[Samba] samba caching group memberships

2010-10-21 Thread Vladimir Vassiliev
Hi all, our setup is Samba 3.3 in W2K8 domain. It seems samba cache group memberships somewhere and after adding user to a new group it's necessary to relogin for that user to get new memberships. Is it possible to eliminate that nasty procedure? Thanks. -- Vladimir Vassiliev -- To

[Samba] Windows seven

2010-10-21 Thread Pascal Legrand
Hello, i'm using samba 3.2.5 on debian lenny. Our service have some windows 7 station. I saw on the wiki (http://wiki.samba.org/index.php/Windows7) that only Samba 3.4 and Samba 3.3 worked. Is there really no way to make work samba 3.2.5 (as domain controller)with windows 7. If not, what is the

[Samba] net ads printer publish ?

2010-10-21 Thread Hannu Tikka
Should that command work? I'm getting Unable to do enumdataex error. Samba version is 3.5.6, windows drivers are installed and cupsaddsmb command is done. Domain controller is samba4 git version less than month old. regards Hannu -- To unsubscribe from this list go to the following URL and read

Re: [Samba] samba caching group memberships

2010-10-21 Thread Brian Cowan
Actually, this group cache behavior is *Windows* behavior. Group membership is loaded at login time and not refreshed until you log out and back in. It's annoying @ times. Having been a Novell NetWare user in my ancient past, it was something of a shock to me too. Brian C. On Oct 21, 2010 2:35

Re: [Samba] Windows seven

2010-10-21 Thread Miguel Medalha
Is there really no way to make work samba 3.2.5 (as domain controller)with windows 7. No If not, what is the best way? use backport, compile the last samba version (wich version) or wait for the next debian version Very good quality, pre-compiled Enterprise Samba versions for several

Re: [Samba] Windows seven

2010-10-21 Thread Vladimir Psenicka
Dne 21.10.2010 11:50, Pascal Legrand napsal(a): Hello, i'm using samba 3.2.5 on debian lenny. Our service have some windows 7 station. I saw on the wiki (http://wiki.samba.org/index.php/Windows7) that only Samba 3.4 and Samba 3.3 worked. Is there really no way to make work samba 3.2.5 (as

Re: [Samba] Accented characters in share names

2010-10-21 Thread Moray Henderson
Nicolas Jungers wrote: I'm facing a problem that should be common but for which I don't find much info. I'm trying to smbmount some smb share served by a w2k3 server. I've no problem to mount the shares unless their name includes accented letters. I've successfully replaced the spaces in the

Re: [Samba] Windows seven

2010-10-21 Thread Olivier FONTES
On Thu, 21 Oct 2010 12:50:26 +0200, Vladimir Psenicka vladimir.pseni...@gmail.com wrote: Dne 21.10.2010 11:50, Pascal Legrand napsal(a): Hello, i'm using samba 3.2.5 on debian lenny. Our service have some windows 7 station. I saw on the wiki (http://wiki.samba.org/index.php/Windows7) that

Re: [Samba] Error was Transport endpoint is not connected

2010-10-21 Thread Moray Henderson
Inactivity timeout either on the NAS or somewhere else on the network? If the network connectivity is interrupted, that would break the backup and give a genuine transport endpoint error. Does changing the time of the job make any difference? Moray. To err is human. To purr, feline

Re: [Samba] samba caching group memberships

2010-10-21 Thread Vladimir Vassiliev
Thanks. Still not clear for me is it cached on SMB-server when SMB-client connects or on client when user logs in? 21.10.2010 14:20, Brian Cowan пишет: Actually, this group cache behavior is *Windows* behavior. Group membership is loaded at login time and not refreshed until you log out and

Re: [Samba] Upgrading Samba-LDAP

2010-10-21 Thread Clark Johnston
John Drescher wrote: I am looking to upgrade my Samba server to Samba 3.5.x from Samba 3.0.20 and openldap from 2.2.13 to 2.3.43. Is there anyway to do this and still keep my current domain intact? The interest in upgrading is so that we can suppport Win 7 systems. Of course you can keep

Re: [Samba] Broken support for Smart Card Logon in Windows 2003 and XP

2010-10-21 Thread Love Hörnquist Åstrand
17 okt 2010 kl. 20.31 skrev Николай Домуховский: 2010/10/7 Love Hörnquist Åstrand l...@kth.se: 6 okt 2010 kl. 02:49 skrev Michael Wood: hx509_cms_create_signed function and make sigctx.cmsidflag always equal CMS_ID_NAME) I think this failed because you are looking at enveloped data

[Samba] getpeername failed

2010-10-21 Thread David Dumortier
Hello all, I have a simple share on samba 3.2.5-4lenny13 defined like this : [global] workgroup = MYDOMAIN realm = MYDOMAIN.ORG server string = %h server security = ADS obey pam restrictions = Yes load printers = No idmap uid = 1-2

[Samba] Roaming profiles and delete files reappearing.

