[KLUG Members] Samba Win2k logon scripts

Adam Williams members@kalamazoolinux.org
Wed, 12 Sep 2001 18:18:41 -0400 (EDT)


>>I have a Samba 2.2.1a-ldap.4 PDC on RedHat 7.1.  It happily deals
>>out logon
>>scripts (those batch files that run when you log on) to NT 4.0sp6
>>and Win9x
>>machines.  But on WinY2k workstations the logon scripts simply don't
>>run.
>>Documentation makes it appear that NT/WinY2k handle logon scripts
>>the same,  so
>>any pointers from those who know more about Redmond product than me?
>>Or is ita Samba thing?
>Windows 2000 has a much fancier way of assigning drive letters, installing
>programs, and configuring the client machines than the previous script
>system.  If you actually have LDAP working properly, there's probably a
>place buried in it somewhere that you can put scripts, but I'm not familiar
>enough with the schema to know where.

I got a couple of pointers from the Samba team.  In stock Samba it seems
to expect to find such info in the smb.conf file on a global basis.  With
LDAP you populate the information into the user objects.  Haven't tried it
yet,  but these people are usually right. (I often wonder if they were put
on this earth to make up for people like me,  kind of an intellectual
ying/yang :)

>>The WinY2k machines have happily joined the domain,  automatically
>>created machine accounts for themselves in the LDAP directory, etc...
>>It even works
>>to upload print drivers to the Samba box...  I'm simply amazed,
>>those Samba
>>guys rock.  I'll even admit that WinY2k is a big leap forward from
>>NT 4.0.
>>I'd very much like to know more about your LDAP configuration since I"m
>trying to do something similar to my own setup.  In particular, have you
>managed to get a Samba PDC and a W2k domain controller to share a domain
>and replicate with each other?

Nothing so elaborate.  I don't want a Windows 2000 server,  and since I
don't NEED one for anything at this point in time I just wanted to plug
the WinY2k boxes into my existing LDAP infrastructure.

>In NT compatibility or 2000 only mode?

This is a Windows NT domain (I like to call it NT version 6,  MSCEs look
at me crosseyed)..

>Centralized security through Kerberos?

Not yet.  I'll fiddle with getting them to talk to the KDC once I get
everything working "normally".

>All I've managed so far is a w2k
>DNS subzone from a BIND root.

Sounds cool.  Do you propogate SRV records?

-- 
-----------------------------------------------------------
Ximian GNOME, Evolution, LTSP, and RedHat Linux + LVM & XFS
-----------------------------------------------------------