How JustAnswer Works:
  • Ask an Expert
    Experts are full of valuable knowledge and are ready to help with any question. Credentials confirmed by a Fortune 500 verification firm.
  • Get a Professional Answer
    Via email, text message, or notification as you wait on our site. Ask follow up questions if you need to.
  • 100% Satisfaction Guarantee
    Rate the answer you receive.
Ask NetworkConsultant247 Your Own Question
NetworkConsultant247, Consultant
Category: Computer
Satisfied Customers: 28
Experience:  20 year’s experience. Networking Administration A.A.S, MCP, N+, A+
Type Your Computer Question Here...
NetworkConsultant247 is online now
A new question is answered every 9 seconds

HiI could join domain(PDC:samba+LDAP)........but I couldnt

This answer was rated:


I could join domain(PDC:samba+LDAP)........but I couldnt "login"
error is that machines trust relationship fails

what can I do?
Customer: replied 4 years ago.
Relist: I still need help.
Hello my name isXXXXX am sorry you are having a technical problem and I will answer your questions and find a solution to the best of my ability.

I will need additional information to troubleshoot such as what have you tried so far?
Customer: replied 4 years ago.

I have tried "login" after "join domain"..... but I cant

Hello Ken, since you have already fixed the SID problem, this is usually a user password XXXXX fix. The domain controller does not recognize. Please reset the user password.

Let me know if this fixes the login.Smile
Customer: replied 4 years ago.

I made 1 users named "test01"

#useradd test01

#passwd test01

New password:XXX


#pdbedit -a test01

I did this... But account flag is [DU ]....why .......?

anyway ,I try user password XXXXX

as a command #smbpasswd test01 (for example)?

Are you saying you did reset the password? I am not finding {DU} please clarify, thanks.
There is a utility to do the reset if you have no joy!Smile
Customer: replied 4 years ago.

at first I dont know how to do reset the password XXXXX samba server

If you tell me how ... I will try :)

and next , I tried ...... I made one samba user ........ But ........ this user's account flag is [DU ](which means Disabled User)........ I dont know why ..........I think we need more infomations....... I send you zip file ok?

Thats ok I found the flag user disabled. Try new:


This option is used to add a user into the database. This command needs a user name specified with the -u switch. When adding a new user, pdbedit will also ask for the password XXXXX be used.

Example: pdbedit -a -u sorce

Enable the user accounts with smbpasswd -e username . This is normally done as an account is created.

Until a few minutes after Samba has started, clients get the error `Domain Controller Unavailable'”

A domain controller has to announce its role on the network. This usually takes a while. Be patient for up to 15 minutes, then try again.


Let me know if this is workingSmile

And this

If you added the account using an editor rather than using the smbpasswd utility, make sure that the account name is XXXXX XXXXX NetBIOS name with a “$” appended to it (i.e., computer_name$). There must be an entry in both the POSIX UNIX system account backend as well as in the SambaSAMAccount backend.
Did you use the UNIX tool vipw?
Customer: replied 4 years ago.

no, I didnt use UNIX tool vipw.

Thank you for the reply this answer window has a bug and I have tried to send my answers. I may have to upload a link.
Customer: replied 4 years ago.

I am confused........ plz help me.

Yes I will send the link that explains the password XXXXX up. You should use the utility vipw
This may also help clarify:

I want to make sure you can login after you make the password XXXXX or new account using the tool. It shows that if you created the accounts manually it may not work.
Customer: replied 4 years ago.

I am seeing its URL ..... but I dont make sense.......

"#pdbedit -a -u XXX" is for loggingin?.....hmmmmm

Customer: replied 4 years ago.

BTW, Account Flag Problem resolved.

#smbldap-groupadd abc

#smbldap-useradd -am -g abc abc

#smbldap-passwd abc

New Password:

Retyype new password:

after that

I typed #pdbedit -L -w

I can see account flag is like [U ]

Was reseting password XXXXX? It shows that you have to make some checks to make sure the group does not have the same name

Did you see this: pdbedit -a -m -u w2k-wks this is to add a machine trust account.
Its from the second link page I sent.
A little more than halfway scroll down and look under -mj--machine

It has all the checks to make and so let me know if you can log in, and if not what is the error after you make the modifications to the user account.
{U} is regular user account! Thats better!Smile
Ok sorry I see you typed the answer to my questions and I sent my reply after you sent yours.
So it appears you have success!Smile I am happy for you!
Customer: replied 4 years ago.

so would you tell me how to create new user account to login on commands?

Yes :
This option is used to add a user into the database, the command needs a username specified with the -u switch.

pdbedit -a -u sorce

new password
retype new password

Are you satisfied and happy to get to this point? If so please rate my service so that I can be compensated. If not please let me know what else I can do to help you with the log in!SmileSmileSmileSmile
Are you asking to use synchronising for Samba and Unix?
which means the Samba user automatically created whenever a unix user is created?
That is :

smbldap-useradd johndoe

or useradd johndoe this one requires the first user to login to activate the second
And in addition to that to set the user password XXXXX the database to login without having to use a password XXXXX XXXXX:

smbpasswd -a

Let me know if this is what you needed.
Customer: replied 4 years ago.

I could not do smbpasswd -a <username>

error occurred


It has to be an active user account. Was the sync of accounts successful so that the user account would create as in the: smbldap-useradd johndoe?
Customer: replied 4 years ago.

I did smbldap-useradd johndoe

and did smbpasswd -a johndoe

but I couldnt login .....

I think useradd <username> and pdbedit -a <username> is better I think .......... BUT if I do so ......... account flag problem occurrs and cant login after all...........


what can we do?

what does the flag show? The last flag you gave was {U} regular user.
And from the links to guidelines I sent you should go through the checks listed to make sure the user accounts are active.
When I read the text log you sent it appears the attribute is not allowed.
It may be a version difference that you have. So then you could check all of the updates for the version Samba that you use.
The domain trust is fixed , and the only thing that was stopping the login was the password. So was the reset successful I asked and you sent the log, it showed (U) flag which is normal. Have you restarted ?After making these changes as in one of the checks listed shows to restart. Let me know after you update.Smile
Customer: replied 4 years ago.

finally I understarnd how to create correct samba users

I typed these commands....... it was sucessfull below.

#smbldap-useradd johndoe
#smbldap-passwd -a johndoe

#useradd johndoe

#pdbedit -a -u johndoe



and samba version is 3.6. This is latest version. and I restart smb nmb and slapd

You are awesome!! I am so happy for you! SmileSmile

I will have to go offline in a bit Ken but again it was very nice to be of help to you!
SAL waving since no emoticon...
NetworkConsultant247 and other Computer Specialists are ready to help you
Hello Ken thank you for using JustAnswer to help you resolve your technical questions.
I am just checking back with you to ask if you had any further questions that I may help you with?
Have A Great Day!