Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Kai Blin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 2012-10-31 22:25, Dmitry Khromov wrote: Samba 4 rc 3. I had noticed a strange behavior. If host creates a record, it won't be further updated until the record gets deleted manually. What could cause this? What updates are you expecting?

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
Hello! Samba 4 rc 3. I had noticed a strange behavior. If host creates a record, it won't be further updated until the record gets deleted manually. What could cause this? What updates are you expecting? When Windows DHCP client receives a lease or when you manually issue ipconfig

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
By the way, maybe an option should be added for Samba internal DNS server that will allow to force TTL of individual records since it's not tunable in Windows? This would be a feature I missed in MS DNS server much. In my opinion, network administrator, not MS DNS client alone, should have a

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Kai Blin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 2012-11-01 09:40, Dmitry Khromov wrote: Hi, When Windows DHCP client receives a lease or when you manually issue ipconfig /renew command, Windows sends out DNS messages (unsigned, then signed if needed) with UPDATE opcode towards a NS

Re: [Samba] Windows 7 8 + HomeGroup support

2012-11-01 Thread Emmanuel Florac
Le Wed, 31 Oct 2012 22:11:36 -0700 vous écriviez: As windows 8 is continuing the tradition of using HomeGroup instead of traditional sharing, I'd like to re-request that some consideration be given to implementing HomeGroup support in Samba. From my understanding of HomeGroup (admittedly

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
I expected Samba to behave like MS DNS server and replace the old record with a new one. Yes, that should work. If it doesn't work for you, you need to tell us some more details about your smb.conf and maybe provide a network capture of the failing DNS update. # cat etc/smb.conf # Global

Re: [Samba] [samba] printer cups

2012-11-01 Thread Moray Henderson
From: root [mailto:r...@server-ready.aghezzi.it] Sent: 30 October 2012 17:47 my samba is working good, only a problem with the classic pdf printer I get this message from testparm Warning: Service pdf-printer defines a print command, but print command parameter is ignored when using

[Samba] sambar4: user creation with ldap and initial password

2012-11-01 Thread Thomas Mueller
hi trying to create a user with ldap from a remote server. The user is created successfully. I'm failing setting the initial password. Setting the unicodePwd with kerberos administrator credentials with ldbmodify and the ldif below results in 2035: setup_io: it's not allowed to set the NT

[Samba] force user not working

2012-11-01 Thread L . P . H . van Belle
Hai,   small question.   Im running debian squeeze, samba 3.6.6-2~bpo60+1  in with domain with ldap.   I joint my domain with a new server as domain member, so far so good.   im having problems with the force user parameter. Its not working.  ;-) the force group is working fine.   strange

[Samba] Samba/WinBind Trusted domain

2012-11-01 Thread Stevenson, Ryan
Our AD Forest has user account in one domain and resources in a trusted domain. I have gotten the Samba3x to join to the domain and authenticated to user accounts in both domains. The question I have is, is there a way to set the default domain for when people are not putting in a

[Samba] Group membership lost unpredictably

2012-11-01 Thread Ian Frisbie
Hi, I have a very bizarre problem linking to my Active Directory from my Ubuntu 11.10 system. I have three AD users setup with them belonging to a specific AD group. When I first login a user onto my Ubuntu system, that user is shown to be a member of the group: wbinfo -r user And if I show

Re: [Samba] SYSVOL ACLs and GPOs

2012-11-01 Thread Alex Matthews
On 30/10/2012 00:08, Jeremy Allison wrote: On Tue, Oct 30, 2012 at 11:00:31AM +1100, Andrew Bartlett wrote: be a particular trigger - but it shouldn't be able to make a modification that doesn't go via vfs_acl_xattr. For Alex, before running the Group Policy tools on WinXP, he gets (at level

[Samba] Samba Active Directory w/ Kerberos Trust

2012-11-01 Thread Rafferty, Joseph
Hello, I'm having some difficulty understanding the best approach to setting up a samba fileserver in our environment. We have an active directory domain (2008) that has account stubs that we use for security and authorization (the passwords are unknown/random). This domain has a one-way

[Samba] libkdc-policy.so: cannot open shared object file: No such file or directory?

2012-11-01 Thread samba . to . anomalyst
Built from tar. Same result from git pull as of 01NOV install sudo samba-tool domain provision --realm=hen.us.mentats.us --domain=NEWDOM --dns-backend=BIND9_DLZ --adminpass=badpass --server-role='domain controller' libkdc-policy.so: cannot open shared object file: No such file or directory How

[Samba] smbd daemon crash when connect to shared folder

2012-11-01 Thread Le, Anh
Hi All, I've installed and configured Samba 3.5.11 on a Solaris 8 machine. I was able to join it to the 2008 R2 AD. However, its smbd daemon is crashed everytime I connect to its shared folder from the windows machine, so I'm not able to connect to its shared folders. Below is its log from

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
According to the dump, Windows just doesn't try to send a signed update after receiveng TKEY. However, this host had succeded at least once today. Rebooted it, now no updates happen, but Samba started to say: [2012/11/01 14:32:30, 1]

Re: [Samba] Windows 7 8 + HomeGroup support

2012-11-01 Thread Christ Schlacta
My understanding was that it was purely a new authentication method on top of existing CIFS/AD protocols. Either way, I believe home-group integration is important, and samba is where it belongs. On 11/01/12 02:26, Emmanuel Florac wrote: Le Wed, 31 Oct 2012 22:11:36 -0700 vous écriviez:

Re: [Samba] Windows 7 8 + HomeGroup support

2012-11-01 Thread Jeremy Allison
On Thu, Nov 01, 2012 at 01:17:10PM -0700, Christ Schlacta wrote: My understanding was that it was purely a new authentication method on top of existing CIFS/AD protocols. H. http://download.microsoft.com/download/9/5/E/95EF66AF-9026-4BB0-A41D-A4F81802D92C/[MS-HGRP].pdf Looks like a web

Re: [Samba] smbd daemon crash when connect to shared folder

2012-11-01 Thread Jeremy Allison
On Thu, Nov 01, 2012 at 03:40:52PM -0400, Le, Anh wrote: Hi All, I've installed and configured Samba 3.5.11 on a Solaris 8 machine. I was able to join it to the 2008 R2 AD. However, its smbd daemon is crashed everytime I connect to its shared folder from the windows machine, so I'm not

Re: [Samba] Restricting DC Roles?

2012-11-01 Thread Andrew Bartlett
On Thu, 2012-11-01 at 19:26 +, Bethel, Zach wrote: I went ahead and updated to samba-master, and the error is replaced by a new one that is rather strange: Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this

Re: [Samba] Joining domain without password?

2012-11-01 Thread Jakov Sosic
On 10/30/2012 06:53 AM, Andrew Bartlett wrote: By some means, we need to securely establish a shared secret between the machine and the DC. You could forward a kerberos ticket to the host, if that's easier to automate and use -k. The old (NT4) style of setting up the account first, which

[Samba] Samba 3.5 - user authentication issues

2012-11-01 Thread Jakov Sosic
Hi. I'm using CentOS 5 with samba3x packages (Samba 3.5.10) and Solaris 10 (Samba 3.5.8) for achieving AD integration. Samba hosts are added as domain members. Now, I've tried to add CentOS 6, which also uses 3.5.10, but have encountered a problem - users cannot authenticate for some

[Samba] ldbsearch returning NT_STATUS_INVALID_PARAMETER

2012-11-01 Thread Bethel, Zach
I have a Samba DC connected to two Windows 2008 R2 DC's. On the Samba machine, if I run `ldbsearch -H ldaps://*SAMBA-DC-IP* -U administrator` It asks for my password and then works great. I can use any domain user and this works. However, if I instead run: `ldbsearch -H ldaps://10.120.160.12

Re: [Samba] Restricting DC Roles?

2012-11-01 Thread Bethel, Zach
I went ahead and updated to samba-master, and the error is replaced by a new one that is rather strange: Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer because this computer's clock is not

[SCM] Samba Shared Repository - branch master updated

2012-11-01 Thread Andrew Tridgell
The branch, master has been updated via dd60dcf test-chgdcpass: test the ldap case for server password change via 0e6c5c0 s4-ldapclient: cope with logon failure retry in LDAP via b0cc0d5 s4-librpc: set error code to LOGON_FAILURE on RPC fault with access denied via

[SCM] Samba Shared Repository - branch v3-5-test updated

2012-11-01 Thread Karolin Seeger
The branch, v3-5-test has been updated via 4067d19 WHATSNEW: Prepare release notes for Samba 3.5.19. from 92bd768 Revert Fix bug #7781 (Samba transforms ShareName to lowercase when adding new share via MMC) http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-5-test - Log

[SCM] Samba Shared Repository - branch master updated

2012-11-01 Thread Michael Adam
The branch, master has been updated via 75c51d6 s3-param: Move the options needed for running smbd in the AD DC to loadparm via fc5caff file_server: put set create mask and directory mask in fileserver.conf from dd60dcf test-chgdcpass: test the ldap case for server

autobuild: intermittent test failure detected

2012-11-01 Thread autobuild
The autobuild test system has detected an intermittent failing test in the current master tree. The autobuild log of the failure is available here: http://git.samba.org/autobuild.flakey/2012-11-01-1221/flakey.log The samba3 build logs are available here:

[SCM] Samba Shared Repository - branch master updated

2012-11-01 Thread Michael Adam
The branch, master has been updated via 2a3eb64 s3:winbindd: use PROTOCOL_LATEST instead of PROTOCOL_SMB2_02 (bug #9175) via 45105af s3:winbindd: disconnection after getting NETWORK_SESSION_EXPIRED (bug #9175) via c5cd22b libcli/smb: add