Shawn Dakin | 6 Jun 2012 21:37

LAM causing "group policy client service failed the logon"

If I create a new user using smbldap-useradd the new user can login to
my win7 workstations. However, if I create the new user in LAM the new
user receives the errorĀ "group policy client service failed the logon.
Access denied"

Any one have an idea what LAM is doing to the user accounts?

Here is a quick comparison.

yo.littledog (GOOD ACCOUNT)
I know the home dir and profile path are wrong.
SAMBA1:/var/log/samba # pdbedit -Lv yo.littledog
smbldap_search_domain_info: Searching
for:[(&(objectClass=sambaDomain)(sambaDomainName=NEVSD))]
StartTLS issued: using a TLS connection
smbldap_open_connection: connection opened
ldap_connect_system: successful connection to the LDAP server
init_sam_from_ldap: Entry found for user: yo.littledog
init_group_from_ldap: Entry found for group: 513
Unix username:        yo.littledog
NT username:          yo.littledog
Account Flags:        [U          ]
User SID:             S-1-5-21-1545272169-3882205488-3325164475-1328
Primary Group SID:    S-1-5-21-1545272169-3882205488-3325164475-513
Full Name:            yo.littledog
Home Directory:       \\PDC-SRV\yo.littledog
HomeDir Drive:        H:
Logon Script:         logon.bat
Profile Path:         \\PDC-SRV\profiles\yo.littledog
Domain:               NEVSD
(Continue reading)

Roland Gruber | 7 Jun 2012 10:53
Picon
Favicon

Re: LAM causing "group policy client service failed the logon"


Hi Shawn,

On 06.06.2012 21:37, Shawn Dakin wrote:
> If I create a new user using smbldap-useradd the new user can login
> to my win7 workstations. However, if I create the new user in LAM
> the new user receives the error "group policy client service failed
> the logon. Access denied"

can you provide an LDIF of both users?
From your listings I can only see that home and profile path are
different. Maybe a non-existent server causes this problem.

--

-- 

Best regards

Roland

LDAP Account Manager
http://www.ldap-account-manager.org/

Want more? Get LDAP Account Manager Pro!
http://www.ldap-account-manager.org/lamcms/lamPro

Gmane