Re: [Samba] Is there a console tool to monitorcontrollognotify the print queue information?

2009-08-11 Thread Rodolphe

Le 10/08/2009 19:20, LiuYan 刘研 a écrit :


Thank you Johan for your reply!

I've already configured the web admin of CUPS, I even assign an 80 port to
it. What I do not want to use it is because of:
1. It can't show the correct document pages if windows clients print to
samba shared printer. it will always be 1 page.
2. It's not real-time enough, we need manually refresh/reload the page like
polling mode.
3. It's a web GUI which need a text browser to display it, and there are
other important management options on it.

Before I migrate to linux print server, I use a Windows 2000 Professional to
act as print server. Workmates know how to open the print/fax folder, view
the print queue, and cancel a print job on the win2000 print server. So I
want a similar simple management like that on a linux print server,
unfortunately, web-admin of CUPS does not fit that very well :(.



Johan Hendriks wrote:



I setup a central Fedora 11 printer server in a big office for 80+ windows
clients due to the max 10 connections limitation of windows 2000/xp. 2
physical printers are connected to the server, and I configured 3 CUPS
printers(1 printer with 2 different printer drivers) in Fedora 11.



Is there a console tool to
1. Monitor the print queue(s) in real-time like windows system? A history
windows hold some recent printed jobs information, and a real-time window
hold the current printing/queueing jobs information. The current
printing/queueing job information contains the information like windows
system provided such as: Document Name, Status, Owner, Pages, File Size,
Submit Time, Port.



2. Control the print queue(s). Everyone who stand in front of Fedora 11

can

cancel any print job.



3. Log the job informations. Log job information to database, especially

the

'Pages' and 'Owner' info of a job, so that I get a total Pages/Papers
consumed in a month. CUPS can't provide a correct Pages value if job comes

from Samba.


4. Notify the Owner when the job is finished via windows messenger
mechanism. Many workmates(especially workmates from HR department) often
print documents which have hundreds of pages. Their office is 30+ meters

far

from the printer, they rarely watch the print queue in their windows

workstation, and watching a 'hundreds of pages' print job is boring. So,

if

owner can be notified when print job is finished, it will be very
convenient. (hmmm, it's a weird idea that job information been notified

via

windows messenger mechanism, but windows messenger service comes with
windows 2000+ system, so client users don't need install other softwares

to

receive notification.)



ps:
(1). the printer server is an old computer (Celeron 900MHz, 128M+32M
memory), so it's not good to run GUI desktop.
(2). Document name contains Chinese characters, all I know is: there's an
open source project named zhCon to deal the display/input of
Chinese/Japanese/Korean characters in text console mode. And the encoding

of

zhCon may be different to the linux system (I mean, the linux system may
have LANG=en_US.UTF-8, but zhCon may working with zh_CN.GBK), so the
encoding can be configurable.



:working:
If there's no such a tool, can anybody guide me how to get these print

queue

information from Samba?



Any hint will be appreciated! :)


Can't you use the webbased frontend of CUPS
Like http://your-printserver:631/admin

You need to edit the cups config file to allow other machine's other then
localhost to acces the web gui.

Here you find some info
http://www.cups.org/doc-1.1/sam.html#5_3

regards,
Johan



No virus found in this outgoing message.
Checked by AVG - www.avg.com
Version: 8.5.392 / Virus Database: 270.13.49/2293 - Release Date: 08/09/09
18:10:00
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba





Hi,

Under GNOME see the gnome-cups-manager package, and if you want try to 
accounting your jobs, maybe the pykota suite or just the pkpgcounter 
tool.


Regards,

Rodolphe

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

[Samba] Re : Samba/Winbind slow with Active Directory (Hoogstraten, Ton)

2007-06-04 Thread Rodolphe A.

How many entries ?

TDB Database is limited 250 users.

--

Rodolphe

-- Message transféré --
From: Hoogstraten, Ton [EMAIL PROTECTED]
To: samba@lists.samba.org
Date: Sun, 3 Jun 2007 16:08:06 +0200
Subject: [Samba] Samba/Winbind slow with Active Directory
Hi all,

I'm looking for answers regarding a problem I'm having with Samba. Since
a year our Samba fileserver is part of out worldwide corporate Active
Directory. Before that Samba was part of our local NT4 domain. Since the
change to Active Directory the Samba server became slower and sometimes
does not respond at all to share requests.
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] RE : Samba/Winbind slow with Active Directory (Hoogstraten, Ton)

2007-06-04 Thread Rodolphe A.

