Ok, figured it out kinda... or at least got the groupmapping working
and thats a relief.  The problem was in the smb.conf file which I
will include the updated one below. Which leaves me with only two
questions: <br>
When I run "ldapsearch -x -Z '(uid=testuser)' I get the following error and info:<br>
[root@beefylinux slapd-beefylinux]# ldapsearch -x -Z '(uid=testuser)'<br>
ldap_start_tls: Protocol error (2)<br>
        additional info: unsupported extended operation<br>
# extended LDIF<br>
#<br>
# LDAPv3<br>
# base <> with scope sub<br>
# filter: (uid=testuser)<br>
# requesting: ALL<br>
#<br>
<br>
# testuser, People, <a href="http://beefylinux.com">beefylinux.com</a><br>
dn: uid=testuser,ou=People,dc=beefylinux,dc=com<br>
uid: testuser<br>
sambaSID: S-1-5-21-110894667-3098860623-2699652354-2006<br>
sambaPrimaryGroupSID: S-1-5-21-110894667-3098860623-2699652354-513<br>
displayName: Test domainshiat<br>
sambaPwdCanChange: 1127837149<br>
sambaPwdMustChange: 2147483647<br>
sambaLMPassword: ECD96218B47A5336AAD3B435B51404EE<br>
sambaNTPassword: 3F5A79137212E2026748DDA7A48F656C<br>
sambaPasswordHistory: 00000000000000000000000000000000000000000000000000000000<br>
 00000000<br>
sambaPwdLastSet: 1127837149<br>
sambaAcctFlags: [U          ]<br>
objectClass: sambaSamAccount<br>
objectClass: account<br>
objectClass: top<br>
<br>
# search result<br>
search: 3<br>
result: 0 Success<br>
<br>
# numResponses: 2<br>
# numEntries: 1<br>
[root@beefylinux slapd-beefylinux]#<br>
******************************************************************************<br>
<br>
last question is how to add a domain computer account to a windows machine could join the domain..<br>
<br>
Thank you again<br>
Ryan<br><br><div><span class="gmail_quote">On 9/27/05, <b class="gmail_sendername"><a href="mailto:fedora-directory-users-request@redhat.com">fedora-directory-users-request@redhat.com</a></b> <<a href="mailto:fedora-directory-users-request@redhat.com">
fedora-directory-users-request@redhat.com</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Send Fedora-directory-users mailing list submissions to
<br>        <a href="mailto:fedora-directory-users@redhat.com">fedora-directory-users@redhat.com</a><br><br>To subscribe or unsubscribe via the World Wide Web, visit<br>        <a href="https://www.redhat.com/mailman/listinfo/fedora-directory-users">
https://www.redhat.com/mailman/listinfo/fedora-directory-users</a><br>or, via email, send a message with subject or body 'help' to<br>        <a href="mailto:fedora-directory-users-request@redhat.com">fedora-directory-users-request@redhat.com
</a><br><br>You can reach the person managing the list at<br>        <a href="mailto:fedora-directory-users-owner@redhat.com">fedora-directory-users-owner@redhat.com</a><br><br>When replying, please edit your Subject line so it is more specific
<br>than "Re: Contents of Fedora-directory-users digest..."<br><br><br>Today's Topics:<br><br>   1. FC3 - AdminUtil - Prb3 (Jason Kullo Sam)<br>   2. Re: FC3 - AdminUtil - Prb3 (Noriko Hosoi)<br>   3. FDS && SAMBA (Ryan Taylor)
<br><br><br>----------------------------------------------------------------------<br><br>Message: 1<br>Date: Mon, 26 Sep 2005 15:48:26 -0600<br>From: Jason Kullo Sam <<a href="mailto:kullo@lws.bia.edu">kullo@lws.bia.edu
</a>><br>Subject: [Fedora-directory-users] FC3 - AdminUtil - Prb3<br>To: <a href="mailto:fedora-directory-users@redhat.com">fedora-directory-users@redhat.com</a><br>Message-ID: <<a href="mailto:43386CAA.2060208@lws.bia.edu">
43386CAA.2060208@lws.bia.edu</a>><br>Content-Type: text/plain; charset=ISO-8859-1; format=flowed<br><br>Ok...NEXT screwup on my part...here is below. Got past the perl<br>scripts...now onto...???SOMETHING???<br><br>FC3 box...adminutil setup...and once more...thanks for all your help so
<br>far guys!<br><br>===================================================================<br>[root@genie fedora-adminutil-devel-7.1]# gmake BUILD_DEBUG=optimize<br>BUILD_RPM=1<br>cat:<br>/root/Desktop/dsbuild-static/ds/fedora-
adminutil-devel-7.1/Linux2.6/buildnum.dat:<br>No such file or directory<br>if test ! -d Linux2.6; then mkdir Linux2.6; fi;<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/buildnum.pl<br>-p Linux2.6<br>perl<br>
/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/pumpkin.pl 90<br>pumpkin.dat<br>if test ! -d<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal/include;<br>then mkdir -p
<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal/include;<br>fi;<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/dirver.pl -v<br>"7.1" -o<br>/root/Desktop/dsbuild-static/ds/fedora-
adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal/include/dirver.h<br>The components are up to date<br><br>==== Building AdminUtil ==========<br><br>cd lib/libadminutil;    gmake BUILD_OPT=1 NSPR_BASENAME= USE_PTHREADS=1
<br>SECURITY=domestic MOZILLA_SOURCE_ROOT_EXT= ICU_SOURCE_ROOT_EXT= USE_64=<br>gmake[1]: Entering directory<br>`/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/lib/libadminutil'<br>echo<br>/root/Desktop/dsbuild-static/ds/fedora-
adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil71.a<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil71.a<br>echo<br>
/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil71.so<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil71.so
<br><br>---------------------- SNIP MAKE CRUD<br>-----------------------------------------<br><br> -I../../../mozilla/dist/Linux2.6_x86_glibc_PTH_OPT.OBJ/include<br>-I../../../mozilla/dist/public/nss -I../../../mozilla/dist/public/ldap
<br>-I../../../icu/built/include strlist.c -o<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil/strlist.o<br>gcc -c -fPIC -pipe -DLINUX -Dlinux -DBSD -D_POSIX_SOURCE -D_XOPEN_SOURCE
<br>-D_BSD_SOURCE -DHAVE_STRERROR -DNO_DBM -DNO_NODELOCK   -DXP_UNIX -DLinux<br>-O2 -DNET_SSL -DSPAPI20 -DBUILD_NUM=\"2005.269.2130\"<br>-I/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/include<br>-I../../../mozilla/dist/Linux2.6_x86_glibc_PTH_OPT.OBJ/include
<br>-I../../../mozilla/dist/public/nss -I../../../mozilla/dist/public/ldap<br>-I../../../icu/built/include resource.c -o<br>/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil/resource.o
<br>resource.c:26:26: unicode/ures.h: No such file or directory<br>resource.c:27:29: unicode/ustring.h: No such file or directory<br>resource.c: In function `res_getstring':<br>resource.c:90: error: `UResourceBundle' undeclared (first use in this
<br>function)<br>resource.c:90: error: (Each undeclared identifier is reported only once<br>resource.c:90: error: for each function it appears in.)<br>resource.c:90: error: `bundle' undeclared (first use in this function)
<br>resource.c:91: error: `UErrorCode' undeclared (first use in this function)<br>resource.c:91: error: syntax error before "status"<br>resource.c:98: error: `status' undeclared (first use in this function)<br>resource.c
:102: error: syntax error before '*' token<br>resource.c:104: error: `umsg' undeclared (first use in this function)<br>resource.c:110: warning: assignment makes pointer from integer without a<br>cast<br>resource.c:113: error: `U_ZERO_ERROR' undeclared (first use in this
<br>function)<br>gmake[1]: ***<br>[/root/Desktop/dsbuild-static/ds/fedora-adminutil-devel-7.1/built/Linux2.6-domestic-optimize-normal-pth/lib/libadminutil/resource.o]<br>Error 1<br>gmake[1]: Leaving directory<br>`/root/Desktop/dsbuild-static/ds/fedora-
adminutil-devel-7.1/lib/libadminutil'<br>gmake: *** [buildAdminUtil] Error 2<br>[root@genie fedora-adminutil-devel-7.1]#<br><br><br><br>------------------------------<br><br>Message: 2<br>Date: Mon, 26 Sep 2005 15:02:04 -0700
<br>From: Noriko Hosoi <<a href="mailto:nhosoi@redhat.com">nhosoi@redhat.com</a>><br>Subject: Re: [Fedora-directory-users] FC3 - AdminUtil - Prb3<br>To: "General discussion list for the Fedora Directory server project."
