- Timestamp:
- Aug 5, 2009, 6:33:18 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.0/docs/htmldocs/Samba3-HOWTO/InterdomainTrusts.html
r286 r311 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3. 2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619683">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619755">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620033">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620070">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620166">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620252">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620461">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620809">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621005">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621155">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621167">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621213">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p>2 <a class="indexterm" name="id26194 63"></a>3 <a class="indexterm" name="id26194 70"></a>4 <a class="indexterm" name="id26194 77"></a>5 <a class="indexterm" name="id2619 484"></a>6 <a class="indexterm" name="id2619 491"></a>7 <a class="indexterm" name="id2619 498"></a>8 <a class="indexterm" name="id26195 05"></a>9 <a class="indexterm" name="id26195 12"></a>10 <a class="indexterm" name="id26195 18"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 19. Interdomain Trust Relationships</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="The Official Samba 3.0.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="securing-samba.html" title="Chapter 18. Securing Samba"><link rel="next" href="msdfs.html" title="Chapter 20. Hosting a Microsoft Distributed File System Tree"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 19. Interdomain Trust Relationships</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="securing-samba.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="msdfs.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="InterdomainTrusts"></a>Chapter 19. Interdomain Trust Relationships</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Rafal</span> <span class="orgname">Samba Team</span> <span class="surname">Szczesniak</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:mimir@samba.org">mimir@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Jelmer</span> <span class="othername">R.</span> <span class="orgname">The Samba Team</span> <span class="surname">Vernooij</span></h3><span class="contrib">drawing</span> <div class="affiliation"><span class="orgname">The Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jelmer@samba.org">jelmer@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Stephen</span> <span class="surname">Langasek</span></h3><div class="affiliation"><div class="address"><p><code class="email"><<a class="email" href="mailto:vorlon@netexpress.net">vorlon@netexpress.net</a>></code></p></div></div></div></div><div><p class="pubdate">April 3, 2003</p></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619706">Features and Benefits</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2619778">Trust Relationship Background</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620056">Native MS Windows NT4 Trusts Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620092">Creating an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620189">Completing an NT4 Domain Trust</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620274">Interdomain Trust Facilities</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2620483">Configuring Samba NT-Style Domain Trusts</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#samba-trusted-domain">Samba as the Trusted Domain</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2620824">Samba as the Trusting Domain</a></span></dt></dl></dd><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621020">NT4-Style Domain Trusts with Windows 2000</a></span></dt><dt><span class="sect1"><a href="InterdomainTrusts.html#id2621170">Common Errors</a></span></dt><dd><dl><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621182">Browsing of Trusted Domain Fails</a></span></dt><dt><span class="sect2"><a href="InterdomainTrusts.html#id2621228">Problems with LDAP ldapsam and Older Versions of smbldap-tools</a></span></dt></dl></dd></dl></div><p> 2 <a class="indexterm" name="id2619486"></a> 3 <a class="indexterm" name="id2619493"></a> 4 <a class="indexterm" name="id2619499"></a> 5 <a class="indexterm" name="id2619506"></a> 6 <a class="indexterm" name="id2619513"></a> 7 <a class="indexterm" name="id2619520"></a> 8 <a class="indexterm" name="id2619527"></a> 9 <a class="indexterm" name="id2619534"></a> 10 <a class="indexterm" name="id2619541"></a> 11 11 Samba-3 supports NT4-style domain trust relationships. This is a feature that many sites 12 12 will want to use if they migrate to Samba-3 from an NT4-style domain and do not want to … … 16 16 trusts. 17 17 </p><p> 18 <a class="indexterm" name="id26195 36"></a>19 <a class="indexterm" name="id26195 43"></a>20 <a class="indexterm" name="id26195 50"></a>21 <a class="indexterm" name="id26195 56"></a>22 <a class="indexterm" name="id26195 63"></a>18 <a class="indexterm" name="id2619558"></a> 19 <a class="indexterm" name="id2619565"></a> 20 <a class="indexterm" name="id2619572"></a> 21 <a class="indexterm" name="id2619579"></a> 22 <a class="indexterm" name="id2619586"></a> 23 23 The use of interdomain trusts requires use of <code class="literal">winbind</code>, so the 24 24 <code class="literal">winbindd</code> daemon must be running. Winbind operation in this mode is 25 25 dependent on the specification of a valid UID range and a valid GID range in the <code class="filename">smb.conf</code> file. 26 26 These are specified respectively using: 27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2619 597"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619609"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p>28 <a class="indexterm" name="id26196 21"></a>29 <a class="indexterm" name="id26196 28"></a>30 <a class="indexterm" name="id26196 35"></a>31 <a class="indexterm" name="id26196 42"></a>27 </p><table class="simplelist" border="0" summary="Simple list"><tr><td><a class="indexterm" name="id2619620"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td><a class="indexterm" name="id2619631"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr></table><p> 28 <a class="indexterm" name="id2619643"></a> 29 <a class="indexterm" name="id2619650"></a> 30 <a class="indexterm" name="id2619657"></a> 31 <a class="indexterm" name="id2619664"></a> 32 32 The range of values specified must not overlap values used by the host operating system and must 33 33 not overlap values used in the passdb backend for POSIX user accounts. The maximum value is … … 36 36 (32-bit unsigned variable). 37 37 </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 38 <a class="indexterm" name="id26196 60"></a>39 <a class="indexterm" name="id26196 66"></a>40 <a class="indexterm" name="id26196 73"></a>38 <a class="indexterm" name="id2619682"></a> 39 <a class="indexterm" name="id2619689"></a> 40 <a class="indexterm" name="id2619696"></a> 41 41 The use of winbind is necessary only when Samba is the trusting domain, not when it is the 42 42 trusted domain. 43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619 683"></a>Features and Benefits</h2></div></div></div><p>44 <a class="indexterm" name="id2619 691"></a>45 <a class="indexterm" name="id2619 698"></a>43 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619706"></a>Features and Benefits</h2></div></div></div><p> 44 <a class="indexterm" name="id2619714"></a> 45 <a class="indexterm" name="id2619720"></a> 46 46 Samba-3 can participate in Samba-to-Samba as well as in Samba-to-MS Windows NT4-style 47 47 trust relationships. This imparts to Samba scalability similar to that with MS Windows NT4. 48 48 </p><p> 49 <a class="indexterm" name="id26197 11"></a>50 <a class="indexterm" name="id26197 18"></a>51 <a class="indexterm" name="id26197 25"></a>52 <a class="indexterm" name="id26197 32"></a>53 <a class="indexterm" name="id26197 39"></a>49 <a class="indexterm" name="id2619734"></a> 50 <a class="indexterm" name="id2619740"></a> 51 <a class="indexterm" name="id2619748"></a> 52 <a class="indexterm" name="id2619754"></a> 53 <a class="indexterm" name="id2619761"></a> 54 54 Given that Samba-3 can function with a scalable backend authentication database such as LDAP, and given its 55 55 ability to run in primary as well as backup domain control modes, the administrator would be well-advised to … … 57 57 function, this system is fragile. That was, after all, a key reason for the development and adoption of 58 58 Microsoft Active Directory. 59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26197 55"></a>Trust Relationship Background</h2></div></div></div><p>60 <a class="indexterm" name="id26197 64"></a>61 <a class="indexterm" name="id26197 70"></a>62 <a class="indexterm" name="id2619 777"></a>63 <a class="indexterm" name="id2619 784"></a>64 <a class="indexterm" name="id2619 791"></a>65 <a class="indexterm" name="id2619 798"></a>59 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619778"></a>Trust Relationship Background</h2></div></div></div><p> 60 <a class="indexterm" name="id2619786"></a> 61 <a class="indexterm" name="id2619793"></a> 62 <a class="indexterm" name="id2619800"></a> 63 <a class="indexterm" name="id2619807"></a> 64 <a class="indexterm" name="id2619814"></a> 65 <a class="indexterm" name="id2619820"></a> 66 66 MS Windows NT3/4-type security domains employ a nonhierarchical security structure. 67 67 The limitations of this architecture as it effects the scalability of MS Windows networking … … 70 70 large and diverse organizations. 71 71 </p><p> 72 <a class="indexterm" name="id26198 15"></a>73 <a class="indexterm" name="id26198 22"></a>74 <a class="indexterm" name="id26198 28"></a>75 <a class="indexterm" name="id26198 35"></a>76 <a class="indexterm" name="id26198 42"></a>72 <a class="indexterm" name="id2619837"></a> 73 <a class="indexterm" name="id2619844"></a> 74 <a class="indexterm" name="id2619851"></a> 75 <a class="indexterm" name="id2619857"></a> 76 <a class="indexterm" name="id2619864"></a> 77 77 Microsoft developed Active Directory Service (ADS), based on Kerberos and LDAP, as a means 78 78 of circumventing the limitations of the older technologies. Not every organization is ready … … 81 81 desire to go through a disruptive change to adopt ADS. 82 82 </p><p> 83 <a class="indexterm" name="id26198 59"></a>84 <a class="indexterm" name="id26198 66"></a>85 <a class="indexterm" name="id26198 73"></a>86 <a class="indexterm" name="id2619 880"></a>87 <a class="indexterm" name="id2619 887"></a>88 <a class="indexterm" name="id2619 894"></a>89 <a class="indexterm" name="id26199 01"></a>83 <a class="indexterm" name="id2619882"></a> 84 <a class="indexterm" name="id2619888"></a> 85 <a class="indexterm" name="id2619895"></a> 86 <a class="indexterm" name="id2619902"></a> 87 <a class="indexterm" name="id2619909"></a> 88 <a class="indexterm" name="id2619916"></a> 89 <a class="indexterm" name="id2619923"></a> 90 90 With Windows NT, Microsoft introduced the ability to allow different security domains 91 91 to effect a mechanism so users from one domain may be given access rights and privileges … … 98 98 necessary to establish two relationships, one in each direction. 99 99 </p><p> 100 <a class="indexterm" name="id26199 31"></a>101 <a class="indexterm" name="id26199 38"></a>102 <a class="indexterm" name="id26199 44"></a>103 <a class="indexterm" name="id26199 51"></a>104 <a class="indexterm" name="id26199 58"></a>100 <a class="indexterm" name="id2619953"></a> 101 <a class="indexterm" name="id2619960"></a> 102 <a class="indexterm" name="id2619967"></a> 103 <a class="indexterm" name="id2619974"></a> 104 <a class="indexterm" name="id2619980"></a> 105 105 Further, in an NT4-style MS security domain, all trusts are nontransitive. This means that if there are three 106 106 domains (let's call them red, white, and blue), where red and white have a trust relationship, and white and … … 108 108 Relationships are explicit and not transitive. 109 109 </p><p> 110 <a class="indexterm" name="id26199 75"></a>111 <a class="indexterm" name="id26 19981"></a>112 <a class="indexterm" name="id26 19988"></a>113 <a class="indexterm" name="id26 19995"></a>114 <a class="indexterm" name="id26200 02"></a>115 <a class="indexterm" name="id26200 09"></a>116 <a class="indexterm" name="id26200 16"></a>110 <a class="indexterm" name="id2619997"></a> 111 <a class="indexterm" name="id2620004"></a> 112 <a class="indexterm" name="id2620010"></a> 113 <a class="indexterm" name="id2620017"></a> 114 <a class="indexterm" name="id2620024"></a> 115 <a class="indexterm" name="id2620031"></a> 116 <a class="indexterm" name="id2620038"></a> 117 117 New to MS Windows 2000 ADS security contexts is the fact that trust relationships are two-way by default. 118 118 Also, all inter-ADS domain trusts are transitive. In the case of the red, white, and blue domains, with … … 120 120 domains. Samba-3 implements MS Windows NT4-style interdomain trusts and interoperates with MS Windows 200x ADS 121 121 security domains in similar manner to MS Windows NT4-style domains. 122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26200 33"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p>123 <a class="indexterm" name="id26200 41"></a>124 <a class="indexterm" name="id26200 50"></a>125 <a class="indexterm" name="id26200 57"></a>122 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620056"></a>Native MS Windows NT4 Trusts Configuration</h2></div></div></div><p> 123 <a class="indexterm" name="id2620063"></a> 124 <a class="indexterm" name="id2620072"></a> 125 <a class="indexterm" name="id2620079"></a> 126 126 There are two steps to creating an interdomain trust relationship. To effect a two-way trust 127 127 relationship, it is necessary for each domain administrator to create a trust account for the 128 128 other domain to use in verifying security credentials. 129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26200 70"></a>Creating an NT4 Domain Trust</h3></div></div></div><p>130 <a class="indexterm" name="id2620 078"></a>131 <a class="indexterm" name="id2620 085"></a>132 <a class="indexterm" name="id2620 092"></a>133 <a class="indexterm" name="id2620 099"></a>134 <a class="indexterm" name="id26201 06"></a>129 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620092"></a>Creating an NT4 Domain Trust</h3></div></div></div><p> 130 <a class="indexterm" name="id2620100"></a> 131 <a class="indexterm" name="id2620107"></a> 132 <a class="indexterm" name="id2620114"></a> 133 <a class="indexterm" name="id2620121"></a> 134 <a class="indexterm" name="id2620128"></a> 135 135 For MS Windows NT4, all domain trust relationships are configured using the 136 136 <span class="application">Domain User Manager</span>. This is done from the Domain User Manager Policies … … 143 143 trusting domain will use when authenticating users from the trusted domain. 144 144 The password needs to be typed twice (for standard confirmation). 145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26201 66"></a>Completing an NT4 Domain Trust</h3></div></div></div><p>146 <a class="indexterm" name="id26201 75"></a>147 <a class="indexterm" name="id2620 182"></a>148 <a class="indexterm" name="id2620 188"></a>149 <a class="indexterm" name="id2620 195"></a>150 <a class="indexterm" name="id26202 02"></a>151 <a class="indexterm" name="id26202 09"></a>145 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620189"></a>Completing an NT4 Domain Trust</h3></div></div></div><p> 146 <a class="indexterm" name="id2620197"></a> 147 <a class="indexterm" name="id2620204"></a> 148 <a class="indexterm" name="id2620211"></a> 149 <a class="indexterm" name="id2620218"></a> 150 <a class="indexterm" name="id2620225"></a> 151 <a class="indexterm" name="id2620232"></a> 152 152 A trust relationship will work only when the other (trusting) domain makes the appropriate connections 153 153 with the trusted domain. To consummate the trust relationship, the administrator launches the … … 156 156 next to the box that is labeled <span class="guilabel">Trusted Domains</span>. A panel opens in which 157 157 must be entered the name of the remote domain as well as the password assigned to that trust. 158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26202 52"></a>Interdomain Trust Facilities</h3></div></div></div><p>159 <a class="indexterm" name="id26202 60"></a>160 <a class="indexterm" name="id26202 67"></a>161 <a class="indexterm" name="id26202 74"></a>162 <a class="indexterm" name="id2620 281"></a>163 <a class="indexterm" name="id2620 288"></a>164 <a class="indexterm" name="id2620 294"></a>158 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620274"></a>Interdomain Trust Facilities</h3></div></div></div><p> 159 <a class="indexterm" name="id2620282"></a> 160 <a class="indexterm" name="id2620289"></a> 161 <a class="indexterm" name="id2620296"></a> 162 <a class="indexterm" name="id2620303"></a> 163 <a class="indexterm" name="id2620310"></a> 164 <a class="indexterm" name="id2620317"></a> 165 165 A two-way trust relationship is created when two one-way trusts are created, one in each direction. 166 166 Where a one-way trust has been established between two MS Windows NT4 domains (let's call them … … 202 202 Global groups from the trusted domain can be made members in local groups on 203 203 MS Windows domain member machines. 204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26204 61"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p>205 <a class="indexterm" name="id26204 69"></a>204 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620483"></a>Configuring Samba NT-Style Domain Trusts</h2></div></div></div><p> 205 <a class="indexterm" name="id2620491"></a> 206 206 This description is meant to be a fairly short introduction about how to set up a Samba server so 207 207 that it can participate in interdomain trust relationships. Trust relationship support in Samba 208 208 is at an early stage, so do not be surprised if something does not function as it should. 209 209 </p><p> 210 <a class="indexterm" name="id2620 484"></a>211 <a class="indexterm" name="id2620 491"></a>212 <a class="indexterm" name="id2620 498"></a>213 <a class="indexterm" name="id26205 05"></a>210 <a class="indexterm" name="id2620506"></a> 211 <a class="indexterm" name="id2620513"></a> 212 <a class="indexterm" name="id2620520"></a> 213 <a class="indexterm" name="id2620527"></a> 214 214 Each of the procedures described next assumes the peer domain in the trust relationship is controlled by a 215 215 Windows NT4 server. However, the remote end could just as well be another Samba-3 domain. It can be clearly … … 217 217 sections leads to trust between domains in a purely Samba environment. 218 218 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="samba-trusted-domain"></a>Samba as the Trusted Domain</h3></div></div></div><p> 219 <a class="indexterm" name="id26205 32"></a>220 <a class="indexterm" name="id26205 39"></a>221 <a class="indexterm" name="id26205 46"></a>222 <a class="indexterm" name="id26205 53"></a>223 <a class="indexterm" name="id26205 59"></a>219 <a class="indexterm" name="id2620554"></a> 220 <a class="indexterm" name="id2620561"></a> 221 <a class="indexterm" name="id2620568"></a> 222 <a class="indexterm" name="id2620575"></a> 223 <a class="indexterm" name="id2620582"></a> 224 224 In order to set the Samba PDC to be the trusted party of the relationship, you first need 225 225 to create a special account for the domain that will be the trusting party. To do that, … … 240 240 account with the Interdomain trust flag</span>”. 241 241 </p><p> 242 <a class="indexterm" name="id26206 29"></a>243 <a class="indexterm" name="id26206 36"></a>244 <a class="indexterm" name="id26206 43"></a>245 <a class="indexterm" name="id26206 50"></a>242 <a class="indexterm" name="id2620651"></a> 243 <a class="indexterm" name="id2620658"></a> 244 <a class="indexterm" name="id2620665"></a> 245 <a class="indexterm" name="id2620672"></a> 246 246 The account name will be “<span class="quote">rumba$</span>” (the name of the remote domain). 247 247 If this fails, you should check that the trust account has been added to the system … … 249 249 can add it manually and then repeat the previous step. 250 250 </p><p> 251 <a class="indexterm" name="id26206 73"></a>252 <a class="indexterm" name="id2620 680"></a>253 <a class="indexterm" name="id2620 687"></a>254 <a class="indexterm" name="id2620 694"></a>251 <a class="indexterm" name="id2620696"></a> 252 <a class="indexterm" name="id2620702"></a> 253 <a class="indexterm" name="id2620709"></a> 254 <a class="indexterm" name="id2620716"></a> 255 255 After issuing this command, you will be asked to enter the password for the account. You can use any password 256 256 you want, but be aware that Windows NT will not change this password until 7 days following account creation. … … 260 260 Windows NT Server. 261 261 </p><p> 262 <a class="indexterm" name="id26207 24"></a>263 <a class="indexterm" name="id26207 31"></a>264 <a class="indexterm" name="id26207 38"></a>265 <a class="indexterm" name="id26207 45"></a>266 <a class="indexterm" name="id26207 52"></a>262 <a class="indexterm" name="id2620739"></a> 263 <a class="indexterm" name="id2620746"></a> 264 <a class="indexterm" name="id2620753"></a> 265 <a class="indexterm" name="id2620760"></a> 266 <a class="indexterm" name="id2620767"></a> 267 267 Open <span class="application">User Manager for Domains</span> and from the <span class="guimenu">Policies</span> menu, select 268 268 <span class="guimenuitem">Trust Relationships...</span>. Beside the <span class="guilabel">Trusted domains</span> list box, … … 271 271 time of account creation. Click on <span class="guibutton">OK</span> and, if everything went without incident, you 272 272 will see the <code class="computeroutput">Trusted domain relationship successfully established</code> message. 273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26208 09"></a>Samba as the Trusting Domain</h3></div></div></div><p>274 <a class="indexterm" name="id26208 17"></a>275 <a class="indexterm" name="id26208 24"></a>273 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620824"></a>Samba as the Trusting Domain</h3></div></div></div><p> 274 <a class="indexterm" name="id2620832"></a> 275 <a class="indexterm" name="id2620839"></a> 276 276 This time activities are somewhat reversed. Again, we'll assume that your domain 277 277 controlled by the Samba PDC is called SAMBA and the NT-controlled domain is called RUMBA. … … 279 279 The very first step is to add an account for the SAMBA domain on RUMBA's PDC. 280 280 </p><p> 281 <a class="indexterm" name="id26208 42"></a>282 <a class="indexterm" name="id26208 49"></a>283 <a class="indexterm" name="id26208 56"></a>281 <a class="indexterm" name="id2620857"></a> 282 <a class="indexterm" name="id2620864"></a> 283 <a class="indexterm" name="id2620871"></a> 284 284 Launch the <span class="application">Domain User Manager</span>, then from the menu select 285 285 <span class="guimenu">Policies</span>, <span class="guimenuitem">Trust Relationships</span>. … … 288 288 the relationship. 289 289 </p><p> 290 <a class="indexterm" name="id2620 898"></a>291 <a class="indexterm" name="id26209 05"></a>290 <a class="indexterm" name="id2620913"></a> 291 <a class="indexterm" name="id2620920"></a> 292 292 The password can be arbitrarily chosen. It is easy to change the password from the Samba server whenever you 293 293 want. After you confirm the password, your account is ready for use. Now its Samba's turn. 294 294 </p><p> 295 295 Using your favorite shell while logged in as root, issue this command: 296 <a class="indexterm" name="id26209 20"></a>296 <a class="indexterm" name="id2620935"></a> 297 297 </p><p> 298 298 <code class="prompt">root# </code><strong class="userinput"><code>net rpc trustdom establish rumba</code></strong> 299 299 </p><p> 300 <a class="indexterm" name="id26209 48"></a>301 <a class="indexterm" name="id26209 55"></a>302 <a class="indexterm" name="id26209 62"></a>300 <a class="indexterm" name="id2620964"></a> 301 <a class="indexterm" name="id2620970"></a> 302 <a class="indexterm" name="id2620977"></a> 303 303 You will be prompted for the password you just typed on your Windows NT4 Server box. 304 304 An error message, <code class="literal">"NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT,"</code> … … 312 312 You have to run this command as root because you must have write access to 313 313 the <code class="filename">secrets.tdb</code> file. 314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26210 05"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p>315 <a class="indexterm" name="id26210 14"></a>316 <a class="indexterm" name="id26210 21"></a>317 <a class="indexterm" name="id26210 28"></a>318 <a class="indexterm" name="id26210 34"></a>314 </p></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621020"></a>NT4-Style Domain Trusts with Windows 2000</h2></div></div></div><p> 315 <a class="indexterm" name="id2621029"></a> 316 <a class="indexterm" name="id2621036"></a> 317 <a class="indexterm" name="id2621043"></a> 318 <a class="indexterm" name="id2621049"></a> 319 319 Although <span class="application">Domain User Manager</span> is not present in Windows 2000, it is 320 320 also possible to establish an NT4-style trust relationship with a Windows 2000 domain … … 322 322 Samba to trust a Windows 2000 server; however, more testing is still needed in this area. 323 323 </p><p> 324 <a class="indexterm" name="id26210 56"></a>325 <a class="indexterm" name="id26210 63"></a>326 <a class="indexterm" name="id26210 70"></a>327 <a class="indexterm" name="id26210 76"></a>324 <a class="indexterm" name="id2621071"></a> 325 <a class="indexterm" name="id2621078"></a> 326 <a class="indexterm" name="id2621085"></a> 327 <a class="indexterm" name="id2621092"></a> 328 328 After <a class="link" href="InterdomainTrusts.html#samba-trusted-domain" title="Samba as the Trusted Domain">creating the interdomain trust account on the Samba server</a> 329 329 as described previously, open <span class="application">Active Directory Domains and Trusts</span> on the AD … … 339 339 <code class="computeroutput">The trusted domain has been added and the trust has been verified.</code> Your 340 340 Samba users can now be granted access to resources in the AD domain. 341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26211 55"></a>Common Errors</h2></div></div></div><p>341 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621170"></a>Common Errors</h2></div></div></div><p> 342 342 Interdomain trust relationships should not be attempted on networks that are unstable 343 343 or that suffer regular outages. Network stability and integrity are key concerns with 344 344 distributed trusted domains. 345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26211 67"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p>345 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621182"></a>Browsing of Trusted Domain Fails</h3></div></div></div><p> 346 346 <span class="emphasis"><em>Browsing from a machine in a trusted Windows 200x domain to a Windows 200x member of 347 347 a trusting Samba domain, I get the following error:</em></span> … … 361 361 the domain. If you are running as an account that has privileges to do this 362 362 when you unjoin the machine, it is done; otherwise it is not done. 363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26212 13"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p>363 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2621228"></a>Problems with LDAP ldapsam and Older Versions of smbldap-tools</h3></div></div></div><p> 364 364 If you use the <code class="literal">smbldap-useradd</code> script to create a trust 365 365 account to set up interdomain trusts, the process of setting up the trust will
Note:
See TracChangeset
for help on using the changeset viewer.