<div>U menja nepoluchajetsja zapustits sambu s avtorizacijei na Active Directory. V principe takoe prechustvie shto nesrabativajet naslednosti grupp v Active directory. Jesli na sharu zapisivaju valid user = domain\username vsjo rabotajet, a jesli tuda stavlju domennuju gruppu, nechavo njepaluchajetsa.... v logah pokazijajet wrong password ili no such user! 
</div>
<div>Pri etom vse komandi vidajut pravilnije znachenija!</div>
<div>kinit rabotajet</div>
<div>getent group vidajot vse domennije grupi</div>
<div>getent passwd vidajot vse domennije usera</div>
<div>id vidajot gid dlja domennih juzerov</div>
<div>pam rabotajet i cherez konsolj domennije juzera mozhet zalogonitsja na freebsd, tolko home papochki nerabotajut...</div>
<div>getent groupmap list&nbsp; - pokazivajet shto netu nekokogo mappinga grupp</div>
<div>&nbsp;</div>
<div>FreeBSD 6.2, samba 3.0.24</div>
<div>&nbsp;</div>
<div>No na sharing nepuskajet, jesli prava dostupa prapisivajetsa na grupi!!!</div>
<div>&nbsp;</div>
<div>Faili kofiguracii:</div>
<div>&nbsp;</div>
<div>#smb.conf</div>
<div>&nbsp;</div>
<div>[global]<br>&nbsp;&nbsp; workgroup = CA<br>&nbsp;&nbsp; server string = Serveris<br>&nbsp;&nbsp; realm = CA.VP<br>&nbsp;&nbsp; security = ADS<br>&nbsp;&nbsp;&nbsp;log file = /var/log/samba/log.%U<br>&nbsp;&nbsp; max log size = 150<br>&nbsp;&nbsp; socket options = SO_KEEPALIVE SO_BROADCAST TCP_NODELAY IPTOS_THROUGHPUT SO_RCVBUF=8192 SO_SNDBUF=8192 
<br>&nbsp;&nbsp; os level = 0<br>&nbsp;&nbsp; dns proxy = no <br>&nbsp;&nbsp; case sensitive = no<br>&nbsp;&nbsp;&nbsp; nt acl support = Yes<br>&nbsp;&nbsp;&nbsp; inherit acls = yes<br>&nbsp;&nbsp;&nbsp; map acl inherit = yes<br>&nbsp;&nbsp;&nbsp; winbind uid = 100-10000000<br>&nbsp;&nbsp;&nbsp; winbind gid = 100-10000000<br>
&nbsp;&nbsp;&nbsp; winbind enum groups = Yes<br>&nbsp;&nbsp;&nbsp; winbind enum users = Yes<br>&nbsp;&nbsp;&nbsp; winbind use default domain = Yes<br>&nbsp;&nbsp;&nbsp; template shell = /bin/bash<br>&nbsp;&nbsp;&nbsp; time server = Yes<br>&nbsp;&nbsp;&nbsp; template homedir = /home/D%/U%<br>&nbsp;&nbsp;&nbsp; template shell = /bin/sh 
<br>&nbsp;&nbsp;&nbsp; hide files = /*.ini/*RECYCLER*/*.db/*.tmp/*.rdp/<br><br>[Dati]<br>&nbsp;&nbsp;&nbsp; comment = Dati<br>&nbsp;&nbsp;&nbsp; path = /dati/share<br>&nbsp;&nbsp;&nbsp; valid users = &quot;CA\domain users&quot;<br>&nbsp;&nbsp;&nbsp; writable = yes<br>&nbsp;</div>
<div>&nbsp;</div>
<div>#nsswitch.conf</div>
<div><pre>group: files winbind
group_compat: nis
hosts: files dns
networks: files
passwd: files winbind
shadow: files winbind
passwd_compat: nis
shells: files</pre><pre>#krb5.conf - (Heimdal)</pre><pre><pre>[libdefaults]
        default_realm = CA.VP
        clockskew = 300
        dns_lookup_realm = true
        dns_lookup_kdc = true
        v4_instance_resolve = false
        v4_name_convert = {
                host = {
                        rcmd = host
                        ftp = ftp
                }
                plain = {
                        something = something-else
                }
        }
        
[realms]
        CA.VP = {
                kdc = MAJOR.CA.VP
                kdc = CAPTAIN.CA.VP
                admin_server = MAJOR.CA.VP
        }
        OTHER.REALM = {
                v4_instance_convert = {
                        kerberos = kerberos
                        computer = computer.some.other.domain
                }
        }
[domain_realm]
        .ca.vp = CA.VP
</pre><pre><pre># PAM configuration for the &quot;login&quot; service

auth                sufficient        /usr/local/lib/pam_winbind.so                
auth                required        pam_unix.so                no_warn try_first_pass

account                sufficient        /usr/local/lib/pam_winbind.so
account                required        pam_unix.so</pre><pre>session                include                system
session                required        /usr/local/lib/pam_mkhomedir.so umask=0700
session                required        pam_permit.so
session                sufficient        /usr/local/lib/pam_winbind.so</pre><pre>password        include                system
password        sufficient        /usr/local/lib/pam_winbind.so</pre><pre>&nbsp;</pre><pre>&nbsp;</pre></pre></pre></div>