Bug 7722 - SAMBA as PDC on SLES 10.2 - Error when Users on Windows Client try to change password
SAMBA as PDC on SLES 10.2 - Error when Users on Windows Client try to change ...
Status: NEW
Product: Samba 3.5
Classification: Unclassified
Component: Domain Control
Other Linux
: P3 major
: ---
Assigned To: Guenther Deschner
Samba QA Contact
Depends on:
  Show dependency treegraph
Reported: 2010-10-11 04:36 UTC by luca_santoro@libero.it
Modified: 2010-10-11 04:36 UTC (History)
0 users

See Also:


Note You need to log in before you can comment on or make changes to this bug.
Description luca_santoro@libero.it 2010-10-11 04:36:04 UTC
Dear All,
Two years ago, in our little company, I installed SLES 10.2 with SAMBA to retire our old Microsoft Windows 2000 Server and save some money.

All was fine until last week when our chief asked to me to set password expiration for all clients.
This morning, all users cannot logon because, when they logon, windows asks to change password and then it gives error error "Access Denied".

In SAMBA logs I can see:
chgpasswd: Password change (as_root=Yes) for user: FederPal
PAM: unable to obtain the new authentication token - is password to weak?
smb_pam_error_handler: PAM: Password Change Failed : Authentication token manipulation error
smb_pam_passchange: PAM: Password Change Failed for user FederPal!

Here is my smb.conf:
security = user
interfaces = eth0
ldap ssl = no
passwd chat = *New*password* %n\n *Retype*new*password* %n\n *passwd:*all*authentication*tokens*updated*successfully*
admin users = @admin, root, administrator
time server = Yes
passwd program = /usr/bin/passwd %u
cups options = raw
netbios name = SAMBAPDC
printing = cups
logon script = netlogon.bat
local master = Yes
workgroup = SAMBAPDC
os level = 99
printcap name = cups
add machine script = /usr/sbin/useradd -d /home/machines/%u -g machines -s /bin/false -M %u
max log size = 1000
log level = 3
log file = /var/log/samba/log.%m
load printers = yes
logon drive = H:
map to guest = Bad User
username map = /etc/samba/smbusers
domain master = Yes
encrypt passwords = yes
smb passwd file = /etc/samba/smbpasswd
passdb backend = tdbsam
logon home = \\serverpdc\%U
wins support = Yes
printcap cache time = 750
server string = Samba PDC - Version %v
unix password sync = yes
logon path = \\serverpdc\profiles\%U
syslog = 0
preferred master = Yes
pam password change = yes
domain logons = Yes
name resolve order = wins lmhosts hosts bcast

comment = Users Home Directories
path = /home/profiles
read only = No
create mask = 0600
directory mask = 0700
browseable = No
writeable = yes

Have you any idea?

Thanks and Regards,