[Samba] samba and RODC

2012-11-30 Thread Alex Samad - Yieldbroker
Hi I am trying to setup samba (rhel6/centos 6.2) and I am having some issues. So what I have is Server A (centos 6.2) It exists in my DMZ so very limited access to thing. Juts mainly DNS and some ports for RODC Sever B (W2k8r2) RODC, exists in my insecure vlan, stepping stone into the DMZ

Re: [Samba] Branches

2012-11-30 Thread felix
On 11/29/2012 11:23 AM, fe...@epepm.cupet.cu wrote: Hello list: which git branch contains the latest changes of samba4 as AD DC? Regards, Felix. the master branch Thanks Matthieu. Felix. -- To unsubscribe from this list go to the following URL and read the instructions:

[Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Brian Gold
Hi all, I've been using samba for a few years now on a couple of file servers with a tdbsam backend for our user accounts. We use openldap for the vast majority of our identity management, so I would love to be able to tie into this. We recently started using sambaNTPassword in openldap for

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Gaiseric Vandal
Can you clarify one thing - why are you using the sambaNTPassword in openldap if openldap is not currently used samba authentication? I would have thought that you would use the standard password field. I use Samba 3.x DC's with an ldap back end. I also use the ldap backend for unix

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Brian Gold
On 2012-11-30 9:22 am, Gaiseric Vandal wrote: Can you clarify one thing - why are you using the sambaNTPassword in openldap if openldap is not currently used samba authentication? I would have thought that you would use the standard password field. We are using the standard userPassword

Re: [Samba] Roaming Profiles not working

2012-11-30 Thread L . P . H . van Belle
Hai, should be simple. Try this. [profiles] path = /export/home/comput/profiles comment = Profiles read only = no browseable = No create mask = 0600 directory mask = 0700 guest ok = Yes force user = %U valid users = %U

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Gaiseric Vandal
On 11/30/12 09:42, Brian Gold wrote: On 2012-11-30 9:22 am, Gaiseric Vandal wrote: Can you clarify one thing - why are you using the sambaNTPassword in openldap if openldap is not currently used samba authentication? I would have thought that you would use the standard password field. We

Re: [Samba] Samba PDC group list empty

2012-11-30 Thread Harry Jede
Am Donnerstag, 29. November 2012 schrieben Sie: I still dont understand why ldap search filter generated by samba ( i have this from samba log ) cannot find anything in database: smbldap_search_paged: base = [dc=gymsnv,dc=sk], filter =

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Brian Gold
On 2012-11-30 11:15 am, Gaiseric Vandal wrote: No, you wouldn't sync passwords to TDB. Does your LDAP entry for each user currently have a SambaSID value? Also, when you type pdbedit -Lv someuser you should see the unix account for the user. The unix account is either explicitly created

Re: [Samba] User is invalid on this system

2012-11-30 Thread Kevin Elliott
Ah good ideas. /etc/nsswitch.conf looks correct: passwd: files winbind group: files winbind shadow: compat hosts: files dns networks: files protocols: db files services: db files ethers: db files rpc:db files Winbind is

Re: [Samba] User is invalid on this system

2012-11-30 Thread Dale Schroeder
Kevin, 3.6.x has had several issues with idmap rid. I was hit with this one: https://bugzilla.samba.org/show_bug.cgi?id=8676 . Searching for idmap rid issues with 3.6.x will reveal others as well. Someone indicated that rejoining the domain would fix this issue. As it so happened, I had

Re: [Samba] User is invalid on this system

2012-11-30 Thread Kevin Elliott
Dale, I was afraid of that. We we're forced to upgrade from 3.5.x because of a reoccurring Winbind issue but I'm a bit disappointed to see that 3.6.x introduces a idmap/rid issues. I guess we just traded one for another. Do you think un-joining and then re-joining the existing system could fix

Re: [Samba] User is invalid on this system

2012-11-30 Thread Dale Schroeder
With what I've read and what I've seen with the rebuilds, there's a good chance the rejoin could fix your problem. That being said, there are no guarantees with winbind. It's the part of the Samba suite that has given me the most problems over the years, breaking existing configs almost every

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Gaiseric Vandal
So when you run pdbedit -Lv for a user, is the Unix user name is an account in ldap? If that is the case, then you probably just want to have a script that runs that runs thru a list of user names and they runs ldapmodify to add the appropriate samba attributes.In theory you can use

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Brian Gold
On 2012-11-30 4:01 pm, Gaiseric Vandal wrote: So when you run pdbedit -Lv for a user, is the Unix user name is an account in ldap? If that is the case, then you probably just want to have a script that runs that runs thru a list of user names and they runs ldapmodify to add the appropriate

Re: [Samba] Samba file server using ldap backend without AD or PDC?

2012-11-30 Thread Gaiseric Vandal
On 11/30/12 16:11, Brian Gold wrote: On 2012-11-30 4:01 pm, Gaiseric Vandal wrote: So when you run pdbedit -Lv for a user, is the Unix user name is an account in ldap? If that is the case, then you probably just want to have a script that runs that runs thru a list of user names and they runs

[SCM] Samba Shared Repository - branch v3-6-test updated

2012-11-30 Thread Karolin Seeger
The branch, v3-6-test has been updated via d7fdb05 spoolss: fix segfault when default devmode is disabled from 1106ca5 BUG 9436: Fix leaking sockets of SMB connections to a DC. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-6-test - Log

[SCM] Samba Shared Repository - annotated tag ldb-1.1.14 created

2012-11-30 Thread Stefan Metzmacher
The annotated tag, ldb-1.1.14 has been created at ae3f7139cf13ee222beeb7468977e5c8d2484f28 (tag) tagging 6f47497610352f72128bdbcd3b45313ea9a265ab (commit) replaces ldb-1.1.13 tagged by Stefan Metzmacher on Fri Nov 30 09:50:10 2012 +0100 - Log

[SCM] Samba Shared Repository - annotated tag talloc-2.0.8 created

2012-11-30 Thread Stefan Metzmacher
The annotated tag, talloc-2.0.8 has been created at 055edd4901a0cfe837b0a5e39fd6ad0ea2190b40 (tag) tagging 36ea39edf8dd9ede756debaf9632f3ded2a51abb (commit) replaces ldb-1.1.13 tagged by Stefan Metzmacher on Fri Nov 30 09:52:48 2012 +0100 - Log

[SCM] Samba Shared Repository - annotated tag tdb-1.2.11 created

2012-11-30 Thread Stefan Metzmacher
The annotated tag, tdb-1.2.11 has been created at 259e276dc908ff053142cb9feab0ef2a962bffd1 (tag) tagging c62f8baff878001ead921112dd653ff69d1cfe7d (commit) replaces talloc-2.0.8 tagged by Stefan Metzmacher on Fri Nov 30 09:54:21 2012 +0100 - Log

[SCM] Samba Shared Repository - branch v4-0-test updated

2012-11-30 Thread Karolin Seeger
The branch, v4-0-test has been updated via 121157a WHATSNEW: Update changes since RC5. via 61afd00 docs: man oLschema2ldif: Add missing meta data. via 68eff14 docs: man ntlm_auth4: Add missing meta data. via 91c2674 docs: man smbtorture: Add missing meta data.

[SCM] Samba Shared Repository - branch master updated

2012-11-30 Thread Andreas Schneider
The branch, master has been updated via 234f936 s3:popt_common: Fix password processing. via 3101fccc s3:util: fix usage of popt_burn_cmdline_password() via 4a73adf s3-winbind: use new reconnect logic in rpc_lookup_sids() also. via 7a49c96 s3-winbindd: rework

[SCM] Samba Shared Repository - branch master updated

2012-11-30 Thread Volker Lendecke
The branch, master has been updated via 8f3f38e ldb: fix a typo in the comment for ldb_req_is_untrusted() via 06e1fca libnet: Fix a typo in dbsync error message. via 7a42936 libnet: Fix copy and paste error in dbsync error message. via f3d5d14 torture: Fix copy and

[SCM] Samba Shared Repository - branch master updated

2012-11-30 Thread Michael Adam
The branch, master has been updated via 057c56a s4:dsdb/tests: add SdAutoInheritTests via d317426 s4:dsdb/repl_meta_data: call dsdb_module_schedule_sd_propagation() for replicated changes via fb2a41d s4:dsdb/descriptor: inherit nTSecurityDescriptor changes to children