[Samba] script on user add

2013-06-30 Thread Vladimir A Fomkin
Hi all!
How to set up execution of my script on user adding in AD Samba 4?

-- 
С уважением,
Фомкин Владимир Андреевич
ICQ:220967838
Skype:vladimir.fomkin
http://vaf.net.ru
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Re: [Samba] problem over vpn

2013-06-30 Thread Daniel Müller
Using openvpn in bridge mode and you are up and running! No cisco would
serve the same job.

Greetings
Daniel

---
EDV Daniel Müller

Leitung EDV
Tropenklinik Paul-Lechler-Krankenhaus
Paul-Lechler-Str. 24
72076 Tübingen

Tel.: 07071/206-463, Fax: 07071/206-499
eMail: muel...@tropenklinik.de
Internet: www.tropenklinik.de
---
-Ursprüngliche Nachricht-
Von: samba-boun...@lists.samba.org [mailto:samba-boun...@lists.samba.org] Im
Auftrag von "David González Herrera - [DGHVoIP]"
Gesendet: Dienstag, 25. Juni 2013 17:23
An: Roberto Scattini
Cc: samba@lists.samba.org
Betreff: Re: [Samba] problem over vpn

On 6/25/2013 10:12 AM, Roberto Scattini wrote:
> hi david,
>
>
> On Tue, Jun 25, 2013 at 12:06 PM, "David González Herrera - [DGHVoIP]" 
> < i...@dghvoip.com> wrote:
>
>>   On 6/25/2013 9:58 AM, Roberto Scattini wrote:
>>
>> hi all,
>>
>> i have a Samba version 3.2.5 server running in a debian 5.0.8 (a 
>> little old, i know...).
>>
>> the network setup is:
>>
>> -one local office using samba
>> -one remote office (we call it cberg) using samba remotely over a vpn
>> (linksys-cisco)
>>
>>   Here's you problem don't use cisco.
>>
>>   -another remote office (we call it colon) using samba remotely over 
>> a vpn
>> (linksys-cisco)
>>
>>   Another problem
>>
> ok, that's beyond my possibilities... :-(
No problem that was just a practical joke, just make sure that the
interfaces samba listens on do include your VPN interface if you're using
routing  on the VPN and that port forward is properly configured and the
router advertises the VPN routes to client computers.
>>   I would recommend using wireshark to capture the packets and verify 
>> proper routing, also make sure that samba is starting after the VPN 
>> link is up so it's listening on the proper interface.
>>
> i do have the traffic capture on both ends, where i can upload them?
Well, I wouldn't know what to do with the capture because I'm no expert
reading that but there's lots of gurus here so they might guide you further.

Cheers.
>
> thanks
>
>


--
David Gonzalez
DGHVoIP
USA:
MOBILE: +1.646.559.6200
COL: +57.1.382.6718
COL: +57.4.247.0985
URL: www.dghvoip.com
Skype: davidgonzalezh
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Samba + Winbind ID Mapping Issue

2013-06-30 Thread Andrew Brunton
Hi Everyone,

Not sure if this is the correct place to be asking this but here goes:

We currently are using Samba 3.5.x and Winbind to do ID mapping for our
Active Directory environment. We are currently experiencing an issue where
new users/computers/groups created in the domain, occasionally but not
always will take the UID of someone that already exists. It is important to
note that both the new user and old will have the same UID; this results in
neither user being able to access those files.

We are looking at moving the idmap range in the smb config to a range
outside of what has already been assigned; will this affect users already
in our tdb (database).

Regards

-- 
ANDREW B 
Bundaberg Regional Council
PO Box 3130
Bundaberg QLD 4670
Tel: 1300 883 699
Fax: (07) 4150 5410
http://bundaberg.qld.gov.au/
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] unix password sync doesnt work

2013-06-30 Thread Krzysztof Szarlej
Did you  solve this? Are you using different (older) version of samba?


2013/6/30 Björn JACKE 

> On 2013-06-30 at 11:39 +0200 Krzysztof Szarlej sent off:
> > Hi I am struggling with samba password syncing. Everything works fine but
> > this syncing. It simply doesnt work, I was setting it according to
> > different tutorials aswell as samba docs.
> >
> >
> > My [global] in smb.conf looks as follows I have been changing passwd chat
> > directive to passwd chat = New*password: %n\n Retype*new*password: %n\n
> > passwd:*all*authentication*tokens*updated*successfully  but also it didnt
> > work.
> >
> > [global]
> > workgroup = WORKGROUP
> > security = user
> > map to guest = bad user
> > unix password sync = yes
> > passwd program = /usr/bin/passwd %u
>
> sorry, the "password program" parameter is not usable curently. Have a
> look at
> https://bugzilla.samba.org/show_bug.cgi?id=8299 - maybe this is your
> issue,
> too.
>
> Björn
>
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] unix password sync doesnt work

2013-06-30 Thread Björn JACKE
On 2013-06-30 at 11:39 +0200 Krzysztof Szarlej sent off:
> Hi I am struggling with samba password syncing. Everything works fine but
> this syncing. It simply doesnt work, I was setting it according to
> different tutorials aswell as samba docs.
> 
> 
> My [global] in smb.conf looks as follows I have been changing passwd chat
> directive to passwd chat = New*password: %n\n Retype*new*password: %n\n
> passwd:*all*authentication*tokens*updated*successfully  but also it didnt
> work.
> 
> [global]
> workgroup = WORKGROUP
> security = user
> map to guest = bad user
> unix password sync = yes
> passwd program = /usr/bin/passwd %u

sorry, the "password program" parameter is not usable curently. Have a look at
https://bugzilla.samba.org/show_bug.cgi?id=8299 - maybe this is your issue,
too.

Björn
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] samba4 pdc: Import sudoers active directory schema to ldb

2013-06-30 Thread george Nopicture


> Date: Sun, 30 Jun 2013 06:49:26 +0200
> From: g...@kzsdabas.hu
> To: samba@lists.samba.org; mad-proffes...@hotmail.com
> CC: samba-techni...@lists.samba.org
> Subject: Re: [Samba] samba4 pdc: Import sudoers active directory schema to ldb
> 
> 2013-06-29 11:00 keltezéssel, george Nopicture írta:
> > Hi guys and congrats for bringing a fantastic project to the open source 
> > world. I' ve setup a samba4 pdc succefully and i am able to do domain 
> > logins. I was also able to add the automount schema into the ldb. But when 
> > it comes to sudoers schema i cant import it in.
> > Further system details:
> > Debian wheezy 7,
> > samba 4.0.6 compiled from source,
> > sudo-ldap standard binary package from repos.
> > I have split the sudoers active directory schema that came with sudo to 2 
> > ldifs(classSchema apart from attributeSchema) and tried to import them in 
> > but  i had no luck. I googled around but came up nothing about it.
> > This is the error i get:
> > ERR: (Invalid attribute syntax) "LDAP error 21 
> > LDAP_INVALID_ATTRIBUTE_SYNTAX -  <200B: objectclass_attrs: attribute 
> > 'mayContain' on entry 
> > 'CN=sudoRole,CN=Schema,CN=Configuration,DC=example,DC=com' contains at 
> > least one invalid value!> <>" on DN 
> > CN=sudoRole,CN=Schema,CN=Configuration,DC=example,DC=com at block before 
> > line 31.
> >   
> > 
> First: I've cc-ed samba-technical as extending the schema is still an 
> experimental feature.
> Second: it would be helpful to be able to look at the ldif files you try 
> to load (messages like block before line 31 doesn't make too much sense 
> without it)
> 
> Regards
> 
> Geza Gemes

Hello, it appears that i have directly sent you some emails at your 
personal email address, sorry for that.I am attaching the 2 files for the list 
and i am 
also posting their contents here.

sudoers-class.ldif:

dn: CN=sudoRole,CN=Schema,CN=Configuration,DC=example,DC=com
objectClass: top
objectClass: classSchema
cn: sudoRole
distinguishedName: CN=sudoRole,CN=Schema,CN=Configuration,DC=example,DC=com
instanceType: 4
possSuperiors: container
possSuperiors: top
subClassOf: top
governsID: 1.3.6.1.4.1.15953.9.2.1
mayContain: sudoUser
mayContain: sudoHost
mayContain: sudoCommand
mayContain: sudoRunAs
mayContain: sudoOption
mayContain: sudoRunAsUser
mayContain: sudoRunAsGroup
mayContain: sudoNotBefore
mayContain: sudoNotAfter
mayContain: sudoOrder
rDNAttID: cn
showInAdvancedViewOnly: FALSE
adminDisplayName: sudoRole
adminDescription: Sudoer Entries
objectClassCategory: 1
lDAPDisplayName: sudoRole
name: sudoRole
schemaIDGUID:: SQn432lnZ0+ukbdh3+gN3w==
systemOnly: FALSE
objectCategory: CN=Class-Schema,CN=Schema,CN=Configuration,DC=example,DC=com
defaultObjectCategory: CN=sudoRole,CN=Schema,CN=Configuration,DC=example,DC=com


sudoers.ldif

dn: CN=sudoUser,CN=Schema,CN=Configuration,DC=example,DC=com
objectClass: top
objectClass: attributeSchema
cn: sudoUser
distinguishedName: CN=sudoUser,CN=Schema,CN=Configuration,DC=example,DC=com
instanceType: 4
attributeID: 1.3.6.1.4.1.15953.9.1.1
attributeSyntax: 2.5.5.5
isSingleValued: FALSE
showInAdvancedViewOnly: TRUE
adminDisplayName: sudoUser
adminDescription: User(s) who may run sudo
oMSyntax: 22
searchFlags: 1
lDAPDisplayName: sudoUser
name: sudoUser
schemaIDGUID:: JrGcaKpnoU+0s+HgeFjAbg==
objectCategory: CN=Attribute-Schema,CN=Schema,CN=Configuration,DC=example,DC=com

dn: CN=sudoHost,CN=Schema,CN=Configuration,DC=example,DC=com
objectClass: top
objectClass: attributeSchema
cn: sudoHost
distinguishedName: CN=sudoHost,CN=Schema,CN=Configuration,DC=example,DC=com
instanceType: 4
attributeID: 1.3.6.1.4.1.15953.9.1.2
attributeSyntax: 2.5.5.5
isSingleValued: FALSE
showInAdvancedViewOnly: TRUE
adminDisplayName: sudoHost
adminDescription: Host(s) who may run sudo
oMSyntax: 22
lDAPDisplayName: sudoHost
name: sudoHost
schemaIDGUID:: d0TTjg+Y6U28g/Y+ns2k4w==
objectCategory: CN=Attribute-Schema,CN=Schema,CN=Configuration,DC=example,DC=com

dn: CN=sudoCommand,CN=Schema,CN=Configuration,DC=example,DC=com
objectClass: top
objectClass: attributeSchema
cn: sudoCommand
distinguishedName: CN=sudoCommand,CN=Schema,CN=Configuration,DC=example,DC=com
instanceType: 4
attributeID: 1.3.6.1.4.1.15953.9.1.3
attributeSyntax: 2.5.5.5
isSingleValued: FALSE
showInAdvancedViewOnly: TRUE
adminDisplayName: sudoCommand
adminDescription: Command(s) to be executed by sudo
oMSyntax: 22
lDAPDisplayName: sudoCommand
name: sudoCommand
schemaIDGUID:: D6QR4P5UyUen3RGYJCHCPg==
objectCategory: CN=Attribute-Schema,CN=Schema,CN=Configuration,DC=example,DC=com

dn: CN=sudoRunAs,CN=Schema,CN=Configuration,DC=example,DC=com
objectClass: top
objectClass: attributeSchema
cn: sudoRunAs
distinguishedName: CN=sudoRunAs,CN=Schema,CN=Configuration,DC=example,DC=com
instanceType: 4
attributeID: 1.3.6.1.4.1.15953.9.1.4
attributeSyntax: 2.5.5.5
isSingleValued: FALSE
showInAdvancedViewOnly: TRUE
adminDisplayName: sudoRunAs
adminDescription: User(s) impersonated by sudo (de

[Samba] unix password sync doesnt work

2013-06-30 Thread Krzysztof Szarlej
Hi I am struggling with samba password syncing. Everything works fine but
this syncing. It simply doesnt work, I was setting it according to
different tutorials aswell as samba docs.


My [global] in smb.conf looks as follows I have been changing passwd chat
directive to passwd chat = New*password: %n\n Retype*new*password: %n\n
passwd:*all*authentication*tokens*updated*successfully  but also it didnt
work.

[global]
workgroup = WORKGROUP
security = user
map to guest = bad user
unix password sync = yes
passwd program = /usr/bin/passwd %u
passwd chat = *New password* %n\n *new password* %n\n *success*
debug level = 100
passwd chat debug = yes

 I am running Samba 3.6.9 on Centos 6.4
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] unix password sync doesnt work

2013-06-30 Thread Krzysztof Szarlej
Hi I am struggling with unix password sync. My samba works good but it
cannot sync the password .

My [global] look as follows:
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba