r tried the
>>>> samba tools like smbpasswd.
>>>>
>>>> I still have a wiki how-to in the works, but I had to focus on some other
>>>> issues for a while.
>>>>
>>>> Chris
>>>>
>>>>
>>>>
>>>> F
swd.
>>>
>>> I still have a wiki how-to in the works, but I had to focus on some other
>>> issues for a while.
>>>
>>> Chris
>>>
>>>
>>>
>>> From: "Matt ."
>>> To: Youenn PIOLET
>>> Cc:
ouenn PIOLET
>> Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
>> "freeipa-users@redhat.com"
>> Date: 20.08.2015 08:12
>> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>>
>>
>>
>> HI Guys,
>&g
Youenn PIOLET
> Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
> "freeipa-users@redhat.com"
> Date: 20.08.2015 08:12
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> HI Guys,
>
> Anyone still a working clue/te
m: "Matt ."
To: Youenn PIOLET
Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
"freeipa-users@redhat.com"
Date: 20.08.2015 08:12
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
HI Guys,
Anyone still a working clue/test here ?
I d
n I do DOMAIN\username
>>>> as username
>>>>
>>>> So, the IPA way should work.
>>>>
>>>> Any comments here ?
>>>>
>>>> Cheers,
>>>>
>>>> Matt
>>>>
>>>>
Uys,
>>> >
>>> > I'm testing this out and I think I almost setup, this on a CentOS samba
>>> > server.
>>> >
>>> > I'm using the ipa-adtrust way of Youeen but it seems we still need to
>>> > add (objectclass=sambaSamAccount))
;> > Thanks!
>> >
>> > Matt
>> >
>> > 2015-08-10 11:16 GMT+02:00 Christopher Lamb
>> > :
>> >> The next route I will try - is the one Youeen took, using ipa-adtrust
>> >>
>> >>
>> >>
>> >> Fr
; Matt
> >
> > 2015-08-10 11:16 GMT+02:00 Christopher Lamb >:
> >> The next route I will try - is the one Youeen took, using ipa-adtrust
> >>
> >>
> >>
> >> From: "Matt ."
> >> To: Christopher Lamb/Switzerland/IBM
Youeen took, using ipa-adtrust
>>
>>
>>
>> From: "Matt ."
>> To: Christopher Lamb/Switzerland/IBM@IBMCH,
>> "freeipa-users@redhat.com"
>> Date: 10.08.2015 10:03
>> Subject:Re: [Freeipa-users] Ubuntu Samba Server Au
aft for the wiki page, I will mail you.
>>
>>
>>
>> From: "Matt ."
>> To: Christopher Lamb/Switzerland/IBM@IBMCH,
>> "freeipa-users@redhat.com"
>> Date: 09.08.2015 21:17
>> Subject:Re: [Freeipa-users
;freeipa-users@redhat.com"
> Date: 09.08.2015 21:17
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> Hi,
>
> Yes I know about "anything" but which way did you use now ?
>
>
>
> 2015-08-09 20:56 GMT+02:00 Christopher
The next route I will try - is the one Youeen took, using ipa-adtrust
From: "Matt ."
To: Christopher Lamb/Switzerland/IBM@IBMCH,
"freeipa-users@redhat.com"
Date: 10.08.2015 10:03
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IP
quot;freeipa-users@redhat.com"
> Date: 09.08.2015 16:45
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> Hi Chris,
>
> This sounds great!
>
> What are you using now, both CentOS ? So Samba and FreeIPA ?
>
> Maybe it's go
islands that sit on
> the
>> same network.
>>
>> The route that Youenn has taken (unless I have got completely the wrong
> end
>> of the stick) requires Active Directory in the architecture.
>>
>> Chris
>>
>>
>>
>> From: "M
Hi,
Yes I understood, but this seems to take at least some months before
it will be "usable".
There is no release target date yet ?
Cheers,
Matt
2015-08-09 12:33 GMT+02:00 Jakub Hrozek :
> On Sun, Aug 09, 2015 at 10:23:50AM +0200, Matt . wrote:
>> Hi,
>>
>> Yes that is known for SSSD, but ther
On Sun, Aug 09, 2015 at 10:23:50AM +0200, Matt . wrote:
> Hi,
>
> Yes that is known for SSSD, but there must be another way maybe ?
>
> I wonder what the future is there, as it seems there is non when this
> is not changed I guess.
The future is MIT according to the recent development and commit
Hi,
Yes that is known for SSSD, but there must be another way maybe ?
I wonder what the future is there, as it seems there is non when this
is not changed I guess.
2015-08-09 9:11 GMT+02:00 Jakub Hrozek :
> On Fri, Aug 07, 2015 at 11:49:24PM +0200, Matt . wrote:
>> Hi Alexander,
>>
>> Yes I'm
On Fri, Aug 07, 2015 at 11:49:24PM +0200, Matt . wrote:
> Hi Alexander,
>
> Yes I'm on the same path, but for now I would like to get it working
> on Ubuntu for the time being.
>
> Are you sure Ubuntu is no MIT ? We have discusses that some time ago
> on IRC and it seemed to be that Ubuntu was bu
sions and configuration, and generate SIDs, etc.
>
> I need to update the code in Samba upstream to merge some of ipasam features
> to ldapsam and maybe make it aware of IPA schema/ability to switch using IPA
> schema so that the configuration could be simplified.
> At least authenti
>
> Cheers
>
> Chris
>
>
>
>
>
>
> From: Alexander Bokovoy
> To: Christopher Lamb/Switzerland/IBM@IBMCH
> Cc: "Matt ." , "freeipa-users@redhat.com"
>
> Date: 07.08.2015 23:09
> Subject: Re: [Freeipa-
From: Alexander Bokovoy
To: Christopher Lamb/Switzerland/IBM@IBMCH
Cc: "Matt ." , "freeipa-users@redhat.com"
Date: 07.08.2015 23:09
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
On Thu, 06 Aug 2015, Christopher Lamb wrote
Hi Alexander,
Yes I'm on the same path, but for now I would like to get it working
on Ubuntu for the time being.
Are you sure Ubuntu is no MIT ? We have discusses that some time ago
on IRC and it seemed to be that Ubuntu was build against MIT.
Cheers,
Matt
2015-08-07 23:37 GMT+02:00 Alexander
On Fri, 07 Aug 2015, Matt . wrote:
Hi Alexander,
Yes this is know, but it's not usable yet, at least not on an Ubuntu
Samba server as far as I know ?
If so, maybe you can help us out here to clear this up how to do it.
Sorry, I cannot help you with Ubuntu setup, you need to figure it out
yours
Hi Alexander,
Yes this is know, but it's not usable yet, at least not on an Ubuntu
Samba server as far as I know ?
If so, maybe you can help us out here to clear this up how to do it.
Thanks!
Matt
2015-08-07 23:09 GMT+02:00 Alexander Bokovoy :
> On Thu, 06 Aug 2015, Christopher Lamb wrote:
>>
On Thu, 06 Aug 2015, Christopher Lamb wrote:
Hi Matt
As far as I can make out, there are at least 2 viable Samba / FreeIPA
integration paths.
The route I took is suited where there is no Active Directory involved: In
my case all the Windows, OSX and Linux clients are islands that sit on the
sam
Christopher Lamb/Switzerland/IBM@IBMCH,
> "freeipa-users@redhat.com"
> Date: 06.08.2015 14:42
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> Hi,
>
> OK, this sounds already quite logical, but I'm still refering to
;
>> > Now you have got it going, and the solution is fresh in your mind, how
>> > about adding a How-to page on this solution to the FreeIPA wiki?
>> >
>> > Chris
>> >
>> >
>> >
>> > From: Youenn PIOLET
>> > To:
that sit on
> the
> > same network.
> >
> > The route that Youenn has taken (unless I have got completely the wrong
> end
> > of the stick) requires Active Directory in the architecture.
> >
> > Chris
> >
> >
> >
> > From: "Matt .&quo
quot; type activity, I don't know how fast I
will be.
From: Youenn PIOLET
To: "Matt ."
Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
"freeipa-users@redhat.com"
Date: 06.08.2015 17:16
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth aga
fresh in your mind, how
>> > about adding a How-to page on this solution to the FreeIPA wiki?
>> >
>> > Chris
>> >
>> >
>> >
>> > From: Youenn PIOLET
>> > To: "Matt ."
>> > Cc: Christopher Lamb/Swi
ot;
> > Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
> > "freeipa-users@redhat.com"
> > Date: 05.08.2015 14:51
> > Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
> >
> >
> >
> > Hi guys,
> >
> Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
> "freeipa-users@redhat.com"
> Date: 05.08.2015 14:51
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> Hi guys,
>
> Thank you so much your previous answers.
&g
/IBM@IBMCH,
"freeipa-users@redhat.com"
Date: 05.08.2015 14:51
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Hi guys,
Thank you so much your previous answers.
I realised my SID were stored in ipaNTsecurityidentifier, thanks to
ipa-adtrust-install
.
> >
> > When adding the attribute, the wizard offered me "ipaCustomFields" as
> > attribute type in a drop down list.
> >
> > Once we get this cracked, we really must write a how-to on the FreeIPA
> > Wiki.
> >
> > Chris
>
pe in a drop down list.
>
> Once we get this cracked, we really must write a how-to on the FreeIPA
> Wiki.
>
> Chris
>
>
>
> From: Christopher Lamb/Switzerland/IBM@IBMCH
> To: "Matt ."
> Cc: "freeipa-users@redhat.com"
> Date: 05.08
.
Once we get this cracked, we really must write a how-to on the FreeIPA
Wiki.
Chris
From: Christopher Lamb/Switzerland/IBM@IBMCH
To: "Matt ."
Cc: "freeipa-users@redhat.com"
Date: 05.08.2015 07:31
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth again
-Y GSSAPI <
To: Christopher Lamb/Switzerland/IBM@IBMCH
Cc: Youenn PIOLET , "freeipa-users@redhat.com"
Date: 05.08.2015 01:01
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Hi Chris,
I'm at the right path, but my issue is th
nsions missing on new users / groups?
>
> Cheers
>
> Chris
>
>
>
>
>
> From: Youenn PIOLET
> To: "Matt ."
> Cc: Christopher Lamb/Switzerland/IBM@IBMCH,
> "freeipa-users@redhat.com"
> Date: 04.08.2015 18:56
> S
>
> Chris
>
>
>
>
> From: "Matt ."
> To: Christopher Lamb/Switzerland/IBM@IBMCH
> Cc: "freeipa-users@redhat.com"
> Date: 04.08.2015 15:33
> Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against
IPA
; not need to do anything like that.
> >
> > Chris
> >
> >
> >
> >
> > From: "Matt ."
> > To: Christopher Lamb/Switzerland/IBM@IBMCH
> > Cc: "freeipa-users@redhat.com"
> > Date: 04.08.2015 15:33
> >
like that.
>
> Chris
>
>
>
>
> From: "Matt ."
> To: Christopher Lamb/Switzerland/IBM@IBMCH
> Cc: "freeipa-users@redhat.com"
> Date: 04.08.2015 15:33
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
&g
att ."
To: Christopher Lamb/Switzerland/IBM@IBMCH
Cc: "freeipa-users@redhat.com"
Date: 04.08.2015 15:33
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Hi Chris,
A puppet run added another passdb backend, that was causing my issue.
What I sti
ot;
> To: Christopher Lamb/Switzerland/IBM@IBMCH
> Cc: "freeipa-users@redhat.com"
> Date: 04.08.2015 13:32
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
>
>
>
> Hi Chris,
>
> Thanks for the heads up, indeed local is 4 I see
3:20 GMT+02:00 Christopher Lamb
:
>>> HI Matt
>>>
>>> It looks like I skipped that step ... (And as we already had samba
groups
>>> in place, did not need to make new ones via the WebUI).
>>>
>>> However a quick google trawled up this old thread th
Unit Share
>> path = /samba/junit
>> browseable = no
>> valid users = @smb-junit
>> write list = @smb-junit
>> force group = smb-junit
>> create mask = 0770
>>
>>
>> Ciao
>>
>> Chris
&g
etr
Vobornik
Date: 03.08.2015 16:03
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Hi,
OK, I have a Samba Group Type now in my groups details list and also
in the groups settings tab.
I'm not 100% how this is managed. I have Grouptype 4, in the groups
ov
omFields
>>>> ipaCustomFields: "Samba Group Type,sambagrouptype,true"
>>>> EOF
>>> SASL/GSSAPI authentication started
>>> SASL username: l...@my.silly.example.com
>>> SASL SSF: 56
>>> SASL data security layer installed.
>>> adding new
/freeipa-users/2014-May/msg00137.html
Chris
From: "Matt ."
To:
Cc: "freeipa-users@redhat.com"
Date: 03.08.2015 12:45
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Sent by:freeipa-users-boun...@redhat.com
In my previous reply, I
g,cn=etc,dc=my,dc=silly,dc=example,dc=com"
>> ldap_add: Already exists (68)
>>
>> Chris
>>
>>
>>
>>
>> From: "Matt ."
>> To:
>> Cc: "freeipa-users@redhat.com"
>> Date: 02.08.2015 13:33
>&g
alled.
> adding new entry "cn=ipaconfig,cn=etc,dc=my,dc=silly,dc=example,dc=com"
> ldap_add: Already exists (68)
>
> Chris
>
>
>
>
> From: "Matt ."
> To:
> Cc: "freeipa-users@redhat.com"
> Date: 02.08.2015 13:33
> Subject:
t;cn=ipaconfig,cn=etc,dc=my,dc=silly,dc=example,dc=com"
ldap_add: Already exists (68)
Chris
From: "Matt ."
To:
Cc: "freeipa-users@redhat.com"
Date: 02.08.2015 13:33
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Sent by:fr
find any notes from the time we did the
integration.
Chris
From: "Matt ."
To:
Cc: "freeipa-users@redhat.com"
Date: 02.08.2015 13:33
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Sent by:freeipa-users-boun...@redhat.com
Chris,
Are
ise what is going on and to verify
>> if your changes are present! (and is sometime easier to manually change
>> attributes rather than by LDAPMODIFY script)
>>
>> There is another ongoing thread in this mailing list about problems with
>> the attribute SambaPwdL
e SambaPwdLastSet.
>
> Chris
>
>
>
> From: "Matt ."
> To:
> Cc: "freeipa-users@redhat.com"
> Date: 31.07.2015 16:58
> Subject:Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
> Sent by:freeipa-users-boun...@redhat.com
>
list about problems with
the attribute SambaPwdLastSet.
Chris
From: "Matt ."
To:
Cc: "freeipa-users@redhat.com"
Date: 31.07.2015 16:58
Subject: Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA
Sent by:freeipa-users-boun...@redhat.com
Hi,
On (31/07/15 18:15), Matt . wrote:
>Hi Lucas,
>
>Thank you for this reply.
>
>In this case it simply should work as it shoul by creating the
>symlinks, Or are there other issues we might get ?
>
1st problem: current samba version of libwbclient need to be moved ot other
place.
2nd problem: manualy
Hi Lucas,
Thank you for this reply.
In this case it simply should work as it shoul by creating the
symlinks, Or are there other issues we might get ?
Thanks,
Matt
2015-07-31 17:21 GMT+02:00 Lukas Slebodnik :
> On (31/07/15 16:03), Matt . wrote:
>>Hi Guys,
>>
>>I'm really struggeling getting a
On (31/07/15 16:03), Matt . wrote:
>Hi Guys,
>
>I'm really struggeling getting a NON AD Samba server authing against a
>FreeIPA server:
>
>Ubuntu 14.04 -> Samba (no AD) / SSD 1.12.5
>CentOS 7.1 -> FreeIPA 4.1
>
>Now this seems to be the way:
>
>https://www.freeipa.org/page/Howto/Integrating_a_Samba
en trying to connect to a share. Once the password is reset (via
> CLI or FreeIPA WebUi), they can access the shares again.
>
> Chris
>
>
>
> From: Youenn PIOLET
> To: "Matt ."
> Cc: "freeipa-users@redhat.com"
> Date: 31.07.2015
word is not
accepted when trying to connect to a share. Once the password is reset (via
CLI or FreeIPA WebUi), they can access the shares again.
Chris
From: Youenn PIOLET
To: "Matt ."
Cc: "freeipa-users@redhat.com"
Date: 31.07.2015 16:21
Subject: Re:
Hi,
I asked the very same question a few weeks ago, but no answer yet.
http://comments.gmane.org/gmane.linux.redhat.freeipa.user/18174
The only method I see is to install samba extensions in FreeIPA's LDAP
directory, and bind samba with LDAP. There may be a lot of difficulties
with password manage
Hi Guys,
I'm really struggeling getting a NON AD Samba server authing against a
FreeIPA server:
Ubuntu 14.04 -> Samba (no AD) / SSD 1.12.5
CentOS 7.1 -> FreeIPA 4.1
Now this seems to be the way:
https://www.freeipa.org/page/Howto/Integrating_a_Samba_File_Server_With_IPA
But as this, which I al
63 matches
Mail list logo