|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Michael Pigurnow 2:5020/400 01 Sep 2005 00:16:44 To : All Subject : [q] samba -- профиль пользователя -------------------------------------------------------------------------------- Guten Abend, Alle! Поднял PDC на samba с использованием ldap согласно доке http://us2.samba.org/samba/docs/man/Samba-Guide/ Проблема имеецца в том, что один из пользователей при входе в домен на тазике с WinXP (на VMware, host-only connection) не имеет доступа к серверной копии своего профиля (она собсна и не создаецца). Пользователи добавлены в ldap через smbldap-tools. Проблемный пользователь angriff@pziv:~> getent passwd | grep proba1 proba1:x:1001:513:System User:/home/proba1:/bin/bash При этом запись о нем имеецца тока в ldap, в /etc/passwd | /etc/shadow о нем ни слуху ни духу. Другой юзверь входит в домен нормально, профиль его виден: angriff@pziv:~> getent passwd | grep angriff angriff:x:1000:0::/home/angriff:/bin/bash angriff:x:1000:513:System User:/home/angriff:/bin/bash Этот прописан окромя ldap ышо и в /etc/passwd | /etc/shadow. Пермишены на профиля такие: angriff@pziv:~> ls -la /var/lib/samba/ | grep prof drwxr-xr-x 4 root root 96 2005-08-29 11:35 profdata drwxrwx--- 4 root users 96 2005-08-20 17:11 profiles angriff@pziv:~> ls -la /var/lib/samba/profiles итого 1 drwxrwx--- 4 root users 96 2005-08-20 17:11 . drwxr-xr-x 8 root root 920 2005-08-31 00:53 .. drwx------ 13 angriff Domain Users 504 2005-08-31 00:21 angriff drwx------ 2 proba1 Domain Users 48 2005-08-29 11:36 proba1 angriff@pziv:~> ls -la /var/lib/samba/profdata итого 1 drwxr-xr-x 4 root root 96 2005-08-29 11:35 . drwxr-xr-x 8 root root 920 2005-08-31 00:53 .. drwxr-x--- 10 angriff Domain Users 272 2005-08-29 11:34 angriff drwxr-x--- 10 proba1 Domain Users 272 2005-08-29 11:35 proba1 Конфиг самбы /ets/samba/smb.conf ======================================================================== [global] workgroup = ANGRIFF netbios name = pziv interfaces = eth0, vmnet1, lo bind interfaces only = Yes passdb backend = ldapsam:ldap://pziv.angriff.org.ua enable privileges = Yes username map = /etc/samba/smbusers log level = 5 log file = /var/log/samba/%m.log max log size = 0 smb ports = 139 name resolve order = wins bcast hosts show add printer wizard = No add user script = /opt/IDEALX/sbin/smbldap-useradd -m "%u" delete user script = /opt/IDEALX/sbin/smbldap-userdel "%u" add group script = /opt/IDEALX/sbin/smbldap-groupadd -p "%g" delete group script = /opt/IDEALX/sbin/smbldap-groupdel "%g" add user to group script = /opt/IDEALX/sbin/smbldap-groupmod -m "%u" "%g" delete user from group script = /opt/IDEALX/sbin/smbldap-groupmod -x "%u" "%g" set primary group script = /opt/IDEALX/sbin/smbldap-usermod -g "%g" "%u" add machine script = /opt/IDEALX/sbin/smbldap-useradd -w "%u" logon script = scripts\logon.bat logon path = \\%L\profiles\%U logon home = \\%L\%U logon drive = X: domain logons = yes domain master = yes preferred master = Yes wins support = yes ldap suffix = dc=angriff,dc=org,dc=ua ldap machine suffix = ou=People ldap user suffix = ou=People ldap group suffix = ou=Groups ldap idmap suffix = ou=Idmap ldap admin dn = "cn=root,dc=angriff,dc=org,dc=ua" idmap backend = ldap:ldap://pziv.angriff.org.ua idmap uid = 10000-20000 idmap gid = 10000-20000 os level = 65 map acl inherit = Yes [homes] comment = Home Directories valid users = %S browseable = no read only = no inherit acls = yes [profiles] comment = Network Profiles Service path = /var/lib/samba/profiles read only = no profile acls = Yes [profdata] comment = Profile Data Share path = /var/lib/samba/profdata read only = No profile acls = Yes [netlogon] comment = Network Logon Service path = /var/lib/samba/netlogon locking = no read only = yes write list = ntadmin guest ok = Yes browseable = No [users] comment = All users path = /home read only = no inherit acls = yes veto files = /aquota.user/groups/shares/ [fat-d] comment = FAT partition path = /fat-d writeable = yes ======================================================================== Версии ПО: SuSE 9.2, angriff@pziv:~> rpm -q samba samba-3.0.20-0.1 Раздел доки Configuring Profile Directories читал, усио сделал как там. Кто что может посоветовать? Sehen Wir spaeter, Alle! -- Beste Gruesse, Michael -=+ XMMS: Молчит +=- () ascii ribbon campaign - against html mail /\ [http://arc.pasp.de/] - against microsoft attachments --- ifmail v.2.15dev5.3 * Origin: Digital Generation (2:5020/400) Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/8637cb2205a7.html, оценка из 5, голосов 10
|