Re: [Samba] posixAccount objectClass
Hi there was a thread Samba 4, Winbind RFC2307 at 26.12.2012 on this list which covers that issue, including a patch from andrew and another fix I provided Regrads Hansjörg -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstraße 10 80335 München Tel: +49-89-52 04 68-41 Fax: +49-89-52 04 68-59 E-Mail: hansjoerg.mau...@itsd.de mailto:hansjoerg.mau...@itsd.de mailto:hansjoerg.mau...@itsd.de mailto:hansjoerg.mau...@itsd.de Web:http://www.itsd.de http://www.itsd.de http://www.itsd.de/ http://www.itsd.de/%3E ; Amtsgericht München HRB 132146 USt-IdNr. DE 812991301 Steuer-Nr. 143/100/81575 Aufsichtsratsvorsitzender: Stefan Adam Vorstand: Dr. Michael Krocka Dr. Hansjörg Maurer -Ursprüngliche Nachricht- Von:Andreas Gaiser/L i...@multifake.net mailto:i...@multifake.net Gesendet: Sam 23 Februar 2013 18:52 An: Samba Mailing List samba@lists.samba.org mailto:samba@lists.samba.org Betreff: Re: [Samba] posixAccount objectClass Hi Thomas, greeting to all readers, Is there something I miss or is this to be considered a bug? If this is the problem I am thinking of, I originally noticed it in 4.0.0. I believe Andrew provided a patch, however I don't need this in my production environment and only stumbled onto the issue while testing something else, so I don't know if what I'm referring to was fixed in later releases. I'll see if I can find the thread and bug shortly. I remember a thread which was about winbind ignoring objects without posixAccount/posixGroup OCs. The conclusion was to change winbind to not ignore them. But, actually, shouldn't S4 in DC mode really add them? Or is ADUC the culprit here? I didn't check out yet how recent Samba 3.6 winbind behaves as a member here. When I tried against 4.0.0 I ended up using Wireshark to analyse LDAP traffic and figured RFC2307 attrs weren't returned by the LDAP server although requested by winbind, whereas they WERE returned to Apache Directory Studio at the same time - logged in as administra...@sub.domain.tld mailto:administra...@sub.domain.tld ; a permission issue I guess. Is this a known issue? I blamed it to poor provisioning (without RFC2307 in the beginning) that day. Will try again this part later this weekend. At the moment, I'm working on a script that adds Unix Attributes automatically to all relevant users (i.e. all that winbind shows on a member. Btw. I would love to have a way to filter them, because most groups I won't ever need and they're gonna make things look complicated on the Unix side. Does anybody know anything about this?). Andreas -- Andreas Gaiser, Berlin, Germany -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba http://www.itsd.de/files/2913/5783/3549/mailfooter.gif itsystems Deutschland AG Sorglos und leise. So geht IT. http://www.itsd.de Kontakt: i...@itsd.de mailto:i...@itsd.de | F: +49 89 520468 40 | Linprunstr. 10 | 80335 München Amtsgericht München HRB 132146 | USt-IdNr. DE 812991301 | Steuer-Nr. 143/100/81575 i Aufsichtsratsvorsitzender: Stefan Adam | Vorstand: Dr. Hansjörg Maurer -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
Re: Still problems with 3.0.9 and AD WAS::Re: [Samba] Problem with lowercase Computernames in winbind samba 3.0.8
Hi, thank you for your reply. It is good to know, that we don't have to use winbind, if we are using users from nis and not from the AD-Domain. I thought there might be a kind of a way to use winbind without let him doing the userid generation and the nss things (as a kind of proxy for including userinformation directly from the MS-Domain to samba) Unfortunatly, switching completly to winbind would not be possible in our heterogenous network (Solaris, IRIX, Linuy, VxWorks...), and using a third (manually generated) database for hostnames (when putting them in passwd) near NIS hosts and DNS would be some work too. As you can see, I am not an expert in SMB things, but would it be reasonable and if so possible to - merge nis and winbind (getting users only from nis passwd database and hosts (only hosts with $ ) from winbind) or - ask winbind directly from samba for a machine name (not going through system nss an back to winbind again) I am sure, the best way for aur situation would be to move to samba and openldap as a pdc instead of W2003. But unfortunatly we are using a Citrix Terminalserverfarm, and I am not sure, if settings like TerminalServerProfilePath (we use) are included in samba. Thank you very much Hansjörg Andrew Bartlett schrieb: On Tue, 2004-11-23 at 14:59 +0100, Hansjoerg Maurer wrote: Hi I reported a problem with samba as a AD-memberserver two weeks ago. If you acess a share with a W2k client (rmts1) the following message appears Username NTROBOTIC\rmts1$ is invalid on this system I get the unix-users from NIS. Do I need winbind (I am running it, and wbinfo -g/u works)? Do I need to adjust nsswitch.conf in order to get the machines appear in getent passwd (I tried it, it works, but it does not solve the problem above and it duplicates usernames (nis+winbindd)) You must either add all your machines to NIS, or use only winbind. Yes, machines can, do and will log in, and they expect this to work. Andrew Bartlett -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
[Samba] Problem with lowercase Computernames in winbind samba 3.0.8
Hi, we have several samba servers running as AD members (w2003 domain). Since the Upgrade to samba 3.0.8 the following message appears, when accessing a share on the memberserver from clienthost rmts2. [2004/11/10 12:09:02, 1] smbd/sesssetup.c:reply_spnego_kerberos(250) Username NTROBOTIC\rmts2$ is invalid on this system [2004/11/10 12:09:02, 1] smbd/sesssetup.c:reply_spnego_kerberos(250) Username NTROBOTIC\rmts2$ is invalid on this system [EMAIL PROTECTED] samba]# wbinfo -u | grep -i rmts2 NTROBOTIC\RMTS2$ Cound that be a case Problem rmts2 ne RMTS2 The share is accessible, but it seems to be very slow, because the message is generated very often. Thank you very much Hansjörg -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] largosh printing patch for Samba 3.0.7
Hi i have tried these Patches on our samba 3.0.7 (Cups 1.20, Solaris 8) installation Here some observations The problem with the queue updated disappeard imediately Our printserver (with netbios name printserver and IP 129.247.189.2) shows the printers as printername at printserver But clients who had connected printers during the time when samba 3.0.7 shows a name like printername at 129.247.189.2 keep this name I am unable to remove the connections to these printers from the client to server as normal user. There is an error like no such printer on printserver, but printing is possible to this printer !!! I don't now, if this is just a wired W2k and XP caching behavior, or if there still is a problem. I noticed, that if I connect some printers after the Patch Update, they still connect as printername at 129.247.189.2 But after renewing the driver on the server (cupsaddsmb) the connection works as printername at printserver Thank you very much Hansjörg Gerald (Jerry) Carter wrote: For anyone interested in testing some printing fixes: I've just uplaoded a moderate sized patch for Samba 3.0.7 that addresses the following bugs: https://bugzilla.samba.org/show_bug.cgi?id=1519 https://bugzilla.samba.org/show_bug.cgi?id=1679 Both fixes have been checked in for incusion in the next 3.0.8 preview release. The patch for 3.0.7 can be found at http://samba.org/~jerry/patches/post-3.0.7/printername_and_queue_update.patch cheers, jerry - Alleviating the pain of Windows(tm) --- http://www.samba.org GnuPG Key- http://www.plainjoe.org/gpg_public.asc If we're adding to the noise, turn off this song--Switchfoot (2003) -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
[Samba] change Active Directory Password with client tools (smbpasswd, net arp) ?
Hi I am trying to change the password of an User in an Active Directory using the samba client tools (samba 3.0.7). A normal user can change the password using smbpasswd -r ADSERVERNAME But now a user forgetts his password, and I want to change it as an user ADMINUSER, who has admin rights in the domain. Is there a command, weher I can do something like this: smbpasswd -r ADSERVERNAME USERNAME -U ADMINUSER The command should print for the ADMINPASSWD of ADMINUSER and for the new passwd of USERNAME, who's passwd has to be reset. net -S ADSERVERNAME -U ADMINUSER rap password USERNAME newpass Does nor work to If I do an ethereal, the answer of ADSERVERNAME is SAMOEMCHANGEPASSWORD (214) Status: the specified password is invalid (86) Is it possible to change a userpasswd as admin with the client tools without knowing the old password Thank you very much -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
[Samba] Problems with administrator entry with uid=0 in Samba-Ldap Backend
Hi, I am running a samba pdc (3.05) with an openldap backend und Linux. I put an Administrator account in it with uid=0 as decriebed in the docs. The ldap server ist a passwd backend for a number of linux clients to with nss_ldap an pam_ldap. On the Linux-Clients (not on the samba-server) we run nscd in order to decrease the number of ldap request eg. when doing an 'ls -l' in a directory with ~1000 files. After some times, 'ls -l' reports, that files, who belong to root, belong to Administrator. It seems, that nscd does not take care about the order passwd: files ldap in /etc/nsswitch.conf resulting in the cached Username-uid pair Administrator-0 instead of root-0. Is there a way to configure Samba/pam.ldap not the use the Administrator account in ldap (for example putting it in a different ou not asked by pam_ldap? Thank you very much Hansjörg -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] 3.0.4: smbd's + nscd's = 100% CPU; load 4
Hi, I had a similiar Problem , and a loglevel of 4 shows , that samba was trying to look up a user nobody and a user Administrator, all the time. If I killed nscd the load of the ldap server becomes high... I added these user to my ldap backend, and the problem disappears. Greetings Hansjörg Dragan Krnic schrieb: the new 3.0.4 Samba installation seems to work fine except that from time to time but at least a couple of times a day one or more smbd processes start running at 20%-40% CPU each and 6 nscd processes then share the remaining CPU power. System 70%-80% users the rest 20%-30%. Load rises fast to over 4. I'm sure that each such process is just idling, but why does it engage so much nscd processing? As soon as I kill the excessive smbd process(es) the situation drops to normal, i.e. load 0,1 no perceptible CPU%. Does anyone know what's happening? What does strace say ? Can you attach with gdb to a CPU bound process and give a backtrace ? Ah backtrace, to see the steps to the black hole? OK. Will do, sooen as I get back to office (tomorrow). A pot watched never boils. But as soon as it happens again, I'll consult strace and gdb to see how and why it happens. It does, when you stop watching. I was away yesterday and what do I see this morning: top - 09:55:35 up 6 days, 17:28, 6 users, load average: 3.59, 3.82, 3.15 Tasks: 182 total, 3 running, 179 sleeping, 0 stopped, 0 zombie Cpu(s): 21.6% user, 78.4% system, 0.0% nice, 0.0% idle Mem: 2060704k total, 2004324k used,56380k free, 185272k buffers Swap: 2402296k total, 5236k used, 2397060k free, 1068752k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ Command 12808 robf 25 0 2996 2596 2244 R 23.6 0.1 4:46.98 smbd 12741 robf 22 0 3028 2628 2280 R 20.6 0.1 5:44.55 smbd 2354 root 15 0 724 716 536 S 15.3 0.0 150:31.23 nscd 2356 root 15 0 724 716 536 S 14.9 0.0 150:35.87 nscd 2352 root 15 0 724 716 536 S 9.0 0.0 151:14.08 nscd 2353 root 15 0 724 716 536 S 6.3 0.0 150:39.89 nscd 2355 root 15 0 724 716 536 S 6.3 0.0 150:31.82 nscd 2350 root 15 0 724 716 536 S 3.7 0.0 150:49.78 nscd I attached both of the smbd processes to gdb and backtrace was always: #0 0x402e5328 in read () from /lib/libc.so.6 #1 0x40343b90 in __DTOR_END__ () from /lib/libc.so.6 #2 0x4031d58b in __nscd_getpwnam_r () from /lib/libc.so.6 #3 0x402c130d in getpwnam_r@@GLIBC_2.1.2 () from /lib/libc.so.6 #4 0x402c0e6f in getpwnam () from /lib/libc.so.6 #5 0x081298fd in get_memberuids () #6 0x08129b09 in _samr_query_groupmem () #7 0x081215d1 in api_samr_query_groupmem () #8 0x081358b2 in api_rpcTNP () #9 0x08135632 in api_pipe_request () #10 0x0812fc10 in process_request_pdu () #11 0x0812fdec in process_complete_pdu () #12 0x08130069 in process_incoming_data () #13 0x08130220 in write_to_internal_pipe () #14 0x081301a4 in write_to_pipe () #15 0x080883e0 in api_fd_reply () #16 0x080885b9 in named_pipe () #17 0x080891bc in reply_trans () #18 0x080c80e0 in switch_message () #19 0x080c8172 in construct_reply () #20 0x080c8491 in process_smb () #21 0x080c9004 in smbd_process () #22 0x081f812e in main () #23 0x402268ae in __libc_start_main () from /lib/libc.so.6 After killing both smbd processes with -9 the top soon stabilizes at: top - 10:12:01 up 6 days, 17:45, 6 users, load average: 0.03, 0.19, 1.17 Tasks: 175 total, 2 running, 173 sleeping, 0 stopped, 0 zombie Cpu(s): 0.0% user, 0.7% system, 0.0% nice, 99.3% idle Mem: 2060704k total, 2034272k used,26432k free, 185272k buffers Swap: 2402296k total, 5236k used, 2397060k free, 1100020k cached PID USER PR NI VIRT RES SHR S %CPU %MEMTIME+Command 15182 root 15 0 956 956 700 R 0.3 0.0 0:03.67 top Unfortunately I didn't trace the nscd processes. What a shame! I'll do it next time. Nobody complained yet about reduced performance. It's hard to tell when this behaviour started. The upper bound seems to be 9 hours, the combined run times of the nscd processe, some time during the night when the computers were totally quiet. The lower bound based on the run times of the smbd processes is more like half an hour ago. This is the fourth out of 5 times that the same user, robf, is involved as the effective UID of the smbd process. The other one time was root's own smbd. Jeremy, can I provide more information? Cheers, Dragan -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany
Re: [Samba] samba with acl support as member auf a samba controlled domain?
Hi we got it working. There were two poblems. -we had to update the samba PDC to 3.0.4 (formerly 3.0.1), because an error. -we had to use winbindwithout a uid and gid range some tests for winbind [EMAIL PROTECTED] root]# wbinfo -t checking the trust secret via RPC calls succeeded This message I get after installing 3.0,4 on the pdc. Without samba 3.01 on ther PDC there was an error [EMAIL PROTECTED] root]# wbinfo -g ... Management itsdgroup [EMAIL PROTECTED] root]# wbinfo -u [EMAIL PROTECTED] root]# wbinfo -u Administrator itsd krocka maurer trinkl Find attched my smb.conf for the client Greetings Hansjörg [global] log file = /var/log/samba/log.%m #log level = 3 passdb:5 auth:10 winbind:5 log level =0 security = domain workgroup = ITSYSTEMS encrypt passwords = yes netbios name = chardonnay server string = Install-Server password server = 192.168.0.1 machine password timeout = 60480 winbind trusted domains only = yes winbind use default domain = yes winbind nested groups = yes idmap uid = 1-1 idmap gid = 1-1 guest account = gast os level=25 wins support = no wins server = 192.168.0.1 dns proxy = no username map = /etc/samba/smbusers #preferred master = no #domain master = no #local master = no name resolve order = wins hosts socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192 hosts allow = 192.168.0. bind interfaces only = Yes interfaces = 127.0.0.1, bond0 deadtime=180 keepalive = 3600 unix charset = iso8859-15 display charset = iso8859-15 [install] comment = Install Verzeichnis path = /install read only = no # security mask = 0770 # force group = itsdgroup # force user = itsd # force create mode = 0664 # create mask = 0664 # directory mask = 0777 [backup] comment = Backup von Kunden path = /backup read only = no force group = itsdgroup force user = itsd force create mode = 0664 create mask = 0664 directory mask = 0777 Guillaume Anfroy wrote: Guten tag, I am trying to make the acl working on a domain with a single samba server(as a PDC). I've checked the docs, the newsgroup and I haven't found any information about anyone who did in any other way that with a Windows(tm) PDC. I will try to get a confirmation on that information and I will keep you informed. Unless you already get the confirmation that it is impossible to make samba works with acl withtout a Windows PDS or AD server ? Regards, Guillaume - Original Message - From: Dr. Hansjörg Maurer [EMAIL PROTECTED] Newsgroups: linux.samba Sent: Friday, June 04, 2004 10:30 PM Subject: [Samba] samba with acl support as member auf a samba controlled domain? Hi I am running a Samba PDC and a Samba member server in his domain. The member server acts as a file server with unix acl's working. Is it possible to get these acl's working under samba to? The docs seem to say, that acl's are only possible if samba is a memberserver in an NT-Domain using winbind. In my case the PDC acts as a LDAP Server and the Member server is gets the unix account information from Ldap. I am running samba 3.0.4 and had no sucesse with this setup. The windows client shows acls not as for the domain\user but for the memberserver\user Here is my smb.conf [global] log file = /var/log/samba/log.%m log level =2 security = domain workgroup = ITSYSTEMS encrypt passwords = yes netbios name = chardonnay server string = Install-Server password server = 192.168.0.1 machine password timeout = 60480 guest account = gast os level=25 wins support = no wins server = 192.168.0.1 dns proxy = no username map = /etc/smbusers preferred master = no domain master = no local master = no name resolve order = wins hosts socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192 hosts allow = 192.168.0. bind interfaces only = Yes deadtime=180 keepalive = 3600 unix charset = iso8859-15 display charset = iso8859-15 [install] comment = Install Verzeichnis path = /install read only = no public = yes Thank you very much Hansjörg Maurer -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstr. 10 D-80335 München Ph/Fax +49 89 52 04 68-41/-59 -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe
Re: [Samba] Samba 3.0 PDC+LDAP Help in Fedora Core 1
