Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Luca Olivetti
Al 27/08/13 01:52, En/na Marc Muehlfeld ha escrit: Am 27.08.2013 01:19, schrieb Luca Olivetti: https://wiki.samba.org/index.php/Local_user_management_and_authentication/nslcd Yep, I only had to comment the map group uniqueMember member line, though (migrated) groups show the members fine.

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-27 Thread steve
On Tue, 2013-08-27 at 01:39 +0200, Marc Muehlfeld wrote: Hello Steve, thanks for your suggestions. Am 27.08.2013 00:40, schrieb steve: 1. Nested groups work fine with nslcd. Please use the latest version: man nslcd.conf(5) I use the version Redhat ships. I haven't used that

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Luca Olivetti
Al 27/08/13 01:46, En/na Marc Muehlfeld ha escrit: Am 27.08.2013 01:13, schrieb Luca Olivetti: In ADUC on Win7 the tab should be there (on XP you need to install something additionally if I remember right). Ah, OK, I'm on XP and I installed the tools here:

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Marc Muehlfeld
Am 27.08.2013 10:38, schrieb Luca Olivetti: http://support.microsoft.com/kb/921913/en Thank you, I was missing idmu.exe Now I can see the unix tab, but, whenever I click accept, it tells me Unable to modify the object property values. Check your credentials. There could be a network problem.

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-27 Thread Marc Muehlfeld
Am 27.08.2013 10:11, schrieb steve: Your distro must be still using the 0.7 series. Yes. RHEL ships 0.7.5. I had a short search for 0.8 and it seems that since that, some comfortable changes where done for AD. If I have time tonight, I'll compile the latest version and try to find out

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Luca Olivetti
Al 27/08/13 10:45, En/na Marc Muehlfeld ha escrit: Am 27.08.2013 10:38, schrieb Luca Olivetti: http://support.microsoft.com/kb/921913/en Thank you, I was missing idmu.exe Now I can see the unix tab, but, whenever I click accept, it tells me Unable to modify the object property values.

[Samba] Samba4 - Wrong ipv6 DNS entry

2013-08-27 Thread Andreas Grabner
Hello, i am using samba 4.0.8 with integrated DNS. Now i notice a wrong DNS entry of the PDC. ip addr (GGG for security ;-): br0: BROADCAST,MULTICAST,UP,LOWER_UP mtu 1500 inet6 2GGG:::G::/64 scope global inet6 fe80::225:90ff:fe77:18e4/64 scope link # ./samba-tool dns query PDC

Re: [Samba] Replication issue

2013-08-27 Thread dahopkins
Any ideas on how to get replication working correctly? I'd demote/delete ncssamba2 but samba-tool fails and ADUC won't let me either. Is there some way to get a more informative message than WERR_INVALID_PARAM? Sincerely, Dave Hopkins - Original Message - I checked and the ping

[Samba] Excel cannot save modifications. No errors for user

2013-08-27 Thread Carlos Eduardo Valente
Text: The problem occurs on any excel file that this especific user try to change. Environment: - XLS file saved on the samba server and then opened from the same server. - User Machine has windows XP and Office 2007. It happens on office 2010 too. -When the user goes clicking SAVE few times on

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Bruno Vane
Hi Luca, If you provisioned your domain with --use-rfc2307, then in Win7 ADUC you can see the posixAccount (UNIX Attributes) of the users. 2013/8/27 Luca Olivetti l...@wetron.es Al 27/08/13 10:45, En/na Marc Muehlfeld ha escrit: Am 27.08.2013 10:38, schrieb Luca Olivetti:

[Samba] DNS managment error

2013-08-27 Thread Antun Horvat
Hello, i have an issue with existing installation of samba4 domain controller that is specific to dns managment. In the domain I have two samba4 4.0.7 and one windows 2003 server that I plug periodically to manage the dns. All fsmo roles are transfered to samba. All aspects of the domain

[Samba] DNS managment error

2013-08-27 Thread Antun Horvat
Hello, i have an issue with existing installation of samba4 domain controller that is specific to dns managment. In the domain I have two samba4 4.0.7 and one windows 2003 server that I plug periodically to manage the dns. All fsmo roles are transfered to samba. All aspects of the domain work

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Luca Olivetti
Al 27/08/13 16:56, En/na Bruno Vane ha escrit: Hi Luca, If you provisioned your domain with --use-rfc2307, then in Win7 ADUC you can see the posixAccount (UNIX Attributes) of the users. I did a classicupgrade, not a provisioning, and I can see the unix attributes of the migrated users, the

[Samba] Change default GID of users

2013-08-27 Thread Bruno Vane
Hi all, I'm using samba4 as DC and using ssh/nslcd/pam in some machines to lookup ldap base in samba4 to allow access for users. My question is, how can I set the default GID os users to 100, to match the GID of groupusers in my linux machines? All users I create with ADUC is getting UID 513.

Re: [Samba] Change default GID of users

2013-08-27 Thread steve
On Tue, 2013-08-27 at 12:14 -0300, Bruno Vane wrote: Hi all, I'm using samba4 as DC and using ssh/nslcd/pam in some machines to lookup ldap base in samba4 to allow access for users. My question is, how can I set the default GID os users to 100, to match the GID of groupusers in my linux

Re: [Samba] DNS managment error

2013-08-27 Thread Garth Keesler
This issue has been discussed at length before with no resolution to my knowledge. If you use samba-tool drs showrepl, you will probably notice that Forest and Domain DNS is not being replicated to/from all DCs. Additionally, if you use Win2003 DNS MMC, you will not be able to detect that DNS

Re: [Samba] DNS managment error

2013-08-27 Thread Antun Horvat
Thanks for such quick reply, I have just executed samba-tool drs showrepl command and it seems that Forest and Domain LDAP DIT are being replicated successfully. But I still doubt that it can not be fixed since all RR records that are added to w2k3 server are successfully propagated and

[Samba] objectClass:posixAccount missing

2013-08-27 Thread Marc Muehlfeld
Hello, I start a new thread, because the other one meanwhile drifted far away from what the OP asked. :-) Am 27.08.2013 17:02, schrieb Luca Olivetti: If you provisioned your domain with --use-rfc2307, then in Win7 ADUC you can see the posixAccount (UNIX Attributes) of the users. I did a

Re: [Samba] Change default GID of users

2013-08-27 Thread steve
On Tue, 2013-08-27 at 14:33 -0300, Bruno Vane wrote: Hi Steve, I did what you said, and when create the user, nothing changes: Hi Sorry, you have to add: gidNumber: 100 to the DN of each user too. Make sure that you clear the nscd cache after making any change to AD. Steve -- To

Re: [Samba] objectClass:posixAccount missing

2013-08-27 Thread steve
On Tue, 2013-08-27 at 20:11 +0200, Marc Muehlfeld wrote: Do posixAccount/posixGroup objectClasses have to be there normally? No. With the AD schema, you can use all of rfc2307 without the need for the objectclassed which define them. Just add the attributes. HTH Steve -- To unsubscribe

Re: [Samba] DNS managment error

2013-08-27 Thread Garth Keesler
Interesting. Are Forest and Domain records being replicated in both directions from all DCs? It always worked from the WinDC to the S4DC but not in the other direction. Also, were you able to use the WIN DNS MMC to examine the DNS records on any of the Samba DCs? If so, you are probably close

Re: [Samba] objectClass:posixAccount missing

2013-08-27 Thread Luca Olivetti
Al 27/08/13 20:46, En/na steve ha escrit: On Tue, 2013-08-27 at 20:11 +0200, Marc Muehlfeld wrote: Do posixAccount/posixGroup objectClasses have to be there normally? No. With the AD schema, you can use all of rfc2307 without the need for the objectclassed which define them. Just add the

Re: [Samba] DNS managment error

2013-08-27 Thread Antun Horvat
Well that's the thing, I can only replicate DNS changes from WinDC to Samba, but not in other way. I can't even update DNS records on Samba side, only on Windows side. I managed to figure out an error on Samba caused by RPC call: dnsserver: Found DNS zone . Failed to find DNS Zones in

Re: [Samba] Change default GID of users

2013-08-27 Thread Bruno Vane
Hi Steve, Seems that this attribute does not matter, see my user bruno.vane: primaryGroupID: 513 gidNumber: 100 If I try to change the value of primaryGroupID I get an error: Using: root@samba:~# ldbedit -e vim --url=/usr/local/samba/private/sam.ldb samaccountname=bruno.vane failed to modify

Re: [Samba] DNS managment error

2013-08-27 Thread Garth Keesler
Unfortunate since that's exactly what I saw. I've no answers but I will keep watch in hope that you have better luck solving it than I did. See ya... Garth On 08/27/2013 02:00 PM, Antun Horvat wrote: Well that's the thing, I can only replicate DNS changes from WinDC to Samba, but not in other

Re: [Samba] objectClass:posixAccount missing

2013-08-27 Thread Rowland Penny
On 27/08/13 19:56, Luca Olivetti wrote: Al 27/08/13 20:46, En/na steve ha escrit: On Tue, 2013-08-27 at 20:11 +0200, Marc Muehlfeld wrote: Do posixAccount/posixGroup objectClasses have to be there normally? No. With the AD schema, you can use all of rfc2307 without the need for the

Re: [Samba] objectClass:posixAccount missing

2013-08-27 Thread Gary Greene
If you set it up with '--use-rfc2307', nslcd needs configured as though it is talking to an SFU 3.5 DC. The RFC 2307bis attributes never add additional classes to the AD member objects, even in an SFU environment. -- Gary L. Greene, Jr. Sr. Systems Administrator IT Operations Minerva Networks,

Re: [Samba] objectClass:posixAccount missing

2013-08-27 Thread Luca Olivetti
Al 27/08/13 23:56, En/na Gary Greene ha escrit: If you set it up with '--use-rfc2307', nslcd needs configured as though it is talking to an SFU 3.5 DC. The RFC 2307bis attributes never add additional classes to the AD member objects, even in an SFU environment. Thank you, that gave me an

[SCM] Samba Shared Repository - branch v4-1-test updated

2013-08-27 Thread Karolin Seeger
The branch, v4-1-test has been updated via 6b6cab7 Fix bug #10063 - source3/lib/util.c:1493 leaking memory w/ pam_winbind.so / winbind from c41ffd5 ntdbtool.8.xml: Bump version up to 4.1. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v4-1-test - Log

[SCM] Samba Shared Repository - branch v4-0-test updated

2013-08-27 Thread Karolin Seeger
The branch, v4-0-test has been updated via 1787174 Fix bug #10063 - source3/lib/util.c:1493 leaking memory w/ pam_winbind.so / winbind from 16e6631 s3-winbindd: fix fallback to ncacn_np in cm_connect_lsat(). http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v4-0-test - Log

autobuild: intermittent test failure detected

2013-08-27 Thread autobuild
The autobuild test system has detected an intermittent failing test in the current master tree. The autobuild log of the failure is available here: http://git.samba.org/autobuild.flakey/2013-08-27-1351/flakey.log The samba3 build logs are available here:

[SCM] Samba Shared Repository - branch master updated

2013-08-27 Thread David Disseldorp
The branch, master has been updated via 323cccd smbd: Use #defines in smb2_getinfo_send from d1593a2 Fix the UNIX extensions CHOWN calls to use FCHOWN if available, else LCHOWN. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2013-08-27 Thread Jeremy Allison
The branch, master has been updated via 617c647 Fix valgrind errors with memmove and talloc pools. via cbfc3ef Add simple limited pool tests to test_memlimit(). via 3d0f717 Remove talloc_memlimit_update(). No longer used. via 8e2a543 Inside _talloc_realloc(), keep