Ignore:
Timestamp:
Aug 5, 2009, 6:33:18 PM (16 years ago)
Author:
Herwig Bauernfeind
Message:

Update 3.0 to final 3.0.36 (docs)

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/samba-3.0/docs/htmldocs/Samba3-HOWTO/InterdomainTrusts.html

    r286 r311  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3.2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>&gt;</code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619683">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619755">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620033">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620070">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620166">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620252">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620461">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620809">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621005">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621155">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621167">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621213">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p>
    2 <a class="indexterm" name="id2619463"></a>
    3 <a class="indexterm" name="id2619470"></a>
    4 <a class="indexterm" name="id2619477"></a>
    5 <a class="indexterm" name="id2619484"></a>
    6 <a class="indexterm" name="id2619491"></a>
    7 <a class="indexterm" name="id2619498"></a>
    8 <a class="indexterm" name="id2619505"></a>
    9 <a class="indexterm" name="id2619512"></a>
    10 <a class="indexterm" name="id2619518"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3.0.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>&gt;</code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>&gt;</code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619706">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619778">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620056">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620092">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620189">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620274">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620483">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620824">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621020">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621170">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621182">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621228">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p>
     2<a class="indexterm" name="id2619486"></a>
     3<a class="indexterm" name="id2619493"></a>
     4<a class="indexterm" name="id2619499"></a>
     5<a class="indexterm" name="id2619506"></a>
     6<a class="indexterm" name="id2619513"></a>
     7<a class="indexterm" name="id2619520"></a>
     8<a class="indexterm" name="id2619527"></a>
     9<a class="indexterm" name="id2619534"></a>
     10<a class="indexterm" name="id2619541"></a>
    1111Samba-3 supports NT4-style domain trust relationships. This is a feature that many sites
    1212will want to use if they migrate to Samba-3 from an NT4-style domain and do not want to
     
    1616trusts.
    1717</p><p>
    18 <a class="indexterm" name="id2619536"></a>
    19 <a class="indexterm" name="id2619543"></a>
    20 <a class="indexterm" name="id2619550"></a>
    21 <a class="indexterm" name="id2619556"></a>
    22 <a class="indexterm" name="id2619563"></a>
     18<a class="indexterm" name="id2619558"></a>
     19<a class="indexterm" name="id2619565"></a>
     20<a class="indexterm" name="id2619572"></a>
     21<a class="indexterm" name="id2619579"></a>
     22<a class="indexterm" name="id2619586"></a>
    2323The use of interdomain trusts requires use of <code class="literal">winbind</code>, so the
    2424<code class="literal">winbindd</code> daemon must be running. Winbind operation in this mode is
    2525dependent on the specification of a valid UID range and a valid GID range in the <code class="filename">smb.conf</code> file.
    2626These are specified respectively using:
    27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2619597"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619609"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p>
    28 <a class="indexterm" name="id2619621"></a>
    29 <a class="indexterm" name="id2619628"></a>
    30 <a class="indexterm" name="id2619635"></a>
    31 <a class="indexterm" name="id2619642"></a>
     27</p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2619620"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619631"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p>
     28<a class="indexterm" name="id2619643"></a>
     29<a class="indexterm" name="id2619650"></a>
     30<a class="indexterm" name="id2619657"></a>
     31<a class="indexterm" name="id2619664"></a>
    3232The range of values specified must not overlap values used by the host operating system and must
    3333not overlap values used in the passdb backend for POSIX user accounts. The maximum value is
     
    3636(32-bit unsigned variable).
    3737</p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p>
    38 <a class="indexterm" name="id2619660"></a>
    39 <a class="indexterm" name="id2619666"></a>
    40 <a class="indexterm" name="id2619673"></a>
     38<a class="indexterm" name="id2619682"></a>
     39<a class="indexterm" name="id2619689"></a>
     40<a class="indexterm" name="id2619696"></a>
    4141The use of winbind is necessary only when Samba is the trusting domain, not when it is the
    4242trusted domain.
    43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619683"></a>Features and Benefits</h2></div></div></div><p>
    44 <a class="indexterm" name="id2619691"></a>
    45 <a class="indexterm" name="id2619698"></a>
     43</p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619706"></a>Features and Benefits</h2></div></div></div><p>
     44<a class="indexterm" name="id2619714"></a>
     45<a class="indexterm" name="id2619720"></a>
    4646Samba-3 can participate in Samba-to-Samba as well as in Samba-to-MS Windows NT4-style
    4747trust relationships. This imparts to Samba scalability similar to that with MS Windows NT4.
    4848</p><p>
    49 <a class="indexterm" name="id2619711"></a>
    50 <a class="indexterm" name="id2619718"></a>
    51 <a class="indexterm" name="id2619725"></a>
    52 <a class="indexterm" name="id2619732"></a>
    53 <a class="indexterm" name="id2619739"></a>
     49<a class="indexterm" name="id2619734"></a>
     50<a class="indexterm" name="id2619740"></a>
     51<a class="indexterm" name="id2619748"></a>
     52<a class="indexterm" name="id2619754"></a>
     53<a class="indexterm" name="id2619761"></a>
    5454Given that Samba-3 can function with a scalable backend authentication database such as LDAP, and given its
    5555ability to run in primary as well as backup domain control modes, the administrator would be well-advised to
     
    5757function, this system is fragile.  That was, after all, a key reason for the development and adoption of
    5858Microsoft Active Directory.
    59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619755"></a>Trust Relationship Background</h2></div></div></div><p>
    60 <a class="indexterm" name="id2619764"></a>
    61 <a class="indexterm" name="id2619770"></a>
    62 <a class="indexterm" name="id2619777"></a>
    63 <a class="indexterm" name="id2619784"></a>
    64 <a class="indexterm" name="id2619791"></a>
    65 <a class="indexterm" name="id2619798"></a>
     59</p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619778"></a>Trust Relationship Background</h2></div></div></div><p>
     60<a class="indexterm" name="id2619786"></a>
     61<a class="indexterm" name="id2619793"></a>
     62<a class="indexterm" name="id2619800"></a>
     63<a class="indexterm" name="id2619807"></a>
     64<a class="indexterm" name="id2619814"></a>
     65<a class="indexterm" name="id2619820"></a>
    6666MS Windows NT3/4-type security domains employ a nonhierarchical security structure.
    6767The limitations of this architecture as it effects the scalability of MS Windows networking
     
    7070large and diverse organizations.
    7171</p><p>
    72 <a class="indexterm" name="id2619815"></a>
    73 <a class="indexterm" name="id2619822"></a>
    74 <a class="indexterm" name="id2619828"></a>
    75 <a class="indexterm" name="id2619835"></a>
    76 <a class="indexterm" name="id2619842"></a>
     72<a class="indexterm" name="id2619837"></a>
     73<a class="indexterm" name="id2619844"></a>
     74<a class="indexterm" name="id2619851"></a>
     75<a class="indexterm" name="id2619857"></a>
     76<a class="indexterm" name="id2619864"></a>
    7777Microsoft developed Active Directory Service (ADS), based on Kerberos and LDAP, as a means
    7878of circumventing the limitations of the older technologies. Not every organization is ready
     
    8181desire to go through a disruptive change to adopt ADS.
    8282</p><p>
    83 <a class="indexterm" name="id2619859"></a>
    84 <a class="indexterm" name="id2619866"></a>
    85 <a class="indexterm" name="id2619873"></a>
    86 <a class="indexterm" name="id2619880"></a>
    87 <a class="indexterm" name="id2619887"></a>
    88 <a class="indexterm" name="id2619894"></a>
    89 <a class="indexterm" name="id2619901"></a>
     83<a class="indexterm" name="id2619882"></a>
     84<a class="indexterm" name="id2619888"></a>
     85<a class="indexterm" name="id2619895"></a>
     86<a class="indexterm" name="id2619902"></a>
     87<a class="indexterm" name="id2619909"></a>
     88<a class="indexterm" name="id2619916"></a>
     89<a class="indexterm" name="id2619923"></a>
    9090With Windows NT, Microsoft introduced the ability to allow different security domains
    9191to effect a mechanism so users from one domain may be given access rights and privileges
     