<br>        <<a href="mailto:fedora-directory-users@redhat.com">fedora-directory-users@redhat.com</a>><br>Message-ID: <<a href="mailto:43386FDC.3070900@redhat.com">43386FDC.3070900@redhat.com</a>><br>Content-Type: text/plain; charset="us-ascii"
<br><br>An HTML attachment was scrubbed...<br>URL: <a href="https://www.redhat.com/archives/fedora-directory-users/attachments/20050926/8674a01d/attachment.html">https://www.redhat.com/archives/fedora-directory-users/attachments/20050926/8674a01d/attachment.html
</a><br>-------------- next part --------------<br>A non-text attachment was scrubbed...<br>Name: smime.p7s<br>Type: application/x-pkcs7-signature<br>Size: 3170 bytes<br>Desc: S/MIME Cryptographic Signature<br>Url : <a href="https://www.redhat.com/archives/fedora-directory-users/attachments/20050926/8674a01d/smime.bin">
https://www.redhat.com/archives/fedora-directory-users/attachments/20050926/8674a01d/smime.bin</a><br><br>------------------------------<br><br>Message: 3<br>Date: Tue, 27 Sep 2005 10:02:42 -0400<br>From: Ryan Taylor <
<a href="mailto:rtaylor82@gmail.com">rtaylor82@gmail.com</a>><br>Subject: [Fedora-directory-users] FDS && SAMBA<br>To: <a href="mailto:fedora-directory-users@redhat.com">fedora-directory-users@redhat.com</a><br>
Message-ID: <<a href="mailto:611ae400050927070224ed2dc3@mail.gmail.com">611ae400050927070224ed2dc3@mail.gmail.com</a>><br>Content-Type: text/plain; charset="iso-8859-1"<br><br>hi,<br><br>followed the howto at:
<br><a href="http://directory.fedora.redhat.com/wiki/Howto:Sambaword">http://directory.fedora.redhat.com/wiki/Howto:Sambaword</a> for word and<br>ran into same problems...<br>When I try to exec net groupmap add... I get error:
<br><br>[root@beefylinux ~]# net groupmap add rid=512 ntgroup='Domain Admins'<br>unixgroup='Domain Admins'<br>Can't lookup UNIX group Domain Admins<br>[root@beefylinux ~]#<br>************************************************
<br>if I run getent group:<br>*************************************************<br>[root@beefylinux ~]# getent group root::0:root<br>bin::1:root,bin,daemon<br>daemon::2:root,bin,daemon<br>sys::3:root,bin,adm<br>adm::4:root,adm,daemon
<br>tty::5:<br>disk::6:root<br>lp::7:daemon,lp<br>mem::8:<br>kmem::9:<br>wheel::10:root<br>mail::12:mail<br>news::13:news<br>uucp::14:uucp<br>man::15:<br>games::20:<br>gopher::30:<br>dip::40:<br>ftp::50:<br>lock::54:<br>nobody::99:
<br>users:!!:100:micro<br>dbus:x:81:<br>floppy:x:19:<br>vcsa:x:69:<br>nscd:x:28:<br>rpm:x:37:<br>haldaemon:x:68:<br>utmp:x:22:<br>netdump:x:34:<br>slocate:x:21:<br>sshd:x:74:<br>rpc:x:32:<br>rpcuser:x:29:<br>nfsnobody:x:65534:
<br>mailnull:x:47:<br>smmsp:x:51:<br>pcap:x:77:<br>apache:x:48:<br>squid:x:23:<br>webalizer:x:67:<br>xfs:x:43:<br>ntp:x:38:<br>gdm:x:42:<br>mysql:x:27:<br>micro:!:500:<br>ldap:!:55:<br>dcldap::501:<br>Domain Admins:x:2512:
<br>Domain Users:x:2513:<br>Domain Guests:x:2514:<br>Domain Computers:x:2515:<br>[root@beefylinux ~]#<br>******************************************************************<br>Which is what I have read it is supposed to say...
