Domain Users cannot connect to share

Questions about using Windows AD service.
Post Reply
weinertuhh
New here
Posts: 3
Joined: Wed May 18, 2016 4:49 pm

Domain Users cannot connect to share

Post by weinertuhh »

Hi all,

it's really an urgent problem because all my users are blocked from share folders.

System:
TVS-471U-RP
Version 4.2.4

I joined to an Active Directory, created necessary shares and everything was fine the last two weeks.

Yesterday I had troubles with virtualization station where a vm with debian / samba for active driectory was located.
I decided to reboot and to upgrade Firmware to newest version hoping to solve this - it didn't, so I went with the vm to another nas, where it started succesfully.

After rebooting TVS-471U-RP my shares where no more reachable.

I rejoined active directory domain again with success, but no AD-authentication possible.
If I try to create a new share, Domain Groups and Users are listed but I cannot set the rights for them.

In log I see after rejoining domain:
[Security Mode] Local user authentification selected for Microsoft Network
[Security Mode] LDAP authentfication disabled
[Security Mode] Join domain ... successfully

Error when setting permissions:
[Advanced Folder Permissions] ACL user/group not found; dom+Domain Admins, dom+Domain Users

I decided to downgrade to 4.2.4 again but it didn't have any effect.

Update:
In console I see that winbind fails:
/usr/local/samba/bin/wbinfo -t
could not obtain winbind interface details: WBC_ERR_WINBIND_NOT_AVAILABLE
could not obtain winbind domain name!
checking the trust secret for domain (null) via RPC calls failed
failed to call wbcCheckTrustCredentials: WBC_ERR_WINBIND_NOT_AVAILABLE
Could not check secret

What should I do?

Thanks,
Thomas
weinertuhh
New here
Posts: 3
Joined: Wed May 18, 2016 4:49 pm

Re: Domain Users cannot connect to share

Post by weinertuhh »

Okay, I solved it.

It was my fault, I changed some permissions in some folders of /share/CACHEDEV1_DATA to a domain admin account, unfortunately also in /share/CACHEDEV1_DATA/.samba/
As long as samba was running winbind was fine with permissions (so I didn't notice my error), but of course not after reboot or restarting samba (unknown user Domain Admin ...).

I changed the permissions, now winbind works fine and everything looks okay; I will check other folders, too.

Thanks,
Thomas
Matthew Urch
First post
Posts: 1
Joined: Fri Jun 23, 2017 7:03 pm

Re: Domain Users cannot connect to share

Post by Matthew Urch »

could you explain exactly what you did to fix this please?

We have the exact same symptoms, but i don't think I've altered any permission the folders in /share/CACHEDEV1_DATA/.samba/. . . well not on purpose anyways!
Post Reply

Return to “Windows Domain & Active Directory”