Hi it took some time for me to set this up to. some hints: -check with net getlocalsid if the host sid is the same as the sid in ldap -check with net groumap list is the groupmapping is correct. -check with pdbedit -L -v -u username for each user, if samba can reslove the sid and group sid's correctly I noticed, that if you have one sid (group or user) twice, you can have much trouble.. -don`t use a groupname which is equal to a username (no problem in unix, but in windows) -I have a groupmap which maps Administrator to root. Because of the fact, that root and nobody are already in /etc/passwd I added a tbdsam backend, which only contains root and nobody with the correct SID's (I don't know, if this is the right way) (If you do so, uncomment the user add script in smb.conf for adding root and nobody to the tdb backend with pdbedit -b ) (The reason for the stuff is, that I dont want root and nobody in /etc/passwd and ldap) -set the debug level to 10 and watch the logs...) -check if the smbldap-adduser skript has allready added a machine. The skript adds the posix attributes for the account and sambe shouls add the rest.. -don't use filter in /etc/ldap.conf I used to filter out the computers there (in order to not get them with getent passwd etc) but smbldap determines the next free UID with this. So a UID might be used twice. -Finally I modified the smbldap-tool smbldap-useradd skript, but I am not sure, if this is really necessary. I am off work know. If the above won't help you. let me know, and I sent you my modifications. Greetings Hansjörg Jason P Holland sagte: Hello, I am hoping someone will offer some help. I'm currently trying to setup a samba 3 PDC with LDAP authentication backend in Fedora core 1. I've read loads of documentation, including http://www.hilinski.net/samba/ldap_PDC_samba.doc http://www.unav.es/cti/ldap-smb/smb-ldap-3-howto.html http://samba.idealx.org/samba-ldap-howto.pdf As well as tons of posts in the mailing list archives, but I still cannot get this combination to work. As for the setup, I've installed Openldap 2.1.22, Samba 3.0.0, smbldap-tools-0.8.2. I've run smbpasswd -w to add my slapd.conf password to the secrets.tdb file. I've setup smbldap_conf.pl with my correct SID and ldap dn. I've populated my ldap database using smbldap-populate.pl, everything shows up correctly. I've gone in to the ldap db and fixed roots uid and gid as well as its sambaSID so that it can act as administrator. As far as I can tell, its setup correctly. However, when I go to join a W2k Workstation client, I get The user name could not be found.. Thats using root-testing combination from my config files. Samba does automatically create the machine account, that looks fine. But it refuses to join the machine. Yes, I'm aware of the registry hack for XP,W2K machines, and that has also been changed. The weird thing is from that client, who I cannot join, I can view shares on the PDC using root-testing user pass combination, so I know the authentication is working correctly through ldap. So what does that user name not found error really mean? Does anyone see anything obviously wrong in my config files that would cause this? I've cut them into the post below. I would appreciate any help as I'm just tired of reading and just can't seem to get past adding a machine. Thanks for any help... Jason --- begin ldap.conf HOST 127.0.0.1 BASE dc=test,dc=edu end ldap.conf --- begin slapd.conf include /etc/openldap/schema/core.schema include /etc/openldap/schema/cosine.schema include /etc/openldap/schema/nis.schema include /etc/openldap/schema/inetorgperson.schema include /etc/openldap/schema/samba.schema pidfile /var/run/slapd.pid argsfile /var/run/slapd.args database bdb suffix dc=test,dc=edu rootdn cn=root,dc=test,dc=edu rootpw testing directory /var/lib/ldap index objectClass eq index cn pres,sub,eq index sn pres,sub,eq index uid pres,sub,eq index displayName pres,sub,eq index uidNumber eq index gidNumber eq index memberUid eq index sambaSID eq index sambaPrimaryGroupSID eq index sambaDomainName eq index default sub end slapd.conf begin smb.conf [global] passdb backend = ldapsam ldap suffix = dc=test,dc=edu ldap machine suffix = ou=Computers ldap user suffix = ou=Users ldap group suffix = ou=Groups ldap admin dn = cn=root,dc=test,dc=edu ldap ssl = no idmap backend = ldap:ldap://127.0.0.1 passwd chat debug = Yes passwd program =/usr/local/sbin/smbldap-passwd.pl -o %u passwd chat = *new*password* %n\n *new*password:* %n\ *successfully* socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192 add machine script = /usr/local/sbin/smbldap-useradd.pl -w %m add user script = /usr/local/sbin/smbldap-useradd.pl -a %u delete user script = /usr/local/sbin/smbldap-userdel.pl %u add group script = /usr/local/sbin/smbldap-groupadd.pl %g delete group script =
WAS: Re: [Samba] net groupmap / domain admins problem - Amazon prize
and I have all the tdb and I cahnged the SID to the last PDC. Anyway, how would I get the right SID? I have NTUSER.DAT files that I can run profiles against to read them. Would that help? You can use the Samba-3.0.x tools 'profiles' to reset the SID in the NTUSER.DAT files. To obtain the domain SID just run: net getlocalsid First one that can point me in the right direction to get this resolved - I'll buy them a amazon gift cert for $50. Beats going bald from pulling out my hair. It's a deal man! - John T. -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: WAS: Re: [Samba] net groupmap / domain admins problem - Amazon prize
Hi thank you, for your fast replay. I have a user sporer [EMAIL PROTECTED] root]# id -a sporer uid=1000(sporer) gid=1000(sensodrivegroup) Gruppen=1000(sensodrivegroup),1001(managementgroup) The user and the group is in ldap and nss_ldap seems to work.. [EMAIL PROTECTED] root]# getent group root:x:0:root Domain Admins:x:912: Domain Users:x:913: Domain Guests:x:914: Administrators:x:944: Users:x:945: Guests:x:946: Power Users:x:947: Account Operators:x:948: Server Operators:x:949: Print Operators:x:950:Administrator Backup Operators:x:951: Replicator:x:952: Domain Computers:x:953: sensodrivegroup:x:1000:sporer,haehnle,sporers,unterholzner,geist,bertleff,hauschild,sensodrive,root managementgroup:x:1001:management,root,haehnle,sporer,sporers I am using [EMAIL PROTECTED] root]# rpm -q nss_ldap nss_ldap-207-3 on RH9 Within samba I have to shares [Projekte] comment = Sensodrive-Projekte path = /home/sensodrive force group = sensodrivegroup force user = sensodrive valid users = @sensodrivegroup,root [Management] comment = Sensodrive-Management path = /home/management force group = managementgroup force user = management valid users = @managementgroup,root Every user can access the Projekte share, because the primary group of every user is sensodrivegroup. When user sporer tries to acess the Management share, he gets user 'sporer' (from session setup) not permitted to access this share (Management) If I add the user sporer by his username to valid users it works valid users = @managementgroup,root,sporer,haehnle,sporers Maybe this helps to solve the problem If you need more information, or further testing give me a note Thank you very much Greetings Hansjörg John H Terpstra wrote: On Thu, 8 Jan 2004, Hansjoerg Maurer wrote: Hi i have a question related to the groupmapping with ldapsam as backend. You discribed, that groupentries have to be in /etc/group with tdbsam as backend. I recognized, that samba 3,0.1 with ldapsam does not recognize secondary groups in ldap. (e.g for accessing a share) The problem is described by [EMAIL PROTECTED] to (see his email attached). Do secondary groups have to be in /etc/groups in order to be recognized by samba even with ldapsam? Whether or not this will work depends on how you configure ID resolution. Winbind apparently does not resolve secondary group membership. On the other hand, if you configure LDAP based ID resolution via the name service switcher (NSS) for both users and groups then secondary group membership resolution seems to work ok. The Posix user account should be in the LDAP database. You can then add users to multiple groups either in /etc/group or in the LDAP groups container. How did you configure /etc/nsswitch.conf? What does 'getent group' and 'getent passwd' show? If you have a user who is a member of mulitple secondary groups and you execute: id 'username' What does this report for that user? If LDAP based resolution of multiple group membership fails that is something that must be reported to PADL, the authors of nss_ldap. On the test systems I used to create the environments I used to create the example files for the new Samba-3 by Example book, I compiled nss_ldap version 212 and found that to work fine with multiple groups. Is this what you tried also? Cheers, John T. Thank you very much Hansjörg Hello, I found an interesting thing that I don't know if it is a bug, by design or I need to be doing something that I'm not but here goes. My system RedHat 8.0 (1) PDC with LDAP 2.1.23 backend master, (3) BDC with LDAP slave backend. All are Samba 3.0. I had a probelem with secondary, tertiary etc groups that people belong to and Samba recognizing these groups if they were stored in LDAP. The primary group was no problem. When I created shares but used @groupname for valid users or write list, Samba would fail to get that info from LDAP. They needed to be in /etc/group to work. As soon as I added users in secondary groups to /etc/group users were recognized and rights were assigned. As a side note each line of /etc/group is limited to 1024 bytes, so there is a limit on how many users you can add to a group using /etc/group. If you exceed that when the system scans the /etc/group file, it will fail at the line 1024 bytes and any groups below will fail to be recognized. I believe that this is a bug. If you do ls on a directory or id username where one of the entries in your /etc/group has exceeded the limit, the groups will show as numbers and not a group name. Can I use pam_winbindd to extract group membership from LDAP at this time for secondary, tertiary etc groups? John H Terpstra wrote: On Wed, 7 Jan 2004, Andrew Judge wrote: I think that most of my problems are somewhat resolved except for this last one. I can not get domain admin rights to the ntadmins users. I get the following output for groupmaps: [EMAIL PROTECTED] i386]# net groupmap list System Operators (S-1
Re: WAS: Re: [Samba] net groupmap / domain admins problem
Hi i switched to valid users = +managementgroup and still get 2004/01/08 10:46:52, 2] lib/access.c:check_access(324) Allowed connection from (192.168.1.100) [2004/01/08 10:46:52, 2] smbd/service.c:make_connection_snum(391) user 'sporer' (from session setup) not permitted to access this share (test) [2004/01/08 10:46:52, 3] smbd/error.c:error_packet(118) error packet at smbd/reply.c(286) cmd=117 (SMBtconX) NT_STATUS_ACCESS_DENIED (changed thename of the share to test to avoid a naming conflict with user managment) [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\test Password: tree connect failed: NT_STATUS_ACCESS_DENIED [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\sporer Password: smb: \ [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\projekte-share Password: smb: \ With the share, wher sporer has the primary group in, it still works with the +sensodrivegroup Thank you Hansjörg John H Terpstra wrote: Hansjoerg, Instead of: valid users = @Groupe Please try: valid users = +Groupe Thanks. - John T. On Thu, 8 Jan 2004, Hansjoerg Maurer wrote: Hi thank you, for your fast replay. I have a user sporer [EMAIL PROTECTED] root]# id -a sporer uid=1000(sporer) gid=1000(sensodrivegroup) Gruppen=1000(sensodrivegroup),1001(managementgroup) The user and the group is in ldap and nss_ldap seems to work.. [EMAIL PROTECTED] root]# getent group root:x:0:root Domain Admins:x:912: Domain Users:x:913: Domain Guests:x:914: Administrators:x:944: Users:x:945: Guests:x:946: Power Users:x:947: Account Operators:x:948: Server Operators:x:949: Print Operators:x:950:Administrator Backup Operators:x:951: Replicator:x:952: Domain Computers:x:953: sensodrivegroup:x:1000:sporer,haehnle,sporers,unterholzner,geist,bertleff,hauschild,sensodrive,root managementgroup:x:1001:management,root,haehnle,sporer,sporers I am using [EMAIL PROTECTED] root]# rpm -q nss_ldap nss_ldap-207-3 on RH9 Within samba I have to shares [Projekte] comment = Sensodrive-Projekte path = /home/sensodrive force group = sensodrivegroup force user = sensodrive valid users = @sensodrivegroup,root [Management] comment = Sensodrive-Management path = /home/management force group = managementgroup force user = management valid users = @managementgroup,root Every user can access the Projekte share, because the primary group of every user is sensodrivegroup. When user sporer tries to acess the Management share, he gets user 'sporer' (from session setup) not permitted to access this share (Management) If I add the user sporer by his username to valid users it works valid users = @managementgroup,root,sporer,haehnle,sporers Maybe this helps to solve the problem If you need more information, or further testing give me a note Thank you very much Greetings Hansjörg John H Terpstra wrote: On Thu, 8 Jan 2004, Hansjoerg Maurer wrote: Hi i have a question related to the groupmapping with ldapsam as backend. You discribed, that groupentries have to be in /etc/group with tdbsam as backend. I recognized, that samba 3,0.1 with ldapsam does not recognize secondary groups in ldap. (e.g for accessing a share) The problem is described by [EMAIL PROTECTED] to (see his email attached). Do secondary groups have to be in /etc/groups in order to be recognized by samba even with ldapsam? Whether or not this will work depends on how you configure ID resolution. Winbind apparently does not resolve secondary group membership. On the other hand, if you configure LDAP based ID resolution via the name service switcher (NSS) for both users and groups then secondary group membership resolution seems to work ok. The Posix user account should be in the LDAP database. You can then add users to multiple groups either in /etc/group or in the LDAP groups container. How did you configure /etc/nsswitch.conf? What does 'getent group' and 'getent passwd' show? If you have a user who is a member of mulitple secondary groups and you execute: id 'username' What does this report for that user? If LDAP based resolution of multiple group membership fails that is something that must be reported to PADL, the authors of nss_ldap. On the test systems I used to create the environments I used to create the example files for the new Samba-3 by Example book, I compiled nss_ldap version 212 and found that to work fine with multiple groups. Is this what you tried also? Cheers, John T. Thank you very much Hansjörg Hello, I found an interesting thing that I don't know if it is a bug, by design or I need to be doing something that I'm not but here goes. My system RedHat 8.0 (1) PDC with LDAP 2.1.23 backend master, (3) BDC with LDAP slave backend. All are Samba 3.0. I had a probelem with secondary, tertiary etc groups that people belong to and Samba recognizing these groups if they were stored in LDAP. The primary group was no problem. When I created shares but used @groupname for valid
Re: WAS: Re: [Samba] net groupmap / domain admins problem
Hi, I also deleted my /var/lib/samba/group_mapping.tdb as you suggested in your mail before (I am using ldapsam, but I was afraid that there might be something left after the installation) But unfortunatly it does not work. My groupmap seems to be ok ok time for going to sleep :) greetings from munich hansjörg [EMAIL PROTECTED] root]# net groupmap list Domain Admins (S-1-5-21-3723159834-3326906825-3408399175-512) - Domain Admins Domain Users (S-1-5-21-3723159834-3326906825-3408399175-513) - Domain Users Domain Guests (S-1-5-21-3723159834-3326906825-3408399175-514) - Domain Guests Administrators (S-1-5-21-3723159834-3326906825-3408399175-544) - Administrators Users (S-1-5-21-3723159834-3326906825-3408399175-545) - Users Guests (S-1-5-21-3723159834-3326906825-3408399175-546) - Guests Power Users (S-1-5-21-3723159834-3326906825-3408399175-547) - Power Users Account Operators (S-1-5-21-3723159834-3326906825-3408399175-548) - Account Operators Server Operators (S-1-5-21-3723159834-3326906825-3408399175-549) - Server Operators Print Operators (S-1-5-21-3723159834-3326906825-3408399175-550) - Print Operators Backup Operators (S-1-5-21-3723159834-3326906825-3408399175-551) - Backup Operators Replicators (S-1-5-21-3723159834-3326906825-3408399175-552) - Replicator Domain Computers (S-1-5-21-3723159834-3326906825-3408399175-553) - Domain Computers sensodrivegroup (S-1-5-21-3723159834-3326906825-3408399175-3001) - sensodrivegroup Managementgroup (S-1-5-21-3723159834-3326906825-3408399175-3003) - managementgroup H Hansjoerg Maurer sagte: Hi i switched to valid users = +managementgroup and still get 2004/01/08 10:46:52, 2] lib/access.c:check_access(324) Allowed connection from (192.168.1.100) [2004/01/08 10:46:52, 2] smbd/service.c:make_connection_snum(391) user 'sporer' (from session setup) not permitted to access this share (test) [2004/01/08 10:46:52, 3] smbd/error.c:error_packet(118) error packet at smbd/reply.c(286) cmd=117 (SMBtconX) NT_STATUS_ACCESS_DENIED (changed thename of the share to test to avoid a naming conflict with user managment) [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\test Password: tree connect failed: NT_STATUS_ACCESS_DENIED [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\sporer Password: smb: \ [EMAIL PROTECTED] root]# smbclient -U sporer LINA\\projekte-share Password: smb: \ With the share, wher sporer has the primary group in, it still works with the +sensodrivegroup Thank you Hansjörg John H Terpstra wrote: Hansjoerg, Instead of: valid users = @Groupe Please try: valid users = +Groupe Thanks. - John T. On Thu, 8 Jan 2004, Hansjoerg Maurer wrote: Hi thank you, for your fast replay. I have a user sporer [EMAIL PROTECTED] root]# id -a sporer uid=1000(sporer) gid=1000(sensodrivegroup) Gruppen=1000(sensodrivegroup),1001(managementgroup) The user and the group is in ldap and nss_ldap seems to work.. [EMAIL PROTECTED] root]# getent group root:x:0:root Domain Admins:x:912: Domain Users:x:913: Domain Guests:x:914: Administrators:x:944: Users:x:945: Guests:x:946: Power Users:x:947: Account Operators:x:948: Server Operators:x:949: Print Operators:x:950:Administrator Backup Operators:x:951: Replicator:x:952: Domain Computers:x:953: sensodrivegroup:x:1000:sporer,haehnle,sporers,unterholzner,geist,bertleff,hauschild,sensodrive,root managementgroup:x:1001:management,root,haehnle,sporer,sporers I am using [EMAIL PROTECTED] root]# rpm -q nss_ldap nss_ldap-207-3 on RH9 Within samba I have to shares [Projekte] comment = Sensodrive-Projekte path = /home/sensodrive force group = sensodrivegroup force user = sensodrive valid users = @sensodrivegroup,root [Management] comment = Sensodrive-Management path = /home/management force group = managementgroup force user = management valid users = @managementgroup,root Every user can access the Projekte share, because the primary group of every user is sensodrivegroup. When user sporer tries to acess the Management share, he gets user 'sporer' (from session setup) not permitted to access this share (Management) If I add the user sporer by his username to valid users it works valid users = @managementgroup,root,sporer,haehnle,sporers Maybe this helps to solve the problem If you need more information, or further testing give me a note Thank you very much Greetings Hansjörg John H Terpstra wrote: On Thu, 8 Jan 2004, Hansjoerg Maurer wrote: Hi i have a question related to the groupmapping with ldapsam as backend. You discribed, that groupentries have to be in /etc/group with tdbsam as backend. I recognized, that samba 3,0.1 with ldapsam does not recognize secondary groups in ldap. (e.g for accessing a share) The problem is described by [EMAIL PROTECTED] to (see his email attached). Do secondary groups have to be in /etc/groups in order to be recognized by samba even with ldapsam? Whether
Re: [Samba] incorrect password length when joining domain, need help
Hi I have seen similar messages: log.barolo: check_oem_password: incorrect password length (-504624689). log.barolo: check_oem_password: incorrect password length (289636283). log.barolo: check_oem_password: incorrect password length (289636283). log.barolo: check_oem_password: incorrect password length (289636283). log.barolo: check_oem_password: incorrect password length (-859980248). greetings Hansjoerg Charles Hamel sagte: I fixed my problem, This problem started to appear with 3.0.1rc1 ( maybe pre3 too ). I installed RC2 and it did not fix the problem, 3.0.0 works fine! Charles On Fri, 12 Dec 2003 14:01:51 -0500, Charles Hamel wrote Hi I just re-initiated by ldap sam database using smbldap-populate.pl, modified the Administrator account (uid/gid=0). I can join the domain from a Samba 2.2.7 linux machine, it creates the machine account etc... The problem happens with Windows 2000 SP2, It tells me wrong user/password. Here is the samba error : decode_pw_buffer: incorrect password length (-2118884061). Here is the full log : Attempting administrator password change (level 23) for user workstation$ [2003/12/12 13:25:57, 0] libsmb/smbencrypt.c:decode_pw_buffer(501) decode_pw_buffer: incorrect password length (-2118884061). [2003/12/12 13:25:57, 0] libsmb/smbencrypt.c:decode_pw_buffer(502) decode_pw_buffer: check that 'encrypt passwords = yes' [2003/12/12 13:25:57, 5] rpc_parse/parse_prs.c:prs_debug(82) 00 samr_io_r_set_userinfo [2003/12/12 13:25:57, 5] rpc_parse/parse_prs.c:prs_ntstatus(665) status: NT_STATUS_ACCESS_DENIED [2003/12/12 13:25:57, 5] rpc_server/srv_pipe.c:api_rpcTNP(1549) api_rpcTNP: called samr successfully Here is my smb.conf file [global] ADD SCRIPTS add machine script = /usr/local/samba/share/smbldap-useradd.pl -w %u add user script = /usr/local/samba/share/smbldap-useradd.pl %u delete user script = /usr/local/samba/share/smbldap-userdel.pl %u add group script = /usr/local/samba/share/smbldap-groupadd.pl %g delete group script = /usr/local/samba/share/smbldap-groupdel.pl %g add user to group script = /usr/local/samba/share/smbldap- groupmod.pl -m %u %g delete user from group script = /usr/local/samba/share/smbldap-groupmod.pl -x %u %g set primary group script = /usr/local/samba/share/smbldap-usermod.pl -G %g %u null passwords = yes #unix charset = UTF-8 passdb backend = ldapsam:ldap://localhost/ ldap suffix = o=smb,dc=qc,dc=ca ldap machine suffix = ou=Computers ldap user suffix = ou=Users ldap group suffix = ou=Groups ldap admin dn = cn=root,o=smb,dc=qc,dc=ca guest account = nobody workgroup = LINUX netbios name = PDC comment = Server security = user encrypt passwords = yes logon script = scripts\%U.bat domain logons = Yes os level = 255 preferred master = Yes domain master = Yes #hosts allow = 192.168.0.0/255.255.255.0 share modes = No wins support = Yes [homes] path=/home/domainusers read only = No create mask = 0700 directory mask = 0700 locking = No oplocks = No [netlogon] path = /usr/local/samba/netlogon locking = no read only = yes [profiles] path = /home/domainusers/profiles read only = no writeable = yes create mask = 0600 directory mask = 0700 Here is the LDIF entry of Administrator : dn: uid=Administrator,ou=Users,o=smb,dc=qc,dc=ca cn: Administrator sn: Administrator objectClass: inetOrgPerson objectClass: sambaSAMAccount objectClass: posixAccount uid: Administrator sambaLogonTime: 0 sambaLogoffTime: 2147483647 sambaKickoffTime: 2147483647 sambaPwdCanChange: 0 sambaHomePath: \\PDC\homes sambaHomeDrive: U: sambaProfilePath: \\PDC\profiles\ loginShell: /bin/false gecos: Netbios Domain Administrator sambaSID: S-1-5-21-3655003630-1527190663-3647191254-1000 sambaPrimaryGroupSID: S-1-5-21-3655003630-1527190663-3647191254-1001 uidNumber: 0 gidNumber: 0 homeDirectory: / sambaLMPassword: XX (removed) sambaAcctFlags: [U] sambaNTPassword: XX (removed) sambaPwdLastSet: 1071185436 sambaPwdMustChange: 1075073436 userPassword:: XX (removed) I am running Samba 3.0.1rc1 on Redhat 9.0 Please help me Thank you Charles -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba -- Open WebMail Project (http://openwebmail.org) -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstr. 10 D-80335 München Ph/Fax +49 89 52 04 68-41/-59 -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] Samba-Citrix compatability
Hi thank you for this great explanation. We have similar problems with Citrix and a netapp NAS device and I am wondering, if this may have the same reason This is not related to samba... But your explanation of the original problem may be a good input... Thank you very much. greetings Hansjörg Windows uses one TCP/IP connection to connect to a single server. Windows NT Terminal server had a registry switch to make it spit it up as one-per-user, as there ware problem with only 1000 open files (or something like that). MS fixed their bug, so removed the setting. The problem is that unlike NT, Samba is not multithreaded - it deals with the operations from the client in a strictly serial fashion. This is usually fine for a single PC, and becosue multiple client PCs all use their own seperate TCP/IP connection, Samba scales really well. However, when all the work is on one TCP/IP connection, all the changes between user (seteuid calls) and even worse blocking due to simple disk IO is serialised. Ie, other unreated operations cannot complete. (I think that the fcntl() issues might also make this even worse, but jra would know better). By forcing Windows to make multiple TCP/IP connections to the Samba server, we get back to the situation we had with multiple windows client PCs. Much of the work on Samba4 is to create a compleatly asyncronous design, which can cope with this stuff very well, but until then, we need the workarounds... Andrew Bartlett -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ There are 10 types of people in this world, those who understand binary and those who don't. -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
[Samba] strange smbstatus output after update from 2.2.5 to 2.2.8a
Hi, I updated from Samba 2.2.5 to 2.2.8a. und Redhat 6.2 and since then, smbstatus shows strange values The dates and the pid's are wrong. Any ideas? Was there a change in a locking.tdb? Do I have to remove it? Greetings Hansjörg 28643 DENY_NONE 0x3f407996 RDONLY LEVEL_II ?7??W? Tue Jan 6 22:38:12 1970 1633824626 0x706d622e NONE ?7??W? Thu Jan 1 02:00:00 1970 1836017711 0x56414143 EXCLUSIVE+BATCH Sun Sep 12 13:13:05 2004 1836017711 DENY_FCB 0x74756f2f RDWR EXCLUSIVE Fri Feb 12 21:45:32 2027 1836017711 DENY_FCB 0x2f746b65 RDONLY EXCLUSIVE rmen/06-Schlosser/~WRL3404.tmp Tue May 23 09:03:34 2023 1836017711 0x56414143 EXCLUSIVE+BATCH 7??W? Tue Nov 10 00:41:53 2015 1836017711 DENY_FCB 0x2f746b65 RDONLY EXCLUSIVE rmen/06-Schlosser/~WRL0150.tmp Tue May 23 09:03:34 2023 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@/06-Schlosser/~WRL0150.tmp Tue Nov 10 00:41:53 2015 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@/06-Schlosser/~WRL0150.tmp Tue Nov 10 00:41:53 2015 1836017711 0x2f6c7261 EXCLUSIVE+BATCH 9 Sun Aug 29 22:32:47 2027 28643 DENY_NONE 0x3f407996 RDONLY LEVEL_II Hm'@AVAR.MDB Thu Jan 8 14:57:13 1970 758263666 DENY_WRITE 0x6c6c6575 LEVEL_II Hm'@AVAR.MDB Fri May 28 02:19:59 2032 1836017711 0x7265676e BATCH 9 Mon Dec 1 02:00:31 2031 1836017711 0x6f64412f RDWR EXCLUSIVE Hm'@Hm'@Hm'@uell/baum -10.bmp Fri Nov 17 14:06:42 2023 1836017711 DENY_FCB 0x2f746b65 RDONLY EXCLUSIVE rmen/06-Schlosser/~WRL3330.tmp Tue May 23 09:03:34 2023 1836017711 0x30362f74 NONE 9 Sun Oct 17 17:33:01 2021 1836017711 DENY_FCB 0x2f746b65 RDONLY EXCLUSIVE 3.xls Fri Sep 22 01:20:51 2028 1836017711 0x56414143 EXCLUSIVE+BATCH 9 Sun Sep 12 13:13:05 2004 1836017711 0x35352f74 NONE ad-25.dwg Sun Dec 10 07:57:55 2023 1836017711 0x30362f74 NONE dwg Sun Oct 17 17:33:01 2021 28643 DENY_NONE 0x3f407996 RDONLY LEVEL_II Hm'@AVAR.MDB Thu Jan 8 03:37:49 1970 758263666 DENY_WRITE 0x6c6c6575 LEVEL_II Hm'@AVAR.MDB Fri May 28 02:19:59 2032 1836017711 0x35322f74 NONE n.dwg Sun Jan 30 13:10:58 2011 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@g Tue Nov 10 00:41:53 2015 1836017711 0x56414143 EXCLUSIVE+BATCH 9 Sun Sep 12 13:13:05 2004 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@Hm'@Hm'@Hm'@Hm'@m -4.bmp Tue Nov 10 00:41:53 2015 1836017711 0x30312f74 NONE 5-emoeb/LV/zarge.dwg Sat Sep 9 21:43:39 2028 28643 DENY_NONE 0x3f407996 RDONLY LEVEL_II Hm'@AVAR.MDB Wed Jan 7 15:03:32 1970 758263666 DENY_WRITE 0x6c6c6575 LEVEL_II Hm'@AVAR.MDB Fri May 28 02:19:59 2032 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@entw/aktuell/baum -1.bmp Tue Nov 10 00:41:53 2015 1836017711 DENY_FCB 0x2f746b65 RDONLY EXCLUSIVE rmen/06-Schlosser/Uher-MA-AE04.doc Tue May 23 09:03:34 2023 1836017711 DENY_FCB 0x45535341 NONE Hm'@/06-Schlosser/Uher-MA-AE04.doc Wed Feb 16 17:34:55 1994 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@/06-Schlosser/Uher-MA-AE04.doc Tue Nov 10 00:41:53 2015 1836017711 0x6f6c7475 BATCH Hm'@/06-Schlosser/Uher-MA-AE04.doc Sat Feb 10 01:44:31 2029 1836017711 0x35352f74 NONE ktuell/indexA/ug-og-A.dwg Sun Dec 10 07:57:55 2023 1836017711 0x56414143 EXCLUSIVE+BATCH Hm'@ll/indexA/ug-og-A.dwg Tue Nov 10 00:41:53 2015 1836017711 0x35352f74 NONE wo.bmp Sun Dec 10 07:57:55 2023 -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] Samba 2.2.8 is failing on change machine account password
Andrew Bartlett wrote: If you run 'smbpasswd -t' it should do it on demand. Hi, thank you for the information. It makes testing easier. But unfortunatlly I get the same error. I had performed several tests concerning the case sensitiv writing of the domainname, but I got no solution. (attached the matrix of values I have tested) I removed the samba host (printserver3) each time from the domain unsing the servermanager und added ist (with servermanger) First join with smbpasswd -j NTROBOTIC -r ROBPDC2 works second try with smbpasswd -t NTROBOTIC 2003/03/31 08:24:56 : change_trust_account_password: Failed to change password f or domain NTROBOTIC. fails. printserver3 is a test system only, so I can use it for testing until the end of the next week. If I can supply further testing/information, please let me know. Thank you Hansjörg smb.confsmbpasswd Servermanager Result NTROBOTIC NTROBOTIC NTROBOTIC n ntrobotic ntrobotic ntrobotic NTROBOTIC ntrobotic ntrobotic 17.03.2003 18:00 Uhr Netbios/smb.conf Workgroup/smb.conf Domain/smbpasswd PDC/smbpaswd Servermanager/del Servermanager/add dateResult --- NTROBOTIC NTROBOTICROBPDC2 Y Y 25.03 8:30 bad PRINTSERVER3 NTROBOTIC NTROBOTICROBPDC2 Y Y 25.03 16:30 bad printserver3 NTROBOTIC NTROBOTICROBPDC2 Y Y 26.03 10:30 bad printserver3 NTROBOTIC NTROBOTICrobpdc2 Y Y 26.03 15:30 bad PRINTSERVER3 NTROBOTIC NTROBOTICrobpdc2 Y Y 26.03 17:00 bad --- NTROBOTIC NTROBOTICrobpdc2 Y Y 26.03 17:50 bad --- ntrobotic NTROBOTICROBPDC2 Y Y 27.03 8:30 bad PRINTSERVER3 ntrobotic NTROBOTICROBPDC2 Y Y 27.03 16:30 printserver3 ntrobotic NTROBOTICROBPDC2 Y Y 27.03 10:30 -- NTROBOTIC NTROBOTICROBPDC2 Y Y (passwd server*) 27.03 10:30 bad printserver3 ntrobotic ntroboticrobpdc2 Y Y 27.03 15:30 Andrew Bartlett -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] Samba 2.2.8 is failing on change machine account password
Hi, I have the sampe problem with security=domain but it occurs with older samba versions to. (Solaris 8, NT4 PDC) I have tried serveral setting (upper/lowercase of Domainname (in workgroup and smbpasswd command), adding it via smbpasswd with/without creating the machine account at the NT4 domain before. It works for one week after adding the Samba server to the domain With machine password timeout = 900 you can decrease the time until the problem occurs from one week to eg. 15 min for testing purposes. It is not a real problem, it still works, but it produces strange messages (even on the NT PDC). Greetings Hansjörg /var/log/samba/log.rmts1-[2003/03/27 16:54:34, 0] rpc_client/cli_netlogon.c:cli_net_req_chal(246) /var/log/samba/log.rmts1-[2003/03/27 16:54:34, 0] rpc_client/cli_login.c:cli_nt_setup_creds(47) /var/log/samba/log.rmts1-[2003/03/27 16:54:34, 0] rpc_client/cli_trust.c:modify_trust_password(142) /var/log/samba/log.rmts1-[2003/03/27 16:54:34, 0] rpc_client/cli_trust.c:change_trust_account_password(248) /var/log/samba/log.rmts1: 2003/03/27 16:54:34 : change_trust_account_password: Failed to change password for domain NTROBOTIC. -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] PATCH: downloading drivers from Solaris [was Re: SoSAMBA no longer ...]
of printer driver files [2003/03/13 10:48:05, 3] smbd/lanman.c:api_DosPrintQGetInfo(918) api_DosPrintQGetInfo: Driver files count: 0 [2003/03/13 10:48:05, 3] smbd/lanman.c:fill_printq_info_52(656) printerdriver:inshp4050: [2003/03/13 10:48:05, 3] smbd/lanman.c:fill_printq_info_52(657) Driver:ADOBEPS4.DRV: [2003/03/13 10:48:05, 3] smbd/lanman.c:fill_printq_info_52(658) Data File:inshp4050.PPD: [2003/03/13 10:48:05, 3] smbd/lanman.c:fill_printq_info_52(659) Language Monitor:PSMON.DLL: [2003/03/13 10:48:05, 3] smbd/lanman.c:fill_printq_info_52(661) lp_driverlocation:\\PRINTSERVER2\print$\WIN40\0: Running command: smbclient //localhost/print\$ -N -U'root%X' -c 'mkdir WIN40;put /var/spool/cups/tmp/3e7056b3134b8 WIN40/inshp4050.PPD;put /usr/share/cups/drivers/ADFONTS.MFM WIN40/ADFONTS.MFM;put /usr/share/cups/drivers/ADOBEPS4.DRV WIN40/ADOBEPS4.DRV;put /usr/share/cups/drivers/ADOBEPS4.HLP WIN40/ADOBEPS4.HLP;put /usr/share/cups/drivers/DEFPRTR2.PPD WIN40/DEFPRTR2.PPD;put /usr/share/cups/drivers/ICONLIB.DLL WIN40/ICONLIB.DLL;put /usr/share/cups/drivers/PSMON.DLL WIN40/PSMON.DLL;' added interface ip=129.247.181.169 bcast=129.247.181.255 nmask=255.255.255.0 added interface ip=127.0.0.1 bcast=127.255.255.255 nmask=255.0.0.0 Domain=[NTROBOTIC] OS=[Unix] Server=[Samba 2.2.8pre2] NT_STATUS_OBJECT_NAME_COLLISION making remote directory \WIN40 putting file /var/spool/cups/tmp/3e7056b3134b8 as \WIN40/inshp4050.PPD (1577.2 kb/s) (average 1577.2 kb/s) putting file /usr/share/cups/drivers/ADFONTS.MFM as \WIN40/ADFONTS.MFM (1149.5 kb/s) (average 1190.6 kb/s) putting file /usr/share/cups/drivers/ADOBEPS4.DRV as \WIN40/ADOBEPS4.DRV (1410.8 kb/s) (average 1328.0 kb/s) putting file /usr/share/cups/drivers/ADOBEPS4.HLP as \WIN40/ADOBEPS4.HLP (1139.4 kb/s) (average 1305.0 kb/s) putting file /usr/share/cups/drivers/DEFPRTR2.PPD as \WIN40/DEFPRTR2.PPD (212.5 kb/s) (average 1265.2 kb/s) putting file /usr/share/cups/drivers/ICONLIB.DLL as \WIN40/ICONLIB.DLL (1891.1 kb/s) (average 1286.8 kb/s) putting file /usr/share/cups/drivers/PSMON.DLL as \WIN40/PSMON.DLL (861.5 kb/s) (average 1271.7 kb/s) Running command: rpcclient localhost -N -U'root%X' -c 'adddriver Windows 4.0 inshp4050:ADOBEPS4.DRV:inshp4050.PPD:NULL:ADOBEPS4.HLP:PSMON.DLL:RAW:ADOBEPS4.DRV,inshp4050.PPD,ADOBEPS4.HLP,PSMON.DLL,ADFONTS.MFM,DEFPRTR2.PPD,ICONLIB.DLL' cmd = adddriver Windows 4.0 inshp4050:ADOBEPS4.DRV:inshp4050.PPD:NULL:ADOBEPS4.HLP:PSMON.DLL:RAW:ADOBEPS4.DRV,inshp4050.PPD,ADOBEPS4.HLP,PSMON.DLL,ADFONTS.MFM,DEFPRTR2.PPD,ICONLIB.DLL Printer Driver inshp4050 successfully installed. Running command: rpcclient localhost -N -U'root%X' -c 'setdriver inshp4050 inshp4050' cmd = setdriver inshp4050 inshp4050 Succesfully set inshp4050 to driver inshp4050. -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __
[Samba] Domain member server starts loggingchange_trust_account_password: Failed to change password fordomain after one week
Hi, I am running a Samba printserver (2.2.7a). I have successfully joined the domain with smbpasswd -j NTROBOTIC -r robpdc2 -UAdmin% Eactly one week after joining the domain , the samba server starts logging: (prining still works) [2003/02/27 13:05:04, 2] lib/util_sock.c:open_socket_out(874) error connecting to 129.247.189.234:445 (Verbindungsaufbau abgelehnt) [2003/02/27 13:05:04, 0] rpc_client/cli_netlogon.c:cli_net_req_chal(246) cli_net_req_chal: Error NT_STATUS_INVALID_COMPUTER_NAME [2003/02/27 13:05:04, 0] rpc_client/cli_login.c:cli_nt_setup_creds(47) cli_nt_setup_creds: request challenge failed [2003/02/27 13:05:04, 0] rpc_client/cli_trust.c:modify_trust_password(142) modify_trust_password: unable to setup the PDC credentials to machine 129.247.189.234. Error was : NT_STATUS_UNSUCCESSFUL. [2003/02/27 13:05:04, 0] rpc_client/cli_trust.c:change_trust_account_password(248) 2003/02/27 13:05:04 : change_trust_account_password: Failed to change password for domain NTROBOTIC. What is the problem? Do i have to take care of a case sensitive wirting of the DOMAIN name? A part of smb.conf follows... Thank you very much Greetings Hansjörg [global] log file = /var/log/samba/log.%m log level =3 security = domain workgroup = NTROBOTIC encrypt passwords = yes password server = 129.247.189.234 netbios name = PRINTSERVER server string = PRINTSERVER announce as = NT Server wins support = no wins server = 129.247.189.234 preferred master = no domain master = no local master = yes -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] Re: So SAMBA no longer supports print driver downloads
Robert M. Martel wrote: On Sat Feb 1 11:00:04 GMT 2003, Gerald (Jerry) Carter wrote: On Sat, 1 Feb 2003, Dr. Hansjoerg Maurer wrote: Hi, could it be a problem with the operating system, samba runs on? On Solaris 2.8 I have the same problems, decribed above, but not on linux (both running samba 2.2.7a and cups-1.1.18). Could be. I don't have a Solaris box locally to run regular tests. This morning I set up a linux box to test 2.2.7a on along with the HP printer drivers that have been giving me problems. I followed the documentation for loading and tickling the printer drivers. Initial tests were successful - the printer device settings downloaded for a non-printer admin user. Looks like an issue where Solaris and samba do not play nice together. Jerry, if you or the development team have something you want to test against Sun Solaris 9 let me know. I need to get this resolved, but I don't know where to start looking for clues. Hi, we have solaris 2.8 here (I initially described the problem at our site), and I can help testing to. Could there be any connections to the Solaris fcntl bug, described in other E-Mails, or is this a completly differnt area. Thank you Hansjoerg Hansjörg -Bob Martel ** Speaking only for myself - CSU pays better people than me to speak for them. Bob Martel - System Administrator | I met someone who looks Maxine Goodman Levin College of Urban Affairs |a lot like you Cleveland State University | She does the things you do (216) 687-2214 |But she is an IBM [EMAIL PROTECTED] | -Jeff Lynne ** -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Re: [Samba] So SAMBA no longer supports print driver downloads
Hi, could it be a problem with the operating system, samba runs on? On Solaris 2.8 I have the same problems, decribed above, but not on linux (both running samba 2.2.7a and cups-1.1.18). Another difference is, that our solaris samba printer server is a member server of a NT4.0 controlled domain. The linux samba printer server acts as a PDC itself. I don't know, but maybe this information helps.. Greetings Hansjörg Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, 29 Jan 2003, Robert M. Martel wrote: So SAMBA no longer supports print driver downloads. That is about the only conclusion that I can come to at this point. I've not been able to get Windows printer driver downloads to work right since Samba 2.2.2. No one but printer admins displays the correct settings for printers, everyone else gets the original printer defaults that they cannot change. Did you initialize the driver bound to the printer? Does anyone *REALLY* have downloading printer drivers to Windows 2000 clients working properly? Has anyone documented the steps as the ones in the available documentation DON'T work? Works fine here (on a daily basis). Not sure what to tell you with more information. If you want to tell me exactly how you do it, I'll be glad to review the process. cheers, jerry -- Hewlett-Packard- http://www.hp.com SAMBA Team -- http://www.samba.org GnuPG Key http://www.plainjoe.org/gpg_public.asc You can never go home again, Oatman, but I guess you can shop there. --John Cusack - Grosse Point Blank (1997) -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.0 (GNU/Linux) Comment: For info see http://quantumlab.net/pine_privacy_guard/ iD8DBQE+Oo8nIR7qMdg1EfYRArmwAKDZKX7DRABQiQ62+Jz8i7sv0UJ7GgCaAoFr sFGMdunZezKx8fBLhCCWoUQ= =vovw -END PGP SIGNATURE- -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstr. 10 D-80335 München Ph/Fax +49 89 52 04 68-41/-59 -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Driver download problems: Can't determine number of printer driverfiles
Hi I still have problems downloading Adobe PS-Driver files to W9X clients (files added with cupsaddsmb). (samba-2.2.7a, cups-1.1.18) The upload seems to work, files are all in the printer share, but I have tested the donwload from several W9X clients. They start the Driver Installation Wizzard, instead of using the driver on the server. Driver download with W2K works fine. Attached is a small part of the samba log. I am sorry, but our mailer doesn't accept the log inline (because of some smtp commands?) Thank you very much. Greetings Hansjörg -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ [2003/01/15 15:17:08, 3] smbd/lanman.c:api_DosPrintQGetInfo(884) api_DosPrintQGetInfo: uLevel=52 name=HP2250 [2003/01/15 15:17:08, 3] smbd/lanman.c:get_printerdrivernumber(836) Can't determine number of printer driver files [2003/01/15 15:17:08, 3] smbd/lanman.c:api_DosPrintQGetInfo(918) api_DosPrintQGetInfo: Driver files count: 0 [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(656) printerdriver:hp2250: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(657) Driver:ADOBEPS4.DRV: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(658) Data File:hp2250.PPD: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(659) Language Monitor:PSMON.DLL: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(661) lp_driverlocation:\\PRINTSERVER2\print$\WIN40\0: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(664) Data Type:RAW: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(665) Help File:ADOBEPS4.HLP: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(679) fill_printq_info on hp2250 gave 0 entries [2003/01/15 15:17:09, 3] smbd/process.c:process_smb(878) Transaction 16 of length 39
Printer Driver Donwload with Win9X (Adobe driver/cupsaddsmb) cups-1.1.18,samba-2.2.7]
Hi, printer driver download with W2000/Xp (samba-2.2.7 and cups-1.1.18) and the Adobe PS Driver works fine for our location. But when I try to download a driver with W9X the driver installation widzard starts. Samba logs the following messages... (Cant determine number of printer driver files...) (see second apandix) The installation of the driver works with no error. (see first apendix) Has anyone successfully installed the W9X Adobe Driver? Thank you very much Hansjörg Running command: smbclient //localhost/print\$ -N -U'root%XXX%' -c 'mkdir W32X86;put /var/spool/cups/tmp/3e256bfa5c7d8 W32X86/hp2250.PPD;put /usr/share/cups/drivers/ADOBEPS5.DLL W32X86/ADOBEPS5.DLL;put /usr/share/cups/drivers/ADOBEPSU.DLL W32X86/ADOBEPSU.DLL;put /usr/share/cups/drivers/ADOBEPSU.HLP W32X86/ADOBEPSU.HLP' added interface ip=129.247.181.169 bcast=129.247.181.255 nmask=255.255.255.0 added interface ip=127.0.0.1 bcast=127.255.255.255 nmask=255.0.0.0 Domain=[NTROBOTIC] OS=[Unix] Server=[Samba 2.2.7] NT_STATUS_OBJECT_NAME_COLLISION making remote directory \W32X86 putting file /var/spool/cups/tmp/3e256bfa5c7d8 as \W32X86/hp2250.PPD (787.4 kb/s) (average 787.4 kb/s) putting file /usr/share/cups/drivers/ADOBEPS5.DLL as \W32X86/ADOBEPS5.DLL (1732.1 kb/s) (average 1597.1 kb/s) putting file /usr/share/cups/drivers/ADOBEPSU.DLL as \W32X86/ADOBEPSU.DLL (1965.0 kb/s) (average 1688.9 kb/s) putting file /usr/share/cups/drivers/ADOBEPSU.HLP as \W32X86/ADOBEPSU.HLP (265.5 kb/s) (average 1467.1 kb/s) Running command: rpcclient localhost -N -U'root%XXX%' -c 'adddriver Windows NT x86 hp2250:ADOBEPS5.DLL:hp2250.PPD:ADOBEPSU.DLL:ADOBEPSU.HLP:NULL:RAW:NULL' cmd = adddriver Windows NT x86 hp2250:ADOBEPS5.DLL:hp2250.PPD:ADOBEPSU.DLL:ADOBEPSU.HLP:NULL:RAW:NULL Printer Driver hp2250 successfully installed. Running command: smbclient //localhost/print\$ -N -U'root%XXX%' -c 'mkdir WIN40;put /var/spool/cups/tmp/3e256bfa5c7d8 WIN40/hp2250.PPD;put /usr/share/cups/drivers/ADFONTS.MFM WIN40/ADFONTS.MFM;put /usr/share/cups/drivers/ADOBEPS4.DRV WIN40/ADOBEPS4.DRV;put /usr/share/cups/drivers/ADOBEPS4.HLP WIN40/ADOBEPS4.HLP;put /usr/share/cups/drivers/DEFPRTR2.PPD WIN40/DEFPRTR2.PPD;put /usr/share/cups/drivers/ICONLIB.DLL WIN40/ICONLIB.DLL;put /usr/share/cups/drivers/PSMON.DLL WIN40/PSMON.DLL;' added interface ip=129.247.181.169 bcast=129.247.181.255 nmask=255.255.255.0 added interface ip=127.0.0.1 bcast=127.255.255.255 nmask=255.0.0.0 Domain=[NTROBOTIC] OS=[Unix] Server=[Samba 2.2.7] NT_STATUS_OBJECT_NAME_COLLISION making remote directory \WIN40 putting file /var/spool/cups/tmp/3e256bfa5c7d8 as \WIN40/hp2250.PPD (691.0 kb/s) (average 691.0 kb/s) putting file /usr/share/cups/drivers/ADFONTS.MFM as \WIN40/ADFONTS.MFM (1437.6 kb/s) (average 1354.4 kb/s) putting file /usr/share/cups/drivers/ADOBEPS4.DRV as \WIN40/ADOBEPS4.DRV (1449.5 kb/s) (average 1417.7 kb/s) putting file /usr/share/cups/drivers/ADOBEPS4.HLP as \WIN40/ADOBEPS4.HLP (1199.4 kb/s) (average 1390.1 kb/s) putting file /usr/share/cups/drivers/DEFPRTR2.PPD as \WIN40/DEFPRTR2.PPD (280.4 kb/s) (average 1356.5 kb/s) putting file /usr/share/cups/drivers/ICONLIB.DLL as \WIN40/ICONLIB.DLL (1955.2 kb/s) (average 1378.4 kb/s) putting file /usr/share/cups/drivers/PSMON.DLL as \WIN40/PSMON.DLL (602.1 kb/s) (average 1336.0 kb/s) Running command: rpcclient localhost -N -U'root%XXX%' -c 'adddriver Windows 4.0 hp2250:ADOBEPS4.DRV:hp2250.PPD:NULL:ADOBEPS4.HLP:PSMON.DLL:RAW:ADOBEPS4.DRV,hp2250.PPD,ADOBEPS4.HLP,PSMON.DLL,ADFONTS.MFM,DEFPRTR2.PPD,ICONLIB.DLL' cmd = adddriver Windows 4.0 hp2250:ADOBEPS4.DRV:hp2250.PPD:NULL:ADOBEPS4.HLP:PSMON.DLL:RAW:ADOBEPS4.DRV,hp2250.PPD,ADOBEPS4.HLP,PSMON.DLL,ADFONTS.MFM,DEFPRTR2.PPD,ICONLIB.DLL Printer Driver hp2250 successfully installed. [2003/01/15 15:17:08, 3] smbd/lanman.c:api_DosPrintQGetInfo(884) api_DosPrintQGetInfo: uLevel=52 name=HP2250 [2003/01/15 15:17:08, 3] smbd/lanman.c:get_printerdrivernumber(836) Can't determine number of printer driver files [2003/01/15 15:17:08, 3] smbd/lanman.c:api_DosPrintQGetInfo(918) api_DosPrintQGetInfo: Driver files count: 0 [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(656) printerdriver:hp2250: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(657) Driver:ADOBEPS4.DRV: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(658) Data File:hp2250.PPD: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(659) Language Monitor:PSMON.DLL: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(661) lp_driverlocation:\\PRINTSERVER2\print$\WIN40\0: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(664) Data Type:RAW: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(665) Help File:ADOBEPS4.HLP: [2003/01/15 15:17:08, 3] smbd/lanman.c:fill_printq_info_52(679) fill_printq_info on hp2250 gave 0 entries [2003/01/15 15:17:09, 3] smbd/process.c:process_smb(878) Transaction 16 of length 39 root at wertach:/usr/local/samba/printers/WIN40# ll
[Samba] cups Printer Driver Donwload with Win9X (Adobe driver/cupsaddsmb) cups-1.1.18, samba-2.2.7
/share/cups/drivers/ total 5960 drwxr-xr-x 2 root other512 Oct 23 15:27 ./ dr-xr-xr-x 11 root sys 512 Oct 23 15:25 ../ -rwxr-xr-x 1 root other 575573 Oct 24 10:21 ADFONTS.MFM* -rwxr-xr-x 1 root other1297280 Oct 24 10:21 ADOBEPS4.DRV* -rwxr-xr-x 1 root other 233348 Oct 24 10:21 ADOBEPS4.HLP* -rwxr-xr-x 1 root other 457600 Oct 24 10:21 ADOBEPS5.DLL* -rwxr-xr-x 1 root other 201216 Oct 24 10:21 ADOBEPSU.DLL* -rwxr-xr-x 1 root other 20121 Oct 24 10:21 ADOBEPSU.HLP* -rwxr-xr-x 1 root other 13493 Oct 24 10:21 DEFPRTR2.PPD* -rwxr-xr-x 1 root other 118128 Oct 24 10:21 ICONLIB.DLL* -rwxr-xr-x 1 root other 57344 Oct 24 10:21 PSMON.DLL* root at wertach:/usr/local/samba/printers/WIN40# ll total 1554 drwxr-xr-x 3 root other512 Jan 15 15:15 ./ drwxrwxrwx 4 root other512 Oct 24 10:39 ../ drwxr-xr-x 2 root other512 Jan 15 15:15 0/ -rwxr--r-- 1 root other 575573 Jan 15 15:15 ADFONTS.MFM* -rwxr--r-- 1 root other 13493 Jan 15 15:15 DEFPRTR2.PPD* -rwxr--r-- 1 root other 118128 Jan 15 15:15 ICONLIB.DLL* -rwxr--r-- 1 root other 57344 Jan 15 15:15 PSMON.DLL* root at wertach:/usr/local/samba/printers/WIN40# ll 0/ total 3920 drwxr-xr-x 2 root other512 Jan 15 15:15 ./ drwxr-xr-x 3 root other512 Jan 15 15:15 ../ -rwxr--r-- 1 root other1297280 Jan 15 15:15 ADOBEPS4.DRV* -rwxr--r-- 1 root other 233348 Jan 15 15:15 ADOBEPS4.HLP* -rwxr--r-- 1 root other 39172 Jan 15 15:14 coltekps.PPD* -rwxr--r-- 1 root other 34672 Jan 15 15:14 hp2250.PPD* -rwxr--r-- 1 root other 49602 Jan 15 15:14 hp2500C.PPD* -rwxr--r-- 1 root other 51531 Jan 15 15:14 hp4050.PPD* -rwxr--r-- 1 root other 36307 Jan 15 15:14 hp5000.PPD* -rwxr--r-- 1 root other 36304 Jan 15 15:15 hp5000hf.PPD* -rwxr--r-- 1 root other 24702 Jan 15 15:15 hp5m.PPD* -rwxr--r-- 1 root other 35462 Jan 15 15:15 hp5si.PPD* -rwxr--r-- 1 root other 63936 Jan 15 15:15 hp8000.PPD* -rwxr--r-- 1 root other 51534 Jan 15 15:15 inshp4050.PPD* -rwxr--r-- 1 root other 18770 Jan 15 15:15 magic.PPD* -- _ Dr. Hansjoerg Maurer | LAN- System-Manager | Deutsches Zentrum | DLR Oberpfaffenhofen f. Luft- und Raumfahrt e.V. | Institut f. Robotik | Postfach 1116 | Muenchner Strasse 20 82230 Wessling | 82234 Wessling Germany | | Tel: 08153/28-2431 | E-mail: [EMAIL PROTECTED] Fax: 08153/28-1134 | WWW: http://www.robotic.dlr.de/ __ -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba
Problem viewing printer properties with WinXP and samba-2.2.5-pre1
Hi, I am running XP with samba-2.2.5-pre1 as Domain Controller, print and file server with CUPS-1.1.15 . When I am trying to the DISPLAY Printer Properties of my HP 2100 TN, XP shows an error message like (translated from german): Properties clould not be displayed, procedure could not be finished. Using NT4.0 on the client side, everything works fine. The samba log is attached. Thank you Hansjoerg [2002/06/14 14:37:59, 3] smbd/sec_ctx.c:set_sec_ctx(314) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 [2002/06/14 14:37:59, 3] smbd/sec_ctx.c:set_sec_ctx(319) 8 user groups: 0 1 2 3 4 6 10 503 [2002/06/14 14:37:59, 3] rpc_server/srv_lsa_hnd.c:close_policy_hnd(205) Closed policy [2002/06/14 14:37:59, 3] rpc_server/srv_lsa_hnd.c:close_policy_hnd(205) Closed policy [2002/06/14 14:37:59, 0] rpc_client/cli_pipe.c:rpc_api_pipe(359) cli_pipe: return critical error. Error was NT_STATUS_INVALID_PIPE_STATE [2002/06/14 14:37:59, 0] rpc_server/srv_spoolss_nt.c:srv_spoolss_replycloseprinter(186) srv_spoolss_replycloseprinter: reply_close_printer failed [DOS code 0x001f]. [2002/06/14 14:37:59, 3] smbd/process.c:process_smb(866) Transaction 43 of length 43 [2002/06/14 14:37:59, 3] smbd/process.c:switch_message(673) switch message SMBulogoffX (pid 18526) [2002/06/14 14:37:59, 3] smbd/sec_ctx.c:set_sec_ctx(314) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstr. 10 D-80335 Muenchen Ph/Fax +49 89 52 04 68-41/-59
Printing Problem with 2.2.4 and CUPS -- {2227a280-3aea-1069-a2de-08002b30309d} is not a valid printer name
Hi, I am trying to print with Windows XP and Samba 2.2.4 under RH-7.2 (cups-1.1.14) Sometimes (I know, this isn't helpfull) Windows XP can't connect to the printer (Name: hp2100new) , even can't show the queue by doublecliking on the printer. The printer itself is shown The error mesasage in samba is: barolo (192.168.3.1) connect to service IPC$ as user printeruser (uid=500, gid=100) (pid 12804) [2002/05/12 09:37:50, 3] smbd/sec_ctx.c:set_sec_ctx(313) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 [2002/05/12 09:37:50, 3] smbd/reply.c:reply_tcon_and_X(395) tconX service=ipc$ user=printeruser [2002/05/12 09:37:50, 3] smbd/process.c:process_smb(866) Transaction 58 of length 102 [2002/05/12 09:37:50, 3] smbd/process.c:switch_message(673) switch message SMBtconX (pid 12804) [2002/05/12 09:37:50, 3] smbd/sec_ctx.c:set_sec_ctx(313) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 [2002/05/12 09:37:50, 3] smbd/service.c:find_service(142) checking for home directory ::{2227a280-3aea-1069-a2de-08002b30309d} gave (NULL) [2002/05/12 09:37:50, 3] smbd/service.c:find_service(157) checking whether ::{2227a280-3aea-1069-a2de-08002b30309d} is a valid printer name... [2002/05/12 09:37:50, 0] printing/print_cups.c:cups_printername_ok(290) Unable to get printer status for ::{2227a280-3aea-1069-a2de-08002b30309d} - client-error-not-found [2002/05/12 09:37:50, 3] smbd/service.c:find_service(169) ::{2227a280-3aea-1069-a2de-08002b30309d} is not a valid printer name [2002/05/12 09:37:50, 3] smbd/service.c:find_service(211) find_service() failed to find service ::{2227a280-3aea-1069-a2de-08002b30309d} [2002/05/12 09:37:50, 0] smbd/service.c:make_connection(251) barolo (192.168.3.1) couldn't find service ::{2227a280-3aea-1069-a2de-08002b30309d} [2002/05/12 09:37:50, 3] smbd/error.c:error_packet(106) error packet at smbd/reply.c(165) cmd=117 (SMBtconX) NT_STATUS_BAD_NETWORK_NAME [2002/05/12 09:37:57, 3] smbd/process.c:process_smb(866) Transaction 59 of length 95 [2002/05/12 09:37:57, 3] smbd/process.c:switch_message(673) switch message SMBntcreateX (pid 12804) [2002/05/12 09:37:57, 3] smbd/sec_ctx.c:set_sec_ctx(313) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 [2002/05/12 09:37:57, 3] smbd/sec_ctx.c:set_sec_ctx(319) 7 user groups: 0 1 2 3 4 6 10 [2002/05/12 09:37:57, 3] smbd/nttrans.c:nt_open_pipe(559) nt_open_pipe: Known pipe srvsvc opening. [2002/05/12 09:37:57, 3] smbd/process.c:process_smb(866) Transaction 60 of length 140 [2002/05/12 09:37:57, 3] smbd/process.c:switch_message(673) switch message SMBwriteX (pid 12804) [2002/05/12 09:37:57, 3] smbd/sec_ctx.c:set_sec_ctx(313) setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 [2002/05/12 09:37:57, 3] smbd/sec_ctx.c:set_sec_ctx(319) 7 user groups: 0 1 2 3 4 6 10 The error mesage from cups is: D [12/May/2002:09:37:50 +0200] AcceptClient() 3 from localhost.localdomain:631. D [12/May/2002:09:37:50 +0200] ReadClient() 3 POST / HTTP/1.1 E [12/May/2002:09:37:50 +0200] get_printer_attrs: resource name '/printers/::{2227a280-3aea-1069-a2de-08002b30309d}' no \good! D [12/May/2002:09:37:50 +0200] Sending error: client-error-not-found D [12/May/2002:09:37:50 +0200] CloseClient() 3 D [12/May/2002:09:38:36 +0200] mallinfo: arena = 760512, used = 725032, free = 35480 D [12/May/2002:09:39:36 +0200] mallinfo: arena = 760512, used = 725032, free = 35480 When I switch back to 2.2.2 it works (same smb.conf, same PrinterDriver File) If you need further Information, let me know.. Greetings Hansjoerg -- Dr. Hansjörg Maurer itsystems Deutschland AG Linprunstr. 10 D-80335 Muenchen Ph/Fax +49 89 52 04 68-41/-59
Re: Samba process hanging with 100% CPU load
Hi Noel I am able to kill this processes without any problem. I am testing 2.2.4pre as well in an test environment. But there (Murphy) the error never occurs (even not with 2.2.2) :-( Thank you hanjoerg Noel Kelly schrieb: I had this problem as well. Very nasty as the smbds are unkillable ? The best I can suggest is to try the 2.2.4pre version (or wait for the official release) as it seems by the far the most stable since 2.2.2 was released. I have not had one of these unkillables for a while now. Also I suspect a 2.4 kernel might be more adept at keeping these rogue processes under control. Noel