<br>My smb.conf is as follows:<br>******************************************************************<br><br>[root@beefylinux ~]# cat /etc/samba/smb.conf<br># This is the main Samba configuration file. You should read the<br>
# smb.conf(5) manual page in order to understand the options listed<br># here. Samba has a huge number of configurable options (perhaps too<br># many!) most of which are not shown in this example<br>#<br># Any line which starts with a ; (semi-colon) or a # (hash)
<br># is a comment and is ignored. In this example we will use a #<br># for commentry and a ; for parts of the config file that you<br># may wish to enable<br>#<br># NOTE: Whenever you modify this file you should run the command "testparm"
<br># to check that you have not made any basic syntactic errors.<br>#<br>#======================= Global Settings<br>=====================================<br>[global]<br>log file = /var/log/samba/%m.log<br>load printers = yes
<br>idmap gid = 16777216-33554431<br>socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192<br>null passwords = yes<br>template shell = /bin/false<br>dns proxy = no<br>cups options = raw<br>netbios name = beefylinux<br>
server string = BEEFYLINUX<br>idmap uid = 16777216-33554431<br>password server = None<br>workgroup = workgroup<br>os level = 33<br>domain logons = yes<br>domain master = yes<br>local master = yes<br>preferred master = yes
<br>wins support = yes<br><br>logon home = \\%L\%u\profiles<br>logon path = \\%L\profiles\%u<br>logon drive = H:<br>template shell = /bin/false<br>winbind use default domain = no<br>printcap name = /etc/printcap<br>username map = /etc/samba/smbusers
<br>max log size = 50<br>security = user<br>passdb backend = ldapsam:<a href="ldap://beefylinux.com">ldap://beefylinux.com</a><br>ldap admin dn = cn=Directory Manager<br>ldap suffix = dc=beefylinux,dc=com<br>ldap user suffix = ou=People
<br>ldap machine suffix = ou=Computers<br>ldap group suffix = ou=Groups<br><br>[netlogon]<br>path = /var/lib/samba/netlogon<br>read only = yes<br>browsable = no<br><br>[profiles]<br>path = /var/lib/samba/profiles<br>read only = no
<br>create mask = 0600<br>directory mask = 0700<br><br>[homes]<br>browsable = no<br>writable = yes<br><br>[printers]<br>comment = All Printers<br>path = /var/spool/samba<br>browseable = no<br># Set public = yes to allow user 'guest account' to print
<br>public = yes<br>printable = yes<br><br>[Another]<br>comment = The other one<br>path = /another<br>force user = netfiles<br>force group = users<br>read only = No<br>guest ok = Yes<br><br>[Share]<br>comment = Our file share
<br>path = /linsys<br>force user = netfiles<br>force group = users<br>read only = No<br>guest ok = Yes<br><br>[Wisker]<br>comment = long<br>path = /home/micro/Desktop/SHARED<br>force user = micro<br>force group = micro<br>
read only = No<br>guest ok = Yes<br><br><br># This one is useful for people to share files<br>;[tmp]<br>; comment = Temporary file space<br>; path = /tmp<br>; read only = no<br>; public = yes<br><br># A publicly accessible directory, but read only, except for people in
<br># the "staff" group<br>;[public]<br>; comment = Public Stuff<br>; path = /home/samba<br>; public = yes<br>; read only = yes<br>; write list = @staff<br><br># Other examples.<br>#<br># A private printer, usable only by fred. Spool data will be placed in
<br>fred's<br># home directory. Note that fred must have write access to the spool<br>directory,<br># wherever it is.<br>;[fredsprn]<br>; comment = Fred's Printer<br>; valid users = fred<br>; path = /homes/fred<br>; printer = freds_printer
<br>; public = no<br>; writable = no<br>; printable = yes<br><br># A private directory, usable only by fred. Note that fred requires write<br># access to the directory.<br>;[fredsdir]<br>; comment = Fred's Service<br>; path = /usr/somewhere/private
<br>; valid users = fred<br>; public = no<br>; writable = yes<br>; printable = no<br><br># a service which has a different directory for each machine that connects<br># this allows you to tailor configurations to incoming machines. You could
<br># also use the %u option to tailor it by user name.<br># The %m gets replaced with the machine name that is connecting.<br>;[pchome]<br>; comment = PC Directories<br>; path = /usr/pc/%m<br>; public = no<br>; writable = yes
<br><br># A publicly accessible directory, read/write to all users. Note that all<br>files<br># created in the directory by users will be owned by the default user, so<br># any user with access can delete any other user's files. Obviously this
<br># directory must be writable by the default user. Another user could of<br>course<br># be specified, in which case all files would be owned by that user instead.<br>;[public]<br>; path = /usr/somewhere/else/public<br>
; public = yes<br>; only guest = yes<br>; writable = yes<br>; printable = no<br><br># The following two entries demonstrate how to share a directory so that two<br># users can place files there that will be owned by the specific users. In
<br>this<br># setup, the directory should be writable by both users and should have the<br># sticky bit set on it to prevent abuse. Obviously this could be extended to<br># as many users as required.<br>;[myshare]<br>; comment = Mary's and Fred's stuff
<br>; path = /usr/somewhere/shared<br>; valid users = mary fred<br>; public = no<br>; writable = yes<br>; printable = no<br>; create mask = 0765<br><br>#[Share2]<br>#comment = The other one<br>#path = /home/micro/Desktop/SHARED
<br>#writeable = yes<br>#guest ok = yes<br>#read only = no<br>#force user = netfiles<br>#force group = users<br><br>Anyhelp would be greatly appreciated... im also kinda looking ahead and<br>wondering how you setup "Domain computer" accounts so you can add windows
<br>machines to domain.. but thats pointless until i can get past this hurdle.<br><br>Thank you<br>Ryan<br>-------------- next part --------------<br>An HTML attachment was scrubbed...<br>URL: <a href="https://www.redhat.com/archives/fedora-directory-users/attachments/20050927/dbf373f4/attachment.html">
https://www.redhat.com/archives/fedora-directory-users/attachments/20050927/dbf373f4/attachment.html</a><br><br>------------------------------<br><br>--<br>Fedora-directory-users mailing list<br><a href="mailto:Fedora-directory-users@redhat.com">
Fedora-directory-users@redhat.com</a><br><a href="https://www.redhat.com/mailman/listinfo/fedora-directory-users">https://www.redhat.com/mailman/listinfo/fedora-directory-users</a><br><br><br>End of Fedora-directory-users Digest, Vol 4, Issue 22
<br>*****************************************************<br></blockquote></div><br>