- Timestamp:
- May 20, 2009, 6:46:53 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.2.x/docs/htmldocs/Samba3-HOWTO/InterdomainTrusts.html
r149 r204 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.73.1"><link rel="start" href="index.html" title="The Official Samba 3.2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2612728">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2612800">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2613078">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613114">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613211">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613296">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2613505">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613845">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2614041">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2614191">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2614203">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2614249">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p> 2 <a class="indexterm" name="id2612508"></a> 3 <a class="indexterm" name="id2612515"></a> 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.73.1"><link rel="start" href="index.html" title="The Official Samba 3.2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2612741">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2612813">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2613091">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613127">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613224">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613309">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2613518">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2613858">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2614054">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2614204">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2614216">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2614262">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p> 4 2 <a class="indexterm" name="id2612521"></a> 5 3 <a class="indexterm" name="id2612528"></a> 6 4 <a class="indexterm" name="id2612535"></a> 7 <a class="indexterm" name="id2612542"></a> 8 <a class="indexterm" name="id2612549"></a> 9 <a class="indexterm" name="id2612556"></a> 10 <a class="indexterm" name="id2612563"></a> 5 <a class="indexterm" name="id2612541"></a> 6 <a class="indexterm" name="id2612548"></a> 7 <a class="indexterm" name="id2612555"></a> 8 <a class="indexterm" name="id2612562"></a> 9 <a class="indexterm" name="id2612569"></a> 10 <a class="indexterm" name="id2612576"></a> 11 11 Samba-3 supports NT4-style domain trust relationships. This is a feature that many sites 12 12 will want to use if they migrate to Samba-3 from an NT4-style domain and do not want to … … 16 16 trusts. 17 17 </p><p> 18 <a class="indexterm" name="id2612580"></a>19 <a class="indexterm" name="id2612587"></a>20 18 <a class="indexterm" name="id2612594"></a> 21 <a class="indexterm" name="id2612601"></a> 22 <a class="indexterm" name="id2612608"></a> 19 <a class="indexterm" name="id2612600"></a> 20 <a class="indexterm" name="id2612607"></a> 21 <a class="indexterm" name="id2612614"></a> 22 <a class="indexterm" name="id2612621"></a> 23 23 The use of interdomain trusts requires use of <code class="literal">winbind</code>, so the 24 24 <code class="literal">winbindd</code> daemon must be running. Winbind operation in this mode is 25 25 dependent on the specification of a valid UID range and a valid GID range in the <code class="filename">smb.conf</code> file. 26 26 These are specified respectively using: 27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id26126 42"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2612653"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p>28 <a class="indexterm" name="id26126 65"></a>29 <a class="indexterm" name="id26126 72"></a>30 <a class="indexterm" name="id26126 79"></a>31 <a class="indexterm" name="id26126 86"></a>27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2612655"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2612667"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p> 28 <a class="indexterm" name="id2612678"></a> 29 <a class="indexterm" name="id2612685"></a> 30 <a class="indexterm" name="id2612692"></a> 31 <a class="indexterm" name="id2612699"></a> 32 32 The range of values specified must not overlap values used by the host operating system and must 33 33 not overlap values used in the passdb backend for POSIX user accounts. The maximum value is … … 36 36 (32-bit unsigned variable). 37 37 </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 38 <a class="indexterm" name="id26127 04"></a>39 <a class="indexterm" name="id26127 11"></a>40 <a class="indexterm" name="id26127 18"></a>38 <a class="indexterm" name="id2612717"></a> 39 <a class="indexterm" name="id2612724"></a> 40 <a class="indexterm" name="id2612731"></a> 41 41 The use of winbind is necessary only when Samba is the trusting domain, not when it is the 42 42 trusted domain. 