[Samba] wbinfo, wbinfo_group.pl, user missing from AD group

2013-04-04 Thread Kevin Blackwell
I'm not exactly sure how the mapping of uid, sid, maps to unix gid.

We're using the wbinfo_group.pl script for our squid deployment.

The issue I see is if I run the script, or a valid and a user that
isn't working. On my system it returns a GID.

Got 3kll Hardware from squid
Username 3kll
Groups Hardware
User:  -3kll-
Group: -Hardware-
SID:   -S-1-5-21-1607859618-1323328405-3834754132-2828-
GID:   -16777237-
Sending OK to squid
OK

Here's a failing one.


Got 3lsr Hardware from squid
Username 3lsr
Groups Hardware
User:  -3lsr-
Group: -Hardware-
SID:   -S-1-5-21-1607859618-1323328405-3834754132-2828-
GID:   -16777237-
Sending ERR to squid
ERR

So, I run a wbinfo -r on 3lsr

wbinfo -r 3lsr
16777217
16777221
16777222
16777277
16777279
16777230
16777232
16777267

GID 16777237 isn't listed.

It is listed in 3kll.

So, how do I get user 3lsr to report back that it's in group 16777237?

Thanks
--
Kevin Blackwell
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Winbind keeps failing after a week

2009-07-20 Thread Kevin Blackwell
Hello,

Currently I'm running FC11 with samba 3.0.STABLE15.

I'm using samba with squid to log NTLM authentication.

Well, just about every week, my /var/log/samba/log.wb-$DOMAIN file
starts to get full with these lines.

[2009/07/09 07:11:24,  0]
rpc_client/cli_netlogon.c:rpccli_netlogon_set_trust_password(597)
  rpccli_netr_ServerPasswordSet2 failed: NT_STATUS_WRONG_PASSWORD

If i issue a

net ads join -U Administrator%password,

everything returns to normal. What i can't figure out is why the
authentication keeps falling over on a weekly basis.

Anyone have any ideas?

Kevin
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] getent group fails

2009-06-17 Thread Kevin Blackwell
Hi,

Well, I'll try to start at what I think the root of my problems are.

When I do a getent group, I only get a list of the BUILTIN groups.

BUILTIN+administrators
BUILTIN+users

But if I do a wbinfo -g, all the AD groups show up.

This alone is not the overall problem, but it is creating a problem
because I need getent to return the groups for logging different AD
groups to different log files in squid.

Another problem is the wbinfo_group.pl and I know this is a squid app,
but from what I understand it used wbinfo.

/usr/lib/squid/wbinfo_group.pl
tuser password
Could not get groups for user tuser

I can provice config data and anything else necessary.

Thanks in advance.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Migration to Samba from Windows 2000

2007-03-26 Thread Kevin Blackwell

OK,

I'm attempting to migrate from a Windows 2000 domain operating in
native mode to samba.

Yea, I know I'm screwed because Windows is operating in native mode,
but I know there has  got to be a way around it.

My first thought is to build another domain controller, have it join
the domain as a new forest. But now I seem to be running into the problem
of the DC server being in native mode and the new server being in
mixed mode. Anyone have any thoughts on that?

Actually, after that, I'm out of ideas. I can't use net rpc vampire
because windows is operating in native mode so that does not work.


I could possibly use an ldap browser and and export the information I
need, but little fuzzy on the info I need. I know from initial trials
that you can't simply export AD then do a import into ldap. That would
just be to simple anyways.

Anyways, any thoughts would be appreciated.

Thanks in advance folks.

Kevin
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Migration to Samba from Windows 2000

2007-03-26 Thread Kevin Blackwell

OK,

I'm attempting to migrate from a Windows 2000 domain operating in
native mode to samba.

Yea, I know I'm screwed because Windows is operating in native mode,
but I know there has  got to be a way around it.

My first thought is to build another domain controller, have it join
the domain as a new forest. Now I seem to be running into the problem
of the mail server being in native mode and the new server being in
mixed mode. Anyone have any thoughts on that?

Actually, after that, I'm out of ideas. I can't use net rpc vampire
because windows is operating in native mode and that does not work.

Thanks in advance folks.

Kevin
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba