Samba authentication against Active Directory

A guide to authenticate Samba on a HP UX 11.23 system to Microsoft Active Directory running on W2003 R2.

General setup

Update your software if you want ADS authentication (kerberos), I used samba versie 3.0.22
Cifs server:

  1. When using RPC for authentication (less secure) kerberos is not needed
  2. edit the following files (see examples below):
    /etc/opt/samba/ (if not using kerberos, and I think you don’t need this one at all as long as you don’t give rights to AD users or groups on Unix level)
  3. the command kinit <domainuser> must work if you want an ADS config, use klist to view the certificatewinbind must run, so start samba with option -w
    /opt/samba/bin/startsmb -w
    /opt/samba/bin/stopsmb -w
  4. the following commands to give you the list of all groups or users in Active Directory must work (winbind must be running):
    /opt/samba/bin/wbinfo -g
    /opt/samba/bin/wbinfo -u
  5. folder on unix has the following rights:
    drwxrwxrwx 2 root sys /folder
  6. create groups in Active Directory (whom you give right in smb.conf), add users.
  7. To automatically start winbind when HP UX starts, go to /etc/rc.config.d/samba and set RUN_WINBIND to 1



You can automatically create the global section by using the command /opt/samba/bin/samba_setup.

local master = yes
domain master = auto
domain logons = no
netbios name = <LOCAL_SERVER_NAME>
wins support = no
workgroup = <DOMAIN_NAME>
preferred master = auto
server string = <Description of the server>
password server = <>, *
security = ADS
encrypt passwords = yes
log level = 3
log file = /var/adm/%m
max log size = 50
winbind separator = +
winbind use default domain = yes
winbind enum users=yes
winbind enum groups=yes
idmap uid = 10000-20000
idmap gid = 10000-20000
directory mask = 0775

comment = folders
path = /tmp/testfolder
browseable = yes
read list = @GROUP_READ
write list = @GROUP_WRITE
valid users = @GROUP_READ,@GROUP_WRITE


default = FILEvaradmkrb5libs.log
kdc = FILEvaradmkrb5kdc.log
admin_server = FILEvaradmkadmind.log

default_realm = <DOMAIN_NAME.COM>
default_tkt_enctypes = DES-CBC-MD5 DES-CBC-CRC
default_tgs_enctypes = DES-CBC-MD5 DES-CBC-CRC
ccache_type = 2

kdc = <>:88
kdc = <>:88
admin_server = <>


pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false

smb.conf not using kerberos

If you dont want ADS authentication (kerberos) smb.conf looks like this:
workgroup = <DOMAIN>
security = domain
password server = <>
allow trusted domains = No
preferred master = no
local master = no
domain master = no
idmap backend = idmap_rid: <activedirectorydomainname>=10000-30000
idmap uid = 10000-30000
idmap gid = 10000-30000

username map = /etc/opt/samba/

winbind use default domain = Yes
winbind separator = “+”

log file = /var/opt/samba/log.%m
max log size = 1000
directory mask = 0775
include = /etc/opt/samba/smb.conf.%m


And then you have to create the smbusers.dat file.
root = sqladmin