43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26127 28"></a>Features and Benefits</h2></div></div></div><p>44 <a class="indexterm" name="id26127 36"></a>45 <a class="indexterm" name="id26127 42"></a>43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2612741"></a>Features and Benefits</h2></div></div></div><p> 44 <a class="indexterm" name="id2612749"></a> 45 <a class="indexterm" name="id2612756"></a> 46 46 Samba-3 can participate in Samba-to-Samba as well as in Samba-to-MS Windows NT4-style 47 47 trust relationships. This imparts to Samba scalability similar to that with MS Windows NT4. 48 48 </p><p> 49 <a class="indexterm" name="id2612756"></a> 50 <a class="indexterm" name="id2612762"></a> 51 <a class="indexterm" name="id2612770"></a> 49 <a class="indexterm" name="id2612769"></a> 52 50 <a class="indexterm" name="id2612776"></a> 53 51 <a class="indexterm" name="id2612783"></a> 52 <a class="indexterm" name="id2612790"></a> 53 <a class="indexterm" name="id2612796"></a> 54 54 Given that Samba-3 can function with a scalable backend authentication database such as LDAP, and given its 55 55 ability to run in primary as well as backup domain control modes, the administrator would be well-advised to … … 57 57 function, this system is fragile. That was, after all, a key reason for the development and adoption of 58 58 Microsoft Active Directory. 59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2612800"></a>Trust Relationship Background</h2></div></div></div><p> 60 <a class="indexterm" name="id2612808"></a> 61 <a class="indexterm" name="id2612815"></a> 62 <a class="indexterm" name="id2612822"></a> 63 <a class="indexterm" name="id2612829"></a> 64 <a class="indexterm" name="id2612836"></a> 59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2612813"></a>Trust Relationship Background</h2></div></div></div><p> 60 <a class="indexterm" name="id2612821"></a> 61 <a class="indexterm" name="id2612828"></a> 62 <a class="indexterm" name="id2612835"></a> 65 63 <a class="indexterm" name="id2612842"></a> 64 <a class="indexterm" name="id2612849"></a> 65 <a class="indexterm" name="id2612856"></a> 66 66 MS Windows NT3/4-type security domains employ a nonhierarchical security structure. 67 67 The limitations of this architecture as it effects the scalability of MS Windows networking … … 70 70 large and diverse organizations. 71 71 </p><p> 72 <a class="indexterm" name="id2612859"></a> 73 <a class="indexterm" name="id2612866"></a> 74 <a class="indexterm" name="id2612873"></a> 72 <a class="indexterm" name="id2612872"></a> 75 73 <a class="indexterm" name="id2612879"></a> 76 74 <a class="indexterm" name="id2612886"></a> 75 <a class="indexterm" name="id2612893"></a> 76 <a class="indexterm" name="id2612899"></a> 77 77 Microsoft developed Active Directory Service (ADS), based on Kerberos and LDAP, as a means 78 78 of circumventing the limitations of the older technologies. Not every organization is ready … … 81 81 desire to go through a disruptive change to adopt ADS. 82 82 </p><p> 83 <a class="indexterm" name="id2612904"></a>84 <a class="indexterm" name="id2612910"></a>85 83 <a class="indexterm" name="id2612917"></a> 86 84 <a class="indexterm" name="id2612924"></a> 87 85 <a class="indexterm" name="id2612931"></a> 88 <a class="indexterm" name="id2612938"></a> 89 <a class="indexterm" name="id2612945"></a> 86 <a class="indexterm" name="id2612937"></a> 87 <a class="indexterm" name="id2612944"></a> 88 <a class="indexterm" name="id2612951"></a> 89 <a class="indexterm" name="id2612958"></a> 90 90 With Windows NT, Microsoft introduced the ability to allow different security domains 91 91 to effect a mechanism so users from one domain may be given access rights and privileges … … 98 98 necessary to establish two relationships, one in each direction. 99 99 </p><p> 100 <a class="indexterm" name="id2612975"></a> 101 <a class="indexterm" name="id2612982"></a> 102 <a class="indexterm" name="id2612989"></a> 103 <a class="indexterm" name="id2612996"></a> 100 <a class="indexterm" name="id2612988"></a> 101 <a class="indexterm" name="id2612995"></a> 104 102 <a class="indexterm" name="id2613002"></a> 103 <a class="indexterm" name="id2613009"></a> 104 <a class="indexterm" name="id2613016"></a> 105 105 Further, in an NT4-style MS security domain, all trusts are nontransitive. This means that if there are three 106 106 domains (let's call them red, white, and blue), where red and white have a trust relationship, and white and … … 108 108 Relationships are explicit and not transitive. 109 109 </p><p> 110 <a class="indexterm" name="id2613019"></a>111 <a class="indexterm" name="id2613026"></a>112 110 <a class="indexterm" name="id2613032"></a> 113 111 <a class="indexterm" name="id2613039"></a> … … 115 113 <a class="indexterm" name="id2613053"></a> 116 114 <a class="indexterm" name="id2613060"></a> 115 <a class="indexterm" name="id2613066"></a> 116 <a class="indexterm" name="id2613073"></a> 117 117 New to MS Windows 2000 ADS security contexts is the fact that trust relationships are two-way by default. 118 118 Also, all inter-ADS domain trusts are transitive. In the case of the red, white, and blue domains, with … … 120 120 domains. Samba-3 implements MS Windows NT4-style interdomain trusts and interoperates with MS Windows 200x ADS 121 121 security domains in similar manner to MS Windows NT4-style domains. 122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26130 78"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p>123 <a class="indexterm" name="id26130 85"></a>124 <a class="indexterm" name="id2613 094"></a>125 <a class="indexterm" name="id26131 01"></a>122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2613091"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p> 123 <a class="indexterm" name="id2613098"></a> 124 <a class="indexterm" name="id2613108"></a> 125 <a class="indexterm" name="id2613115"></a> 126 126 There are two steps to creating an interdomain trust relationship. To effect a two-way trust 127 127 relationship, it is necessary for each domain administrator to create a trust account for the 128 128 other domain to use in verifying security credentials. 129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26131 14"></a>Creating an NT4 Domain Trust</h3></div></div></div><p>130 <a class="indexterm" name="id26131 22"></a>131 <a class="indexterm" name="id26131 29"></a>132 <a class="indexterm" name="id26131 36"></a>133 <a class="indexterm" name="id26131 43"></a>134 <a class="indexterm" name="id26131 50"></a>129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2613127"></a>Creating an NT4 Domain Trust</h3></div></div></div><p> 130 <a class="indexterm" name="id2613135"></a> 131 <a class="indexterm" name="id2613142"></a> 132 <a class="indexterm" name="id2613149"></a> 133 <a class="indexterm" name="id2613156"></a> 134 <a class="indexterm" name="id2613163"></a> 135 135 For MS Windows NT4, all domain trust relationships are configured using the 136 136 <span class="application">Domain User Manager</span>. This is done from the Domain User Manager Policies … … 143 143 trusting domain will use when authenticating users from the trusted domain. 144 144 The password needs to be typed twice (for standard confirmation). 145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26132 11"></a>Completing an NT4 Domain Trust</h3></div></div></div><p>146 <a class="indexterm" name="id26132 19"></a>147 <a class="indexterm" name="id26132 26"></a>148 <a class="indexterm" name="id26132 33"></a>149 <a class="indexterm" name="id26132 40"></a>150 <a class="indexterm" name="id26132 47"></a>151 <a class="indexterm" name="id26132 54"></a>145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2613224"></a>Completing an NT4 Domain Trust</h3></div></div></div><p> 146 <a class="indexterm" name="id2613232"></a> 147 <a class="indexterm" name="id2613239"></a> 148 <a class="indexterm" name="id2613246"></a> 149 <a class="indexterm" name="id2613253"></a> 150 <a class="indexterm" name="id2613260"></a> 151 <a class="indexterm" name="id2613267"></a> 152 152 A trust relationship will work only when the other (trusting) domain makes the appropriate connections 153 153 with the trusted domain. To consummate the trust relationship, the administrator launches the … … 156 156 next to the box that is labeled <span class="guilabel">Trusted Domains</span>. A panel opens in which 157 157 must be entered the name of the remote domain as well as the password assigned to that trust. 158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2613 296"></a>Interdomain Trust Facilities</h3></div></div></div><p>159 <a class="indexterm" name="id26133 04"></a>160 <a class="indexterm" name="id26133 11"></a>161 <a class="indexterm" name="id26133 18"></a>162 <a class="indexterm" name="id26133 25"></a>163 <a class="indexterm" name="id26133 32"></a>164 <a class="indexterm" name="id26133 39"></a>158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2613309"></a>Interdomain Trust Facilities</h3></div></div></div><p> 159 <a class="indexterm" name="id2613317"></a> 160 <a class="indexterm" name="id2613324"></a> 161 <a class="indexterm" name="id2613331"></a> 162 <a class="indexterm" name="id2613338"></a> 163 <a class="indexterm" name="id2613345"></a> 164 <a class="indexterm" name="id2613352"></a> 165 165 A two-way trust relationship is created when two one-way trusts are created, one in each direction. 166 166 Where a one-way trust has been established between two MS Windows NT4 domains (let's call them … … 202 202 Global groups from the trusted domain can be made members in local groups on 203 203 MS Windows domain member machines. 204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26135 05"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p>205 <a class="indexterm" name="id26135 13"></a>204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2613518"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p> 205 <a class="indexterm" name="id2613526"></a> 206 206 This description is meant to be a fairly short introduction about how to set up a Samba server so 207 207 that it can participate in interdomain trust relationships. Trust relationship support in Samba 208 208 is at an early stage, so do not be surprised if something does not function as it should. 209 209 </p><p> 210 <a class="indexterm" name="id26135 28"></a>211 <a class="indexterm" name="id26135 35"></a>212 <a class="indexterm" name="id26135 42"></a>213 <a class="indexterm" name="id26135 49"></a>210 <a class="indexterm" name="id2613541"></a> 211 <a class="indexterm" name="id2613548"></a> 212 <a class="indexterm" name="id2613555"></a> 213 <a class="indexterm" name="id2613562"></a> 214 214 Each of the procedures described next assumes the peer domain in the trust relationship is controlled by a 215 215 Windows NT4 server. However, the remote end could just as well be another Samba-3 domain. It can be clearly … … 217 217 sections leads to trust between domains in a purely Samba environment. 218 218 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="samba-trusted-domain"></a>Samba as the Trusted Domain</h3></div></div></div><p> 219 <a class="indexterm" name="id2613576"></a> 220 <a class="indexterm" name="id2613583"></a> 221 <a class="indexterm" name="id2613590"></a> 222 <a class="indexterm" name="id2613597"></a> 219 <a class="indexterm" name="id2613589"></a> 220 <a class="indexterm" name="id2613596"></a> 223 221 <a class="indexterm" name="id2613603"></a> 222 <a class="indexterm" name="id2613610"></a> 223 <a class="indexterm" name="id2613616"></a> 224 224 In order to set the Samba PDC to be the trusted party of the relationship, you first need 225 225 to create a special account for the domain that will be the trusting party. To do that, … … 240 240 account with the Interdomain trust flag</span>”. 241 241 </p><p> 242 <a class="indexterm" name="id26136 72"></a>243 <a class="indexterm" name="id26136 79"></a>244 <a class="indexterm" name="id26136 86"></a>245 <a class="indexterm" name="id2613 693"></a>242 <a class="indexterm" name="id2613685"></a> 243 <a class="indexterm" name="id2613692"></a> 244 <a class="indexterm" name="id2613699"></a> 245 <a class="indexterm" name="id2613706"></a> 246 246 The account name will be “<span class="quote">rumba$</span>” (the name of the remote domain). 247 247 If this fails, you should check that the trust account has been added to the system … … 249 249 can add it manually and then repeat the previous step. 250 250 </p><p> 251 <a class="indexterm" name="id2613716"></a>252 <a class="indexterm" name="id2613723"></a>253 251 <a class="indexterm" name="id2613730"></a> 254 <a class="indexterm" name="id2613737"></a> 252 <a class="indexterm" name="id2613736"></a> 253 <a class="indexterm" name="id2613743"></a> 254 <a class="indexterm" name="id2613750"></a> 255 255 After issuing this command, you will be asked to enter the password for the account. You can use any password 256 256 you want, but be aware that Windows NT will not change this password until 7 days following account creation. … … 260 260 Windows NT Server. 261 261 </p><p> 262 <a class="indexterm" name="id26137 60"></a>263 <a class="indexterm" name="id26137 67"></a>264 <a class="indexterm" name="id26137 74"></a>265 <a class="indexterm" name="id26137 81"></a>266 <a class="indexterm" name="id2613 788"></a>262 <a class="indexterm" name="id2613773"></a> 263 <a class="indexterm" name="id2613780"></a> 264 <a class="indexterm" name="id2613787"></a> 265 <a class="indexterm" name="id2613794"></a> 266 <a class="indexterm" name="id2613801"></a> 267 267 Open <span class="application">User Manager for Domains</span> and from the <span class="guimenu">Policies</span> menu, select 268 268 <span class="guimenuitem">Trust Relationships...</span>. Beside the <span class="guilabel">Trusted domains</span> list box, … … 271 271 time of account creation. Click on <span class="guibutton">OK</span> and, if everything went without incident, you 272 272 will see the <code class="computeroutput">Trusted domain relationship successfully established</code> message. 273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26138 45"></a>Samba as the Trusting Domain</h3></div></div></div><p>274 <a class="indexterm" name="id26138 53"></a>275 <a class="indexterm" name="id26138 60"></a>273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2613858"></a>Samba as the Trusting Domain</h3></div></div></div><p> 274 <a class="indexterm" name="id2613866"></a> 275 <a class="indexterm" name="id2613873"></a> 276 276 This time activities are somewhat reversed. Again, we'll assume that your domain 277 277 controlled by the Samba PDC is called SAMBA and the NT-controlled domain is called RUMBA. … … 279 279 The very first step is to add an account for the SAMBA domain on RUMBA's PDC. 280 280 </p><p> 281 <a class="indexterm" name="id2613878"></a>282 <a class="indexterm" name="id2613884"></a>283 281 <a class="indexterm" name="id2613891"></a> 282 <a class="indexterm" name="id2613898"></a> 283 <a class="indexterm" name="id2613905"></a> 284 284 Launch the <span class="application">Domain User Manager</span>, then from the menu select 285 285 <span class="guimenu">Policies</span>, <span class="guimenuitem">Trust Relationships</span>. … … 288 288 the relationship. 289 289 </p><p> 290 <a class="indexterm" name="id26139 34"></a>291 <a class="indexterm" name="id26139 41"></a>290 <a class="indexterm" name="id2613947"></a> 291 <a class="indexterm" name="id2613954"></a> 292 292 The password can be arbitrarily chosen. It is easy to change the password from the Samba server whenever you 293 293 want. After you confirm the password, your account is ready for use. Now its Samba's turn. 294 294 </p><p> 295 295 Using your favorite shell while logged in as root, issue this command: 296 <a class="indexterm" name="id26139 56"></a>296 <a class="indexterm" name="id2613969"></a> 297 297 </p><p> 298 298 <code class="prompt">root# </code><strong class="userinput"><code>net rpc trustdom establish rumba</code></strong> 299 299 </p><p> 300 <a class="indexterm" name="id2613984"></a>301 <a class="indexterm" name="id2613991"></a>302 300 <a class="indexterm" name="id2613998"></a> 301 <a class="indexterm" name="id2614004"></a> 302 <a class="indexterm" name="id2614011"></a> 303 303 You will be prompted for the password you just typed on your Windows NT4 Server box. 304 304 An error message, <code class="literal">"NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT,"</code> … … 312 312 You have to run this command as root because you must have write access to 313 313 the <code class="filename">secrets.tdb</code> file. 314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2614041"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p> 315 <a class="indexterm" name="id2614050"></a> 316 <a class="indexterm" name="id2614056"></a> 314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2614054"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p> 317 315 <a class="indexterm" name="id2614063"></a> 318 316 <a class="indexterm" name="id2614070"></a> 317 <a class="indexterm" name="id2614077"></a> 318 <a class="indexterm" name="id2614083"></a> 319 319 Although <span class="application">Domain User Manager</span> is not present in Windows 2000, it is 320 320 also possible to establish an NT4-style trust relationship with a Windows 2000 domain … … 322 322 Samba to trust a Windows 2000 server; however, more testing is still needed in this area. 323 323 </p><p> 324 <a class="indexterm" name="id2614092"></a>325 <a class="indexterm" name="id2614098"></a>326 324 <a class="indexterm" name="id2614105"></a> 327 325 <a class="indexterm" name="id2614112"></a> 326 <a class="indexterm" name="id2614119"></a> 327 <a class="indexterm" name="id2614126"></a> 328 328 After <a class="link" href="InterdomainTrusts.html#samba-trusted-domain" title="Samba as the Trusted Domain">creating the interdomain trust account on the Samba server</a> 329 329 as described previously, open <span class="application">Active Directory Domains and Trusts</span> on the AD … … 339 339 <code class="computeroutput">The trusted domain has been added and the trust has been verified.</code> Your 340 340 Samba users can now be granted access to resources in the AD domain. 341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2614 191"></a>Common Errors</h2></div></div></div><p>341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2614204"></a>Common Errors</h2></div></div></div><p> 342 342 Interdomain trust relationships should not be attempted on networks that are unstable 343 343 or that suffer regular outages. Network stability and integrity are key concerns with 344 344 distributed trusted domains. 345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26142 03"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p>345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2614216"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p> 346 346 <span class="emphasis"><em>Browsing from a machine in a trusted Windows 200x domain to a Windows 200x member of 347 347 a trusting Samba domain, I get the following error:</em></span> … … 361 361 the domain. If you are running as an account that has privileges to do this 362 362 when you unjoin the machine, it is done; otherwise it is not done. 363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26142 49"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p>363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2614262"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p> 364 364 If you use the <code class="literal">smbldap-useradd</code> script to create a trust 365 365 account to set up interdomain trusts, the process of setting up the trust will
Note:
See TracChangeset
for help on using the changeset viewer.