly know how to proceed.  It gets more maddening in krb5.conf because: 1. it seems to have been populated with my FQDN where you say I should enter DOMAIN.INTERNAL, 2. you&#039;ve used DOMAIN.INTERNAL and domain.internal
and 3. the some of the lines are only vaguely similar but enough so that I think they suffice for what you say to enter.

So off I go looking for some other tutorial to compare with.  I&#039;m sure to be more confused by the end of all this.</description>
		<content:encoded><![CDATA[<p>A little clarity may be in order here.</p>
<p>As I see it since you only once say to change something you typed:</p>
<blockquote><p>Note:- replace ug01 netbios name with your own</p></blockquote>
<p>That indicates to me that everything else is entered verbatim.  For example instead of entering my own domain information where you have DOMAIN.INTERNAL, I enter DOMAIN.INTERNAL.</p>
<p>This seems wrong to me.  I don&#8217;t honestly know how to proceed.  It gets more maddening in krb5.conf because: 1. it seems to have been populated with my FQDN where you say I should enter DOMAIN.INTERNAL, 2. you&#8217;ve used DOMAIN.INTERNAL and domain.internal<br />
and 3. the some of the lines are only vaguely similar but enough so that I think they suffice for what you say to enter.</p>
<p>So off I go looking for some other tutorial to compare with.  I&#8217;m sure to be more confused by the end of all this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4742</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Thu, 20 Nov 2008 18:04:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4742</guid>
		<description>This is great! It used to be so difficult to get this working in past releases; thanks for researching and showing the simple procedure that works!

I did see one little problem: the &quot;skel&quot; directory is not specified correctly in /etc/pam.d/common-session; it should be:
&lt;code&gt;
session required   pam_mkhomedir.so umask=0022 skel=/etc/skel
&lt;/code&gt;
Otherwise, the newly created home directory is not populated correctly.</description>
		<content:encoded><![CDATA[<p>This is great! It used to be so difficult to get this working in past releases; thanks for researching and showing the simple procedure that works!</p>
<p>I did see one little problem: the &#8220;skel&#8221; directory is not specified correctly in /etc/pam.d/common-session; it should be:<br />
<code><br />
session required   pam_mkhomedir.so umask=0022 skel=/etc/skel<br />
</code><br />
Otherwise, the newly created home directory is not populated correctly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PerfMonk</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4741</link>
		<dc:creator>PerfMonk</dc:creator>
		<pubDate>Wed, 12 Nov 2008 15:34:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4741</guid>
		<description>Sorry,

I just found out it was OK.

My mistake,
               Forget precedent post!

Happy finger triggered too fast...</description>
		<content:encoded><![CDATA[<p>Sorry,</p>
<p>I just found out it was OK.</p>
<p>My mistake,<br />
               Forget precedent post!</p>
<p>Happy finger triggered too fast&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PerfMonk</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4740</link>
		<dc:creator>PerfMonk</dc:creator>
		<pubDate>Wed, 12 Nov 2008 15:19:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4740</guid>
		<description>Hi,

You said

Take a backupof existing file

    sudo mv /var/lib/samba/secrets.tdb /var/lib/samba/secrets.tdb.orig

Create a link to /var/lib/samba

    sudo ln -s /etc/samba/secrets.tdb /var/lib/samba


Could it be possible that the command is &quot;cp&quot; instead of &quot;mv&quot; in the first sudo. Otherwise the next link won&#039;t work either.

Regards,

   Bernard Tremblay</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>You said</p>
<p>Take a backupof existing file</p>
<p>    sudo mv /var/lib/samba/secrets.tdb /var/lib/samba/secrets.tdb.orig</p>
<p>Create a link to /var/lib/samba</p>
<p>    sudo ln -s /etc/samba/secrets.tdb /var/lib/samba</p>
<p>Could it be possible that the command is &#8220;cp&#8221; instead of &#8220;mv&#8221; in the first sudo. Otherwise the next link won&#8217;t work either.</p>
<p>Regards,</p>
<p>   Bernard Tremblay</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4737</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Mon, 10 Nov 2008 04:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4737</guid>
		<description>Thank you very much for sharing this.
I&#039;ve just followed this instruction to integrate Windows AD with Ubuntu (7.10) but failed.
It won&#039;t let me login after I reboot Ubuntu and always says &quot;Login incorrect&quot;.

Any idea?

Thanks again.</description>
		<content:encoded><![CDATA[<p>Thank you very much for sharing this.<br />
I&#8217;ve just followed this instruction to integrate Windows AD with Ubuntu (7.10) but failed.<br />
It won&#8217;t let me login after I reboot Ubuntu and always says &#8220;Login incorrect&#8221;.</p>
<p>Any idea?</p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vinod</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4738</link>
		<dc:creator>Vinod</dc:creator>
		<pubDate>Fri, 07 Nov 2008 16:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4738</guid>
		<description>WOW, something i was searching for long... let me test it
I hope it will work with Readhat LInux also

Regards,
Vinod</description>
		<content:encoded><![CDATA[<p>WOW, something i was searching for long&#8230; let me test it<br />
I hope it will work with Readhat LInux also</p>
<p>Regards,<br />
Vinod</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ramesh</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4736</link>
		<dc:creator>Ramesh</dc:creator>
		<pubDate>Mon, 03 Nov 2008 20:38:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4736</guid>
		<description>Awesome.. I was looking for this nearly for an year now.. Let me give a try in a couple of days. Good Job, keep it up..!!!

Cheers
Ramesh</description>
		<content:encoded><![CDATA[<p>Awesome.. I was looking for this nearly for an year now.. Let me give a try in a couple of days. Good Job, keep it up..!!!</p>
<p>Cheers<br />
Ramesh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Rogerson</title>
		<link>http://www.ubuntugeek.com/how-to-integrate-windows-active-directory-and-samba-in-ubuntu.html/comment-page-1#comment-4739</link>
		<dc:creator>Paul Rogerson</dc:creator>
		<pubDate>Mon, 03 Nov 2008 19:33:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/?p=684#comment-4739</guid>
		<description>Sorry to be obtuse but:

For the smb.conf you say to change the parameters, but those do not seem to be in the default config.  Is that the resulting config, i.e. the whole of smb.conf?  I assume we also need to change the DOMAIN values to match our environment?

Similar questions for the krb5.conf file.</description>
		<content:encoded><![CDATA[<p>Sorry to be obtuse but:</p>
<p>For the smb.conf you say to change the parameters, but those do not seem to be in the default config.  Is that the resulting config, i.e. the whole of smb.conf?  I assume we also need to change the DOMAIN values to match our environment?</p>
<p>Similar questions for the krb5.conf file.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