    9898necessary to establish two relationships, one in each direction.
    9999</p><p>
    100 <a class="indexterm" name="id2619931"></a>
    101 <a class="indexterm" name="id2619938"></a>
    102 <a class="indexterm" name="id2619944"></a>
    103 <a class="indexterm" name="id2619951"></a>
    104 <a class="indexterm" name="id2619958"></a>
     100<a class="indexterm" name="id2619953"></a>
     101<a class="indexterm" name="id2619960"></a>
     102<a class="indexterm" name="id2619967"></a>
     103<a class="indexterm" name="id2619974"></a>
     104<a class="indexterm" name="id2619980"></a>
    105105Further, in an NT4-style MS security domain, all trusts are nontransitive. This means that if there are three
    106106domains (let's call them red, white, and blue), where red and white have a trust relationship, and white and
     
    108108Relationships are explicit and not transitive.
    109109</p><p>
    110 <a class="indexterm" name="id2619975"></a>
    111 <a class="indexterm" name="id2619981"></a>
    112 <a class="indexterm" name="id2619988"></a>
    113 <a class="indexterm" name="id2619995"></a>
    114 <a class="indexterm" name="id2620002"></a>
    115 <a class="indexterm" name="id2620009"></a>
    116 <a class="indexterm" name="id2620016"></a>
     110<a class="indexterm" name="id2619997"></a>
     111<a class="indexterm" name="id2620004"></a>
     112<a class="indexterm" name="id2620010"></a>
     113<a class="indexterm" name="id2620017"></a>
     114<a class="indexterm" name="id2620024"></a>
     115<a class="indexterm" name="id2620031"></a>
     116<a class="indexterm" name="id2620038"></a>
    117117New to MS Windows 2000 ADS security contexts is the fact that trust relationships are two-way by default.
    118118Also, all inter-ADS domain trusts are transitive. In the case of the red, white, and blue domains, with
     
    120120domains. Samba-3 implements MS Windows NT4-style interdomain trusts and interoperates with MS Windows 200x ADS
    121121security domains in similar manner to MS Windows NT4-style domains.
    122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620033"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p>
    123 <a class="indexterm" name="id2620041"></a>
    124 <a class="indexterm" name="id2620050"></a>
    125 <a class="indexterm" name="id2620057"></a>
     122</p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620056"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p>
     123<a class="indexterm" name="id2620063"></a>
     124<a class="indexterm" name="id2620072"></a>
     125<a class="indexterm" name="id2620079"></a>
    126126There are two steps to creating an interdomain trust relationship. To effect a two-way trust
    127127relationship, it is necessary for each domain administrator to create a trust account for the
    128128other domain to use in verifying security credentials.
    129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620070"></a>Creating an NT4 Domain Trust</h3></div></div></div><p>
    130 <a class="indexterm" name="id2620078"></a>
    131 <a class="indexterm" name="id2620085"></a>
    132 <a class="indexterm" name="id2620092"></a>
    133 <a class="indexterm" name="id2620099"></a>
    134 <a class="indexterm" name="id2620106"></a>
     129</p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620092"></a>Creating an NT4 Domain Trust</h3></div></div></div><p>
     130<a class="indexterm" name="id2620100"></a>
     131<a class="indexterm" name="id2620107"></a>
     132<a class="indexterm" name="id2620114"></a>
     133<a class="indexterm" name="id2620121"></a>
     134<a class="indexterm" name="id2620128"></a>
    135135For MS Windows NT4, all domain trust relationships are configured using the
    136136<span class="application">Domain User Manager</span>. This is done from the Domain User Manager Policies
     
    143143trusting domain will use when authenticating users from the trusted domain.
    144144The password needs to be typed twice (for standard confirmation).
    145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620166"></a>Completing an NT4 Domain Trust</h3></div></div></div><p>
    146 <a class="indexterm" name="id2620175"></a>
    147 <a class="indexterm" name="id2620182"></a>
    148 <a class="indexterm" name="id2620188"></a>
    149 <a class="indexterm" name="id2620195"></a>
    150 <a class="indexterm" name="id2620202"></a>
    151 <a class="indexterm" name="id2620209"></a>
     145</p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620189"></a>Completing an NT4 Domain Trust</h3></div></div></div><p>
     146<a class="indexterm" name="id2620197"></a>
     147<a class="indexterm" name="id2620204"></a>
     148<a class="indexterm" name="id2620211"></a>
     149<a class="indexterm" name="id2620218"></a>
     150<a class="indexterm" name="id2620225"></a>
     151<a class="indexterm" name="id2620232"></a>
    152152A trust relationship will work only when the other (trusting) domain makes the appropriate connections
    153153with the trusted domain. To consummate the trust relationship, the administrator launches the
     
    156156next to the box that is labeled <span class="guilabel">Trusted Domains</span>. A panel opens in which
    157157must be entered the name of the remote domain as well as the password assigned to that trust.
    158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620252"></a>Interdomain Trust Facilities</h3></div></div></div><p>
    159 <a class="indexterm" name="id2620260"></a>
    160 <a class="indexterm" name="id2620267"></a>
    161 <a class="indexterm" name="id2620274"></a>
    162 <a class="indexterm" name="id2620281"></a>
    163 <a class="indexterm" name="id2620288"></a>
    164 <a class="indexterm" name="id2620294"></a>
     158</p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620274"></a>Interdomain Trust Facilities</h3></div></div></div><p>
     159<a class="indexterm" name="id2620282"></a>
     160<a class="indexterm" name="id2620289"></a>
     161<a class="indexterm" name="id2620296"></a>
     162<a class="indexterm" name="id2620303"></a>
     163<a class="indexterm" name="id2620310"></a>
     164<a class="indexterm" name="id2620317"></a>
    165165A two-way trust relationship is created when two one-way trusts are created, one in each direction.
    166166Where a one-way trust has been established between two MS Windows NT4 domains (let's call them
     
    202202        Global groups from the trusted domain can be made members in local groups on
    203203        MS Windows domain member machines.
    204         </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620461"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p>
    205 <a class="indexterm" name="id2620469"></a>
     204        </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620483"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p>
     205<a class="indexterm" name="id2620491"></a>
    206206This description is meant to be a fairly short introduction about how to set up a Samba server so
    207207that it can participate in interdomain trust relationships. Trust relationship support in Samba
    208208is at an early stage, so do not be surprised if something does not function as it should.
    209209</p><p>
    210 <a class="indexterm" name="id2620484"></a>
    211 <a class="indexterm" name="id2620491"></a>
    212 <a class="indexterm" name="id2620498"></a>
    213 <a class="indexterm" name="id2620505"></a>
     210<a class="indexterm" name="id2620506"></a>
     211<a class="indexterm" name="id2620513"></a>
     212<a class="indexterm" name="id2620520"></a>
     213<a class="indexterm" name="id2620527"></a>
    214214Each of the procedures described next assumes the peer domain in the trust relationship is controlled by a
    215215Windows NT4 server. However, the remote end could just as well be another Samba-3  domain. It can be clearly
     
    217217sections leads to trust between domains in a purely Samba environment.
    218218</p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="samba-trusted-domain"></a>Samba as the Trusted Domain</h3></div></div></div><p>
    219 <a class="indexterm" name="id2620532"></a>
    220 <a class="indexterm" name="id2620539"></a>
    221 <a class="indexterm" name="id2620546"></a>
    222 <a class="indexterm" name="id2620553"></a>
    223 <a class="indexterm" name="id2620559"></a>
     219<a class="indexterm" name="id2620554"></a>
     220<a class="indexterm" name="id2620561"></a>
     221<a class="indexterm" name="id2620568"></a>
     222<a class="indexterm" name="id2620575"></a>
     223<a class="indexterm" name="id2620582"></a>
    224224In order to set the Samba PDC to be the trusted party of the relationship, you first need
    225225to create a special account for the domain that will be the trusting party. To do that,
     
    240240account with the Interdomain trust flag</span>&#8221;.
    241241</p><p>
    242 <a class="indexterm" name="id2620629"></a>
    243 <a class="indexterm" name="id2620636"></a>
    244 <a class="indexterm" name="id2620643"></a>
    245 <a class="indexterm" name="id2620650"></a>
     242<a class="indexterm" name="id2620651"></a>
     243<a class="indexterm" name="id2620658"></a>
     244<a class="indexterm" name="id2620665"></a>
     245<a class="indexterm" name="id2620672"></a>
    246246The account name will be &#8220;<span class="quote">rumba$</span>&#8221; (the name of the remote domain).
    247247If this fails, you should check that the trust account has been added to the system
     
    249249can add it manually and then repeat the previous step.
    250250</p><p>
    251 <a class="indexterm" name="id2620673"></a>
    252 <a class="indexterm" name="id2620680"></a>
    253 <a class="indexterm" name="id2620687"></a>
    254 <a class="indexterm" name="id2620694"></a>
     251<a class="indexterm" name="id2620696"></a>
     252<a class="indexterm" name="id2620702"></a>
     253<a class="indexterm" name="id2620709"></a>
     254<a class="indexterm" name="id2620716"></a>
    255255After issuing this command, you will be asked to enter the password for the account. You can use any password
    256256you want, but be aware that Windows NT will not change this password until 7 days following account creation.
     
    260260Windows NT Server.
    261261</p><p>
    262 <a class="indexterm" name="id2620724"></a>
    263 <a class="indexterm" name="id2620731"></a>
    264 <a class="indexterm" name="id2620738"></a>
    265 <a class="indexterm" name="id2620745"></a>
    266 <a class="indexterm" name="id2620752"></a>
     262<a class="indexterm" name="id2620739"></a>
     263<a class="indexterm" name="id2620746"></a>
     264<a class="indexterm" name="id2620753"></a>
     265<a class="indexterm" name="id2620760"></a>
     266<a class="indexterm" name="id2620767"></a>
    267267Open <span class="application">User Manager for Domains</span> and from the <span class="guimenu">Policies</span> menu, select
    268268<span class="guimenuitem">Trust Relationships...</span>.  Beside the <span class="guilabel">Trusted domains</span> list box,
     
    271271time of account creation.  Click on <span class="guibutton">OK</span> and, if everything went without incident, you
    272272will see the <code class="computeroutput">Trusted domain relationship successfully established</code> message.
    273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620809"></a>Samba as the Trusting Domain</h3></div></div></div><p>
    274 <a class="indexterm" name="id2620817"></a>
    275 <a class="indexterm" name="id2620824"></a>
     273</p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620824"></a>Samba as the Trusting Domain</h3></div></div></div><p>
     274<a class="indexterm" name="id2620832"></a>
     275<a class="indexterm" name="id2620839"></a>
    276276This time activities are somewhat reversed. Again, we'll assume that your domain
    277277controlled by the Samba PDC is called SAMBA and the NT-controlled domain is called RUMBA.
     
    279279The very first step is to add an account for the SAMBA domain on RUMBA's PDC.
    280280</p><p>
    281 <a class="indexterm" name="id2620842"></a>
    282 <a class="indexterm" name="id2620849"></a>
    283 <a class="indexterm" name="id2620856"></a>
     281<a class="indexterm" name="id2620857"></a>
     282<a class="indexterm" name="id2620864"></a>
     283<a class="indexterm" name="id2620871"></a>
    284284Launch the <span class="application">Domain User Manager</span>, then from the menu select
    285285<span class="guimenu">Policies</span>, <span class="guimenuitem">Trust Relationships</span>.
     
    288288the relationship.
    289289</p><p>
    290 <a class="indexterm" name="id2620898"></a>
    291 <a class="indexterm" name="id2620905"></a>
     290<a class="indexterm" name="id2620913"></a>
     291<a class="indexterm" name="id2620920"></a>
    292292The password can be arbitrarily chosen. It is easy to change the password from the Samba server whenever you
    293293want. After you confirm the password, your account is ready for use. Now its Samba's turn.
    294294</p><p>
    295295Using your favorite shell while logged in as root, issue this command:
    296 <a class="indexterm" name="id2620920"></a>
     296<a class="indexterm" name="id2620935"></a>
    297297</p><p>
    298298<code class="prompt">root# </code><strong class="userinput"><code>net rpc trustdom establish rumba</code></strong>
    299299</p><p>
    300 <a class="indexterm" name="id2620948"></a>
    301 <a class="indexterm" name="id2620955"></a>
    302 <a class="indexterm" name="id2620962"></a>
     300<a class="indexterm" name="id2620964"></a>
     301<a class="indexterm" name="id2620970"></a>
     302<a class="indexterm" name="id2620977"></a>
    303303You will be prompted for the password you just typed on your Windows NT4 Server box.
    304304An error message, <code class="literal">"NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT,"</code>
     
    312312You have to run this command as root because you must have write access to
    313313the <code class="filename">secrets.tdb</code> file.
    314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621005"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p>
    315 <a class="indexterm" name="id2621014"></a>
    316 <a class="indexterm" name="id2621021"></a>
    317 <a class="indexterm" name="id2621028"></a>
    318 <a class="indexterm" name="id2621034"></a>
     314</p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621020"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p>
     315<a class="indexterm" name="id2621029"></a>
     316<a class="indexterm" name="id2621036"></a>
     317<a class="indexterm" name="id2621043"></a>
     318<a class="indexterm" name="id2621049"></a>
    319319Although <span class="application">Domain User Manager</span> is not present in Windows 2000, it is
    320320also possible to establish an NT4-style trust relationship with a Windows 2000 domain
     
    322322Samba to trust a Windows 2000 server; however, more testing is still needed in this area.
    323323</p><p>
    324 <a class="indexterm" name="id2621056"></a>
    325 <a class="indexterm" name="id2621063"></a>
    326 <a class="indexterm" name="id2621070"></a>
    327 <a class="indexterm" name="id2621076"></a>
     324<a class="indexterm" name="id2621071"></a>
     325<a class="indexterm" name="id2621078"></a>
     326<a class="indexterm" name="id2621085"></a>
     327<a class="indexterm" name="id2621092"></a>
    328328After <a class="link" href="InterdomainTrusts.html#samba-trusted-domain" title="Samba as the Trusted Domain">creating the interdomain trust account on the Samba server</a>
    329329as described previously, open <span class="application">Active Directory Domains and Trusts</span> on the AD
     
    339339<code class="computeroutput">The trusted domain has been added and the trust has been verified.</code> Your
    340340Samba users can now be granted access to resources in the AD domain.
    341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621155"></a>Common Errors</h2></div></div></div><p>
     341</p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621170"></a>Common Errors</h2></div></div></div><p>
    342342Interdomain trust relationships should not be attempted on networks that are unstable
    343343or that suffer regular outages. Network stability and integrity are key concerns with
    344344distributed trusted domains.
    345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621167"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p>
     345</p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621182"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p>
    346346<span class="emphasis"><em>Browsing from a machine in a trusted Windows 200x domain to a Windows 200x member of
    347347a trusting Samba domain, I get the following error:</em></span>
     
    361361the domain.  If you are running as an account that has privileges to do this
    362362when you unjoin the machine, it is done; otherwise it is not done.
    363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621213"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p>
     363</p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621228"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p>
    364364If you use the <code class="literal">smbldap-useradd</code> script to create a trust
    365365account to set up interdomain trusts, the process of setting up the trust will
Note: See TracChangeset for help on using the changeset viewer.