Стоит сервер centaurus, настроенный полностью при помощи альтератора.
(openldap, dhcp, dns, шлюз, smb).
Аутентификация происходит через ldap базу. Завел клиента в домен (corp.org), но он не может получить доступ на самбовскую шару.
slapd-corp.org.conf
database hdb
suffix "dc=corp,dc=org"
rootdn "cn=ldaproot,dc=corp,dc=org"
rootpw eijaizee3vuogh7o
directory /var/lib/ldap/bases/corp.org
index objectClass eq
index uid eq
index cn eq
index uidNumber eq
index gidNumber eq
access to attrs=userPassword,sambaLMPassword,sambaNTPassword
by self writeaccess to dn.subtree="ou=kdcroot,dc=corp,dc=org"
by dn.exact="cn=kdc,ou=kdcroot,dc=corp,dc=org" read
by dn.exact="cn=kadmin,ou=kdcroot,dc=corp,dc=org" write
by * none
access to dn.subtree="cn=CORP.ORG,cn=kerberos,ou=kdcroot,dc=corp,dc=org"
by dn.exact="cn=kdc,ou=kdcroot,dc=corp,dc=org" read
by dn.exact="cn=kadmin,ou=kdcroot,dc=corp,dc=org" write
by * none
access to *
by * read
by anonymous auth
by * none
smb.conf
[global]
realm = CORP.ORG
server string = Samba server on %h (v. %v)
security = user
dedicated keytab file = /etc/krb5.keytab
kerberos method = dedicated keytab
log file = /var/log/samba/log.%m
max log size = 50
printcap name = cups
dns proxy = No
use sendfile = Yes
passdb backend = ldapsam:ldap://127.0.0.1/
ldap admin dn = cn=ldaproot,dc=corp,dc=org
ldap suffix = dc=corp,dc=org
ldap group suffix = ou=Group
ldap user suffix = ou=People
[share]
comment = Commonplace
path = /srv/share
read only = No
[homes]
comment = Home Directory for '%u'
browseable = no
writable = yes
Почему пользователь не может зайти на шару используя свой доменный пароль?