Re: [Samba] GPO Permissions _AGAIN_

2013-10-13 Thread Alex Matthews
On 09/10/2013 16:41, Alex Matthews wrote: Hi all, I'm afraid I'm back to my old issue of GPO permissions. I have two ADDCs providing an AD Domain (internal.stmaryscollege.co.uk (short-name 'SMC')). Servers are called 'ad-01' and 'tainan'. ad-01 is

Re: [Samba] GPO Permissions _AGAIN_

2013-10-10 Thread Alex Matthews
On 09/10/2013 16:41, Alex Matthews wrote: Hi all, I'm afraid I'm back to my old issue of GPO permissions. I have two ADDCs providing an AD Domain (internal.stmaryscollege.co.uk (short-name 'SMC')). Servers are called 'ad-01' and 'tainan'. ad-01 is

[Samba] GPO Permissions _AGAIN_

2013-10-09 Thread Alex Matthews
%s from GPO object' % (acl_type(direct_db_access), path, fsacl_sddl, acl)) Would it also be possible, as an update to sysvolcheck, to not throw an uncaught exception but more gracefully give the errors and continue after the first one? Thanks, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Migrate samba 3.4.17 from i686 to x86_64

2013-09-10 Thread Alex Domoradov
Hello, I need to migrate our current pdc based on samba-3.4.17 which is installed on CentOS-5.9 # uname -a Linux pdc.example.net 2.6.18-348.16.1.el5 #1 SMP Wed Aug 21 04:03:57 EDT 2013 i686 i686 i386 GNU/Linux To the new server, that will be have 8 Gb of RAM. And I want to migrate to x86_64 archi

Re: [Samba] Debian Package Updates

2013-08-06 Thread Alex Ferrara
Hi Andrew, Would it be possible to upload the packages to the samba team ppa? Sent from my iPhone On 05/08/2013, at 10:28 AM, Andrew Bartlett wrote: > On Fri, 2013-08-02 at 14:41 +0100, Dominic Evans wrote: >> The debian package of samba4 is still sitting at 4.0.3 in >> experimental. Please co

Re: [Samba] Samba4 using existing DNS and LDAP

2013-08-06 Thread Alex Ferrara
Hi Olivier, I had a similar situation for many of my clients, and I am not anywhere near the end of it yet. I can offer some of my experience though. The upgrade procedure is documented in https://wiki.samba.org/index.php/Samba4/samba-tool/domain/classicupgrade/HOWTO and I ended up using --dns

Re: [Samba] Joining DC

2013-08-04 Thread Alex Ferrara
On 05/08/2013, at 7:03 AM, Mike Ray wrote: > Alex- > > A few things: > > 1) Don't run DCs on the same domain with different versions of Samba. Either > add in another 4.0.1 DC and replicate, or use the backup tool to create a > copy of the database first. > 2) C

Re: [Samba] Joining DC

2013-08-04 Thread Alex Ferrara
Does nobody know how to manually remove items from Samba4 directory? I've tried using adsiedit but cn=deleted items doesn't show up. Sent from my iPhone On 02/08/2013, at 1:58 PM, Alex Ferrara wrote: > I am having some trouble joining a new samba4 server as a DC. I am pretty

[Samba] Joining DC

2013-08-01 Thread Alex Ferrara
bject) ../source4/rpc_server/drsuapi/getncchanges.c:220: Failed to find attribute in schema for attrid 2786216 mentioned in replPropertyMetaData of CN=Recipient Update Service (DOMAIN)\0ADEL:cbf078d9-a0ff-4609-a05b-743816af619d,CN=Deleted Objects,CN=Configuration,DC=domain,DC=local Alex

Re: [Samba] Compiling Samba 4.0.7 - make test results

2013-07-29 Thread Alex Ferrara
Nice to see my how to is helping out. Sent from my iPhone On 29/07/2013, at 4:12 PM, "Mgr. Peter Tuharsky, MsU Banska Bystrica" wrote: > Thank You > > Dňa 24.07.2013 15:38, L.P.H. van Belle wrote / napísal(a): >> Hai, >> >> Just look here >> >> http://www.enterprisesamba.com/samba/ >>

