Release Announcements
-
This is a security release in order to address CVE-2013-0172.
o CVE-2013-0172:
Samba 4.0.0 as an AD DC may provide authenticated users with write access
to LDAP directory objects.
In AD, Access Control Entries can be assigned based on the
Did you use MS ADS-Tool to set your permissions on that share.
In some cases it is usefull to do so.
---
EDV Daniel Müller
Leitung EDV
Tropenklinik Paul-Lechler-Krankenhaus
Paul-Lechler-Str. 24
72076 Tübingen
Tel.: 07071/206-463, Fax: 07071/206-499
Hi all,
In Sum My Question is:
How do I allow domain users to add printers which are shared from other
servers desktops without having to give everyone domain admin privileges??
*** BACKGROUND ***
1. I have set up SAMBA 3.6.3 as a domain controller with roaming profiles
on an Ubuntu 12.04 LTS
samba eXPerience 2013 - call for papers
---
The SAMBA 4 birthday event!
From May 14th to 17th 2013 developers and users will meet again in
Goettingen, Germany at the 12th international SAMBA conference, the
samba eXPerience 2013.
The first Linux distro
On Tue, 2013-01-15 at 11:19 +, Chris Lewis wrote:
On 11/01/13 12:22, Andrew Bartlett wrote:
On Thu, 2013-01-10 at 16:50 +, Chris Lewis wrote:
Hi All,
I have joined a samba4 instance to en existing W2k8 AD domain as an
additional domain controller.
When I do
samba-tool
On 11/01/13 12:22, Andrew Bartlett wrote:
On Thu, 2013-01-10 at 16:50 +, Chris Lewis wrote:
Hi All,
I have joined a samba4 instance to en existing W2k8 AD domain as an
additional domain controller.
When I do
samba-tool dbcheck
I get (example) :
ERROR: wrong instanceType 4 on
Running the environment you described (beside openchange). I guess you need
acl:read=false
in your smb.conf.
achim~
Am 14.01.2013 23:29, schrieb Christian Hailer:
Hello Samba group,
I ran into a problem concerning Dovecot LDAP authentication to the Samba4
Active Directory.
Background: I
Version 4.1.0pre1-GIT-94f11e9 on Ubuntu 12.04 LTS.
Thanks,
Max
Andrew Bartlett abart...@samba.org 1/14/2013 3:01 PM
On Mon, 2013-01-14 at 14:14 -0700, Max Olivas wrote:
Hey All,
Thanks for the feedback. I've cleaned up my .tdb files some and have
moved farther with the upgrade command
Hi,
Is there a tutorial somewhere on the Internet to configure a Samba4 as a
RODC in a AD domain environment with a W2K8 PDC ?
How to configure smb.conf, krb5.conf and the Samba4 Internal DNS server ?
Thanks.
--
To unsubscribe from this list go to the following URL and read the
instructions:
The subject pretty much says it all. This has been the holy grail for
some friends and me, and we'd love to incorporate it into our
environment... if it can join the domain as a DC.
Can it?
Thanks!
-Ken
--
This mail was scanned by BitDefender
For more information please visit
OK, after some other hours of surfing through the net I stubled
accross the needed information:
It looks like to try setting ACLs in smb.conf like it was done on
Samba3 is obsolete in Samba4. You do everything by setting the ACLs on
the share by Windows-GUI.
[testshare]
Comment =
Solved this problem
gentle rant
This is precisely the sort of question that should be answerable on this list.
Has no one run into this before?
I've brought it up twice here and several times on the irc channel with no
response, but the solution was simple enough
/gentle rant
anyway here
Originalnachricht
Betreff: Re: [Samba] Samba4 AD delegation to read userPassword attribute
Von: Christian Hailer chri...@amusing.de
An: Achim Gottinger ac...@ag-web.biz
Cc:
Hi Achim,
thank you for this information! Unfortunately it doesn't work in my
environment, the
Hi All,
I recently stood up a Linux server with Samba and wanted to
re-generate any keys the Samba server might be using. I used an
Entropy Key (http://www.entropykey.co.uk/), and I believe the PRNG is
in good working order now.
Could anyone point out what I should do to re-generate any keys
I'm running a samba pdc+ldap and am having issue with a windows 7 client.
Checking the logs, I see nothing about smbldap-useradd. If I manually run
smbldap-useradd -w hostname$, I'm able to add the client to the domain, but
then run into the trust issue preventing anyone from logging in.
The PDC
Am 15.01.2013 20:02, schrieb Christian Hailer:
Hi Achim,
thank you for this information! Unfortunately it doesn't work in my environment, the
userPassword attribute still can't be read by the ldap user...
I tried to bind with the domain administrator account, there it doesn't work
too.
Would
Quoting Ken D'Ambrosio k...@jots.org:
The subject pretty much says it all. This has been the holy grail
for some friends and me, and we'd love to incorporate it into our
environment... if it can join the domain as a DC.
Can it?
Yes.
--
To unsubscribe from this list go to the following
Quoting Robert Moggach r...@dashing.tv:
I'm using BIND9_FLATFILE and able to join windows machines and have DNS
updates working but Linux machines join with DNS update errors. Is there
additional configuration necessary on Linux for the machines' NICs to be
seen as valid?
We are using Samba
PERFECT! It works!!! Thank you very much!!!
Best regards, Christian
-Ursprüngliche Nachricht-
Von: samba-boun...@lists.samba.org [mailto:samba-boun...@lists.samba.org] Im
Auftrag von Achim Gottinger
Gesendet: Dienstag, 15. Januar 2013 21:42
An: samba@lists.samba.org
Betreff: Re: [Samba]
Andrew Bartlett abartlet at samba.org writes:
Using Samba 4.0.0, the python bindings or even samba-tool ntacl get/set
would be quite a good choice here. We can read directly the NT ACL from
the tdb and then set it using the xattr code.
I'm very happy to help out if you have any more
Just to report back in on this, the traditional build system under source3
worked for us, and we were able to build and install a working set of Samba
binaries. At this time, we only need the file server bits.
I'll give the new build system another shot when 4.0.1 comes out.
Thanks again!
Hi,
I used to successfully migrated Samba3 to Samba4 but there are some
problems which I can't proceed coz it needs to be re-authenticated the
computers/machines previously connected in Samba3.
As I observed, using the Windows Remote Administration Tools (Active
Directory Users and Computers)
Anyone? If this is the wrong list or if no one can answer I can definitely ask
a different list - just point me in the right direction?
On Jan 11, 2013, at 10:54 PM, Chris Stoneburner
200406...@panthers.greenville.edu wrote:
First off, I apologize if this is a duplicate - I had some issues
In relation to this, I used to clone a copy of the windows xp client
uchiha. After that run clone and change the computer name to senju, which
ask to restart. It is running fine.
But when I shutdown senju to run the original one uchiha, I can't login.
What I did login as local administrator
The branch, master has been updated
via 54d54b2 Announce Samba 4.0.1.
from 0c1d1cd Add itsd.de
http://gitweb.samba.org/?p=samba-web.git;a=shortlog;h=master
- Log -
commit 54d54b266be6477438a7f5e8bdb56112eba5f814
The branch, v4-0-stable has been updated
via d2e9007 VERSION: Bump version number up to 4.0.1. (CVE-2013-0172)
via 0c02492 WHATSNEW: Update release notes for Samba 4.0.1.
(CVE-2013-0172)
via 8bafe08 dsdb: Add test for modification of two attributes, one
permitted, one
The annotated tag, samba-4.0.1 has been created
at 0248ab73a8113122e7b44c377f7b7e899fc6d75c (tag)
tagging d2e900757d8e8e2a82cb14e79814ed3cbc8d93c1 (commit)
replaces samba-4.0.0
tagged by Karolin Seeger
on Mon Jan 14 19:36:49 2013 +0100
- Log
The branch, v4-0-test has been updated
via 9712362 Merge tag 'samba-4.0.1' into v4-0-test
via d2e9007 VERSION: Bump version number up to 4.0.1. (CVE-2013-0172)
via 0c02492 WHATSNEW: Update release notes for Samba 4.0.1.
(CVE-2013-0172)
via 8bafe08 dsdb: Add test
The branch, master has been updated
via ccd6164 Announce Call for Papers SambaXP 2013.
from 54d54b2 Announce Samba 4.0.1.
http://gitweb.samba.org/?p=samba-web.git;a=shortlog;h=master
- Log -
commit
The branch, v3-6-test has been updated
via c89f3dd Fix bug 9548: Correctly detect O_DIRECT
from a8658bc Fix bug #9196 - defer_open is triggered multiple times on
the same request.
http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-6-test
- Log
The branch, v4-0-test has been updated
via 6907b3f VERSION: Bump version number up to 4.0.2.
from 9712362 Merge tag 'samba-4.0.1' into v4-0-test
http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v4-0-test
- Log -
The branch, master has been updated
via 8f8ca58 tevent: Fix bug 9550 - sigprocmask does not work on FreeBSD
to stop further signals in a signal handler
via 0258138 lib/replace: Include sys/ucontext.h if available.
via fe6e323 lib/replace: Add ucontext configure autoconf
The branch, v4-0-test has been updated
via 46473b4 Fix bug 9548: Correctly detect O_DIRECT
from 6907b3f VERSION: Bump version number up to 4.0.2.
http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v4-0-test
- Log -
The branch, master has been updated
via 065c0ec dsdb: Add test for modification of two attributes, one
permitted, one denied (bug #9554 - CVE-2013-0172)
via b7b91c8 dsdb-acl: Run sec_access_check_ds on each attribute
proposed to modify (bug #9554 - CVE-2013-0172)
via
The branch, master has been updated
via 6bb7bf9 test: dbwrap_tool requires --persistent for the registry now
via 7f65434 docs: document the --persistent option in dbwrap_tool(1)
via 770b1aa s3:dbwrap_tool: add --persistent switch and mode for
non-persistent DBs
via
The autobuild test system has detected an intermittent failing test in
the current master tree.
The autobuild log of the failure is available here:
http://git.samba.org/autobuild.flakey/2013-01-15-2019/flakey.log
The samba3 build logs are available here:
36 matches
Mail list logo