Cannot access SMB shares from Windows boxes in AD domain

Hey folks
I've needed to tackel this for sometime, but Santa is bringing me a dual core G5 and the urgency just increased.
I have an Active Directory domain and all of my macs are successfully joined and get Kerberos tickets upon login. I can access any shares I need from OS X -> windows but NOT the other way around.
I did finally noticed that only local user accounts seem to appear in the accounts list in the sharing pref pane. So I have figured out that I can access any users folder with that one account- OUCH! What I need is access control based on the user.
For instance if I want to share ~jdoe and jdoe is a mobile account and an AD user then if I am logged into windows as [email protected] then I should be able to access the share on the mac. Conversly I should not be able to access ~jdoe with the mac's local admin account and pass.
Do I need to change my smb.conf to reflect AD and if so, where/what?
Also, do I need to map UIDs to anything? And, is that a security risk?
Thanks!
-N

Hi SpaceBass, have you looked into sharepoints or into Netinfo manager. I have been playing around with sharepoints and it does let me enter non local users into the sharing prefs- albeit manually. Only thing is , depending on the number of macs you have, it could be a long and tedious job entering it all by hand. Netinfo may have an easier way, I'll do some more digging and post back.
Cheers.

Similar Messages

  • Cannot access CIFS shares from Windows 2008R2 on NSS3000

    Hi,
    I am trying to upgrade our 2008 domain to 2008R2 but with that last version we cannot access to cifs shares on the NSS3000. Access from all other clients are OK. It was 100% OK under 2008...
    Whether I use the IP or the FQDN, I got an error from Windows 2008R2. From IP, I got "No process is on the other end of pipe." and from network Gui, I got "Windows cannot access \\nas0026CB647BC6. Check the spelling of the name...blabla. Details : Error Code : 0x80070035, The network path was not found".
    On the NAS, I got this errors in the cifs logs :
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: rpc_api_pipe: Remote machine WIN2008-PDC.bluemoon.holywell.leics pipe \NETLOGON fnum 0x4002returned critical error. Error was NT_STATUS_PIPE_DISCONNECTED 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: [2011/02/24 14:12:45, 0] rpc_client/cli_pipe.c:rpc_api_pipe(790) 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: rpc_api_pipe: Remote machine WIN2008-PDC.bluemoon.holywell.leics pipe \NETLOGON fnum 0x4002returned critical error. Error was NT_STATUS_PIPE_DISCONNECTED 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: [2011/02/24 14:12:45, 0] rpc_client/cli_pipe.c:rpc_api_pipe(790) 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: rpc_api_pipe: Remote machine WIN2008-PDC.bluemoon.holywell.leics pipe \NETLOGON fnum 0x4002returned critical error. Error was NT_STATUS_PIPE_DISCONNECTED 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: [2011/02/24 14:12:45, 0] rpc_client/cli_pipe.c:rpc_api_pipe(790) 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: rpc_api_pipe: Remote machine WIN2008-PDC.bluemoon.holywell.leics pipe \NETLOGON fnum 0x4002returned critical error. Error was NT_STATUS_PIPE_DISCONNECTED 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: [2011/02/24 14:12:45, 0] rpc_client/cli_pipe.c:rpc_api_pipe(790) 
    Feb 24 14:12:45 NAS0026cb647bc6 winbindd[28457]: rpc_api_pipe: Remote machine WIN2008-PDC.bluemoon.holywell.leics pipe \NETLOGON fnum 0x4002returned critical error. Error was NT_STATUS_PIPE_DISCONNECTED 
    Feb 24 14:12:48 NAS0026cb647bc6 winbindd[28457]: [2011/02/24 14:12:48, 0] rpc_client/cli_pipe.c:rpc_api_pipe(790) 
    It is likely to be an incompatibility between Windows 2008R2 smbv2 and the NSS3000 smbd but I can't find any firmware update and I can't find the process to allow in the registry.
    I can ping it, I can connect on the web interface, I can connect on FTP but no CIFS at all.
    Firmware version running is 1.20.1. Hardware rev : V03.
    Any idea?

    Hi SpaceBass, have you looked into sharepoints or into Netinfo manager. I have been playing around with sharepoints and it does let me enter non local users into the sharing prefs- albeit manually. Only thing is , depending on the number of macs you have, it could be a long and tedious job entering it all by hand. Netinfo may have an easier way, I'll do some more digging and post back.
    Cheers.

  • How to access ZFS share from Windows 7?

    I am new to UNIX and am having a hard time to get a ZFS share to access from windows 7 on my home network.
    I was able to access both WHS 2011 and QNAP 459 share on SE 11 by using the file manager - Server - windows & then just using the IP address, username, password. That was easy or at least similar to what I was used with windows 7.
    However, I have yet to be able to access a ZFS pool containing a share that I can access from another windows 7 machine at home.
    Apparently, I can mount the share from windows but the login name/password do not get accepted when I add a network connection in windows. Windows does seem to find the path \\solaris\tank_share1 and even mounts it, but the login for SE 11 does not work for some reason.
    I changes the workgroup name to WORKGROUP in windows but that did not change anything. I tried to edit the pam.conf file by changing the ownership from root to myself so I could use gedit since it has been 15 years since I last used vi. However, that corrupted the setup as I got "system error" message on reboot that never got out of that infinite loop.
    I am basically using the instruction through the following link:
    http://blogs.oracle.com/observatory/entry/accessing_opensolaris_shares_from_windows
    Any help to get this problem resolved is much appreciated
    Thanks,
    Kurt

    The documented procedure of having to edit the pam_conf file seems to work followed by resetting one's password seems to work after all. I believe, by taking away ownership from root to "admin user" screwed things up. I had to relearn how to use vi but that didn't take very long.
    Got about 50 MB/s speed coping from Windows SSD to SE11 SSD via very small (5 GB) RAIDZ array in VMWare (running on top of WIN 7-64). I have to try native SE11 SSD next as the VMWare setup is just for practice.
    Q: Is there a way to launch gedit from the terminal window in root mode so I wouldn't have to use vi?
    Kurt

  • Random error accessing CIFS shares from Windows

    I am setting up some CIFS shares to be used from Windows clients and in the process I had some random problems accessing the shares.
    In hope of finding the answer I checked the CIFS Service and the Active Directory Service, and while watching the screen for Active Directory Service I saw that the "Selected Domain Controller" changed from one to another. I now stayed within this screen and noticed that the "Selected Domain Controller" continued to change and then I found the problem, because an unknown Domain Controller appeared. The IP was 216.150.17.8
    I found that when ever this Domain Controller was the selected one, all access to CIFS shares from Windows clients failed! This is correct, because the 216.150.17.8 of course is unaware of all users in Our Domain
    So the Questions are:
    - what is happening?
    - and how to solve this?
    - why is a Domain Controller 216.150.17.8 sometimes the Selected Controller?
    - where does this 216.150.17.8 come from?
    Have You seen anything like this?

    I now have found out why the DC changes - it is because the CIFS service is restarting ;-(
    This is a log snip
    2009-5-14 09:24:53 Executing start method ("exec /usr/lib/smbsrv/smbd start").
    2009-5-14 09:24:53 Executing stop method (:kill).
    2009-5-14 09:24:53 Stopping because all processes in service exited.
    2009-5-14 09:24:39 Method "start" exited with status 0.
    2009-5-14 09:23:48 Executing start method ("exec /usr/lib/smbsrv/smbd start").
    smbd: NetBIOS services started
    2009-5-14 09:23:48 Executing stop method (:kill).
    2009-5-14 09:23:48 Stopping because all processes in service exited.
    2009-5-14 09:23:34 Method "start" exited with status 0.
    It seems to happen when I access the share and thereby force a uservalidation
    Any ideas?

  • Can't access Network share from Windows 8 computer

    I have a clean install of Windows 8 x64 running in a workgroup environment. I can access multiple computer/NAS shares except one share off a partifular NAS. This share is accessible from other computers and the other shares on the NAS are accessible from
    this Windows 8 computer. I have cheked the credentials and they are fine, added them under the credential manager, tried to map a drive and selected use other credentials etc but it continually says "Windows cannot access \\ComputerName\ShareName"
    you do not have permission. I have permission and nothing is wrong with the permissions or the server. This is driving me crazy if anyone could help it would be greatly appreciated.
    I have tried:
    1. Mapping drive with ip address e.g. \\ip address\sharename
    2. disabled ipv6, made sure netbios enabled, made sure client for ms networks enabled.
    3. Setup a new account on server, doesn't work either.
    4. All sharing options enabled. I even modified the permissions on the share for "everyone" full access and it still didn't work.
    Has to be something with this windows 8 machine.

    Dear all,
    Hi am using 2012 r2 server and i have created share folder ,and added the user Id in that share folder but while accessing in windows pc (local admin) its opning all share folder , but its not asking password if i click in share folder it shows you do not have
    permission to access . but till lastweek it was worked fine . and if i tried in administrator login its asking password authentication. Please help me ASAp.
    Thanks
    mahamad
    8884209555 

  • Can only connect to smb share from Windows as "nobody"

    I'm trying to share some folders on my Mac using samba. When I connect from Windows, I do not get asked for a username and password, and I get connected as a guest user (nobody). What do I do to get connected as a real user? I've tried playing with /etc/smb.conf, but I'm not sure what to change.

    when you enable smb in haring system preferences on your mac, did you check the box to enable smb on a specific account?
    if you did, when you initiate smb from windows try entering
    smb://[email protected]
    instead of
    smb://mac.ip.address

  • Cannot access RDS Farm from Windows 8.1

    Hi,
    my problem is following. We have a RDS Farm (Windows 2012) and after update my Windows to 8.1 I cannot access the RemoteApp.
    The Problem exist only on Clients with Windows 8.1 and Windows 2012R2. Windows 8.1 using the new rdp protocol(8.1)
    I don't have this problem on windows 2012 or windows 8 with rpd 8.0
    I've tried to replace the mstsc.exe and mstscax.dll in c:\windows\system32, but that didn't work. I can start mstsc, but I get error like "TS Gateway is not supported from system setting. And the gateway settings in Remote Desktop client is grayed.
    Can me somebody help or can me tell how can I downgrade to rdp 8.0?

    Hi,
    What's the RemoteAPPs you point? Desktop APPs or Store APPs? What's the type of your account? Please check your remote account authority in Remote System, try to add your account to Administrator group for test.
    In addition, it would be better to provide more details when start RemoteAPPs failed. Is there any error message?
    Roger Lu
    TechNet Community Support

  • Can't mount 10.6.8 Server SMB share from Windows

    Actually, I can mount it...I just can't read or write it.
    So I'm running Snow Leopard Server on this Intel-based Mac Mini. I have a group of users who want to be able to have a common area to store files. "Easy", I think. "Just create a folder, give it the appropriate permissions for the group, and make it a share point in the SMB configuration."
    So I do all this-- through the Server Admin UI, BTW.
    I create the folder. I give the specified group read and write access; everybody else gets nothing.
    I make the folder a share point and ensure that SMB sharing it turned on.
    Then I try to mount it from my Windows machines. I create a new network place, but I'm never asked for a user name and password. So the network place is created fine, but any attempt to open it or drag something to it fails because I'm not logged into the server.
    So the question is:
         Why isn't my server asking users to authenticate?
    And:
         How can I make it start doing this?

    Hehe... Servers are tricky things for sure. 
    It sounds like you're expecting to have users log in from outside your network, but that you're testing from within?  Is this the case?
    If your users are trying to log in from outside the local network of the server, then you'll need to ensure that the correct port forwarding is set up on your firewall.
    Next thing I'd try...  Simplify your share to ensure that the problem isn't with your group set up.  Eliminate all the ACL's associated with it.
    Add one sole user to the ACL, give it read and write, and try to log in using that credential.
    Ensure that the POSIX Permissions are set to default.  (administrator should be the owner, staff should be group, read and writable only by the owner, everyone else gets read only)
    If that works, remove that user, add a group to the ACL and try and log in using a user that's listed in the new group specified.
    Perhaps if you supplied a little more info about your server and how it's connected to it's network.  What it's roles are etc. we might be able to give a little more insight.
    HTH
    -Graham

  • I cannot access the Camera RAW dialogue box in PSE8 in windows 7. Is it possible?

    I cannot  access the Camera Raw Dialogue Box in PSE8 in windows 7.  Is it possible?

    I have PSEv.8 & WIN 7. I installed Camera raw three or four days ago without a problem, and it works just fine. Detailed directions are here:
    http://www.adobe.com/support/downloads/detail.jsp?ftpID=4810

  • I need help! I cannot access my iTunes from my window's. I keep getting message "error 7" and also MSVCR80.dll missing. I do not know how to access this?

    I need help! I cannot access my iTunes from my window's. I keep getting message "error 7" and also MSVCR80.dll missing. I do not know how to access this?
    I tried downloading the latest version of iTunes, but it does not sync to my windos 7 HP because of the previous messages. Any feedback would be greatly appreciated.
    Thank you,
    ElsaV73

    Hope this article helps you:
    http://support.apple.com/kb/TS5376
    Pleas reply with any further questions.

  • I can't access folder share in WIndows Server 2012 R2 from windows 8.1

    i have a strange case:
    I have a Windows Server 2012 R2 machine with a shared folder. Accessing this folder using a Win7, Win8,
    Win 2008 R2 machine using \\servername  works fine but form windows 8.1 or windows
    2012 r2 i can't so any one can help me. 

    Hi,
    Would you please let me know the complete error message that you can find, when can’t access to the share folder
    that host in the Windows Server 2012 R2?
    If you logon the Windows 8.1 (or server 2012 r2) with administrator account, will encounter the same issue?
    Meanwhile, please access the share folder via \\server’s IP address\share folder. Then please check if this issue still persists.
    In addition, there is a similar thread. Please refer to and check if can help you.
    Can't
    access UNC share on Windows Server 2012 R2
    Hope this helps.
    Best regards,
    Justin Gu

  • Moving files on share from Windows results in permission loss

    Here's the setup:
    -- Leopard, with shared SMB folders; specific user and everyone have read/write permissions for the share
    -- Windows machine is accessing the share via the specific user & password, connecting fine
    When I access the share from the Windows machine, and move files between folders, the file loses all permissions (they are set to 0000) so it cannot be read by anyone at all. The only way of getting access to them again (from either machine) is to chmod them back to 0644.
    Copying files is OK, as is creating files and moving a folder from Win -> Mac. It only affects moving files between folders on the Mac.
    Can anyone else confirm this, or is it a setup issue here?

    10.5.1 has not helped the situation. Any ideas???

  • Hi. I am using a time capsule for few PC s. I have made 5 different account to access time capsule. but in windows when i enter account name and password for one account, i cannot access other accounts, because windows saves username

    Hi. I am using a time capsule for few PC s. I have made 5 different account to access time capsule. but in windows when I enter account name and password for one account, i cannot access other accounts, because windows saves username. how can i prevent this from happenning. I really need to access all my accounts and dont want it to save automaticlly.

    Why have 5 accounts if you need to access all of them.. just have one account?
    Sorry I cannot follow why you would even use the PC to control the Time Capsule. Apple have not kept the Windows version of the utility up to date.. so they keep making it harder and harder to run windows with apple routers.

  • Cannot Create New Share from Azure PowerShell - The remote name could not be resolved

    I have created a storage account. It seems that there isn't a specific way to create file storage rather than blob storage.
    I followed the instruction for creating a share in Azure Power Shell but when I try $s=New-AzureStorageShare... I keep getting the error "The remote name could not be resolved".  I checked the account name and it matched what is shown on the
    Azure site.
    I also cannot access the storage from the URL's.  I get the message "This page can't be displayed.
    How can I create a file storage account and a share to it?
    Thanks,
    Glen

    Hi Glen,
    Thanks for your post!
    Did you sign up your File Service ?
    To sign up, go to the Microsoft Azure Preview Portal, and sign up for the Microsoft Azure Files service using one or more of your subscriptions. As subscriptions
    are approved for the Azure File preview, you will get an email notifying you of the approval. We will be slowly opening up the service to users in batches, so please be patient after signing up.
    After sign up and enable this feature, I suggest you could refer to this blog for how to use Azure File service (
    http://blogs.msdn.com/b/windowsazurestorage/archive/2014/05/12/introducing-microsoft-azure-file-service.aspx#faq7 ).
    Regards,
    Will
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • HT203163 I cannot access iTunes store from my laptop. I could for years but suddenly - no. Have removed all recently installed software. Have uninstalled and re-installed both my anti-virus software and iTunes. Have allowed pop-ups. Have flushed the DNS.

    I cannot access iTunes store from my laptop. I could for years but suddenly - no.
    Have removed all recently installed software. Have uninstalled and re-installed both my anti-virus software and iTunes.
    Have allowed pop-ups.
    Have flushed the DNS. Nothing.
    Still can't access the store. Please help!

    Close your iTunes,
    Go to command Prompt -
    (Win 7/Vista) - START/ALL PROGRAMS/ACCESSORIES, right mouse click "Command Prompt", choose "Run as Administrator".
    (Win XP SP2 n above) - START/ALL PROGRAMS/ACCESSORIES/Command Prompt
    In the "Command Prompt" screen, type in
    netsh winsock reset
    Hit "ENTER" key
    Restart your computer.
    If you do get a prompt after restart windows to remap LSP, just click NO.
    Now launch your iTunes and see if it is working now.
    If you are still having these type of problems after trying the winsock reset, refer to this article to identify which software in your system is inserting LSP:
    iTunes 10.5 for Windows: May see performance issues and blank iTunes Store
    http://support.apple.com/kb/TS4123?viewlocale=en_US

Maybe you are looking for