G
Guest
I'm helping to migrating an NT 4.0 domain into my existing W2K AD domain OU.
The NT domain has one or more Unix boxes running Samba to provide file
sharing capabilitles for that domain.
I know very little about Samba, but I have read that it can be set to
emulate (at least NT 4.0 and maybe W2K) Domain Controllers.
What kind of damage can these Samba users do to the DCs in my W2Ksp4 AD
Forest/Domain.
Can they cause a Denial of Service if incorrectly set to emulate DCs in the
domain.
Is there anything special I need to do to my AD to protect it from them.
Is there anything I need to make sure the Samba users don't do that could
cause a problem.
None of the Samba users will have Administrative rights in my Forest or
Domain at this point, however, they may have the ability to create/remove
users in their OU at some point.
In the past, I've had users 'attempt' to configure Samba against my native
Microsoft domains in the past and they appear to 'pound' the DCs if
mis-configured (appearently attempting to authenticate?, even if not part of
the domain?). This has always gone away if I ask if they are using Samba and
they say yes and ask them to stop. I don't know what they did in these
cases, either turned it off, or configured it correctly?
Sorry this is so rambling, but I'm not sure what to ask as I don't run/use
the Samba product, so I don't really know how it works against standard
MS-DCs.
The NT domain has one or more Unix boxes running Samba to provide file
sharing capabilitles for that domain.
I know very little about Samba, but I have read that it can be set to
emulate (at least NT 4.0 and maybe W2K) Domain Controllers.
What kind of damage can these Samba users do to the DCs in my W2Ksp4 AD
Forest/Domain.
Can they cause a Denial of Service if incorrectly set to emulate DCs in the
domain.
Is there anything special I need to do to my AD to protect it from them.
Is there anything I need to make sure the Samba users don't do that could
cause a problem.
None of the Samba users will have Administrative rights in my Forest or
Domain at this point, however, they may have the ability to create/remove
users in their OU at some point.
In the past, I've had users 'attempt' to configure Samba against my native
Microsoft domains in the past and they appear to 'pound' the DCs if
mis-configured (appearently attempting to authenticate?, even if not part of
the domain?). This has always gone away if I ask if they are using Samba and
they say yes and ask them to stop. I don't know what they did in these
cases, either turned it off, or configured it correctly?
Sorry this is so rambling, but I'm not sure what to ask as I don't run/use
the Samba product, so I don't really know how it works against standard
MS-DCs.