<html><body><p>Hi Jeff<br><br>As far as I can see, your command looks ok (though I don't know what your dn should look like). <br><br>Did you run the "kinit admin" command before?<br><br>When I was doing the Samba + FreeIPA integration I found using an LDAP browser (Apache Directory Studio) very useful to visualise the LDAP "tree" (and even if required to manually edit objects ....)<br><br>Chris<br><br><br><br><img width="16" height="16" src="cid:1__=8FBBF5E9DFC454208f9e8a93df938690918c8FB@" border="0" alt="Inactive hide details for Jeff Goddard ---18.03.2016 16:43:14---Christopher, Thank you for the response. IT seems my syntax is "><font color="#424282">Jeff Goddard ---18.03.2016 16:43:14---Christopher, Thank you for the response. IT seems my syntax is still not correct. HEre</font><br><br><font size="2" color="#5F5F5F">From: </font><font size="2">Jeff Goddard <jgoddard@emerlyn.com></font><br><font size="2" color="#5F5F5F">To: </font><font size="2">Christopher Lamb/Switzerland/IBM@IBMCH</font><br><font size="2" color="#5F5F5F">Cc: </font><font size="2">freeipa-users@redhat.com</font><br><font size="2" color="#5F5F5F">Date: </font><font size="2">18.03.2016 16:43</font><br><font size="2" color="#5F5F5F">Subject: </font><font size="2">Re: [Freeipa-users] Trouble creating userobjectlass sambaSAMAccount</font><br><hr width="100%" size="2" align="left" noshade style="color:#8091A5; "><br><br><br><font size="4">Christopher,<br></font><br><font size="4">Thank you for the response. IT seems my syntax is still not correct. HEre is the command and output I received:<br><br>[root@id-management-1 ~]# ldapmodify -Y GSSAPI <<EOF<br>dn: cn=etc,cn=ipaconfig,dc=internal,dc=emerlyn,dc=com<br>changetype: modify<br>add: ipaUserObjectClasses<br>ipaUserObjectClasses: sambaSAMAccount<br>-<br>add: ipaGroupObjectClasses<br>ipaGroupObjectClasses: sambaGroupMapping<br>EOF<br>SASL/GSSAPI authentication started<br><br>SASL username: </font><a href="mailto:admin@INTERNAL.EMERLYN.COM"><u><font size="4" color="#0000FF">admin@INTERNAL.EMERLYN.COM</font></u></a><font size="4"><br>SASL SSF: 56<br>SASL data security layer installed.<br>modifying entry "cn=etc,cn=ipaconfig,dc=internal,dc=emerlyn,dc=com"<br>ldap_modify: No such object (32)<br></font><br><font size="4">Do you have any more pointers?<br><br></font><br><font size="4">Thanks,<br></font><br><font size="4">Jeff</font><br><br><br><font size="4">On Fri, Mar 18, 2016 at 11:35 AM, Christopher Lamb <</font><a href="mailto:christopher.lamb@ch.ibm.com" target="_blank"><u><font size="4" color="#0000FF">christopher.lamb@ch.ibm.com</font></u></a><font size="4">> wrote:</font><ul><font size="4">Hi Jeff<br><br>When I last integrated FreeIPA and Samba I used ldapmodify to successfully add sambaSAMAccount and sambaGroupMapping.<br><br></font><tt><font size="5" color="#2F2F2F"><br>ldapmodify -Y GSSAPI <<EOF<br>dn: cn=etc,cn=ipaconfig,dc=my,dc=silly,dc=example,dc=com<br>changetype: modify<br>add: ipaUserObjectClasses<br>ipaUserObjectClasses: sambaSAMAccount<br>-<br>add: ipaGroupObjectClasses<br>ipaGroupObjectClasses: sambaGroupMapping<br>EOF</font></tt><font size="4"><br><br>Note, also there is a notorious spelling mistake under Point 5 of the Fedora instructions you are following<br></font><tt><font size="4"><br>cosAttribute: sambaGrouptType</font></tt><font size="4"><br><br>should be: <br></font><tt><font size="4"><br>cosAttribute: sambaGroupType</font></tt><font size="4"><br><br>i.e. sambaGroupType has only one "T".<br><br>Chris<br><br></font><img src="cid:1__=8FBBF5E9DFC454208f9e8a93df938690918c8FB@" width="16" height="16" alt="Inactive hide details for Jeff Goddard ---18.03.2016 16:11:10---Hello all, I'm following this guide:"><font size="4" color="#424282">Jeff Goddard ---18.03.2016 16:11:10---Hello all, I'm following this guide:</font><font size="4"><br></font><font color="#5F5F5F"><br>From: </font>Jeff Goddard <<a href="mailto:jgoddard@emerlyn.com" target="_blank"><u><font color="#0000FF">jgoddard@emerlyn.com</font></u></a>><font color="#5F5F5F"><br>To: </font><a href="mailto:freeipa-users@redhat.com" target="_blank"><u><font color="#0000FF">freeipa-users@redhat.com</font></u></a><font color="#5F5F5F"><br>Date: </font>18.03.2016 16:11<font color="#5F5F5F"><br>Subject: </font>[Freeipa-users] Trouble creating userobjectlass sambaSAMAccount<font color="#5F5F5F"><br>Sent by: </font><a href="mailto:freeipa-users-bounces@redhat.com" target="_blank"><u><font color="#0000FF">freeipa-users-bounces@redhat.com</font></u></a><br><hr width="100%" size="2" align="left" noshade><font size="4"><br><br><br></font><font size="5"><br>Hello all,</font><font size="4"><br></font><font size="5"><br>I'm following this guide: </font><a href="https://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/cifs.html" target="_blank"><u><font size="5" color="#0000FF">https://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/cifs.html</font></u></a><font size="5"> in attempts to have a SAMBA server with freeipa as the back-end authentication method. My problem is that the command: ipa config-mod --userobjectclasses=top,person,organizationalperson,inetorgperson,inetuser,posixaccount,krbprincipalaux,krbticketpolicyaux,ipaobject,sambaSAMAccount fails with the message: ipa: ERROR: objectclass top,person,organizationalperson,inetorgperson,inetuser,posixaccount,krbprincipalaux,krbticketpolicyaux,ipaobject,sambaSAMAccount not found. <br><br>Using the web GUI I was able to add this field but it doesn't dynamically add it to my existing users and so I get errors such as:<br><br>[2016/03/18 10:20:21.052605, 3] ../source3/lib/smbldap.c:579(smbldap_start_tls)<br> StartTLS issued: using a TLS connection<br>[2016/03/18 10:20:21.052661, 2] ../source3/lib/smbldap.c:794(smbldap_open_connection)<br> smbldap_open_connection: connection opened<br>[2016/03/18 10:20:21.055250, 3] ../source3/lib/smbldap.c:1013(smbldap_connect_system)<br> ldap_connect_system: successful connection to the LDAP server<br>[2016/03/18 10:20:21.056774, 4] ../source3/passdb/pdb_ldap.c:1496(ldapsam_getsampwnam)<br> ldapsam_getsampwnam: Unable to locate user [jgoddard] count=0<br>[2016/03/18 10:20:21.056856, 3, pid=9121, effective(0, 0), real(0, 0), class=auth] ../source3/auth/check_samsec.c:400(check_sam_security)<br> check_sam_security: Couldn't find user 'jgoddard' in passdb.<br>[2016/03/18 10:20:21.056890, 5, pid=9121, effective(0, 0), real(0, 0), class=auth] ../source3/auth/auth.c:252(auth_check_ntlm_password)<br> check_ntlm_password: sam authentication for user [jgoddard] FAILED with error NT_STATUS_NO_SUCH_USER<br>[2016/03/18 10:20:21.056944, 2, pid=9121, effective(0, 0), real(0, 0), class=auth] ../source3/auth/auth.c:315(auth_check_ntlm_password)<br> check_ntlm_password: Authentication for user [jgoddard] -> [jgoddard] FAILED with error NT_STATUS_NO_SUCH_USER<br>[2016/03/18 10:20:21.056972, 2] ../auth/gensec/spnego.c:746(gensec_spnego_server_negTokenTarg)<br> SPNEGO login failed: NT_STATUS_NO_SUCH_USER<br>[2016/03/18 10:20:21.057837, 3] ../source3/smbd/server_exit.c:249(exit_server_common)<br> Server exit (NT_STATUS_CONNECTION_RESET)</font><font size="4"><br></font><font size="5"><br>When trying to authenticate to my share.</font><font size="4"><br></font><font size="5"><br>The search from the samba server: ldapsearch -LLL -x -h </font><a href="http://id-management-1.internal.emerlyn.com/" target="_blank"><u><font size="5" color="#0000FF">id-management-1.internal.emerlyn.com</font></u></a><font size="5"> uid=jgoddard<br> does not return a value for sambaSAMAccount either. Can anyone provide me a pointer or documentation on where I'm going wrong?</font><font size="4"><br></font><font size="5"><br>Thanks,</font><font size="4"><br></font><font size="5"><br>Jeff</font><tt><font size="4">-- <br>Manage your subscription for the Freeipa-users mailing list:</font></tt><tt><u><font size="4" color="#0000FF"><br></font></u></tt><a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank"><tt><u><font size="4" color="#0000FF">https://www.redhat.com/mailman/listinfo/freeipa-users</font></u></tt></a><tt><font size="4"><br>Go to </font></tt><a href="http://freeipa.org/" target="_blank"><tt><u><font size="4" color="#0000FF">http://freeipa.org</font></u></tt></a><tt><font size="4"> for more info on the project</font></tt><font size="4"><br><br></font></ul><br><font size="4"><br><br></font><p><p><BR>
</body></html>