Before creating or enabling eDirectory users for Samba access, it is important to understand certain requirements regarding Samba passwords.
The preferred method for Samba authentication in OES involves the use of a Universal Password (UP) policy in eDirectory. The primary reason for this is that it eliminates the need for password synchronization when users change their passwords in eDirectory.
The first time you install Samba on an OES Linux server in a given eDirectory tree, the install creates a Universal Password (UP) policy in the tree named
. The policy is located in eDirectory > > .The following sections explain the issues associated with Universal Password and Samba.
You can set a Universal Password for an existing eDirectory user by using iManager >
> . However, if you do this, you have changed the user’s password and you must notify the user of the change.Some organizations have set up portals for users to change their passwords. After a password policy is set, send the users to the portal to reset the password so both the NDS and Universal Password are set.
For a Password Policy to qualify for use by Samba users, the following configuration options must be enabled on the iManager >
> > the tabbed page:Enable Universal Password
Allow Admin to Retrieve Password
Log in to iManager, then click
> > .Name the policy, then click
.At the
prompt, click .Click
.Select the
option.Continue creating the policy and in Step 7 of 8 assign it as follows:
If you are using the smbbulkadd utility to enable Samba users you must assign it to either
Each User object being enabled
or
The Organizational Unit of your User objects
If you are using iManager to enable Samba Users, assign the policy to either
Each User object being enabled
The Organization Unit of your User objects
or
The Organization object at the root of the tree above the User objects.
Click
.Click
.Click
.Log in to iManager, then click
>Select a policy, then click
.Make whatever changes you need.
In the drop-down list, click
, or in Internet Explorer click the tab, then click the link.Make sure the
and the options are both selected.In the drop-down list, click
, or in Internet Explorer click the tab.If you are using the smbbulkadd utility to enable Samba users you must assign it to either
Each User object being enabled
or
The Organizational Unit of your User objects
If you are using iManager to enable Samba Users, assign the policy to either
Each User object being enabled
The Organization Unit of your User objects
or
The Organization object at the root of the tree above the User objects.
Click
.Click
.