Bug 3599 - Samba failing group authorizations with Windows 2003 SP 1 domain
Summary: Samba failing group authorizations with Windows 2003 SP 1 domain
Alias: None
Product: Samba 3.0
Classification: Unclassified
Component: winbind (show other bugs)
Version: 3.0.21c
Hardware: x86 Linux
: P3 regression
Target Milestone: none
Assignee: Gerald (Jerry) Carter (dead mail address)
QA Contact: Samba QA Contact
Depends on:
Reported: 2006-03-10 19:32 UTC by tonyb
Modified: 2006-04-10 07:45 UTC (History)
1 user (show)

See Also:


Note You need to log in before you can comment on or make changes to this bug.
Description tonyb 2006-03-10 19:32:10 UTC
Will not authenicate with AD using groups anymore after the windows 2003 server is upgraded to sp1. This is tested with 15 samba machines and every known patch and build .. including krb5 and heimdal .,., openldap and so on.

Samba is somehow able to see the groups with wbinfo -g but the shares are not able to authenicate users in the groups ..

Any help on this would be much apperciated.
Comment 1 tonyb 2006-03-10 19:34:03 UTC
I see a huge amount of these posts on the web with no resolv i hope this gets fixed because i need to update that last server with sp1 .
Comment 2 Gerald (Jerry) Carter (dead mail address) 2006-03-10 20:23:46 UTC
I can verify that Samba works fine with Windows 2003 sp1.
Please attach level 10 debug logs (compressed) from winbindd
and smbd.  And please specificy exactly how to reproduce 
the failure. 
Comment 3 tonyb 2006-04-04 18:29:41 UTC
Figured it out. 

We changed the + for the winbindd seperator to = this for some stupid reason was stopping it for allowing the groups to be authenicated.

I can reproduce this .. all 15 are working beautifully now .. Thanks guys.

Hope this helps out.
Comment 4 Gerald (Jerry) Carter (dead mail address) 2006-04-10 07:45:29 UTC