LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-27-2018, 11:04 AM   #1
ReinaldoGomes
LQ Newbie
 
Registered: Jul 2016
Posts: 15

Rep: Reputation: Disabled
Samba can't fetch domain SID


This is my scenario:

I have a CentOS 7.5 server which must act as a file server and allow AD-integrated authentication for Samba access, without the need to create local users with smbpasswd.
Samba Version 4.7.1
SSSD Version 1.16.0


What I've done so far:

Joined my linux server to my AD domain using REALMD(client-software=sssd) and configured Samba to serve shares.


Upon completing these steps, I have the following problem:

Can't authenticate domain users accessing Samba shares because Samba complains that "Failed to fetch domain SID for MYDOMAIN".
"net getdomainsid" shows SID for local machine, but also reports that "Could not fetch domain SID".


I found a workaround to solve this by either:
  1. Leaving the domain then joining again with REALMD (but this time with client-software=winbind)
  2. Manually setting the SID with "net setdomainsid"

Both approaches will set the domain SID for Samba and allow me to use AD authentication.


So, I would like to know why is it that joining the domain with client-software=winbind sets this domain SID, while joining with client-software=sssd doesn't. And finally: is there a way to automatically have SSSD set this domain SID for Samba while joining the domain?

Last edited by ReinaldoGomes; 09-27-2018 at 12:25 PM.
 
Old 10-02-2018, 10:00 AM   #2
ReinaldoGomes
LQ Newbie
 
Registered: Jul 2016
Posts: 15

Original Poster
Rep: Reputation: Disabled
I still haven't figured out why the domain SID isn't set when joining with SSSD, or if that's even possible. But i've found out that I can use "net rpc getsid" to set the domain SID into samba's secrets.tdb, without knowing it beforehand.
 
  


Reply

Tags
samba4, sssd, winbind



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba/Winbind - Could not fetch domain SID Kustom42 Linux - Software 2 09-26-2018 09:22 PM
Bind9 Server Issues ( Tried to fetch SOA record for domain ) Jacob843 Linux - Networking 0 09-02-2012 01:33 AM
Samba 3.0.21a and Samba Domain Member Servers in a Windows 2003 ADS Domain ramz Linux - Networking 3 04-09-2006 08:26 PM
winbindd cannot fetch SID for our domain DaddyBad Fedora 2 10-04-2004 01:51 PM
samba :Failed to fetch domain database : NT_STATUS_ACCESS_DENIED sanjayid Linux - Networking 1 12-31-2003 07:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration