[Samba] smbclient fails to connect wuth krb + signing

2013-02-07 Thread Michael Wilke
Dear all, I hope you could assist me in finding a problem with samba and krb connects when packet signing is activated in a domain. I have a samba server as a AD 2k3 domain member and the connects are working well, but when I try to use krb auth to connect to another Windows server in the network

[Samba] Unable to re-connect to roaming profile in samba4

2013-02-07 Thread Nick Semenkovich
I've just configured Samba4 on Ubuntu (4.0.0+dfsg1-1), and can't seem to get roaming profiles working (I followed the guide at https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO ) 1. Logons work just fine. 2. DNS is configured and working, running through SAMBA_INTERNAL 3. Clients can talk to the

[Samba] Trouble with user who has mixed case login (upper and lower)

2013-02-07 Thread BillDorrian
We're having an issue with a user who has a login with mixed case - we'll call him "USERone". Samba does not recognize him; it says that the "user does not exist" even though he does - and we're using the correct case for each letter. We would rename him to an all lower case name, but he there

Re: [Samba] AD uid/gid attributes

2013-02-07 Thread Michael Ray
One last thing that stumped me for awhile: For getent passwd to display an AD user with uid/gid, the user must (obviously) have a uidNumber defined, but their *primary* group must have a gidNumber defined as well. If either of these pieces are missing, the user will not show up. - Origin

Re: [Samba] Strange winbindd messages

2013-02-07 Thread Andrew Bartlett
On Fri, 2013-02-08 at 08:43 +1100, Andrew Bartlett wrote: > On Wed, 2013-01-23 at 11:59 -0500, John Center wrote: > > Hi, > > > > We are running samba v3.6.3 on Ubuntu 12.04 server. This is being used > > with FreeRADIUS for wireless authentication with AD. We just logged a > > set of messages

Re: [Samba] AD uid/gid attributes

2013-02-07 Thread Michael Ray
Here is the solution that worked for me, on the off chance another poor soul has trouble figuring this all out: (That is assuming that you were in my boat, i.e. user authentication but UID/GID were not mapped) smb.conf : [global] netbios name = realm = DOMAIN_FQDN workgroup = DOMAIN pre

Re: [Samba] Strange winbindd messages

2013-02-07 Thread Andrew Bartlett
On Wed, 2013-01-23 at 11:59 -0500, John Center wrote: > Hi, > > We are running samba v3.6.3 on Ubuntu 12.04 server. This is being used > with FreeRADIUS for wireless authentication with AD. We just logged a > set of messages from winbindd that I don't understand: > > Jan 23 10:35:28 as3 winbi

Re: [Samba] samba4 AD DC & manually creating DNS records?

2013-02-07 Thread Andrew Bartlett
On Thu, 2013-02-07 at 13:49 -0600, Nick Semenkovich wrote: > I'm trying to use a DNS server independent from Samba (non BIND, on a > different machine/system). Please, please do not do this. It will only cause trouble. Instead, have your independent DNS server forward the Samba zone to Samba, wh

Re: [Samba] Strange winbindd messages

2013-02-07 Thread John Center
Any help? -John On 01/23/2013 11:59 AM, John Center wrote: Hi, We are running samba v3.6.3 on Ubuntu 12.04 server. This is being used with FreeRADIUS for wireless authentication with AD. We just logged a set of messages from winbindd that I don't understand: Jan 23 10:35:28 as3 winbindd[253

Re: [Samba] samba4 AD DC & manually creating DNS records?

2013-02-07 Thread Bob Miller
On Thu, 2013-02-07 at 13:49 -0600, Nick Semenkovich wrote: > I'm trying to use a DNS server independent from Samba (non BIND, on a > different machine/system). > > Beyond the two simple records of: > > SRV _ldap._tcp.samdom.example.com > and > SRV _kerberos._udp.samdom.example.com > > > If I m

[Samba] samba4 AD DC & manually creating DNS records?

2013-02-07 Thread Nick Semenkovich
I'm trying to use a DNS server independent from Samba (non BIND, on a different machine/system). Beyond the two simple records of: SRV _ldap._tcp.samdom.example.com and SRV _kerberos._udp.samdom.example.com If I maintain all the A records for individual hosts (& the server.samdom.example.com ma

Re: [Samba] Samba 4 AD DC "Element not found" error in Windows 8

2013-02-07 Thread Nick Semenkovich
Ah yeah, that definitely works #facepalm I guess I figured \\corp.domain.com should just fail entirely (though netlogon and sysvol work) -- \\dcname.corp.domain.com works perfectly. Thanks! On Thu, Feb 7, 2013 at 2:17 AM, Ufficiotecnico Acknow wrote: > Using \\dcname.corp.domain.com\share or

[Samba] smbclient php extension

2013-02-07 Thread Eric PEYREMORTE
Hi there, I know it's not the good place to ask but don't know where to... It would be great to have a compiled native php smbclient extension. Several people, including owncloud, still use Victor M. Varela, php library (which use exec smbclient) to access smb files. This is not optimized, an

Re: [Samba] AD DC LDAP support for the 'password change' extended operation

2013-02-07 Thread Luis Angel Fernandez Fernandez
2013/2/6 Andrew Bartlett > > I can help on this part of the question: No, the extended operation is > not supported - it remains a wishlist item that one of our developers > was working on at some point, but has not progressed beyond that. First of all, thank you for your answer. I think

Re: [Samba] about samba4 and external ldap and dns

2013-02-07 Thread Taylor, Jonn
On 02/07/2013 08:54 AM, Amaury Viera Hernández wrote: On 02/07/2013 08:53 AM, fe...@epepm.cupet.cu wrote: Could I use samba4 as a domain controller with and external ldap? Could I use samba4 as a domain controller with and external dns? samba4 as DC uses an internal ldap server, you can't c

[Samba] removing local policies

2013-02-07 Thread Cristian Saavedra
Hello Everyone We are upgrading to Samba4 from Samba 3.x, we got a fully functional domain over the last 4 years and we are trying to do our migration as smooth as possible. I have migrated, users, machines and everything to the new samba4 domain (not in production yet), however when i log and

Re: [Samba] about samba4 and external ldap and dns

2013-02-07 Thread Gregory Sloop
AVH> thanks, AVH> there is any documentation for using samba4 with an external bind9? https://wiki.samba.org/index.php/Samba4/HOWTO#Bind_9.8.0_or_newer [There's a "problem" with the Wiki - it's only accepting HTTPS connections today - just a heads-up for whomever in the Samba crew might be resp

Re: [Samba] about samba4 and external ldap and dns

2013-02-07 Thread Amaury Viera Hernández
On 02/07/2013 08:53 AM, fe...@epepm.cupet.cu wrote: Could I use samba4 as a domain controller with and external ldap? Could I use samba4 as a domain controller with and external dns? samba4 as DC uses an internal ldap server, you can't change that. but you can use an external dns server: bin

Re: [Samba] about samba4 and external ldap and dns

2013-02-07 Thread felix
> Could I use samba4 as a domain controller with and external ldap? > Could I use samba4 as a domain controller with and external dns? > > samba4 as DC uses an internal ldap server, you can't change that. but you can use an external dns server: bind9 Felix. -- To unsubscribe from this list go

[Samba] about samba4 and external ldap and dns

2013-02-07 Thread Amaury Viera Hernández
Could I use samba4 as a domain controller with and external ldap? Could I use samba4 as a domain controller with and external dns? Regards un advance, Amaury. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Web Site Authentication extra attributes

2013-02-07 Thread Vijay Thakur
Hi All Members, I have deployed a Samba4 server in my Office. And all Desktop and Server machines are able to authenticate by samba4. Now i want to authenticate my external web site with samba4. Hence it required some extra attributes (fields) to be queried from Samba4 Server by web application,

Re: [Samba] Upgrading from 4.0.0 to 4.0.3

2013-02-07 Thread Adam Tauno Williams
On Wed, 2013-02-06 at 13:14 +, Brian Haupt wrote: > I have the same question. +1 [and PLEASE bottom post] > -Original Message- > From: samba-boun...@lists.samba.org [mailto:samba-boun...@lists.samba.org] On > Behalf Of Thomas Simmons > Sent: Tuesday, February 05, 2013 2:15 PM > To: s

Re: [Samba] AD DC LDAP support for the 'password change' extended operation

2013-02-07 Thread Adam Tauno Williams
On Thu, 2013-02-07 at 08:25 +1100, Andrew Bartlett wrote: > On Mon, 2013-02-04 at 10:31 +0100, Luis Angel Fernandez Fernandez wrote: > > ldappasswd -d4 -h 192.168.0.137 "cn=juan.lapuerta,ou=alisys.net > > ,dc=aliratiun,dc=tic" > > ldap_build_search_req ATTRS: supportedSASLMechanisms > > SASL/GSSAPI

Re: [Samba] Samba 4 AD DC "Element not found" error in Windows 8

2013-02-07 Thread Ufficiotecnico Acknow
Using \\dcname.corp.domain.com\share or \\your_ip\share works? Check also security tab on folder to set right permsission. Il 07/02/2013 08.14, Nick Semenkovich ha scritto: Hi: I've just configured a Samba 4 install as an AD DC, following the Wiki page at https://wiki.samba.org/index.php/Samb