[Samba] [problem for] compile Samba + Mysql (pdbsql)

2007-12-31 Thread Frédéric Notet

Hi everybody !

First, sorry for my bad english...

I try to compile my samba with mysql backend but i have a problem with  
the compil of pdbsql  (on a Debian ETCH installation)


Let's see what i did :


(The Bold lignes are the return error message that i have)


Thanks for you help...


1° installer outils de compilation et de subversion :

- aptitude install dpkg-dev

- aptitude install subversion

2° aller dans le répertoire /tmb

- cd /tmp

3° download des sources de samba :

- apt-get source samba

4° récupérer sources de pdbsql :

- wget 
http://kent.dl.sourceforge.net/sourceforge/pdbsql/pdbsql-0.2-samba-3.0.23.tar.bz2

- tar xvjf pdbsql-0.2-samba-3.0.23.tar.bz2

5° récupérer les dépendances de Samba :

- apt-get build-dep samba

6° je commence la compilation :

- cd samba-3.0.24/

- debian/rules configure-stamp

- cd source

- make proto

7° compiler pdbsql

- cd ../../pdbsql-0.2-samba-3.0.23

- ./configure --with-samba-source=../samba-3.0.24/source/

( = checking for Samba source directory... configure: error: smbd not  
found, please specify --with-samba-dir)


- ./configure --with-samba-source=../samba-3.0.24/source/ --with-samba- 
dir=../samba-3.0.24/source/


(= configure: WARNING: Can't find MySQL libraries, not building  
pdb_mysql)


- ./configure --with-samba-source=../samba-3.0.24/source/ --with-samba- 
dir=../samba-3.0.24/source/ --with-mysql-prefix=/usr/bin/mysql


(= checking for mysql_config... /usr/bin/mysql/bin/mysql_config
checking for MYSQL... ./configure: line 2512: /usr/bin/mysql/bin/ 
mysql_config: Not a directory

./configure: line 2513: /usr/bin/mysql/bin/mysql_config: Not a directory
yes
)

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba Problem

2007-12-31 Thread Sven Buchstaller
Hi List,

Last week i have upgrate my samba from 3.023d to 3.0.28 and now i have
some trouble in my LOGs like this:

Dec 31 08:59:23 ldapmaster smbd[10453]:
pdb_increment_bad_password_count: pdb_get_account_policy failed.
Dec 31 08:59:39 ldapmaster smbd[12758]: [2007/12/31 08:59:39, 0,
effective(0, 0), real(0, 0)] passdb/pdb_get_set.c:pdb_get_group_sid(211)
Dec 31 08:59:39 ldapmaster smbd[12758]:   pdb_get_group_sid: Failed to
find Unix account for pcoc081$
Dec 31 09:02:53 ldapmaster smbd[12836]: [2007/12/31 09:02:53, 0,
effective(0, 0), real(0, 0)] passdb/pdb_get_set.c:pdb_get_group_sid(211)
Dec 31 09:02:53 ldapmaster smbd[12836]:   pdb_get_group_sid: Failed to
find Unix account for application1$
Dec 31 09:02:53 ldapmaster smbd[12836]: [2007/12/31 09:02:53, 0,
effective(0, 0), real(0, 0)] passdb/pdb_get_set.c:pdb_get_group_sid(211)
Dec 31 09:02:53 ldapmaster smbd[12836]:   pdb_get_group_sid: Failed to
find Unix account for application1$
Dec 31 09:02:53 ldapmaster smbd[12836]: [2007/12/31 09:02:53, 0,
effective(0, 0), real(0, 0)] passdb/pdb_get_set.c:pdb_get_group_sid(211)
Dec 31 09:02:53 ldapmaster smbd[12836]:   pdb_get_group_sid: Failed to
find Unix account for application1$
Dec 31 09:02:53 ldapmaster smbd[12836]: [2007/12/31 09:02:53, 0,
effective(0, 0), real(0, 0)] passdb/pdb_get_set.c:pdb_get_group_sid(211)
Dec 31 09:02:53 ldapmaster smbd[12836]:   pdb_get_group_sid: Failed to
find Unix account for application1$
Dec 31 09:02:53 ldapmaster smbd[12836]: [2007/12/31 09:02:53, 0,
effective(10064, 1), real(10064, 0)]
rpc_parse/parse_samr.c:init_sam_u
ser_info21A(6318)
Dec 31 09:02:53 ldapmaster smbd[12836]:   init_sam_user_info_21A: User
application1$ has Primary Group SID (NULL SID),
Dec 31 09:02:53 ldapmaster smbd[12836]:   which conflicts with the
domain sid S-1-5-21-3991578539-3149662252-1894531253.  Failing operation

It looks like only Maschines are involved, anyone an idear?
what can i do ?


.


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Driver installation fails on samba server

2007-12-31 Thread Joachim Kieferle

Dear list,

since days I am trying to install several HP-drivers from a XP client on 
the samba server (DC) - 3.0.28 on OpenSuse 10.3.


Installing the drivers contained in Windows works.
Installing drivers from a disk (e.g. for a Designet 4000) does NOT work. 
It says Driver for Designjet  could not be installed. Access 
denied. It is however creating a directory under W32X86 named 
__SKIP_ (where  are different figures e.g. 00DA).


Linux-permissions at W32X86 are set to 777.
The directory named __SKIP_  is created as drwxrwxr-x root ntadmin 
, so as admin root there should be sufficient access.


Even log level 10 didn't show me any hints. I changed to different 
smb.conf settings, etc.


Did anybody of you experience a similar problem and has a solution?

Best

Joachim






--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba and AD login Problem

2007-12-31 Thread Serbulent UNSAL
Hi All,

I am trying to join an AD domain due to the this (
http://gentoo-wiki.com/HOWTO_Active_Directory_with_Samba_and_Winbind
)  document.

but when i try to add my computer to AD i get these error messages.

haploit srb # net ads join -U Administrator
Administrator's password:
Using short domain name -- ISTANBUL
Failed to set servicePrincipalNames. Please ensure that
the DNS domain of this server matches the AD domain,
Or rejoin with using Domain Admin credentials.
Deleted account for 'HAPLOIT' in realm 'ISTANBUL'
Failed to join domain: Type or value exists

I put some of my config files and logs to web here are the adresses;

http://cekirdek.pardus.org.tr/~serbulent/hosts
http://cekirdek.pardus.org.tr/~serbulent/krb5.conf
http://cekirdek.pardus.org.tr/~serbulent/smb.conf
http://cekirdek.pardus.org.tr/~serbulent/log.smbd
http://cekirdek.pardus.org.tr/~serbulent/log.winbindd
http://cekirdek.pardus.org.tr/~serbulent/log.winbindd

Do any one have any ideas ? Thanx a lot.

PS: Happy new year to all :)

Serbulent
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Samba and AD login Problem

2007-12-31 Thread Volker Lendecke
On Mon, Dec 31, 2007 at 04:41:16PM +0200, Serbulent UNSAL wrote:
 I am trying to join an AD domain due to the this (
 http://gentoo-wiki.com/HOWTO_Active_Directory_with_Samba_and_Winbind
 )  document.
 
 but when i try to add my computer to AD i get these error messages.
 
 haploit srb # net ads join -U Administrator
 Administrator's password:
 Using short domain name -- ISTANBUL
 Failed to set servicePrincipalNames. Please ensure that
 the DNS domain of this server matches the AD domain,
 Or rejoin with using Domain Admin credentials.
 Deleted account for 'HAPLOIT' in realm 'ISTANBUL'
 Failed to join domain: Type or value exists
 
Make sure that the fully qualified domain name and your host
name differ in the sense that you actually have a domain
appended.

Under Linux, hostname and hostname -f need to return
different things, hostname -f should preferrably show your
AD domain name appended.

Volker


pgp4Jrx5Qwn2r.pgp
Description: PGP signature
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Re: [Samba] Samba and AD login Problem

2007-12-31 Thread Chad
On Dec 31, 2007 7:59 AM, Volker Lendecke [EMAIL PROTECTED] wrote:
 On Mon, Dec 31, 2007 at 04:41:16PM +0200, Serbulent UNSAL wrote:
  I am trying to join an AD domain due to the this (
  http://gentoo-wiki.com/HOWTO_Active_Directory_with_Samba_and_Winbind
  )  document.
 
  but when i try to add my computer to AD i get these error messages.
 
  haploit srb # net ads join -U Administrator
  Administrator's password:
  Using short domain name -- ISTANBUL
  Failed to set servicePrincipalNames. Please ensure that
  the DNS domain of this server matches the AD domain,
  Or rejoin with using Domain Admin credentials.
  Deleted account for 'HAPLOIT' in realm 'ISTANBUL'
  Failed to join domain: Type or value exists

 Make sure that the fully qualified domain name and your host
 name differ in the sense that you actually have a domain
 appended.

 Under Linux, hostname and hostname -f need to return
 different things, hostname -f should preferrably show your
 AD domain name appended.

 Volker

In addition, make sure that Administrator is your Domain Admin.  I
used my Domain Admin account (an actual account not Administrator) and
it worked great.  Also a piece of information that seems to be
floating around is that the krb5.conf doesn't need to exist and may
actually cause problems if configured incorrectly.  Samba will get the
Kerberos info from AD if it's configured correctly.

-Chad
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] HTTP authentication

2007-12-31 Thread Tero Mäntyvaara
Hi

Is it possible to authenticate at WWW page/site by Samba server?


Tero Mäntyvaara
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] HTTP authentication

2007-12-31 Thread Aaron J. Zirbes
Google: ntlm_auth

Tero Mäntyvaara wrote:
 Hi
 
 Is it possible to authenticate at WWW page/site by Samba server?
 
 
 Tero Mäntyvaara
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] HTTP authentication

2007-12-31 Thread Greg Byshenk
On Mon, Dec 31, 2007 at 11:02:05PM +0200, Tero M?ntyvaara wrote:
 
 Is it possible to authenticate at WWW page/site by Samba server?

Assuming you mean using a Samba DC as an authentication backend for
Apache... (and with the caveat that I've never used these modules), then
I think the answer is problably yes.

Check out mod_ntlm http://modntlm.sourceforge.net/ or auth_ldap
http://www.rudedog.org/auth_ldap/ (and there may be other options, as
well).

-- 
greg byshenk  -  [EMAIL PROTECTED]  -  Leiden, NL
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] idmap_nss: Default domain not being used

2007-12-31 Thread Patrick Rynhart
I have an existing PDC which I am attempting to move across to a new
server.  On the new server, I'm having trouble with idmap (using an LDAP
backend) and trusted domains.  The smb.conf file is the same on both
servers.  My idmap  winbind parameters are as follows:

ldap idmap suffix = ou=idmap
idmap backend = ldap:ldap://127.0.0.1
idmap uid = 1-29000
idmap gid = 1-29000
winbind use default domain = yes
winbind enum users = yes
winbind enum groups = yes

On the new box, 'wbinfo -t' suceeds and I can list users and groups on
the foreign domain using 'wbinfo -u' and 'wbinfo -g'.  'net rpc trustdom
list' lists the trusted domain.

Comparing the winbind debug logs of the existing and new PDC, I have
discovered that the cruical difference appears to be the following line
(which is missing on the new PDC)

SID S-1-5-21-15318837-110984162-118601546-6958 is being handled by
default domain

On the new server I get:


[ 3008]: lookupsid S-1-5-21-15318837-110984162-118601546-6958
refresh_sequence_number: IIST time ok
refresh_sequence_number: IIST seq number is now 60700
centry_expired: Key U/S-1-5-21-15318837-110984162-118601546-6958 for
domain IIST is good.
wcache_fetch: returning entry
U/S-1-5-21-15318837-110984162-118601546-6958 for domain IIST
query_user: [Cached] - cached info for domain IIST status: NT_STATUS_OK
Storing response for pid 3030, len 3240
Destroying timed event 99b8b28 async_request_timeout
Retrieving response for pid 3030
timed_events_timeout: 215/946559
Added timed event async_request_timeout: 99b8b28
timed_events_timeout: 215/946536
child daemon request 48
process_request: request fn DUAL_SID2UID
[ 3008]: sid to uid S-1-5-21-15318837-110984162-118601546-6958
idmap_sid_to_uid: sid = [S-1-5-21-15318837-110984162-118601546-6958]
Query backends to map sids-ids
Could not find idmap backend for SID
S-1-5-21-15318837-110984162-118601546-6958Adding cache entry with key =
IDMAP/SID/S-1-5-21-15318837-110984162-118601546-6958; value =
1198915597/IDMAP/NEGATIVE and timeout = Sat Dec 29 21:06:37 2007
 (120 seconds ahead)
sid [S-1-5-21-15318837-110984162-118601546-6958] not mapped to an uid
[2,1,2683630]
Storing response for pid 3021, len 3240
Destroying timed event 99b8b28 async_request_timeout
Retrieving response for pid 3021
sid2uid returned an error
Could not query uid for user IIST\prynhart

On the existing (working) server I get:
---

idmap_sid_to_uid: sid = [S-1-5-21-15318837-110984162-118601546-6958]
Cache entry with key =
IDMAP/SID/S-1-5-21-15318837-110984162-118601546-6958 couldn't be found
Query backends to map sids-ids
SID S-1-5-21-15318837-110984162-118601546-6958 is being handled by
default domain
Query ids from domain default domain
Filter:
[((objectClass=sambaIdmapEntry)(sambaSID=S-1-5-21-15318837-110984162-118601546-6958))]
smbldap_search_ext: base = [ou=idmap,dc=ist,dc=massey,dc=ac,dc=nz],
filter =
[((objectClass=sambaIdmapEntry)(sambaSID=S-1-5-21-15318837-110984162-118601546-6958))],
scope = [2]
NO SIDs found
Search of the id pool (filter: (objectClass=sambaUnixIdPool))
smbldap_search_ext: base = [ou=idmap,dc=ist,dc=massey,dc=ac,dc=nz],
filter = [(objectClass=sambaUnixIdPool)], scope = [2]
Try to atomically increment the id (10734 - 10735)
smbldap_modify: dn = [ou=idmap,dc=ist,dc=massey,dc=ac,dc=nz]
Setting mapping: S-1-5-21-15318837-110984162-118601546-6958 - UID 10734
smbldap_make_mod: adding attribute |uidNumber| value |10734|
smbldap_make_mod: adding attribute |sambaSID| value
|S-1-5-21-15318837-110984162-118601546-6958|
Set DN
sambaSID=S-1-5-21-15318837-110984162-118601546-6958,ou=idmap,dc=ist,dc=massey,dc=ac,dc=nz
(S-1-5-21-15318837-110984162-118601546-6958 - 10734)
smbldap_add: dn =
[sambaSID=S-1-5-21-15318837-110984162-118601546-6958,ou=idmap,dc=ist,dc=massey,dc=ac,dc=nz]
ldap_set_mapping: Successfully created mapping from
S-1-5-21-15318837-110984162-118601546-6958 to 10734 [uidNumber]
Adding cache entry with key =
IDMAP/SID/S-1-5-21-15318837-110984162-118601546-6958; value =
1199090322/IDMAP/UID/10734 and timeout = Mon Dec 31 21:38:42 2007
 (900 seconds ahead)

And the authentication suceeds.

net getlocalsid gives the correct SID on the new server.

Could anyone please advise/assist ?

Thank you,

Patrick

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Upgrade from SLES9 3.0.20 to 3.0.26a breaks getent

2007-12-31 Thread bdehn

All -

This evening I attempted to catch up on security releases and upgraded from
SLES9 3.0.20 to 3.0.26a and found that getent only returns local UNIX
groups and users. We are using winbind to communicate with an NT domain.
The server has been restarted and services are running. Using wbinfo -u and
-g does provide NT domain groups and users as expected and net rpc testjoin
result is OK. I have checked config files and they appear OK. What have I
missed?


Bob Dehn

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Build status as of Tue Jan 1 00:00:02 2008

2007-12-31 Thread build
URL: http://build.samba.org/

--- /home/build/master/cache/broken_results.txt.old 2007-12-31 
00:00:34.0 +
+++ /home/build/master/cache/broken_results.txt 2008-01-01 00:00:54.0 
+
@@ -1,4 +1,4 @@
-Build status as of Mon Dec 31 00:00:02 2007
+Build status as of Tue Jan  1 00:00:02 2008
 
 Build counts:
 Tree Total  Broken Panic 
@@ -13,13 +13,13 @@
 pidl 16 4  0 
 ppp  9  7  0 
 python   0  0  0 
-rsync25 10 0 
+rsync25 8  0 
 samba-docs   0  0  0 
 samba-gtk3  3  0 
 samba4   22 14 2 
 samba_3_21  0  0 
-samba_3_2_test 23 9  0 
+samba_3_2_test 23 10 0 
 smb-build23 3  0 
 talloc   25 5  0 
-tdb  25 3  0 
+tdb  24 3  0 
 


svn commit: samba r26635 - in branches/SAMBA_4_0/source/setup: .

2007-12-31 Thread abartlet
Author: abartlet
Date: 2008-01-01 03:27:53 + (Tue, 01 Jan 2008)
New Revision: 26635

WebSVN: 
http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=26635

Log:
The OpenLDAP folks have been very accommodating, and their memberof plugin 
allows the error being returned to be adjusted.

Andrew Bartlett

Modified:
   branches/SAMBA_4_0/source/setup/provision-backend


Changeset:
Modified: branches/SAMBA_4_0/source/setup/provision-backend
===
--- branches/SAMBA_4_0/source/setup/provision-backend   2007-12-30 19:18:17 UTC 
(rev 26634)
+++ branches/SAMBA_4_0/source/setup/provision-backend   2008-01-01 03:27:53 UTC 
(rev 26635)
@@ -161,6 +161,7 @@
 memberof-group-oc top
 memberof-member-ad  + res.msgs[i].lDAPDisplayName + 
 memberof-memberof-ad  + target + 
+memberof-dangling-error 32
 
 ;
}



svn commit: samba r26636 - in branches/SAMBA_4_0/source/setup: .

2007-12-31 Thread abartlet
Author: abartlet
Date: 2008-01-01 04:01:07 + (Tue, 01 Jan 2008)
New Revision: 26636

WebSVN: 
http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=26636

Log:
Remove useless 'backend' parameter, and make the memberof overlay use global.

Andrew Bartlett

Modified:
   branches/SAMBA_4_0/source/setup/slapd.conf


Changeset:
Modified: branches/SAMBA_4_0/source/setup/slapd.conf
===
--- branches/SAMBA_4_0/source/setup/slapd.conf  2008-01-01 03:27:53 UTC (rev 
26635)
+++ branches/SAMBA_4_0/source/setup/slapd.conf  2008-01-01 04:01:07 UTC (rev 
26636)
@@ -21,7 +21,8 @@
 
 defaultsearchbase ${DOMAINDN}
 
-backendhdb
+include ${LDAPDIR}/memberof.conf
+
 databasehdb
 suffix ${SCHEMADN}
 directory  ${LDAPDIR}/db/schema
@@ -74,5 +75,3 @@
 overlay syncprov
 syncprov-checkpoint 100 10
 syncprov-sessionlog 100
-
-include ${LDAPDIR}/memberof.conf