Bug 6188 - unable to access homes from another domain
unable to access homes from another domain
Status: NEW
Product: Samba 3.3
Classification: Unclassified
Component: Winbind
3.3.2
x86 Solaris
: P3 normal
: ---
Assigned To: Michael Adam
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2009-03-14 12:21 UTC by mchugh19@yahoo.com
Modified: 2009-05-03 01:43 UTC (History)
0 users

See Also:


Attachments
debug 10 log (40.77 KB, application/gzip)
2009-03-14 12:22 UTC, mchugh19@yahoo.com
no flags Details
smb.conf used (2.48 KB, application/octet-stream)
2009-03-14 12:23 UTC, mchugh19@yahoo.com
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description mchugh19@yahoo.com 2009-03-14 12:21:10 UTC
Using samba 3.3.2, a user in admin users from one domain is unable to access home directories for users in another domain. 

User NAU-STUDENTS\mmchugh is in the admin users directory and log.smbd reports a successful login with uid 0. NAU-STUDENTS\mmchugh is able to access its own home directory of /home/mcm75 and able to access the home directory of other users on the NAU-STUDENTS domain such as /home/cwb32. However, NAU-STUDENTS\mmchugh gets an error when trying to access NAU\jtt3's home directory at /home/jtt3.
Comment 1 mchugh19@yahoo.com 2009-03-14 12:22:42 UTC
Created attachment 3992 [details]
debug 10 log

Log of mmchugh attemping to access jtt3's home directory via smbclient
Comment 2 mchugh19@yahoo.com 2009-03-14 12:23:31 UTC
Created attachment 3993 [details]
smb.conf used
Comment 3 mchugh19@yahoo.com 2009-03-16 11:32:16 UTC
This seems to be related to "winbind use default domain" 

If that is disabled, then I am unable to connect to any users home directory. Samba seems to be unable to resolve \\SERVER\USERNAME into DOMAIN\USERNAME

So in this case the machine is joined to domain NAU-STUDENTS. If winbind use default domain is set, then an admin user is able to connect to home directories for users in NAU-STUDENTS, and cannot connect to home directories for NAU domain users. If winbind use default domain is unset or disabled, then an admin user seems to only be able to connected to their own directory and no one else, which makes it rather difficult to administer shares from windows.
Comment 4 mchugh19@yahoo.com 2009-03-26 15:17:15 UTC
Is there anything more I can provide on this?