If you using Ldap, no limited for entries. (5000 tested)

But, have you enable log on openldap ?

It is may be the problem...

Could you monitored CPU, SWAP, Interfaces on the server ?



--


Rodolphe
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Issue joining a PC to a Samba domain from a subnet otherthe one that Samba PDC

2007-04-01 Thread Rodolphe A.
Hello,

Please, enable log in samba server
And check log for ip/name workstation.



Rodolphe

-Message d'origine-
De : powderskier9 @hotmail.com [mailto:[EMAIL PROTECTED] 
Envoyé : samedi 31 mars 2007 16:53
À : samba@lists.samba.org
Objet : [Samba] Issue joining a PC to a Samba domain from a subnet otherthe
one that Samba PDC 

Hello,

Thanks in advance for taking the time to look at this issue. We are 
currently experiencing an issue with PC's not being able to join a Samba PDC

controlled domain when the PC's are located outside of the subnet that the 
Samba PDC is part of. The PC's are located in the same physical building as 
the PDC, connecting over a Cisco VLAN to the Samba PDC subnet. For example, 
the PDC is part of the 192.168.1.x subnet and the client PC is part of 
192.168.70.x . subnet.  If the client tries to join the domain from this 
network segment, then error message;

Logon failure: unknown username or bad password

will appear on the client end. The client PC's are Windows XP SP2 systems. 
They have File  Printer sharing enabled, disabled Windows Firewall, 
disabled 3 digital signing policies. These same PC settings will work in 
respect to joining the domain when I am wired into the same network segment 
as the PDC. However, once the same PC is moved out of the server subnet, 
then the domain join will fail. I have read a posting on this on the Samba 
list which recommends removing the loopback address as a resolution. Can 
anyone please explain why this would resolve this problem?

We are currently running the following setup on the PDC;

OS=Suse Linux Server version 9.1
Server=Samba 3.0.20b-3.4
Linux Kernel   =Linux version 2.6.5-7.97-smp

I have tried to add an lmhosts entry(ie.129.x.x.x Cancer #PRE #DOM:cruk) to 
the PC's that are not on the same subnet as the PDC, and the problem still 
appears to occur.

If anyone could please provide some insight to the cause of this problem and

how it can be resolve, I would appreciate it.

Thanks,

Mark

_
http://local.live.com/?mkt=en-ca/?v=2cid=A6D6BDB4586E357F!399



--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Relationship between 2 PDC Samba and ACL

2007-02-26 Thread Rodolphe A.

First solution find :
1 - start winbind
2 - test command #/usr/bin/wbinfo -s
S-1-5-21-1976411989-4095823373-4291834733-21003

Second problem, modify nsswitch.conf.

I am searching.


Rodolphe

Rodolphe A. [EMAIL PROTECTED] a écrit dans le message news:
[EMAIL PROTECTED]...

Hello,

 I have setup 2 PDC servers with samba 3.0.20b and openldap 2.2.24.
There is 2 Domains differents.

 Relationship is done.
 #net rpc trustdom list
 - result is perfect in two servers.
Connection from workstation with 1 user :
- result is perfect with the same user between two servers.

 But I face a problem with rules on share :
 - In server B (domain B), I am searching to add an ACL access on a
folder with  an user or a group on domain A.
 - method : with a workstation windows XP, click right on folder /

security

/
 add / domain A / Group / add / ok
 - message error in log samba :

 [2007/02/23 14:37:51, 0] smbd/posix_acls.c:create_canon_ace_lists(1405)
   create_canon_ace_lists: unable to map SID
S-1-5-21-1976411989-4095823373-4291834733-21003 to uid or gid.


 An idea ?

 Thanks.


 Rodolphe
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Relationship between 2 PDC Samba and ACL

2007-02-26 Thread Rodolphe A.

And solution has found :

1-
/etc/nsswitch.conf
passwd: files ldap winbind
shadow: files ldap
group:  files ldap winbind
[..]

2-
/etc/samba/smb.conf
idmap uid = 1-2
idmap gid = 1-2

3-
start winbind

4- test
/usr/bin/wbinfo -u

5- update ACL
by windows xp client from share samba.



Rodolphe

2007/2/26, Rodolphe A. [EMAIL PROTECTED]:


First solution find :
1 - start winbind
2 - test command #/usr/bin/wbinfo -s
S-1-5-21-1976411989-4095823373-4291834733-21003

Second problem, modify nsswitch.conf.

I am searching.


Rodolphe

Rodolphe A. [EMAIL PROTECTED] a écrit dans le message news:
[EMAIL PROTECTED]...
 Hello,

  I have setup 2 PDC servers with samba 3.0.20b and openldap 2.2.24.
 There is 2 Domains differents.

  Relationship is done.
  #net rpc trustdom list
  - result is perfect in two servers.
 Connection from workstation with 1 user :
 - result is perfect with the same user between two servers.

  But I face a problem with rules on share :
  - In server B (domain B), I am searching to add an ACL access on a
 folder with  an user or a group on domain A.
  - method : with a workstation windows XP, click right on folder /
security
 /
  add / domain A / Group / add / ok
  - message error in log samba :

  [2007/02/23 14:37:51, 0] smbd/posix_acls.c:create_canon_ace_lists(1405)
create_canon_ace_lists: unable to map SID
 S-1-5-21-1976411989-4095823373-4291834733-21003 to uid or gid.


  An idea ?

  Thanks.


  Rodolphe
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Relationship between 2 PDC Samba and ACL

2007-02-24 Thread Rodolphe A.

Hello,

I have setup 2 PDC servers with samba 3.0.20b and openldap 2.2.24.
There is 2 Domains differents.

Relationship is done.
#net rpc trustdom list
- result is perfect in two servers.
Connection from workstation with 1 user :
- result is perfect with the same user between two servers.

But I face a problem with rules on share :
- In server B (domain B), I am searching to add an ACL access on a folder
with
an user or a group on domain A.
- method : with a workstation windows XP, click right on folder / security
/
add / domain A / Group / add / ok
- message error in log samba :

[2007/02/23 14:37:51, 0] smbd/posix_acls.c:create_canon_ace_lists(1405)
  create_canon_ace_lists: unable to map SID
S-1-5-21-1976411989-4095823373-4291834733-21003 to uid or gid.


An idea ?

Thanks.


Rodolphe
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: samba 3.0.20 + squid 2.5 : automatic logonwithinternetexplorer

2006-06-29 Thread Rodolphe A.
I can't found the good, sentence for conf squid.

any idea ?


Rodolphe A. [EMAIL PROTECTED] wrote in message
news:[EMAIL PROTECTED]
 after #net join
 Success in line command.I am searching the good sentence for
squid.confwith,
 or  not with that : --helper-protocol=squid-2.5-ntlmsspan idea ?Rodolphe
 A. [EMAIL PROTECTED] wrote in message
 news:[EMAIL PROTECTED] thanks for answer.
 
  my problem :
 
  after start winbind, i have tested
  #/usr/bin/ntlm_auth PARIS.VISEO.NET --username=root
  NT_STATUS_CANT_ACCESS_DOMAIN_INFO: NT_STATUS_CANT_ACCESS_DOMAIN_INFO
  (0xc0da)
 
  the server squid is samba pdc.
 
 
 
 
 
  Robert Schetterer [EMAIL PROTECTED] wrote in message
  news:[EMAIL PROTECTED]
   -BEGIN PGP SIGNED MESSAGE-
   Hash: SHA1
  
   Rodolphe A. schrieb:
hello,
   
samba is setup PDC with ldap
   
client : windows xp pro sp2
server : samba 3.0.20 + openldap 2.2 + squid 2.5stable14 +
squidGuard
   
is it possible to create an automatic logon with internet explorer ?
   
perhaps with ntlm_auth, but i can't find the good sentence.
   
   
thanks.
   
   
   
   
   Hi, i ve did right this and i works now perfekt for nearly a year.
   But you have many choises to realize this.
   The setup which will include all possible features with a smb pdc (
with
   ldap )is like this.
   If you use firefox or ie with the automatic search proxy setting
   the search to files like proxy.dat , proxy.pac
   wpad.dat on  a webserver on the gateway of the lokal network, these
   files held the data which where the browser will find the proxy.
   Additional you hav to have entries in you internal
   dns like
   wpad.tcpSRV 0 0 80 wpad
   wpadA   192.168.110.1
   TXT service:
   wpad:!http://intranet.gundk.intern:80/proxy.pac;
   and on the internal dhcp server
   like this
   option wpad code 252 = text;
   option wpad http://192.168.110.1/proxy.pac\n;;
   you can find faqs an doku about this on the squid side.
   I have implemented different groups
   in the win domain like wwwuser , which can join the internet via proxy
,
   and a group filteroveride to join directly www without using
   squidguard ( for admins etc ).
   So you can manage the groups out from usrmgr.
  
   so i have entries like this in squid.conf
  
   # user group which are allowed to access the internet in general
  
   auth_param ntlm program /usr/bin/ntlm_auth
   - --helper-protocol=squid-2.5-ntlmssp
 
 - --require-membership-of=S-1-5-21-3962140368-478742891-1658383817-3001
   auth_param basic program /usr/bin/ntlm_auth
   - --helper-protocol=squid-2.5-basic
 
 - --require-membership-of=S-1-5-21-3962140368-478742891-1658383817-3001
   auth_param basic children 5
  
   #   auth_param ntlm use_ntlm_negotiate on
   #   auth_param ntlm max_challenge_reuses 0
   auth_param ntlm max_challenge_lifetime 15 minutes
  
   auth_param basic realm Squid proxy-caching web server
   auth_param basic credentialsttl 2 hours
   acl user proxy_auth REQUIRED
   http_access allow user
  
   #pam auth agains a system group works here too (nss_ldap), we use it
to
   overide the redirector vor vips
  
   external_acl_type unix_group %LOGIN /usr/sbin/squid_unix_group -g
  wwwdirect
   acl direct external unix_group wwwdirect
   redirector_access deny direct
   always_direct allow direct
   http_access allow direct
  
   as you see i used the sid of the nt groups , cause their names didint
   work, to overide the squidgauard i use a system group which is tha
same
   as a nt group cause there is mapping over nss_ldap
   ( other setups may be better but this works )
  
   the i configured winbind to use the lokal smb pdc ( just join your own
   domain )...im not sure why i did this but i think it was a must with
   squid , squid must run with a user that is able to join the winbind
   socket ( see squid, samba doku )
   After all you need a few iptables rules to forbid bypass the proxy.
  
   note you cant use squid auth with a transparent proxy squid setup!
   But if you dont need auth and the group stuff
   a setup with a squid transparent proxy and iptables is much more easy
to
   implement  automatic filtering ( see squid faqs how to do this ), if
you
   do so you can only manage things with the source ip of the client
   computer  , but not by user name or group auth.
  
   ( dont copy and paste this , read the faqs )
   Best Regards
  
   - --
   Mit freundlichen Gruessen
   Best Regards
   Robert Schetterer
  
   robert_at_schetterer_dot_org
   Munich / Bavaria / Germany
   https://www.schetterer.org
   https://www.schetterer.com/public-gpg-robert-schetterer.key
   -BEGIN PGP SIGNATURE-
   Version: GnuPG v1.4.3 (MingW32)
  
   iD8DBQFEn6DeNxddAhXBw7QRAg3UAJ4rvf4cloRykMkbpWoyfEK+EEeRkQCfQB+s
   kf/FSvVp4RbIfgdY6pj1Hmw=
   =RYf+
   -END PGP SIGNATURE-
  
   --
   Diese Nachricht wurde auf Viren und andere gefährliche Inhalte

[Samba] Migration from AD2003 - Samba 3

2006-06-29 Thread Rodolphe A.
Hello,

Do you know a good/simple doc to use ADMT3 for migration all list user to
new domain.

My Migration is with a new domain, no the same domain.
(domain A - domain B)



Thanks
Rodolphe



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Migration from AD2003 - Samba 3

2006-06-29 Thread Rodolphe A.
first solution find :
MMC AD 2003 , Users , Export to csv



Rodolphe A. [EMAIL PROTECTED] wrote in message
news:[EMAIL PROTECTED]
 Hello,

 Do you know a good/simple doc to use ADMT3 for migration all list user to
 new domain.

 My Migration is with a new domain, no the same domain.
 (domain A - domain B)



 Thanks
 Rodolphe



 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Migration from AD2003 - Samba 3

2006-06-29 Thread Rodolphe A.
second solution find :
LDAP Account Manager
(util import by csv)


Rodolphe A. [EMAIL PROTECTED] wrote in message
news:[EMAIL PROTECTED]
 first solution find :
 MMC AD 2003 , Users , Export to csv



 Rodolphe A. [EMAIL PROTECTED] wrote in message
 news:[EMAIL PROTECTED]
  Hello,
 
  Do you know a good/simple doc to use ADMT3 for migration all list user
to
  new domain.
 
  My Migration is with a new domain, no the same domain.
  (domain A - domain B)
 
 
 
  Thanks
  Rodolphe
 
 
 
  --
  To unsubscribe from this list go to the following URL and read the
  instructions:  https://lists.samba.org/mailman/listinfo/samba
 



 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] usrmgr.exe group name could not be found error

2006-06-27 Thread Rodolphe A.
Hello,

I have the same problem this post :
http://marc.theaimsgroup.com/?l=sambam=114881731013700w=2

After read the solution,
What can i do for an production server on next week ?

samba 3.0.22 is stable version, anybody know if it fixed this bug.


thanks.
Rodolphe



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: usrmgr.exe group name could not be found error

2006-06-27 Thread Rodolphe A.
after Upgrade on 3.0.22(-17)
the bug is always present.

an idea ?


Rodolphe A. [EMAIL PROTECTED] wrote in message
news:[EMAIL PROTECTED]
 Hello,

 I have the same problem this post :
 http://marc.theaimsgroup.com/?l=sambam=114881731013700w=2

 After read the solution,
 What can i do for an production server on next week ?

 samba 3.0.22 is stable version, anybody know if it fixed this bug.


 thanks.
 Rodolphe



 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: usrmgr.exe group name could not be found error

2006-06-27 Thread Rodolphe
Hello,


Thanks for your answer. It may be a good idea.

But, this user has created by usrmgr.exe.

The primary group has a mapped group.



My new test :
-  create a user toto
-  create a global group internet-basic-a
-  edit the user toto and add this group.
-  Immediately : errors = users is not in this group.
-  Command execute by samba : smb_add_user_group: Running the
command `/usr/local/sbin/smbldap-groupmod -m test3 squid' gave 6
-   squid 
-  solution find : delete group, and re-create group internet


if I have more information, I will feedback.

perhaps a second chance for usrmgr...


Best regards.



note :
Samba: 3.0.20b
Openldap: 2.2.24
Smbldap-tools: 0.9.2
OS: SLES9 SP3


Rodolphe A. [EMAIL PROTECTED] a écrit dans le message de news:
[EMAIL PROTECTED]
 after Upgrade on 3.0.22(-17)
 the bug is always present.

 an idea ?


 Rodolphe A. [EMAIL PROTECTED] wrote in message
 news:[EMAIL PROTECTED]
  Hello,
 
  I have the same problem this post :
  http://marc.theaimsgroup.com/?l=sambam=114881731013700w=2
 
  After read the solution,
  What can i do for an production server on next week ?
 
  samba 3.0.22 is stable version, anybody know if it fixed this bug.
 
 
  thanks.
  Rodolphe
 
 
 
  --
  To unsubscribe from this list go to the following URL and read the
  instructions:  https://lists.samba.org/mailman/listinfo/samba
 



 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] samba 3.0.20 + squid 2.5 : automatic logon with internet explorer

2006-06-26 Thread Rodolphe A.
hello,

samba is setup PDC with ldap

client : windows xp pro sp2
server : samba 3.0.20 + openldap 2.2 + squid 2.5stable14 + squidGuard

is it possible to create an automatic logon with internet explorer ?

perhaps with ntlm_auth, but i can't find the good sentence.


thanks.




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: samba 3.0.20 + squid 2.5 : automatic logon with internetexplorer

2006-06-26 Thread Rodolphe A.
thanks for answer.

my problem :

after start winbind, i have tested
#/usr/bin/ntlm_auth PARIS.VISEO.NET --username=root
NT_STATUS_CANT_ACCESS_DOMAIN_INFO: NT_STATUS_CANT_ACCESS_DOMAIN_INFO
(0xc0da)

the server squid is samba pdc.





Robert Schetterer [EMAIL PROTECTED] wrote in message
news:[EMAIL PROTECTED]
 -BEGIN PGP SIGNED MESSAGE-
 Hash: SHA1

 Rodolphe A. schrieb:
  hello,
 
  samba is setup PDC with ldap
 
  client : windows xp pro sp2
  server : samba 3.0.20 + openldap 2.2 + squid 2.5stable14 + squidGuard
 
  is it possible to create an automatic logon with internet explorer ?
 
  perhaps with ntlm_auth, but i can't find the good sentence.
 
 
  thanks.
 
 
 
 
 Hi, i ve did right this and i works now perfekt for nearly a year.
 But you have many choises to realize this.
 The setup which will include all possible features with a smb pdc ( with
 ldap )is like this.
 If you use firefox or ie with the automatic search proxy setting
 the search to files like proxy.dat , proxy.pac
 wpad.dat on  a webserver on the gateway of the lokal network, these
 files held the data which where the browser will find the proxy.
 Additional you hav to have entries in you internal
 dns like
 wpad.tcpSRV 0 0 80 wpad
 wpadA   192.168.110.1
 TXT service:
 wpad:!http://intranet.gundk.intern:80/proxy.pac;
 and on the internal dhcp server
 like this
 option wpad code 252 = text;
 option wpad http://192.168.110.1/proxy.pac\n;;
 you can find faqs an doku about this on the squid side.
 I have implemented different groups
 in the win domain like wwwuser , which can join the internet via proxy ,
 and a group filteroveride to join directly www without using
 squidguard ( for admins etc ).
 So you can manage the groups out from usrmgr.

 so i have entries like this in squid.conf

 # user group which are allowed to access the internet in general

 auth_param ntlm program /usr/bin/ntlm_auth
 - --helper-protocol=squid-2.5-ntlmssp
 - --require-membership-of=S-1-5-21-3962140368-478742891-1658383817-3001
 auth_param basic program /usr/bin/ntlm_auth
 - --helper-protocol=squid-2.5-basic
 - --require-membership-of=S-1-5-21-3962140368-478742891-1658383817-3001
 auth_param basic children 5

 #   auth_param ntlm use_ntlm_negotiate on
 #   auth_param ntlm max_challenge_reuses 0
 auth_param ntlm max_challenge_lifetime 15 minutes

 auth_param basic realm Squid proxy-caching web server
 auth_param basic credentialsttl 2 hours
 acl user proxy_auth REQUIRED
 http_access allow user

 #pam auth agains a system group works here too (nss_ldap), we use it to
 overide the redirector vor vips

 external_acl_type unix_group %LOGIN /usr/sbin/squid_unix_group -g
wwwdirect
 acl direct external unix_group wwwdirect
 redirector_access deny direct
 always_direct allow direct
 http_access allow direct

 as you see i used the sid of the nt groups , cause their names didint
 work, to overide the squidgauard i use a system group which is tha same
 as a nt group cause there is mapping over nss_ldap
 ( other setups may be better but this works )

 the i configured winbind to use the lokal smb pdc ( just join your own
 domain )...im not sure why i did this but i think it was a must with
 squid , squid must run with a user that is able to join the winbind
 socket ( see squid, samba doku )
 After all you need a few iptables rules to forbid bypass the proxy.

 note you cant use squid auth with a transparent proxy squid setup!
 But if you dont need auth and the group stuff
 a setup with a squid transparent proxy and iptables is much more easy to
 implement  automatic filtering ( see squid faqs how to do this ), if you
 do so you can only manage things with the source ip of the client
 computer  , but not by user name or group auth.

 ( dont copy and paste this , read the faqs )
 Best Regards

 - --
 Mit freundlichen Gruessen
 Best Regards
 Robert Schetterer

 robert_at_schetterer_dot_org
 Munich / Bavaria / Germany
 https://www.schetterer.org
 https://www.schetterer.com/public-gpg-robert-schetterer.key
 -BEGIN PGP SIGNATURE-
 Version: GnuPG v1.4.3 (MingW32)

 iD8DBQFEn6DeNxddAhXBw7QRAg3UAJ4rvf4cloRykMkbpWoyfEK+EEeRkQCfQB+s
 kf/FSvVp4RbIfgdY6pj1Hmw=
 =RYf+
 -END PGP SIGNATURE-

 --
 Diese Nachricht wurde auf Viren und andere gefährliche Inhalte untersucht
 und ist - aktuelle Virenscanner vorausgesetzt - sauber.









 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/listinfo/samba



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] samba 3.0.20 + squid 2.5

2006-06-22 Thread Rodolphe
hello,

samba is setup PDC with ldap

client : windows xp pro sp2
server : samba 3.0.20 + openldap 2.2 + squid 2.5stable14 + squidGuard

is it possible to create a, automatic logon with internet explorer ?




thanks.



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba