security=server has many failings (was: Re: [Samba] Any help will be great. THX.)

2004-02-17 Thread Andrew Bartlett
On Tue, 2004-02-17 at 09:30, [EMAIL PROTECTED] wrote:
 I've just installed Samba 2.2.3a on AIX 5.2.  We're using a NT password
 server to authenticate username/password.  Our NT guru's are complaining 
 that there're seeing several authentication failures events with an account 
 called sambatest which is not a valid userid on our site.  It looks like 
 some type of polling that Samba is doing.
 
 This is part of the errors they are seeing:
 
 Logon Failure:
   Reason: Unknown user name or bad password
   User Name:  sambatestHOSTNAME
   Domain: OURDOMAIN
 
 In my smb.conf file I'm using:
 
 security = SERVER
 
 How can we stop these errors from occurring?
 
 
 We are getting a login screen to login to the network and when we try we get
 the same message over and over.

Some versions of NT are prone to allowing any user to log in, no matter
what the password.  This is fine for NT, as it knows the user is just a
guest, but we can't tell, so 'security=server' fails.  

So we check, and clock up the bad logins.

Instead, you should set 'security=domain' and join the domain per the
documentation (smbpasswd -j -Uadministrator -r PDC should do that)

This uses the native NT logon protocols, which don't suffer from this
kind of bug.

Andrew Bartlett

-- 
Andrew Bartlett [EMAIL PROTECTED]
Manager, Authentication Subsystems, Samba Team  [EMAIL PROTECTED]
Student Network Administrator, Hawker College   [EMAIL PROTECTED]
http://samba.org http://build.samba.org http://hawkerc.net


signature.asc
Description: This is a digitally signed message part
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

[Samba] Any help will be great. THX.

2004-02-16 Thread reza . rafiee
I've just installed Samba 2.2.3a on AIX 5.2.  We're using a NT password
server to authenticate username/password.  Our NT guru's are complaining 
that there're seeing several authentication failures events with an account 
called sambatest which is not a valid userid on our site.  It looks like 
some type of polling that Samba is doing.

This is part of the errors they are seeing:

Logon Failure:
Reason: Unknown user name or bad password
User Name:  sambatestHOSTNAME
Domain: OURDOMAIN

In my smb.conf file I'm using:

security = SERVER

How can we stop these errors from occurring?


We are getting a login screen to login to the network and when we try we get
the same message over and over.


Georges's Inc.

402 W. Robinson

Springdale, AR 72764

(  479-927-7134

2 479-927-7101

*  [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba