大大,我遇到真正高難度問題啦!救救我
版主: ross_tt、bryanchang、digdog、chester
大大,我遇到真正高難度問題啦!救救我
因為公司只有我是一個人使用mac,偏偏公司又有網域ABC
我以翻前文去Directory Access裡把群組設成ABC
但我去finder->network->ABC是看到其他電腦
但我要抓取分享資料卻出現替身不存在,無法使用???
這是什麼意思啊!
還有我用smb://server ip但也是不能進去
但我家就可以,只差個網域設定啊!會不會是我網域沒加入成功,
但我之前windows system notebook即使不加入網域,我還是可以
抓到server的資料夾啊
請大大救救我
我以翻前文去Directory Access裡把群組設成ABC
但我去finder->network->ABC是看到其他電腦
但我要抓取分享資料卻出現替身不存在,無法使用???
這是什麼意思啊!
還有我用smb://server ip但也是不能進去
但我家就可以,只差個網域設定啊!會不會是我網域沒加入成功,
但我之前windows system notebook即使不加入網域,我還是可以
抓到server的資料夾啊
請大大救救我
還有一個好辦法!!
啥都不用做,直接等 Mac OS X 10.5.....
不然就要跟我一樣,來原廠討論區爬英文囉.....
http://discussions.info.apple.com/webx? ... 68b7164e/0
啥都不用做,直接等 Mac OS X 10.5.....
不然就要跟我一樣,來原廠討論區爬英文囉.....
http://discussions.info.apple.com/webx? ... 68b7164e/0
We have finally gotten our Mac Tiger to Win 2003 Server SMB file sharing back operational again. I wanted to give a little account of the long and winding path we took to the final solution(s) in hopes that i may be helpful for others out there that have had similar problems.
Background:
1) We have three macs in a primarily PC office in China. We had been using straight SMB file sharing with our Windows 2003 AD Server since Panther days with no problems (but had never been able to get the Active Directory setup with the macs).
2) We all upgraded to Tiger at the same point our IT manager made some changes on the AD server; therefore, when we no longer were able to connect via SMB we weren't sure if it was Tiger or Windows AD that was the root issue.
3) When we tried connect via SMB we got the "Alias XXX can't be found. Do you want to delete, fix, etc"
4) We were, however, able to connect to the SMB connection via the terminal through "smbclient //SERVER/SHARE NAME -W "workgroup name" - U "username"
5) We tried to clean the keychain like some of the posts had recommended with no result.
6) We also did a clean reinstall of one of the Macs with no result.
7) We then realized the error must be coming from the AD server and realized we needed to "disable" "Microsoft Network Servers: Digitally Sign Communications (Always) in the AD Domain Controller Secruity Settings. This was a recomendation from back in the Panther days but since we never had a problem with Panther, we never really paid much attention to it. Anyway, this instanly fixed the problem.
However, we also ran into a problem with the freshly installed mac where we were not able to see any of the windows network shares. We realized this issue was directly related to either the "Enable Stealth Mode" and/or "Block UDP Traffic" being activated in the "Advanced" tab of the Tiger Firewall. Once we disabled these, all worked. Strangely enough, we did not find this problem with the other macs that we had done an archive and install on...
Anyway, these are just some of the issues we worked through and hope they may be of some help. Our next journey will be to try to get the Macs to connect via Active Directory but have been stumped on the "invalid domain or forrest" error for quite some time.
這麼神奇?有空我也來試試看....
同一篇也有提到
同一篇也有提到
這個寫得難以閱讀:Now, if you and Peebles can solve our AD binding issue we will send you all the Chinese rice wine you can stomach! I was hoping that digital signing issue would kill two birds with one click but no such luck.
http://discussions.info.apple.com/webx? ... 8afb5e8/76Here is what I've found. After setting the encrypt passwords = no in the smb.conf, on my Windows 2003 Server (my Domain Controller), I had to change Domain Controller Security Policy. Administrative Tools>Domain Controller Security Policy then Local Policies>Security Options. Look for the policy Microsoft network server: Digitally sign communications (always) and change this to Disabled, but leave Microsoft network server: Digitally sign communications (if client agrees) intact. Exit out of the Policy Editor and wait at least 15 minute or so for AD to replicate. After making these changes, I was able to mount shares from the Go Menu as well as from the CLI using mount_smbfs. I still got the mount_smbfs: No credentials cache found krb5_cc_get_principal error from the command line, but the share still mounted. It also didn't seem to affect my Windows XP clients which functioned properly. I don't make any guarantees, but this worked for me. Remember to be very judicious in tracking your changes (proper change control) so that you can back out if necessary. My Tiger install was already bound to Active Directory prior to making these additional changes. Again I urge caution; This was all done in my test lab environment at home, NOT ON AN ENTERPRISE OR CORPORATE NETWORK THAT PEOPLE RELY ON TO DO BUSINESS.
Windows 2003 的網域主要就是密碼傳送的問題,你可以先照精華區設定試試看,真不行的話建議你買一套 ADmitMac
http://www.thursby.com/products/admitmac.html
不便宜,不過也不是天價。
http://www.thursby.com/products/admitmac.html
不便宜,不過也不是天價。
ash nazg durbatuluk, ash nazg gimbatul,
ash nazg thrakatuluk agh burzum-ishi krimpatul.
ash nazg thrakatuluk agh burzum-ishi krimpatul.
咳~~來說正經事....
關於 GPO 的【數位簽章】的相關設定是不是在這裡:

無論我怎樣啟用和停用,還是一樣耶..... Mac 仍然沒辦法用 smb:// 連上 AD 共用檔案夾...
這裡也有相關討論:
http://www.macosx.com/content/faq.php/q ... ssues.html
另外還找了一些資料,不過都沒辦法解決!!
不知道是我設錯了??還是阿光我笨??
關於 GPO 的【數位簽章】的相關設定是不是在這裡:

無論我怎樣啟用和停用,還是一樣耶..... Mac 仍然沒辦法用 smb:// 連上 AD 共用檔案夾...
這裡也有相關討論:
http://www.macosx.com/content/faq.php/q ... ssues.html
另外還找了一些資料,不過都沒辦法解決!!
不知道是我設錯了??還是阿光我笨??
有打全路徑嗎?即是:進藤光 寫:無論我怎樣啟用和停用,還是一樣耶..... Mac 仍然沒辦法用 smb:// 連上 AD 共用檔案夾...
代碼: 選擇全部
smb://domain;host/folder$
It is not god who created man. It is man who created God.
Light travels faster than sound. This is why some people appear bright until you hear them speak.
進藤光你設錯了,以下是我家公司我做的設定,基本上要相容98,NT(會降低安全性)就要這麼設:
----------------------------------------
microsoft 網路用戶端: ....SMB---已停用
microsoft 網路用戶端: ....(如果伺服器同意)---已啟用
microsoft 網路用戶端: ....(自動)---尚未定義
microsoft 網路伺服器: ....中斷用戶端連線---尚未定義
microsoft 網路伺服器: ....(如果用戶端同意)---已啟用
microsoft 網路伺服器: ....(自動)---已停用
網域成員: ....已啟用
網域成員: ....尚未定義
網域成員: ....尚未定義
-----------------------------------------
改完之後要等1~2小時讓GPO生效,或是在目標電腦下gpupdate /force ,或重開機,這應該知道吧 !?
確定目標電腦套用GPO後,再用SMB://IP連就可以了。當然,他會跟你要網域帳號密碼,輸入就連上啦!
----------------------------------------
microsoft 網路用戶端: ....SMB---已停用
microsoft 網路用戶端: ....(如果伺服器同意)---已啟用
microsoft 網路用戶端: ....(自動)---尚未定義
microsoft 網路伺服器: ....中斷用戶端連線---尚未定義
microsoft 網路伺服器: ....(如果用戶端同意)---已啟用
microsoft 網路伺服器: ....(自動)---已停用
網域成員: ....已啟用
網域成員: ....尚未定義
網域成員: ....尚未定義
-----------------------------------------
改完之後要等1~2小時讓GPO生效,或是在目標電腦下gpupdate /force ,或重開機,這應該知道吧 !?
確定目標電腦套用GPO後,再用SMB://IP連就可以了。當然,他會跟你要網域帳號密碼,輸入就連上啦!
- MacChiyuan
- 留言五百如一日
- 文章: 780
- 註冊時間: 04/30/2001 1:01 am
- 來自: USA / DFW
- 聯繫: