RE: [Samba] Problems with Samba 3.0.20b and OS X 10.4.3 Clients

2005-12-04 Thread SAMBA
Dunno. I know macs use samba 2.0 which don't support smb signing. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jaccon Sent: Saturday, December 03, 2005 3:48 AM To: samba@lists.samba.org Subject: [Samba] Problems with Samba 3.0.20b and OS X 10.4.3

RE: [Samba] winbind auth using ADS with domain trusts

2005-12-04 Thread SAMBA
I would be interested in contributing, but I have oh so many questions, once I understand, I will document what I know. For myself, I am totally not interested in ANY NT style domain functionality, but rather full 100% pure Active Directory integration. I am now exploring PADL stuff and Kerberos

RE: [Samba] Problems with Samba 3.0.20b and OS X 10.4.3 Clients

2005-12-04 Thread Andrew Bartlett
On Sun, 2005-12-04 at 00:04 -0800, SAMBA wrote: Dunno. I know macs use samba 2.0 which don't support smb signing. I really don't see how this is relevant. Typically, the macs don't use Samba as a client, but instead use a derivative of the FreeBSD smbfs. I see no mention of SMB signing here,

RE: [Samba] Any downsides to using MS Services for Unix NIS server?

2005-12-04 Thread Andrew Bartlett
On Sat, 2005-12-03 at 23:57 -0800, SAMBA wrote: Other than NIS is extremely insecure, and anyone concerned with security would not use it. If you are using SFU, just use LDAP/Kerberos instead of NIS. You'll get the same results, but with more security. The main issues with NIS security

RE: [Samba] User and Groups Problem with ADS (Win2003) and Solaris 10

2005-12-04 Thread Andrew Bartlett
On Sat, 2005-12-03 at 23:38 -0800, SAMBA wrote: Do you need to configure PAM to authenticate through Kerberos? I don't think this is relevant: In general, Samba doesn't use PAM at all, and for the local login case (not the issue here), you probably want pam_winbindd. On the original

Re: [Samba] winbind cache time

2005-12-04 Thread Andrew Bartlett
On Mon, 2005-11-28 at 12:31 -0600, Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Adam Clark wrote: | http://lists.samba.org/archive/samba-technical/2003-February/027095.html | | Which confused me a bit. Ignore that mail. Out of date. | Is the argument

Re: [Samba] Problem with setting Normal attribute for a file owned by another user

2005-12-04 Thread Michael Gasch
are we speaking about MAC Excel or Windows Boxes only? we´ve had several issues with Office Mac, see [Samba] Mac OSX breaking POSIX rights with SMB/CIFS cheerz Oleg Starshinov wrote: Hi Everyone, We have a Samba 3.0.20b server running in a multi-user environment. There is a serveruser

Re: [Samba] winbind auth using ADS with domain trusts

2005-12-04 Thread John H Terpstra
On Sunday 04 December 2005 01:20, SAMBA wrote: I would be interested in contributing, but I have oh so many questions, once I understand, I will document what I know. For myself, I am totally not interested in ANY NT style domain functionality, but rather full 100% pure Active Directory

[Samba] netlogon problems

2005-12-04 Thread Eric Hines
Folks, I'm trying to achieve control over who logs into a share according to the group to which that person belongs, but with no luck. I'm running SUSE Pro 9.3 and Samba 3.0.13, with a Win2k machine on one subnet and an XP laptop on another subnet. In all cases, the user, instead of getting

Re: [Samba] Samba timekeeping

2005-12-04 Thread Andrew Bartlett
On Sat, 2005-12-03 at 12:57 +1100, taso wrote: Just wondering why Samba time and system time are different. Eg: # net time;date Sat Dec 3 12:56:57 2005 Sat Dec 3 12:56:22 EST 2005 Which server is 'net time' talking to? It should be looking for the PDC I think. If that's not the local

[Samba] net rpc vampire not working

2005-12-04 Thread Del
Hi, Can someone help me get net rpc vampire in one of its forms working. The objective is to migrate from an NT4 PDC to a SAMBA 3.0 PDC using LDAP as a back end. I am trying to migrate the user and machine accounts across in a lab environment, separate from the main network (I have replicated

[Samba] Admin Printers and Faxes from Windows XP

2005-12-04 Thread Will Wheatley
hi all, I have been stuffing around with thsi problem for a couple of weeks now, without much success :) I am sure i am missing something simple. I have a Samba server setup as a member server in a 2000 domain. (samba 3.0.10) Samba is printing through CUPS and the printing works fine. when i

[Samba] Samba Trusts Relationship - Users map

2005-12-04 Thread Eduardo Sousa
Sirs, I am studying about the Samba servers and I am with a doubt. I have achieved to configure the trust relationship between two servers, althought I could only log users that would exist in those two domains (trusting and thrusted). Observing the logs I have noticed that Samba could not

Re: [Samba] net rpc vampire not working

2005-12-04 Thread Craig White
On Mon, 2005-12-05 at 08:31 +1100, Del wrote: Hi, Can someone help me get net rpc vampire in one of its forms working. The objective is to migrate from an NT4 PDC to a SAMBA 3.0 PDC using LDAP as a back end. I am trying to migrate the user and machine accounts across in a lab

Re: [Samba] Samba Trusts Relationship - Users map

2005-12-04 Thread Eduardo Sousa
- Original Message - From: Craig White [EMAIL PROTECTED] To: Eduardo Sousa [EMAIL PROTECTED] Sent: Sunday, December 04, 2005 9:41 PM Subject: Re: [Samba] Samba Trusts Relationship - Users map On Sun, 2005-12-04 at 21:00 -0200, Eduardo Sousa wrote: Sirs, I am studying about the Samba

Re: [Samba] net rpc vampire not working

2005-12-04 Thread Del
Use http://www.samba.org/samba/docs/man/Samba-Guide/ntmigration.html Thanks, that is a great help. I have it working now. I would recommend that the user is familiar with setup, usage, maintenance of LDAP prior to doing this. Oh, LDAP is no problem. I'm the author of the LdapImport

Re: [Samba] net rpc vampire not working

2005-12-04 Thread Craig White
On Mon, 2005-12-05 at 12:25 +1100, Del wrote: Use http://www.samba.org/samba/docs/man/Samba-Guide/ntmigration.html Thanks, that is a great help. I have it working now. thought so - the detailed walk through used to be in the 'How-To' and gove moved to the 'by example' and whatever was

[Samba] Missing user in list of Windows 9x

2005-12-04 Thread Ricardo Chamorro
In a server Debian Sarge with Samba 3 PDC user security that spreads to LAN of 15 W9x/2000 clients, weeks ago the user Rick (with permissions of admin) disappeared of the list of users that is seen in the window Share of the Windows 9x clients (NOT in the W2K clients), reason why he cannot be

[Samba] Solaris Winbind causes problem with SSH.

2005-12-04 Thread Security Officer
Hello, I have been testing Samba 3.0.21 (rc1, rc2) on Solaris 8 and Solaris 9 compiled with ADS support. In my testing smbd seems to work with a Windows 2000 ADS and Windows XP workstations in a basic setup where winbindd is running in default mode netlogon proxy only (but winbind is NOT

svn commit: samba r12056 - in branches/SAMBA_4_0/source/auth/kerberos: .

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-04 12:17:02 + (Sun, 04 Dec 2005) New Revision: 12056 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12056 Log: Some clarification fixes for the keytab code, and use the right function for enctype to string. Andrew Bartlett

Build status as of Mon Dec 5 00:00:01 2005

2005-12-04 Thread build
URL: http://build.samba.org/ --- /home/build/master/cache/broken_results.txt.old 2005-12-04 00:00:09.0 + +++ /home/build/master/cache/broken_results.txt 2005-12-05 00:00:48.0 + @@ -1,17 +1,17 @@ -Build status as of Sun Dec 4 00:00:02 2005 +Build status as of Mon Dec

svn commit: samba r12057 - in branches/SAMBA_4_0/source/lib/ldb/tools: .

2005-12-04 Thread tridge
Author: tridge Date: 2005-12-05 00:43:50 + (Mon, 05 Dec 2005) New Revision: 12057 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12057 Log: fixed authentication in ldb client tools Modified: branches/SAMBA_4_0/source/lib/ldb/tools/cmdline.c Changeset:

svn commit: samba r12058 - in branches/SAMBA_4_0/source/auth: .

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-05 01:36:53 + (Mon, 05 Dec 2005) New Revision: 12058 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12058 Log: Set an anonymous fallback, if the machine account isn't available. Andrew Bartlett Modified:

svn commit: samba r12059 - in branches/SAMBA_4_0/source/auth/kerberos: .

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-05 01:38:26 + (Mon, 05 Dec 2005) New Revision: 12059 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12059 Log: Use random keytab names (so we get different keytabs, rather than share the MEMORY: keytab). Andrew Bartlett Modified:

svn commit: samba r12060 - in branches/SAMBA_4_0/source/auth: credentials gensec

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-05 03:20:40 + (Mon, 05 Dec 2005) New Revision: 12060 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12060 Log: Work towards allowing the credentials system to allow/deny certain GENSEC mechansims. This will allow a machine join to

svn commit: samba r12061 - in branches/SAMBA_4_0/source/auth/credentials: .

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-05 03:42:28 + (Mon, 05 Dec 2005) New Revision: 12061 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12061 Log: Add missing file to previous commit. This provides a hook on which to attach a restriction on available GENSEC

svn commit: samba r12062 - in branches/SAMBA_4_0/source/libcli/ldap: .

2005-12-04 Thread abartlet
Author: abartlet Date: 2005-12-05 04:10:13 + (Mon, 05 Dec 2005) New Revision: 12062 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12062 Log: SASL negotiation now requires a gensec_security context, so that we only try permitted mechanims. Andrew Bartlett

svn commit: samba r12063 - in branches/SAMBA_4_0/source/auth/kerberos: .

2005-12-04 Thread tridge
Author: tridge Date: 2005-12-05 06:01:22 + (Mon, 05 Dec 2005) New Revision: 12063 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12063 Log: fixed the krb5 client code to handle ICMP port unreachable errors, and error out immediatelly. This prevents a long timeout

svn commit: samba r12064 - in branches/SAMBA_4_0/source/auth/kerberos: .

2005-12-04 Thread tridge
Author: tridge Date: 2005-12-05 06:05:02 + (Mon, 05 Dec 2005) New Revision: 12064 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12064 Log: pass back the socket level error correctly (so we get NT_STATUS_CONNECTION_REFUSED when a KDC is not listening) Modified:

svn commit: samba r12065 - in branches/SAMBA_4_0/source/auth/credentials: .

2005-12-04 Thread metze
Author: metze Date: 2005-12-05 06:55:20 + (Mon, 05 Dec 2005) New Revision: 12065 WebSVN: http://websvn.samba.org/cgi-bin/viewcvs.cgi?view=revroot=sambarev=12065 Log: fix compiler warning metze Modified: branches/SAMBA_4_0/source/auth/credentials/credentials.h Changeset: Modified: