Before creating or enabling eDirectory users for Samba access, it is important to understand certain requirements regarding Samba passwords.
The preferred method for Samba authentication in OES involves the use of a Universal Password (UP) policy in eDirectory. The primary reason for this is that it eliminates the need for password synchronization when users change their passwords in eDirectory.
The first time you install Samba on an OES server in a given eDirectory tree, the install creates a Universal Password (UP) policy in the tree named Samba Default Password Policy. The policy is located in eDirectory > Security > Password Policies.
The following sections explain the issues associated with Universal Password and Samba.
You can set a Universal Password for an existing eDirectory user by using iManager > Passwords > Set Universal Password. However, if you do this, you have changed the user’s password and you must notify the user of the change.
Some organizations have set up portals for users to change their passwords. After a password policy is set, send the users to the portal to reset the password so both the NDS and Universal Password are set.
For a Password Policy to qualify for use by Samba users, the following configuration options must be enabled on the iManager > Passwords > Password Policies > the Universal Password tabbed page:
Enable Universal Password
Allow Admin to Retrieve Password
Log in to iManager, then click Passwords > Password Policies > New.
Name the policy, then click Next.
At the Would you like to enable Universal Password? prompt, click Yes.
Click View Options.
Select the Allow Admin to Retrieve Password option.
Continue creating the policy and in Step 7 of 8 assign it as follows:
If you are using the smbbulkadd utility to enable Samba users you must assign it to either
Each User object being enabled
or
The Organizational Unit of your User objects
If you are using iManager to enable Samba Users, assign the policy to either
Each User object being enabled
The Organization Unit of your User objects
or
The Organization object at the root of the tree above the User objects.
Click Next.
Click Finish.
Click Close.
Log in to iManager, then click Passwords > Password Policies
Select a policy, then click Edit.
Make whatever changes you need.
In the drop-down list, click Configuration Options, or in Internet Explorer click the Universal Password tab, then click the Configuration Options link.
Make sure the Enable Universal Password and the Allow Admin to Retrieve Password options are both selected.
In the drop-down list, click Policy Assignment, or in Internet Explorer click the Policy Assignment tab.
If you are using the smbbulkadd utility to enable Samba users you must assign it to either
Each User object being enabled
or
The Organizational Unit of your User objects
If you are using iManager to enable Samba Users, assign the policy to either
Each User object being enabled
The Organization Unit of your User objects
or
The Organization object at the root of the tree above the User objects.
Click Apply.
Click OK.