2010-10-21 Thread Andrea Venturoli
Hello. I see a lot of people having this problem, but found not solution so far. The setup: samba 3.0.37 on FreeBSD 7.3/i386 acting as PDC; a similar BDC (only amd64) and XP clients. Users have roaming profiles on the PDC. What happens is: _ a laptop user disconnects from the network (so the

[Samba] Roaming profiles and delete files reappearing.

2010-10-21 Thread Andrea Venturoli
Hello. I see a lot of people having this problem, but found not solution so far. The setup: samba 3.0.37 on FreeBSD 7.3/i386 acting as PDC; a similar BDC (only amd64) and XP clients. Users have roaming profiles on the PDC. What happens is: _ a laptop user disconnects from the network (so the

[Samba] Roaming profiles and delete files reappearing.

2010-10-21 Thread Andrea Venturoli
Hello. I see a lot of people having this problem, but found not solution so far. The setup: samba 3.0.37 on FreeBSD 7.3/i386 acting as PDC; a similar BDC (only amd64) and XP clients. Users have roaming profiles on the PDC. What happens is: _ a laptop user disconnects from the network (so the

[Samba] HELP Documentation for Installation of SAMBA

2010-10-21 Thread Sameer Chawnekar
HI, Can you please provide a step by step guide on installing and configuring SAMBA on AIX 6.1 server. Thanks Regards, Sameer -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Joining ubuntu client to samba domain

2010-10-21 Thread snowman5840
Hi I have installed a smba pdc with openLDAP. With windows clients i can use it without problems (join the domain, login with users ). But i can't join the domain with my ubuntu client 10.04. I have try this to join: sudo net join -W firma1 -U administrator but i get the following error:

[Samba] too many queued ntlmauthenticator requests and squid failed

2010-10-21 Thread Tharanga Abeyseela (RGA)
Hi Guys, I have been running squid with AD authentication and security group authentication for the last 6 months, and suddenly squid failed with the following error message (squid): Too many queued ntlmauthenticator requests. (I tried to start squid in a off peak time there were only 35

Re: [Samba] Windows seven

2010-10-21 Thread Pascal Legrand
THanks for your answers. But what about dependancy ? when i install samba (and only samba) from backports, does the system install also dependancy from backports ? what about the system stability? sorry but i'm not very strong with backports use thanks again --

Re: [Samba] Windows seven

2010-10-21 Thread Vladimir Psenicka
Dne 21.10.2010 13:50, Pascal Legrand napsal(a): THanks for your answers. But what about dependancy ? when i install samba (and only samba) from backports, does the system install also dependancy from backports ? Yes what about the system stability? It works :-) sorry but i'm not very

Re: [Samba] Change password via ctrl+alt+del

2010-10-21 Thread Willy Offermans
Hello Samba Friends, I'm using openldap as well. The users can change the password with ctrl+alt+del. However the parameter ``sambaPwdCanChange'' is set to 0. So this can not be the only trick. On Tue, Oct 12, 2010 at 08:03:28AM +0200, Daniel Müller wrote: If you are with openldap You need to

[Samba] getent group fails on member server after upgrade to 3.5.5

2010-10-21 Thread Neil Price
I have a member server joined to a samba 3 domain. It was working fine with 3.4.8 but after an upgrade to 3.5.5 (debian lenny with backports) getent group no longer works. getent passwd works fine, wbinfo -u and wbinfo -g work fine I upgraded some other servers which are DC's and those work

Re: [Samba] samba caching group memberships

2010-10-21 Thread Volker Lendecke
On Thu, Oct 21, 2010 at 03:26:12PM +0400, Vladimir Vassiliev wrote: Thanks. Still not clear for me is it cached on SMB-server when SMB-client connects or on client when user logs in? That depends on whether you are using Kerberos or NTLM. With Kerberos, you have to re-login to the client. With

Re: [Samba] samba caching group memberships

2010-10-21 Thread Brian Cowan
I think you'll find that the answer can be both. But, only during the context of that connection to the samba server. This is because the client sends its authentication info to the server when it connects. I don't really know if/when the samba server verifies group membership on the domain

Re: [Samba] Revisit - Re: Default Hidden Disk Shares

2010-10-21 Thread Robert Moskowitz
On 10/21/2010 12:42 AM, Jeremy Allison wrote: On Wed, Oct 20, 2010 at 10:29:41PM -0400, Robert Moskowitz wrote: I want admin to be able to access other user data to clean up any messes they have. Kind of standard here at home with my kids getting into challenges and asking for help. Or they

Re: [Samba] HELP Documentation for Installation of SAMBA

2010-10-21 Thread John Doe
From: Sameer Chawnekar sameer.chawne...@archpharmalabs.com Can you please provide a step by step guide on installing and configuring SAMBA on AIX 6.1 server. http://tinyurl.com/2egmh99 JD -- To unsubscribe from this list go to the following URL and read the instructions:

[Samba] INCLUDEs in smb.conf

2010-10-21 Thread Robert Moskowitz
Do I need a separate INCLUDE in each section, or can I have one INCLUDE at the end and just include needed sections? Way 1: smb.conf: [Global] ... INCLUDE smb-global.conf [netlogon] .. smb-global.conf: sambaPwdCanChange=1 Way 2: smb.conf: [Global] ... [netlogon]

Re: [Samba] Roaming profiles and delete files reappearing.

2010-10-21 Thread John Doe
From: Andrea Venturoli m...@netfence.it What happens is: _ a laptop user disconnects from the network (so the local and server profiles are fully synchronized); _ at home [s]he deletes some files; _ back in the office, he connects to the net and logons; _ Windows copies everything

[Samba] Samba Move preserve ACL

2010-10-21 Thread kikxxladmin
Hello, we had some trouble with moving files on a Samba share. We have one share with many subfolders and acl on each folder, when i move a file into another subfolder the file keeps the permissions of the first folder. I as a network administrator know that this is a normal behavior but our

Re: [Samba] INCLUDEs in smb.conf

2010-10-21 Thread Jefferson Diego Gomes
As I know, includes on Samba are like includes at Apache: You don't need to separete in sections, because each include has it own section. I don't know if you Way 1 will work, but Way 2 will. I always do something like: [global] INCLUDE share.adm.conf INCLUDE share.people.conf

Re: [Samba] INCLUDEs in smb.conf

2010-10-21 Thread Robert Moskowitz
On 10/21/2010 11:49 AM, Jefferson Diego Gomes wrote: As I know, includes on Samba are like includes at Apache: Now that actually makes sense! I have little experience editing includes in Apache, but lots in Asterisk. You don't need to separete in sections, because each include has it

Re: [Samba] Samba - Rejecting auth request debug log

2010-10-21 Thread Martin Hochreiter
and maybe somebody can have a look at it and elighten us. Your log seems to have been stripped from the message. Yes - thats right, you can find it here too https://bugzilla.samba.org/show_bug.cgi?id=7678 -- To unsubscribe from this list go to the following URL and read the instructions:

[Samba] Trusted domain users unwantedly mapping onto local domain users

2010-10-21 Thread Bruce Richardson
Having set up two way trust between a Samba domain (with LDAP backend) and an AD domain, I find that 1. Users from the trusted domain are authenticated against the proper DC (that is, their regular password works), but only if there is a corresponding local domain user. 2. Users from the

Re: [Samba] Revisit - Re: Default Hidden Disk Shares

2010-10-21 Thread Jeremy Allison
On Thu, Oct 21, 2010 at 11:05:57AM -0400, Robert Moskowitz wrote: On 10/21/2010 12:42 AM, Jeremy Allison wrote: On Wed, Oct 20, 2010 at 10:29:41PM -0400, Robert Moskowitz wrote: I want admin to be able to access other user data to clean up any messes they have. Kind of standard here at home

Re: [Samba] INCLUDEs in smb.conf

2010-10-21 Thread Helmut Hullen
Hallo, Robert, Du meintest am 21.10.10: Do I need a separate INCLUDE in each section, or can I have one INCLUDE at the end and just include needed sections? include replaces the calling line with the lines of the invoked file. You can put many include lines into the smb.conf. At nearly(?)

Re: [Samba] getent group fails on member server after upgrade to 3.5.5

2010-10-21 Thread Dale Schroeder
Neil, Winbind 3.5.5 is not working properly in Squeeze either. Using idmap backend rid with ads security, It will work for a while, but eventually becomes unresponsive. I tried to report this yesterday, but I assume the zipped log file I attached caused it to be rejected. I tried 3.5.6 on

Re: [Samba] Guest shares in an ADS security model

2010-10-21 Thread Madhusudan Singh
Hello, I have no control over the active directory. I just authenticate a subset of its members to give them access to the fileserver. Does this mean that there is no true guest access when using ADS ? On Wed, Oct 20, 2010 at 3:34 PM, Michael Wood esiot...@gmail.com wrote: On 20 October

[Samba] file locking on linux samba with mac osx and windows have no function?

2010-10-21 Thread Joris Heinrich
hallo list, I have the following problem: smb.conf [global] server string = file1.int.stayfriends.de unix extensions = No socket options = SO_KEEPALIVE TCP_NODELAY IPTOS_LOWDELAY dns proxy = No ldap ssl = no read only = No create mask =

Re: [Samba] INCLUDEs in smb.conf

2010-10-21 Thread Michael Wood
On 21 October 2010 17:19, Robert Moskowitz r...@htt-consult.com wrote: Do I need a separate INCLUDE in each section, or can I have one INCLUDE at the end and just include needed sections? Way 1: smb.conf: [Global] ... INCLUDE smb-global.conf Note that the syntax is: include =

Re: [Samba] Guest shares in an ADS security model

2010-10-21 Thread Michael Wood
On 21 October 2010 20:54, Madhusudan Singh singh.madhusu...@gmail.com wrote: Hello, I have no control over the active directory. I just authenticate a subset of its members to give them access to the fileserver. Does this mean that there is no true guest access when using ADS ? I do not

Re: [Samba] Trusted domain users unwantedly mapping onto local domain users

2010-10-21 Thread Gaiseric Vandal
I have similar issues. II am running Samba 3.4 (compiled from source) on Solaris 10- so selinux is NOT an issue for me. Otherwise I have similar config (LDAP backend for samba, trusted domains to windows 2003 server.) thought this used to work but a month or so ago it wasn't. getent

Re: [Samba] Trusted domain users unwantedly mapping onto local domain users

2010-10-21 Thread Bruce Richardson
On Thu, Oct 21, 2010 at 05:02:55PM -0400, Gaiseric Vandal wrote: I have not tried ssh'ing in as a trusted domain user (I definately don't want that available..) It's not something I want to make available, but it was an important test to prove that winbind was creating the correct idmap

Re: [Samba] Samba Move preserve ACL

2010-10-21 Thread Miguel Medalha
I as a network administrator know that this is a normal behavior but our users don't get it :( So i need a solution. I heard that there is the possibility to bypass this with a VFS module As a network administrator, your best solution is to inform your users instead of going along with bad

Re: [Samba] Trusted domain users unwantedly mapping onto local domain users

2010-10-21 Thread Gaiseric Vandal
Re ssh - I should try that. Windows 2003 Native mode- you can't have NT4 BDC's in the domain. Trusts with NT4 domains are OK (at least should be.) Samba (as a PDC) emulates an NT4 domain but still seems to use kerberos for locating DC's (which would make sense if you want it to be an

[Samba] Slow Samba over VPN

2010-10-21 Thread Colin Reese
Hello. I have Samba on Ibex running over VPN, and am having problems with speed reading and writing from XP and 7 boxes. It takes, for example, 16 minutes to transfer four files for a total of 1.2MB. I assume that this problem is due to SMB block size and the latency I'm dealing with,

[Samba] Winbind user authentication (-a) fails, but kerberos authentication succeeds

2010-10-21 Thread Steven Moyse
I am having trouble setting up winbind authentication. I have successfully joined the domain winbind -t OK winbind -u OK winbind -g OK winbind -K 'DOMAIN\user%password' OK winbind -a 'DOMAIN\user%password' FAIL For winbind -a: Plaintext authentication is attempted, and fails with

Re: [Samba] Winbind user authentication (-a) fails, but kerberos authentication succeeds

2010-10-21 Thread Gaiseric Vandal
What kind of domain - samba PDC or Windows Active Directory ? Maybe the samba version is just too old. -Original Message- From: samba-boun...@lists.samba.org [mailto:samba-boun...@lists.samba.org] On Behalf Of Steven Moyse Sent: Thursday, October 21, 2010 8:52 PM To:

[Samba] Application will not run for domain user

2010-10-21 Thread Robert Moskowitz
I have set up a Samba PDC using the Amahi.org distro, so there might be some things they still have a bit off... Anyway, I have a somewhat old program, Quicken 2000. On my old Win2K workstation on an old NT server, it ran just fine for domain users. The software is installed on the

Re: [Samba] Application will not run for domain user

2010-10-21 Thread Gaiseric Vandal
Two possible options: 1) It may not be a local vs domain user issue. It may be an administrator vs non administrator issus. Can you add the domain user to the local administrators group? 2) It may be the file permissions- samba doesn't always translate the unix acl's to windows

Re: [Samba] Application will not run for domain user

2010-10-21 Thread Robert Moskowitz
On 10/21/2010 11:11 PM, Gaiseric Vandal wrote: Two possible options: 1) It may not be a local vs domain user issue. It may be an administrator vs non administrator issus. Can you add the domain user to the local administrators group? OK. That was it. Though I added the user into

Build status as of Thu Oct 21 06:00:01 2010

2010-10-21 Thread build
URL: http://build.samba.org/ --- /home/build/master/cache/broken_results.txt.old 2010-10-20 00:00:45.0 -0600 +++ /home/build/master/cache/broken_results.txt 2010-10-21 00:00:02.0 -0600 @@ -1,4 +1,4 @@ -Build status as of Wed Oct 20 06:00:03 2010 +Build status as of Thu Oct

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Matthias Dieter Wallnöfer
The branch, master has been updated via 8044a20 ldb:ldb_modules.c - if we don't find the associated dynamic object then please close the handle via 0b8b9ae ldb:ldb_tdb/ldb_cache.c - remove a superflous talloc_free via de9b737 ldb:ldb_tdb/ldb_cache.c - in this function we

Re: [SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Stefan (metze) Metzmacher
Hi Matthias, - Log - commit 8044a20d8d84e740ca5c6d76bacaa977d691f3d0 Author: Matthias Dieter Wallnöfer m...@samba.org Date: Thu Oct 21 08:51:46 2010 +0200 ldb:ldb_modules.c - if we don't find the associated dynamic

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Matthias Dieter Wallnöfer
The branch, master has been updated via 3c74871 ldb:ldb_modules.c - dlclose could cause inference on dlerror from 6c3e670 waf: check the linker accepts a set of ldflags before using them http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Andrew Tridgell
The branch, master has been updated via 2c0ff51 s4-waf: we don't need the smbtorture.static for s3 any more via 6120ef9 autobuild: don't cleanup the pid file within the retry loop via 4fa0ceb waf: RPC_NDR_WINBIND is samba4 specific from 3c74871 ldb:ldb_modules.c -

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Jelmer Vernooij
The branch, master has been updated via 62c4af9 tdb: Set _PUBLIC_ in C file rather than header files (Debian bug 600898) from 2c0ff51 s4-waf: we don't need the smbtorture.static for s3 any more http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Anatoliy Atanasov
The branch, master has been updated via 5785f08 s4-dsdb extended_dn_out: Move lazy dereference control creation to lazy-init from 62c4af9 tdb: Set _PUBLIC_ in C file rather than header files (Debian bug 600898) http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch v3-6-test updated

2010-10-21 Thread Jeremy Allison
The branch, v3-6-test has been updated via 915e419 tdb: Set _PUBLIC_ in C file rather than header files (Debian bug 600898) from 31c74ba talloc: make header C++ safe http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-6-test - Log

[SCM] Samba Shared Repository - branch v3-6-test updated

2010-10-21 Thread Jeremy Allison
The branch, v3-6-test has been updated via 050075f Add SeSecurityPrivilige. from 915e419 tdb: Set _PUBLIC_ in C file rather than header files (Debian bug 600898) http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-6-test - Log

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Jelmer Vernooij
The branch, master has been updated via c529317 Lowercase socket_wrapper name. from 5785f08 s4-dsdb extended_dn_out: Move lazy dereference control creation to lazy-init http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

Re: [SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Stefan (metze) Metzmacher
Hi Jelmer, - Log - commit c529317fe2b48e045b35a613cfd1ad3f03b68435 Author: Jelmer Vernooij jel...@samba.org Date: Thu Oct 21 21:43:13 2010 +0200 Lowercase socket_wrapper name. Avoid linking against

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Matthieu Patou
The branch, master has been updated via c74ef7a waf: Mark the replacement zlib private so that it can build on machine without a system zlib via 4ea7d46 replace: use replace for non 'samba' compliant strptime via 2d0ac59 replace: use a wrapper around strtoll if it didn't

[SCM] Samba Shared Repository - branch master updated

2010-10-21 Thread Kamen Mazdrashki
The branch, master has been updated via 2a00138 s4-dsdb/schema_syntax: Separate validation for numericoid OID values via 14cb61d asn1_tests: Implement negative unit-tests for ber_write_OID_String() via 6b63ad6 asn1: ber_write_OID_String() to be more picky about supplied