# DOmain authentification with root privileges

**URL:** <https://forums.suse.com/t/domain-authentification-with-root-privileges/30686>\
**Category:** SLES Configure-Administer\
**Created:** [December 19, 2017, 11:38am UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686 "2017-12-19T11:38:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm\_rec](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@bm\_rec](https://forums.suse.com/u/bm_rec)\
**Post date:** [December 19, 2017, 11:38am UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686/1 "2017-12-19T11:38:08Z")

</div>

I want to do domain authentification on a server and give some users or AD security group root privileges. And some users deny access to the server.  
I’ve already joined the server to domain using Yast → Windows Domain Membership. Now domain users can login to the server.  
How can I give they root rights? I added string into visudo :  
dvsbs\\abdv ALL = (root) ALL  
but it doesn’t work, I tried su - and error appers: su: User not known to the underlying authentication module  
And in log messages: su: pam\_winbind(su-l:auth): request wbcLogonUser failed: WBC\_ERR\_AUTH\_ERROR, PAM error: PAM\_USER\_UNKNOWN (10), NTSTATUS: NT\_STATUS\_NO\_SUCH\_USER, Error message was: No such user  
I can’t look up any user in Yast’s module User and Group Administration because filter can’t establish connection (see screenshots).

wbinfo -t says succeeed. I didn’t use sssd.

---

<div class="post-metadata">

**Author:** ![thsundel](https://avatars.discourse-cdn.com/v4/letter/t/13edae/32.png) [@thsundel](https://forums.suse.com/u/thsundel)\
**Post date:** [December 19, 2017, 3:51pm UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686/2 "2017-12-19T15:51:40Z")

</div>

[QUOTE=bm\_rec;40608]I want to do domain authentification on a server and give some users or AD security group root privileges. And some users deny access to the server.  
I’ve already joined the server to domain using Yast → Windows Domain Membership. Now domain users can login to the server.  
How can I give they root rights? I added string into visudo :  
dvsbs\\abdv ALL = (root) ALL  
but it doesn’t work, I tried su - and error appers: su: User not known to the underlying authentication module  
And in log messages: su: pam\_winbind(su-l:auth): request wbcLogonUser failed: WBC\_ERR\_AUTH\_ERROR, PAM error: PAM\_USER\_UNKNOWN (10), NTSTATUS: NT\_STATUS\_NO\_SUCH\_USER, Error message was: No such user  
I can’t look up any user in Yast’s module User and Group Administration because filter can’t establish connection (see screenshots).

wbinfo -t says succeeed. I didn’t use sssd.[/QUOTE]

This might help: [https://www.novell.com/support/kb/doc.php?id=7018675](https://www.novell.com/support/kb/doc.php?id=7018675)

Thomas

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [December 19, 2017, 3:46pm UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686/3 "2017-12-19T15:46:14Z")

</div>

Which version, and SP, of SLES are you using? Is there a reason you did  
not use SSSD instead?

I am not an expert in the area of sssd or the older method of just joining  
the microsoft active directory (MAD) domain, but what I have learned about  
SSSD is that makes me want to use that whenever possible, so I would  
probably try using that.

Also, as a note, your commands have some odd characters that may be  
because of formatting from the HTTP interface; there is a “code” tag that  
can be used via a ‘#’ button at the bottom of the text input area which  
makes sure that what you type is not interpreted in an odd way which makes  
commands, and other output, invalid for analysis.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below.

If you want to send me a private message, please let me know in the  
forum as I do not use the web interface often.

---

<div class="post-metadata">

**Author:** ![bm\_rec](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@bm\_rec](https://forums.suse.com/u/bm_rec)\
**Post date:** [December 29, 2017, 10:04am UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686/4 "2017-12-29T10:04:46Z")

</div>

> [@thsundel;40613](#):
>
> This might help: [https://www.novell.com/support/kb/doc.php?id=7018675](https://www.novell.com/support/kb/doc.php?id=7018675)

Thank you, Thomas, this article helped me.

[QUOTE=ab;40614]Which version, and SP, of SLES are you using?[/QUOTE] I metioned it in a title.  
I didn’t try SSSD because I wanted to try simpler method.  
In my future posts I will use these tags, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [January 9, 2018, 5:27am UTC](https://forums.suse.com/t/domain-authentification-with-root-privileges/30686/5 "2018-01-09T05:27:33Z")

</div>

On 12/29/2017 02:14 AM, bm rec wrote:[color=blue]

> thsundel;40613 Wrote:[color=green]
> 
> > This might help: [https://www.novell.com/support/kb/doc.php?id=7018675](https://www.novell.com/support/kb/doc.php?id=7018675)[/color]  
> > Thank you, Thomas, this article helped me.  
> > ab;40614 Wrote:[color=green]  
> > Which version, and SP, of SLES are you using? I metioned it in a title.[/color]  
> > I didn’t try SSSD because I wanted to try simpler method.  
> > In my future posts I will use these tags, thanks!
> 
> [/color]

Just a note on sssd. I tried the Samba + sssd mechanism on CentOS, and found it  
only partially worked. I went back to winbindd which totally works for not just  
auth but also for file serving.
