- Timestamp:
- Jun 17, 2009, 2:19:52 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.3.x/docs/htmldocs/Samba3-HOWTO/InterdomainTrusts.html
r218 r274 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3. 2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619694">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619766">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620044">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620080">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620177">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620262">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620471">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620820">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621016">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621165">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621178">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621224">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p>2 <a class="indexterm" name="id2619 474"></a>3 <a class="indexterm" name="id2619 481"></a>4 <a class="indexterm" name="id2619 488"></a>5 <a class="indexterm" name="id2619 495"></a>6 <a class="indexterm" name="id26195 02"></a>7 <a class="indexterm" name="id26195 09"></a>8 <a class="indexterm" name="id26195 16"></a>9 <a class="indexterm" name="id26195 22"></a>10 <a class="indexterm" name="id26195 29"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3.3.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619747">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619819">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620105">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620141">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620238">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620323">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620532">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620873">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621070">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621219">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621231">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621277">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p> 2 <a class="indexterm" name="id2619527"></a> 3 <a class="indexterm" name="id2619534"></a> 4 <a class="indexterm" name="id2619541"></a> 5 <a class="indexterm" name="id2619548"></a> 6 <a class="indexterm" name="id2619555"></a> 7 <a class="indexterm" name="id2619562"></a> 8 <a class="indexterm" name="id2619569"></a> 9 <a class="indexterm" name="id2619576"></a> 10 <a class="indexterm" name="id2619582"></a> 11 11 Samba-3 supports NT4-style domain trust relationships. This is a feature that many sites 12 12 will want to use if they migrate to Samba-3 from an NT4-style domain and do not want to … … 16 16 trusts. 17 17 </p><p> 18 <a class="indexterm" name="id2619 547"></a>19 <a class="indexterm" name="id2619 554"></a>20 <a class="indexterm" name="id2619 560"></a>21 <a class="indexterm" name="id2619 567"></a>22 <a class="indexterm" name="id2619 574"></a>18 <a class="indexterm" name="id2619600"></a> 19 <a class="indexterm" name="id2619607"></a> 20 <a class="indexterm" name="id2619614"></a> 21 <a class="indexterm" name="id2619620"></a> 22 <a class="indexterm" name="id2619627"></a> 23 23 The use of interdomain trusts requires use of <code class="literal">winbind</code>, so the 24 24 <code class="literal">winbindd</code> daemon must be running. Winbind operation in this mode is 25 25 dependent on the specification of a valid UID range and a valid GID range in the <code class="filename">smb.conf</code> file. 26 26 These are specified respectively using: 27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id26196 08"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619620"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p>28 <a class="indexterm" name="id26196 32"></a>29 <a class="indexterm" name="id26196 38"></a>30 <a class="indexterm" name="id26196 45"></a>31 <a class="indexterm" name="id2619 652"></a>27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2619661"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619673"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p> 28 <a class="indexterm" name="id2619685"></a> 29 <a class="indexterm" name="id2619692"></a> 30 <a class="indexterm" name="id2619699"></a> 31 <a class="indexterm" name="id2619706"></a> 32 32 The range of values specified must not overlap values used by the host operating system and must 33 33 not overlap values used in the passdb backend for POSIX user accounts. The maximum value is … … 36 36 (32-bit unsigned variable). 37 37 </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 38 <a class="indexterm" name="id2619 670"></a>39 <a class="indexterm" name="id2619 677"></a>40 <a class="indexterm" name="id2619 684"></a>38 <a class="indexterm" name="id2619723"></a> 39 <a class="indexterm" name="id2619730"></a> 40 <a class="indexterm" name="id2619737"></a> 41 41 The use of winbind is necessary only when Samba is the trusting domain, not when it is the 42 42 trusted domain. 43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619 694"></a>Features and Benefits</h2></div></div></div><p>44 <a class="indexterm" name="id26197 02"></a>45 <a class="indexterm" name="id26197 09"></a>43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619747"></a>Features and Benefits</h2></div></div></div><p> 44 <a class="indexterm" name="id2619755"></a> 45 <a class="indexterm" name="id2619762"></a> 46 46 Samba-3 can participate in Samba-to-Samba as well as in Samba-to-MS Windows NT4-style 47 47 trust relationships. This imparts to Samba scalability similar to that with MS Windows NT4. 48 48 </p><p> 49 <a class="indexterm" name="id26197 22"></a>50 <a class="indexterm" name="id26197 29"></a>51 <a class="indexterm" name="id26197 36"></a>52 <a class="indexterm" name="id26197 43"></a>53 <a class="indexterm" name="id2619 750"></a>49 <a class="indexterm" name="id2619775"></a> 50 <a class="indexterm" name="id2619782"></a> 51 <a class="indexterm" name="id2619789"></a> 52 <a class="indexterm" name="id2619796"></a> 53 <a class="indexterm" name="id2619803"></a> 54 54 Given that Samba-3 can function with a scalable backend authentication database such as LDAP, and given its 55 55 ability to run in primary as well as backup domain control modes, the administrator would be well-advised to … … 57 57 function, this system is fragile. That was, after all, a key reason for the development and adoption of 58 58 Microsoft Active Directory. 59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619 766"></a>Trust Relationship Background</h2></div></div></div><p>60 <a class="indexterm" name="id2619 774"></a>61 <a class="indexterm" name="id2619 781"></a>62 <a class="indexterm" name="id2619 788"></a>63 <a class="indexterm" name="id2619 795"></a>64 <a class="indexterm" name="id26198 02"></a>65 <a class="indexterm" name="id26198 09"></a>59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619819"></a>Trust Relationship Background</h2></div></div></div><p> 60 <a class="indexterm" name="id2619827"></a> 61 <a class="indexterm" name="id2619834"></a> 62 <a class="indexterm" name="id2619841"></a> 63 <a class="indexterm" name="id2619848"></a> 64 <a class="indexterm" name="id2619855"></a> 65 <a class="indexterm" name="id2619862"></a> 66 66 MS Windows NT3/4-type security domains employ a nonhierarchical security structure. 67 67 The limitations of this architecture as it effects the scalability of MS Windows networking … … 70 70 large and diverse organizations. 71 71 </p><p> 72 <a class="indexterm" name="id26198 26"></a>73 <a class="indexterm" name="id26198 32"></a>74 <a class="indexterm" name="id26198 39"></a>75 <a class="indexterm" name="id26198 46"></a>76 <a class="indexterm" name="id2619 853"></a>72 <a class="indexterm" name="id2619879"></a> 73 <a class="indexterm" name="id2619885"></a> 74 <a class="indexterm" name="id2619892"></a> 75 <a class="indexterm" name="id2619899"></a> 76 <a class="indexterm" name="id2619906"></a> 77 77 Microsoft developed Active Directory Service (ADS), based on Kerberos and LDAP, as a means 78 78 of circumventing the limitations of the older technologies. Not every organization is ready … … 81 81 desire to go through a disruptive change to adopt ADS. 82 82 </p><p> 83 <a class="indexterm" name="id2619 870"></a>84 <a class="indexterm" name="id2619 877"></a>85 <a class="indexterm" name="id2619 884"></a>86 <a class="indexterm" name="id2619 891"></a>87 <a class="indexterm" name="id2619 897"></a>88 <a class="indexterm" name="id26199 04"></a>89 <a class="indexterm" name="id26199 11"></a>83 <a class="indexterm" name="id2619923"></a> 84 <a class="indexterm" name="id2619930"></a> 85 <a class="indexterm" name="id2619937"></a> 86 <a class="indexterm" name="id2619944"></a> 87 <a class="indexterm" name="id2619951"></a> 88 <a class="indexterm" name="id2619958"></a> 89 <a class="indexterm" name="id2619964"></a> 90 90 With Windows NT, Microsoft introduced the ability to allow different security domains 91 91 to effect a mechanism so users from one domain may be given access rights and privileges … … 98 98 necessary to establish two relationships, one in each direction. 99 99 </p><p> 100 <a class="indexterm" name="id26 19941"></a>101 <a class="indexterm" name="id26 19948"></a>102 <a class="indexterm" name="id26 19955"></a>103 <a class="indexterm" name="id26 19962"></a>104 <a class="indexterm" name="id26 19969"></a>100 <a class="indexterm" name="id2620002"></a> 101 <a class="indexterm" name="id2620009"></a> 102 <a class="indexterm" name="id2620016"></a> 103 <a class="indexterm" name="id2620023"></a> 104 <a class="indexterm" name="id2620030"></a> 105 105 Further, in an NT4-style MS security domain, all trusts are nontransitive. This means that if there are three 106 106 domains (let's call them red, white, and blue), where red and white have a trust relationship, and white and … … 108 108 Relationships are explicit and not transitive. 109 109 </p><p> 110 <a class="indexterm" name="id26 19985"></a>111 <a class="indexterm" name="id26 19992"></a>112 <a class="indexterm" name="id26 19999"></a>113 <a class="indexterm" name="id26200 06"></a>114 <a class="indexterm" name="id26200 13"></a>115 <a class="indexterm" name="id26200 20"></a>116 <a class="indexterm" name="id26200 27"></a>110 <a class="indexterm" name="id2620046"></a> 111 <a class="indexterm" name="id2620053"></a> 112 <a class="indexterm" name="id2620060"></a> 113 <a class="indexterm" name="id2620067"></a> 114 <a class="indexterm" name="id2620074"></a> 115 <a class="indexterm" name="id2620080"></a> 116 <a class="indexterm" name="id2620087"></a> 117 117 New to MS Windows 2000 ADS security contexts is the fact that trust relationships are two-way by default. 118 118 Also, all inter-ADS domain trusts are transitive. In the case of the red, white, and blue domains, with … … 120 120 domains. Samba-3 implements MS Windows NT4-style interdomain trusts and interoperates with MS Windows 200x ADS 121 121 security domains in similar manner to MS Windows NT4-style domains. 122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620 044"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p>123 <a class="indexterm" name="id2620 052"></a>124 <a class="indexterm" name="id2620 061"></a>125 <a class="indexterm" name="id2620 068"></a>122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620105"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p> 123 <a class="indexterm" name="id2620112"></a> 124 <a class="indexterm" name="id2620122"></a> 125 <a class="indexterm" name="id2620129"></a> 126 126 There are two steps to creating an interdomain trust relationship. To effect a two-way trust 127 127 relationship, it is necessary for each domain administrator to create a trust account for the 128 128 other domain to use in verifying security credentials. 129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 080"></a>Creating an NT4 Domain Trust</h3></div></div></div><p>130 <a class="indexterm" name="id2620 088"></a>131 <a class="indexterm" name="id2620 095"></a>132 <a class="indexterm" name="id26201 02"></a>133 <a class="indexterm" name="id26201 10"></a>134 <a class="indexterm" name="id26201 16"></a>129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620141"></a>Creating an NT4 Domain Trust</h3></div></div></div><p> 130 <a class="indexterm" name="id2620149"></a> 131 <a class="indexterm" name="id2620156"></a> 132 <a class="indexterm" name="id2620163"></a> 133 <a class="indexterm" name="id2620170"></a> 134 <a class="indexterm" name="id2620177"></a> 135 135 For MS Windows NT4, all domain trust relationships are configured using the 136 136 <span class="application">Domain User Manager</span>. This is done from the Domain User Manager Policies … … 143 143 trusting domain will use when authenticating users from the trusted domain. 144 144 The password needs to be typed twice (for standard confirmation). 145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 177"></a>Completing an NT4 Domain Trust</h3></div></div></div><p>146 <a class="indexterm" name="id2620 185"></a>147 <a class="indexterm" name="id2620 192"></a>148 <a class="indexterm" name="id2620 199"></a>149 <a class="indexterm" name="id26202 06"></a>150 <a class="indexterm" name="id26202 13"></a>151 <a class="indexterm" name="id26202 20"></a>145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620238"></a>Completing an NT4 Domain Trust</h3></div></div></div><p> 146 <a class="indexterm" name="id2620246"></a> 147 <a class="indexterm" name="id2620253"></a> 148 <a class="indexterm" name="id2620260"></a> 149 <a class="indexterm" name="id2620267"></a> 150 <a class="indexterm" name="id2620274"></a> 151 <a class="indexterm" name="id2620281"></a> 152 152 A trust relationship will work only when the other (trusting) domain makes the appropriate connections 153 153 with the trusted domain. To consummate the trust relationship, the administrator launches the … … 156 156 next to the box that is labeled <span class="guilabel">Trusted Domains</span>. A panel opens in which 157 157 must be entered the name of the remote domain as well as the password assigned to that trust. 158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 262"></a>Interdomain Trust Facilities</h3></div></div></div><p>159 <a class="indexterm" name="id2620 270"></a>160 <a class="indexterm" name="id2620 277"></a>161 <a class="indexterm" name="id2620 284"></a>162 <a class="indexterm" name="id2620 291"></a>163 <a class="indexterm" name="id2620 298"></a>164 <a class="indexterm" name="id26203 05"></a>158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620323"></a>Interdomain Trust Facilities</h3></div></div></div><p> 159 <a class="indexterm" name="id2620331"></a> 160 <a class="indexterm" name="id2620338"></a> 161 <a class="indexterm" name="id2620345"></a> 162 <a class="indexterm" name="id2620352"></a> 163 <a class="indexterm" name="id2620359"></a> 164 <a class="indexterm" name="id2620366"></a> 165 165 A two-way trust relationship is created when two one-way trusts are created, one in each direction. 166 166 Where a one-way trust has been established between two MS Windows NT4 domains (let's call them … … 202 202 Global groups from the trusted domain can be made members in local groups on 203 203 MS Windows domain member machines. 204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620 471"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p>205 <a class="indexterm" name="id2620 480"></a>204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620532"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p> 205 <a class="indexterm" name="id2620540"></a> 206 206 This description is meant to be a fairly short introduction about how to set up a Samba server so 207 207 that it can participate in interdomain trust relationships. Trust relationship support in Samba 208 208 is at an early stage, so do not be surprised if something does not function as it should. 209 209 </p><p> 210 <a class="indexterm" name="id2620 495"></a>211 <a class="indexterm" name="id26205 02"></a>212 <a class="indexterm" name="id26205 08"></a>213 <a class="indexterm" name="id26205 15"></a>210 <a class="indexterm" name="id2620556"></a> 211 <a class="indexterm" name="id2620562"></a> 212 <a class="indexterm" name="id2620569"></a> 213 <a class="indexterm" name="id2620576"></a> 214 214 Each of the procedures described next assumes the peer domain in the trust relationship is controlled by a 215 215 Windows NT4 server. However, the remote end could just as well be another Samba-3 domain. It can be clearly … … 217 217 sections leads to trust between domains in a purely Samba environment. 218 218 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="samba-trusted-domain"></a>Samba as the Trusted Domain</h3></div></div></div><p> 219 <a class="indexterm" name="id2620 543"></a>220 <a class="indexterm" name="id2620 550"></a>221 <a class="indexterm" name="id2620 556"></a>222 <a class="indexterm" name="id2620 563"></a>223 <a class="indexterm" name="id2620 570"></a>219 <a class="indexterm" name="id2620603"></a> 220 <a class="indexterm" name="id2620610"></a> 221 <a class="indexterm" name="id2620617"></a> 222 <a class="indexterm" name="id2620624"></a> 223 <a class="indexterm" name="id2620631"></a> 224 224 In order to set the Samba PDC to be the trusted party of the relationship, you first need 225 225 to create a special account for the domain that will be the trusting party. To do that, … … 240 240 account with the Interdomain trust flag</span>”. 241 241 </p><p> 242 <a class="indexterm" name="id2620 640"></a>243 <a class="indexterm" name="id2620 646"></a>244 <a class="indexterm" name="id2620 653"></a>245 <a class="indexterm" name="id2620 660"></a>242 <a class="indexterm" name="id2620700"></a> 243 <a class="indexterm" name="id2620707"></a> 244 <a class="indexterm" name="id2620714"></a> 245 <a class="indexterm" name="id2620721"></a> 246 246 The account name will be “<span class="quote">rumba$</span>” (the name of the remote domain). 247 247 If this fails, you should check that the trust account has been added to the system … … 249 249 can add it manually and then repeat the previous step. 250 250 </p><p> 251 <a class="indexterm" name="id2620 684"></a>252 <a class="indexterm" name="id2620 691"></a>253 <a class="indexterm" name="id2620 698"></a>254 <a class="indexterm" name="id26207 05"></a>251 <a class="indexterm" name="id2620745"></a> 252 <a class="indexterm" name="id2620752"></a> 253 <a class="indexterm" name="id2620758"></a> 254 <a class="indexterm" name="id2620765"></a> 255 255 After issuing this command, you will be asked to enter the password for the account. You can use any password 256 256 you want, but be aware that Windows NT will not change this password until 7 days following account creation. … … 260 260 Windows NT Server. 261 261 </p><p> 262 <a class="indexterm" name="id26207 34"></a>263 <a class="indexterm" name="id26207 41"></a>264 <a class="indexterm" name="id2620 748"></a>265 <a class="indexterm" name="id2620 755"></a>266 <a class="indexterm" name="id2620 762"></a>262 <a class="indexterm" name="id2620788"></a> 263 <a class="indexterm" name="id2620795"></a> 264 <a class="indexterm" name="id2620802"></a> 265 <a class="indexterm" name="id2620809"></a> 266 <a class="indexterm" name="id2620816"></a> 267 267 Open <span class="application">User Manager for Domains</span> and from the <span class="guimenu">Policies</span> menu, select 268 268 <span class="guimenuitem">Trust Relationships...</span>. Beside the <span class="guilabel">Trusted domains</span> list box, … … 271 271 time of account creation. Click on <span class="guibutton">OK</span> and, if everything went without incident, you 272 272 will see the <code class="computeroutput">Trusted domain relationship successfully established</code> message. 273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26208 20"></a>Samba as the Trusting Domain</h3></div></div></div><p>274 <a class="indexterm" name="id26208 28"></a>275 <a class="indexterm" name="id26208 35"></a>273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620873"></a>Samba as the Trusting Domain</h3></div></div></div><p> 274 <a class="indexterm" name="id2620881"></a> 275 <a class="indexterm" name="id2620888"></a> 276 276 This time activities are somewhat reversed. Again, we'll assume that your domain 277 277 controlled by the Samba PDC is called SAMBA and the NT-controlled domain is called RUMBA. … … 279 279 The very first step is to add an account for the SAMBA domain on RUMBA's PDC. 280 280 </p><p> 281 <a class="indexterm" name="id2620 852"></a>282 <a class="indexterm" name="id2620 859"></a>283 <a class="indexterm" name="id2620 866"></a>281 <a class="indexterm" name="id2620906"></a> 282 <a class="indexterm" name="id2620913"></a> 283 <a class="indexterm" name="id2620920"></a> 284 284 Launch the <span class="application">Domain User Manager</span>, then from the menu select 285 285 <span class="guimenu">Policies</span>, <span class="guimenuitem">Trust Relationships</span>. … … 288 288 the relationship. 289 289 </p><p> 290 <a class="indexterm" name="id26209 09"></a>291 <a class="indexterm" name="id26209 16"></a>290 <a class="indexterm" name="id2620962"></a> 291 <a class="indexterm" name="id2620969"></a> 292 292 The password can be arbitrarily chosen. It is easy to change the password from the Samba server whenever you 293 293 want. After you confirm the password, your account is ready for use. Now its Samba's turn. 294 294 </p><p> 295 295 Using your favorite shell while logged in as root, issue this command: 296 <a class="indexterm" name="id26209 31"></a>296 <a class="indexterm" name="id2620984"></a> 297 297 </p><p> 298 298 <code class="prompt">root# </code><strong class="userinput"><code>net rpc trustdom establish rumba</code></strong> 299 299 </p><p> 300 <a class="indexterm" name="id262 0959"></a>301 <a class="indexterm" name="id262 0966"></a>302 <a class="indexterm" name="id262 0973"></a>300 <a class="indexterm" name="id2621013"></a> 301 <a class="indexterm" name="id2621020"></a> 302 <a class="indexterm" name="id2621027"></a> 303 303 You will be prompted for the password you just typed on your Windows NT4 Server box. 304 304 An error message, <code class="literal">"NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT,"</code> … … 312 312 You have to run this command as root because you must have write access to 313 313 the <code class="filename">secrets.tdb</code> file. 314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26210 16"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p>315 <a class="indexterm" name="id26210 24"></a>316 <a class="indexterm" name="id26210 31"></a>317 <a class="indexterm" name="id26210 38"></a>318 <a class="indexterm" name="id26210 45"></a>314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621070"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p> 315 <a class="indexterm" name="id2621078"></a> 316 <a class="indexterm" name="id2621085"></a> 317 <a class="indexterm" name="id2621092"></a> 318 <a class="indexterm" name="id2621099"></a> 319 319 Although <span class="application">Domain User Manager</span> is not present in Windows 2000, it is 320 320 also possible to establish an NT4-style trust relationship with a Windows 2000 domain … … 322 322 Samba to trust a Windows 2000 server; however, more testing is still needed in this area. 323 323 </p><p> 324 <a class="indexterm" name="id2621 066"></a>325 <a class="indexterm" name="id2621 073"></a>326 <a class="indexterm" name="id2621 080"></a>327 <a class="indexterm" name="id2621 087"></a>324 <a class="indexterm" name="id2621120"></a> 325 <a class="indexterm" name="id2621127"></a> 326 <a class="indexterm" name="id2621134"></a> 327 <a class="indexterm" name="id2621141"></a> 328 328 After <a class="link" href="InterdomainTrusts.html#samba-trusted-domain" title="Samba as the Trusted Domain">creating the interdomain trust account on the Samba server</a> 329 329 as described previously, open <span class="application">Active Directory Domains and Trusts</span> on the AD … … 339 339 <code class="computeroutput">The trusted domain has been added and the trust has been verified.</code> Your 340 340 Samba users can now be granted access to resources in the AD domain. 341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621 165"></a>Common Errors</h2></div></div></div><p>341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621219"></a>Common Errors</h2></div></div></div><p> 342 342 Interdomain trust relationships should not be attempted on networks that are unstable 343 343 or that suffer regular outages. Network stability and integrity are key concerns with 344 344 distributed trusted domains. 345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621 178"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p>345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621231"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p> 346 346 <span class="emphasis"><em>Browsing from a machine in a trusted Windows 200x domain to a Windows 200x member of 347 347 a trusting Samba domain, I get the following error:</em></span> … … 361 361 the domain. If you are running as an account that has privileges to do this 362 362 when you unjoin the machine, it is done; otherwise it is not done. 363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26212 24"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p>363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621277"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p> 364 364 If you use the <code class="literal">smbldap-useradd</code> script to create a trust 365 365 account to set up interdomain trusts, the process of setting up the trust will
Note:
See TracChangeset
for help on using the changeset viewer.