Hottest Free Downloads - DownloadPipe.com Over 197,000 downloads! Bookmark Now!
DownloadPipe.com - New Downloads Every Minute
 SEARCH:
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

[Samba] Missing sids for domain administrator?

 
   Linux (Home) -> Samba RSS
Next:  ocamlduce 3.11.1.0-2 MIGRATED to testing  
Author Message
Ian Puleston

External


Since: Jul 17, 2009
Posts: 5



(Msg. 1) Posted: Thu Oct 29, 2009 3:27 pm
Post subject: [Samba] Missing sids for domain administrator?
Archived from groups: linux>samba (more info?)

Hi,

I'm working on bug https://bugzilla.samba.org/show_bug.cgi?id=6592 and
something that has apparently changed in my setup is preventing me from
testing the final stages of the fix. I have a machine running Samba
server and joined to the domain, and am accessing that from the W2K3
domain server logged, logged into the latter as the domain
administrator. But the problem is that in its access checks smbd is not
getting the sid for the Administrators group (S-1-5-32-544).

In an email that I sent back in July
(http://lists.samba.org/archive/samba/2009-July/149285.html) I included
my samba log file, and at that point I was getting the S-1-5-32-544 sid,
but something has changed since then and now I am not. My question is
does anyone have any idea of what may have changed that would cause
that?

Here is an extract from the log in that email:

Checking password for unmapped user [SD80]\[Administrator]@[IANSERVER]
with the new password interface
check_ntlm_password: mapped user is:
[SD80]\[Administrator]@[IANSERVER]
check_ntlm_password: winbind authentication for user [Administrator]
succeeded
check_ntlm_password: authentication for user [Administrator]
->[Administrator] -> [SD80+administrator] succeeded
se_access_check: user sid is
S-1-5-21-4023909512-3739307249-2032274589-500
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-513
se_access_check: also S-1-1-0
se_access_check: also S-1-5-2
se_access_check: also S-1-5-11
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-520
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-519
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-518
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-512
se_access_check: also S-1-5-32-545
se_access_check: also S-1-5-32-544
se_access_check: also S-1-22-1-601
se_access_check: also S-1-22-2-604
se_access_check: also S-1-22-2-607
se_access_check: also S-1-22-2-608
se_access_check: also S-1-22-2-609
se_access_check: also S-1-22-2-610
se_access_check: also S-1-22-2-603
se_access_check: also S-1-22-2-602

And here is what I am seeing now:

check_ntlm_password: Checking password for unmapped user
[SD80]\[Administrator]@[IANSERVER] with the new password interface
check_ntlm_password: mapped user is:
[SD80]\[Administrator]@[IANSERVER]
check_ntlm_password: winbind authentication for user [Administrator]
succeeded
check_ntlm_password: authentication for user [Administrator] ->
[Administrator] -> [SD80+administrator] succeeded
se_access_check: user sid is
S-1-5-21-4023909512-3739307249-2032274589-500
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-513
se_access_check: also S-1-1-0
se_access_check: also S-1-5-2
se_access_check: also S-1-5-11
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-520
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-519
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-518
se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-512

The missing sids are for the Users and Administrators group, plus those
"S-2-22-2" sids, whatever they are.

Thanks
Ian
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Ian Puleston

External


Since: Jul 17, 2009
Posts: 5



(Msg. 2) Posted: Thu Oct 29, 2009 5:25 pm
Post subject: Re: [Samba] Missing sids for domain administrator? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

> -----Original Message-----
> From: samba-bounces.DeleteThis@lists.samba.org On Behalf Of Ian Puleston
> Sent: Thursday, October 29, 2009 11:22 AM
>
> I'm working on bug https://bugzilla.samba.org/show_bug.cgi?id=6592 and
> something that has apparently changed in my setup is preventing me
from
> testing the final stages of the fix. I have a machine running Samba
> server and joined to the domain, and am accessing that from the W2K3
> domain server, logged into the latter as the domain
> administrator. But the problem is that in its access checks smbd is
not
> getting the sid for the Administrators group (S-1-5-32-544).
>
> Back in July I was getting the S-1-5-32-544 sid,
> but something has changed since then and now I am not.

The samba log from back in July:
> se_access_check: user sid is
> S-1-5-21-4023909512-3739307249-2032274589-500
> se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-513
> se_access_check: also S-1-1-0
> se_access_check: also S-1-5-2
> se_access_check: also S-1-5-11
> se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-520
> se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-519
> se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-518
> se_access_check: also S-1-5-21-4023909512-3739307249-2032274589-512
> se_access_check: also S-1-5-32-545
> se_access_check: also S-1-5-32-544
> se_access_check: also S-1-22-1-601
> se_access_check: also S-1-22-2-604
> se_access_check: also S-1-22-2-607
> se_access_check: also S-1-22-2-608
> se_access_check: also S-1-22-2-609
> se_access_check: also S-1-22-2-610
> se_access_check: also S-1-22-2-603
> se_access_check: also S-1-22-2-602
>
> The missing sids are for the Users and Administrators group, plus
those
> "S-2-22-2" sids, whatever they are.

A bit more information I've managed to glean. I'm working on Fedora 10
which has Samba 3.2.15 installed, but the version I was building and
testing with was 3.2.4. Having now downloaded and built 3.2.15 I am now
seeing those "S-2-22-[12]" sids, but still not the sids for the
Administrators and Users groups.

But if I run the Fedora version of smbd 3.2.15 then I see the
S-1-5-32-545 sid too, but still not S-1-5-32-544. If I run the version
of 3.2.15 that I built I see neither. To build it I used "./configure
--with-ads", are there maybe some other options I should have used that
may explain that difference?

And I still need to find why I don't see sid S-1-5-32-544 with any
version?

Ian

--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Ian Puleston

External


Since: Jul 17, 2009
Posts: 5



(Msg. 3) Posted: Fri Oct 30, 2009 4:25 pm
Post subject: Re: [Samba] Missing sids for domain administrator? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

> -----Original Message-----
> From: samba-bounces RemoveThis @lists.samba.org On Behalf Of Ian Puleston
> Sent: Thursday, October 29, 2009 1:44 PM

> > the problem is that in its access checks smbd is not
> > getting the sid for the Administrators group (S-1-5-32-544).
>
> But if I run the Fedora version of smbd 3.2.15 then I see the
> S-1-5-32-545 sid too, but still not S-1-5-32-544.

I'm not sure why, but that problem has cleared up now - I did a yum
reinstall of samba and after that its working OK - I am now getting the
S-1-5-32-544 sid for the domain administrator (maybe I did not have the
distro version installed as I thought I had?).

So I tried rebuilding the samba package "properly" with the correct
options for my fedora distro by using rpmbuild rather than downloading
and making it manually, and that built version works OK too.

> To build it I used "./configure --with-ads", are there maybe
> some other options I should have used that may explain that
> difference?
>
> And I still need to find why I don't see sid S-1-5-32-544 with any
> version?

It would still be nice to know what made the difference if anyone can
shed any light on it?

Ian
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Display posts from previous:   
Related Topics:
[Samba] what is the SID of the domain administrator? - Does the domain administrator SID always end with -1000? I.e., if the SID for the domain is: S-1-2-33-4444444444-555555555-6666666666 does this mean that the domain administrator's SID would be: S-1-2-33-4444444444-555555555-6666666666-1000 ? How..

[Samba] UID of the windows Domain Administrator user? - I have installed lots of samba 3 servers as PDCs for little networks serving 10 users or so. I have always set up the user "root" as the domain administrator, by setting its group SID to <domainSID>-512 with pdbedit. My "roo...

[Samba] Cannot access/write to shares, samba appears not t.. - Hi All, I cannot access/write to shares so I turned the logging level up to 3. This is the error from the 'test' share while attempting to create a new folder: [2009/09/29 09:57:45, 3] lib/util_sid.c:string_to_sid(223) string_to_sid: Sid @domain user...

[Samba] Overview help with SIDs - Hi All, I am migrating an NT4 PDC with around 30 accounts to our new FC4 server Samba Version 3.0.14a-2 I have managed to get as far as the vampire grabbing the data but it can't make the accounts: <snip> Creating account: DanielW Could not cr...

[Samba] Sharing Accounts between Servers and SIDs - I maintain a heterogenous network with a shared LDAP account database. The user accounts have globally unique user names, UIDs and RIDs. Some, but not all accounts are valid on all machines, but there is no need for samba to care about this, because ther...
       Linux (Home) -> Samba All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows Forums
 Game Forums
  Linux Forums
 Mac Forums
 PDA Forums
 Mobile Forums
  Top  |  Store  |  RSS Feeds RSS  |  Data Feeds  |  Advertise  |  Submit  |  Bookmark  |  Newsletter  |  Contact