Re: [Samba] Replication problems

2013-07-20 Thread Alex Ferrara
Thanks Andrew, I did see that in the change log, but haven't tried it as of yet. aF On 17/06/2013, at 9:01 PM, Andrew Bartlett wrote: > On Wed, 2013-06-12 at 06:54 +1000, Alex Ferrara wrote: >> Hi everyone, >> >> Samba4 has been going great for quite a while now

[Samba] Provision new domain from Windows AD

2013-06-20 Thread Alex Ferrara
Hi everyone, What I want to achieve is to provision a new domain with the users, groups and group policy of an existing AD domain. Is this what I would use the vampire function for? Am I on the wrong track? Alex Ferrara Director Receptive IT Solutions -- To unsubscribe from this list go to

[Samba] Replication problems

2013-06-11 Thread Alex Ferrara
icated for Connection! I have tried manually replicating, but this doesn't seem to work. Any insight would be fantastic. Alex Ferrara Director Receptive IT Solutions -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] 'Administrator' account (UID 0) on Samba member of a Samba4 AD DC

2013-05-31 Thread Alex Matthews
mains only = no winbind use default domain = yes winbind enum users = yes winbind enum groups = yes (Note: I changed the idmap config SMC:range to include '0' as I thought this might encourage samba to idmap the root user... but no dice...) Thanks, Alex -- To u

[Samba] question about "ignore system acls"

2013-05-17 Thread Alex Chu
/mnt/ceph/test browseable = yes read only = no guest ok = no create mask = 0644 directory mask = 0755 valid users = Can someone tell me what I had done wrong? Did I misunderstand the option or my configuration is in incorrect format? Thanks a lot! BTW, I'm using version 3.6.3 on Ubuntu Precise.

[Samba] Weird issue when accessing a samba4 domain member by IP vs hostname

2013-05-09 Thread Alex Matthews
omain is the hostname when connecting via said hostname? Thanks, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Is nss_winbind required?

2013-05-09 Thread Alex Matthews
On 09/05/2013 09:56, Andrew Bartlett wrote: On Thu, 2013-05-09 at 09:48 +0100, Alex Matthews wrote: On 09/05/2013 04:00, Andrew Bartlett wrote: On Wed, 2013-05-08 at 15:23 +0100, Alex Matthews wrote: Hi all, Is it a necessity to use the winbind nss module? I have run a few tests and having

Re: [Samba] Is nss_winbind required?

2013-05-09 Thread Alex Matthews
On 09/05/2013 09:56, Andrew Bartlett wrote: On Thu, 2013-05-09 at 09:48 +0100, Alex Matthews wrote: On 09/05/2013 04:00, Andrew Bartlett wrote: On Wed, 2013-05-08 at 15:23 +0100, Alex Matthews wrote: Hi all, Is it a necessity to use the winbind nss module? I have run a few tests and having

Re: [Samba] Is nss_winbind required?

2013-05-09 Thread Alex Matthews
On 09/05/2013 04:00, Andrew Bartlett wrote: On Wed, 2013-05-08 at 15:23 +0100, Alex Matthews wrote: Hi all, Is it a necessity to use the winbind nss module? I have run a few tests and having it enabled creates a massive bottleneck. It's not nss_winbind itself that is the bottlenec

[Samba] Is nss_winbind required?

2013-05-08 Thread Alex Matthews
s (eg a windows roaming profile) can be excruciatingly slow! 50s+ for a 50mb folder! I am sure that it is not a network or drive limitation, copying the folder locally and via NFS happen very quickly and copying the same folder from a standalone S3 install on the same hardware is 'fast&#

Re: [Samba] many smbd processes when sync'ing sysvol

2013-05-08 Thread Alex Matthews
21:55 +0100, Alex Matthews wrote: Hi there, I have three S4 servers running as AD DCs. In order to keep the sysvol share in sync I'm using crontab to run the following command: /usr/bin/rsync -PavAX --delete root@:/var/lib/samba/sysvol/ /var/lib/samba/sysvol/ However everytime this comma

Re: [Samba] many smbd processes when sync'ing sysvol

2013-05-08 Thread Alex Matthews
On 08/05/2013 00:43, Michael Mol wrote: On May 7, 2013 4:56 PM, "Alex Matthews" <mailto:qoole.sa...@lillimoth.com>> wrote: > > Hi there, > > I have three S4 servers running as AD DCs. > In order to keep the sysvol share in sync I'm using crontab to ru

[Samba] many smbd processes when sync'ing sysvol

2013-05-07 Thread Alex Matthews
this issue/know what is causing it? I have taken some level 10 logs of the smbd processes that get formed. However I don't have access to them from my current location. I will email them in tomorrow from work. Thanks, Alex -- To unsubscribe from this list go to the following URL an

Re: [Samba] dns entries look weird in remote administration dns tool

2013-05-02 Thread Alex Matthews
Hiya, My Windows based DNS utility always looks like this: http://i.imgur.com/hhGmm0w.png Is that similar to what you're referring to Chantal? I've not noticed it cause a problem. Although I'm sure it shouldn't be like it! Thanks, Alex On 02/05/2013 08:13, Chantal Rosmu

[Samba] Samba 4 success story

2013-05-01 Thread Alex Ferrara
migrated to Samba4, and I have quite a few more to go. Exciting times. Alex Ferrara Director Receptive IT Solutions -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Migrate from MS-AD to Samba4

2013-04-28 Thread Alex Ferrara
Hi all, This might be a silly question, but what is the best way to migrate an existing AD domain to promote Samba4 as the domain controller. Alex Ferrara Director Receptive IT Solutions P 0403 604 604 F (02) 4822 7700 E a...@receptiveit.com.au W www.receptiveit.com.au -- To unsubscribe

[Samba] Removing and recreating DNS from scratch.

2013-04-04 Thread Alex Matthews
ite-packages/samba/__init__.py", line 224, in add_ldif self.add(msg, controls) _ldb.LdbError: (68, 'ldb_wait: Entry already exists (68)') I have tried with both SAMBA_INTERNAL and BIND9_DLZ both give me the same error. Is there any known method to achieve this? Thanks, Alex

[Samba] ACLs not obeyed when connecting to a share from a trusted domain where share path target contains spaces

2013-03-22 Thread Alex Crow
The odd thing is that if you use smbclient on Linux with creds of a user in the trusted domain it connects to the share just fine! Any ideas? Thanks Alex -- This message is intended only for the addressee and may contain confidential information. Unless you are that person, you may not disclos

Re: [Samba] FOOBAR\usuario1 windows explorer hungs forever while accessing shared dirs in LAPAZ\comp1 (interdomain trust relationships)

2013-02-27 Thread Alex Crow
code is identical. Thanks Alex On 20/11/12 21:10, Fernando Torrez wrote: Hi all I have two samba PDC installed according to these specifications: domain FOOBAR with pdc server name: BAR (ip 192.168.1.1) opensuse 11.1 samba-3.5.6-15.1 openldap2-2.4.12-5.6.1 smbldap-tools-0.9.5-25.1 A winxp

[Samba] What will happen if I disable reverse check for \\server\printer on samba?

2013-02-20 Thread Alex Korobkin
t be fixed soon. Could anything bad happen if I remove this check manually? -Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Request to an old post - Having problem with Samba Internal DNS

2013-02-20 Thread Alex Matthews
On 20/02/2013 10:58, Andrew Bartlett wrote: On Wed, 2013-02-20 at 10:53 +, Alex Matthews wrote: Hiya, I am also having problems with this. When samba starts I get tsig verify failures: [2013/02/20 10:49:05, 0] ../source4/smbd/server.c:369(binary_smbd_main) samba version 4.0.3

Re: [Samba] Request to an old post - Having problem with Samba Internal DNS

2013-02-20 Thread Alex Matthews
stebin.com/ZJQR6hiJ Running dnsupdate shows it fails on the same records as above and dnsupdate --all-names fails on _ALL_ records. Is this correct behaviour? (I can't see that being the case) If not can someone suggest a way forward? Thanks! Alex On 18/01/2013 10:40, Christof König wrote: Hel

Re: [Samba] Slow winbind lookups

2013-01-16 Thread Alex Matthews
Hiya, Having done horrific things (you don't want to know... believe me) I managed to remove the 'dead' server from my domain. No trace of it anywhere that I can find. The slowdown still remains. Can anyone point me in another direction I can persue? Thanks, Alex On 14/01/2

Re: [Samba] Slow winbind lookups

2013-01-14 Thread Alex Matthews
server and timing out. Thus giving the delay. Is there any way to blacklist this server seeing as I am unable to remove it. Or would someone (Andrew??) Be willing to talk me through a way of manually removing it from my domain? Thanks, Alex On 10/01/2013 14:51, Alex Matthews wrote: On 10/01/

[Samba] werr_access_denied when running setdriver for a printer

2013-01-11 Thread Alex Korobkin
_type : 0x (0) uuid : ---- result : WERR_ACCESS_DENIED Thanks in advance. -Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/ma

[Samba] del_driver_init deletes what?

2013-01-10 Thread Alex Korobkin
} ret = (tdb_delete_bystring(tdb_drivers, key) == 0); return ret; === However, I dumped all the keys of ntdrivers.tdb and there is no single key with a name like DRIVER_INIT/. Am I incorrect about this function internals? What does del_driver_init trying to delete and why would it fail? Thanks

Re: [Samba] Slow winbind lookups

2013-01-10 Thread Alex Matthews
On 10/01/2013 13:51, Hleb Valoshka wrote: On 1/10/13, Alex Matthews wrote: wbinfo -u takes a long time to return a list of users I guess that if you attach output of strace wbinfo -u or may be even strace -f wbinfo -u you'll find assistance faster :) # strace -ftT wbinfo -u 14:09:01 e

[Samba] ACL on GPO directory does not match expected value from GPO object. AGAIN.

2013-01-10 Thread Alex Matthews
200a9;;;AU)(A;OICI;0x001200a9;;;ED) O:DAG:DUD:P(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED) The only difference I can see is the 'DAG' vs 'LAG' at the

[Samba] Slow winbind lookups

2013-01-10 Thread Alex Matthews
e for this process to complete but I'll save that for my other post) Is this correct speed? Is there anything I can do to improve performance? Thanks, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Windows 8 printing to CUPS+Samba - will CreatePrinterIC RPC call stub be implemented?

2012-12-20 Thread Alex Korobkin
a harmless answer and proceed with printer connection? -Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Windows 8 printing to CUPS+Samba - will CreatePrinterIC RPC call stub be implemented?

2012-12-19 Thread Alex Korobkin
a harmless answer and proceed with printer connection? -Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Remove dead server from domain.

2012-12-10 Thread Alex Matthews
Hi all, Sorry to bump my own thread but are there any suggestions for this issue? Thanks, Alex On 05/12/2012 12:53, Thomas Simmons wrote: Just to note, I have seen the same problem deleting "real" Windows Server DCs with rc4 and rc5. The first time I try deleting the DC via ADUC,

Re: [Samba] samba and RODC

2012-12-05 Thread Alex Samad - Yieldbroker
Hi Dumping this incase it didn't make it the first time. Also should I be looking at samba4 ? currently using samba on centos 6.2 I think its 3 Alex > -Original Message- > From: Alex Samad - Yieldbroker > Sent: Friday, 30 November 2012 7:44 PM > To: samba@lists.sa

[Samba] Remove dead server from domain.

2012-12-05 Thread Alex Matthews
because: The specified module could not be found." Is there a command line tool that I could try (samba-tool doesn't seem to have an option to remove the machine). Any other suggestions? Thanks, Alex -- To unsubscribe from this list go to the following URL and read the instruction

[Samba] samba and RODC

2012-11-30 Thread Alex Samad - Yieldbroker
o B and no replies from B Thanks Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] [PATCH] Re: SYSVOL ACLs and GPOs

2012-11-06 Thread Alex Matthews
On 06/11/2012 11:43, Alex Matthews wrote: On 05/11/2012 02:10, Andrew Bartlett wrote: It is certainly very helpful to have this happen with samba-tool. Can you remind me the history of this domain, is it the upgrade I was trying to suggest you do, or a fresh provision? If you can tell me what

Re: [Samba] [PATCH] Re: SYSVOL ACLs and GPOs

2012-11-06 Thread Alex Matthews
Ls on the sysvol share from a windows client. There we a couple of issues with samba-tool creating GPOs but I will run through those in an email later this evening when I have had chance to test them on my test domain. Thanks, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] SYSVOL ACLs and GPOs

2012-11-01 Thread Alex Matthews
On 30/10/2012 00:08, Jeremy Allison wrote: On Tue, Oct 30, 2012 at 11:00:31AM +1100, Andrew Bartlett wrote: be a particular trigger - but it shouldn't be able to make a modification that doesn't go via vfs_acl_xattr. For Alex, before running the Group Policy tools on WinXP, he gets

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-27 Thread Alex Matthews
On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex Matthews wrote: Hi, I have installed a virtual testing network consisting of one samba4 PDC (latest git master) and one Windows XP Pro SP3 (fully updated)machine. I

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-26 Thread Alex Matthews
On 26/10/2012 11:03, Andrew Bartlett wrote: On Fri, 2012-10-26 at 10:44 +0100, Alex Matthews wrote: I'm assuming because of the way I laid my directory tree out I could also just provision as normal and run the tests? Just makes it difficult to "un-provision". I did a bit

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-26 Thread Alex Matthews
On 26/10/2012 02:37, Andrew Bartlett wrote: On Fri, 2012-10-26 at 00:34 +0100, Alex Matthews wrote: On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 26/10/2012 00:34, Alex Matthews wrote: On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews wrote: samba-tool ntacl sysvolcheck

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews wrote: samba-tool ntacl sysvolcheck

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews wrote: samba-tool ntacl sysvolcheck shows: sudo /usr/local/samba/bin/samba-tool ntacl sysvolcheck ERROR(): uncaught exception - ProvisioningError: VFS ACL on GPO directory /usr/local/samba/var/locks

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 25/10/2012 10:20, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:01 +0100, Alex Matthews wrote: On 25/10/2012 02:31, Andrew Bartlett wrote: On Wed, 2012-10-24 at 18:36 +0100, Alex Matthews wrote: On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Alex Matthews
On 25/10/2012 02:31, Andrew Bartlett wrote: On Wed, 2012-10-24 at 18:36 +0100, Alex Matthews wrote: On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex Matthews wrote: Hi, I have installed a virtual testing network

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-24 Thread Alex Matthews
On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex Matthews wrote: Hi, I have installed a virtual testing network consisting of one samba4 PDC (latest git master) and one Windows XP Pro SP3 (fully updated)machine. I

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-24 Thread Alex Matthews
On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex Matthews wrote: Hi, I have installed a virtual testing network consisting of one samba4 PDC (latest git master) and one Windows XP Pro SP3 (fully updated)machine. I have successfully provisioned an AD Domain

[Samba] SYSVOL ACLs and GPOs

2012-10-24 Thread Alex Matthews
/2mEvWX6K My smb.conf is stock. No alterations. The server OS is Ubuntu 12.04. The filesystem is ext4 mounted with the following options: "errors=remount-ro,acl,user_xattr,barrier=1". I have all acl packages installed that I have seen referenced by samba or in posts of a similar nature

[Samba] DNS Domain Name vs Samba4 Domain Name vs NT4 Domain Name

2012-10-21 Thread Alex Matthews
t; is:internal.stmaryscollege.co.uk Samba4 Domain is: ??? internal.stmaryscollege.co.uk ??? My NT4 Domain is: ??? internal ??? I currently have a s3 domain set up called "SMC" (I am _NOT_ going to attempt migrate it to a samba4 domain). Does my NT4 domain have to be the first part of my Samba4 do

Re: [Samba] Centos 6.3 smbldap-tools installation issue

2012-08-27 Thread Alex Domoradov
> Hi. > > I got a fresh installation of centos 6.3 x64, I want to setup a PDC > with samba+ldap and see what I need to upgrade my centos 5.x servers. > I follow my manual, but I got issues went I want to install > smbldap-tools, check: > > Processing Dependency: perl(Unicode::MapUTF8) for package:

[Samba] Bind9 Error

2012-07-09 Thread Alex McWhirter
This server is running on Debian Squeeze, update to unstable. When configuring bind for kerberos (step 8 in the how to) it errors out. This is what i get in syslog, using bind 9.8. Jul 8 01:43:58 dc named[1590]: starting BIND 9.8.1-P1 -u bind Jul 8 01:43:58 dc named[1590]: built with '--prefix=/

[Samba] Samba3+OpenLDAP -> Samba4 implications.

2012-06-13 Thread Alex Ferrara
other things relying on OpenLDAP for authentication and configuration, with several custom schemas. Is there a samba4 schema for OpenLDAP or is there a migration path for networks like mine? Alex Ferrara Director Receptive IT Solutions -- To unsubscribe from this list go to the following URL

Re: [Samba] Samba 4 analyse

2012-06-07 Thread Alex Crow
, and mappings are stored in LDAP Idmap ou. Is it possible to continue using trusted domains this way? Thanks Alex -- This message is intended only for the addressee and may contain confidential information. Unless you are that person, you may not disclose its contents or use it in any way and

[Samba] SSH Server and Hash algorithms

2012-06-06 Thread Alex Moen
: smbldap-usershow al...@domain.com dn: uid=al...@domain.com,ou=domain,o=ndtc uid: al...@domain.com cn: Alex M mail: al...@domain.com ... userPassword: {crypt}$1$kxH/MHL7$.51e8u0CooCalDaXsHSKD/ Crypt? OK, well, it's a crypt (MD5) password even though authconfig says it'll be using sha512...

Re: [Samba] 3.6.5 and "not_defined_in_RFC4178@please_ignore" error

2012-06-01 Thread alex . ranskis
t lookup for name CORP<0x1b> Socket options: SO_KEEPALIVE = 0 SO_REUSEADDR = 4 SO_BROADCAST = 32 Could not test socket option TCP_NODELAY. IPTOS_LOWDELAY = 0 IPTOS_THROUGHPUT = 0 SO_SNDBUF = 57344 SO_RCVBUF = 57344 Could

Re: [Samba] 3.6.5 and "not_defined_in_RFC4178@please_ignore" error

2012-05-23 Thread Alex Still
> Now, what seems suspicious (to me, at least !) is the line : > ads_dns_lookup_srv: Failed to resolve _ldap._tcp.pdc._msdcs.CORP > (Connection timed out) > > Shouldn't it try to resolve "_ldap._tcp.pdc._msdcs.CORP.NET" instead ? Now I've tried running it through dbx (dbx) where =>[1] ads_dns_lo

Re: [Samba] 3.6.5 and "not_defined_in_RFC4178@please_ignore" error

2012-05-23 Thread Alex Still
Hello, On Wed, May 23, 2012 at 1:59 PM, Jim McDonough wrote: > On Mon, May 21, 2012 at 12:17 PM,   wrote: >> We're having trouble joining an AD domain with 3.6.5 >> >> This message when running net join looks fishy : >> "got principal=not_defined_in_RFC4178@please_ignore" > I'm sure it looks fish

Re: [Samba] Can't populate LDAP directory with smbldap-populate

2012-05-23 Thread Alex Domoradov
> then your missing perl files on your centos server. No, I didn't. As i said before - the problem is that perl-LDAP on CentOS 5 is too old. I have tested on Debian 4 with libnet-ldap-perl-0.33.2 and got the same error. On Wed, May 23, 2012 at 10:11 AM, L.P.H. van Belle wrote: > then your missing

Re: [Samba] Can't populate LDAP directory with smbldap-populate

2012-05-22 Thread Alex Domoradov
+8irlDG6QkyFr0iswpw/iX1QJhOFFv shadowLastChange: 15482 shadowMax: 45 On Mon, May 21, 2012 at 6:44 PM, Alex Domoradov wrote: > It seems that this issue RHEL/CentOS related. I have tried the following > > Install smbldap-tools-0.9.8 on Debian squeeze, locate smbldap.conf to > my test

[Samba] 3.6.5 and "not_defined_in_RFC4178@please_ignore" error

2012-05-21 Thread alex . ranskis
ET security=ADS encrypt passwords = yes bind interfaces only = true interfaces = msusersncs Any hints on the best way to try and figure out what is wrong when trying to register in the AD ? (the same config worked with samba 3.4.x, but the DCs were running Windows 2003)

Re: [Samba] Can't populate LDAP directory with smbldap-populate

2012-05-21 Thread Alex Domoradov
QeEVoRkFMakVoTk1sTjA= shadowLastChange: 15481 shadowMax: 45 On Mon, May 21, 2012 at 5:01 PM, Alex Domoradov wrote: > No, i don't. It's testing environment, so the password is too simple - > "1234567" :) > > On Mon, May 21, 2012 at 4:58 PM, L.P.H. van Belle

Re: [Samba] Can't populate LDAP directory with smbldap-populate

2012-05-21 Thread Alex Domoradov
No, i don't. It's testing environment, so the password is too simple - "1234567" :) On Mon, May 21, 2012 at 4:58 PM, L.P.H. van Belle wrote: > Hai, > > Are u using, @#$%^&*!() in your password ? > Try itout.. > > Gr. > > Louis > > >&g

[Samba] Can't populate LDAP directory with smbldap-populate

2012-05-21 Thread Alex Domoradov
I have the following environment # cat /etc/redhat-release CentOS release 5.8 (Final) # uname -r 2.6.18-308.4.1.el5 I have installed smbldap-tools from http://download.gna.org/smbldap-tools/packages/el5/smbldap-tools-0.9.8-1.el5.noarch.rpm. Configured OpenLDAP, but when I try to populate LDAP di

[Samba] Should BDC have same local SID as the Domain SID?

2012-05-11 Thread Alex Crow
? Obviously I can force the local SID to the domain one with net setlocalsid, just not sure what is the "correct" procedure. Cheers Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] 3.6.5, Windows 2008 R2, not_defined_in_RFC4178@please_ignore

2012-05-10 Thread Alex Still
I get the same result. I guess the problem comes from our new 2008 R2 DC servers. (we had 2003 previously) Best, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Cannot join domain with samba-3.6.4

2012-04-21 Thread Alex Still
Then it crashes here (only with -d 10) : ads_try_connect: sending CLDAP request to 10.219.244.38 (realm: CIB.NET) &response->data.nt5_ex: ... [...] Any hints on the best way to try and figure out what is wrong when trying to register in the AD ? Cheers, Alex -- To unsubscribe from t

Re: [Samba] samba over nfs mount and free space problem

2012-03-20 Thread Alex Mestiashvili
On 03/19/2012 10:30 PM, Alex Mestiashvili wrote: > On 03/19/2012 08:35 PM, Volker Lendecke wrote: >> On Mon, Mar 19, 2012 at 03:55:44PM +0100, Alex Mestiashvili wrote: >>> "dfree command" also didn't help. >> The dfree command should always help. Yo

Re: [Samba] samba over nfs mount and free space problem

2012-03-19 Thread Alex Mestiashvili
On 03/19/2012 08:35 PM, Volker Lendecke wrote: On Mon, Mar 19, 2012 at 03:55:44PM +0100, Alex Mestiashvili wrote: "dfree command" also didn't help. The dfree command should always help. You could fake 100GB free space always. Volker Hi, that is my dfree command ( I added

[Samba] samba over nfs mount and free space problem

2012-03-19 Thread Alex Mestiashvili
the way free space is calculated between nfs and local filesystems ? And what else can I try to workaround this problem ? here is the output of smbd -b http://www.biotec.tu-dresden.de/~alex/smb_build_options.txt Thank you in advance, Alex -- To unsubscribe from this list go to the fo

Re: [Samba] samba Digest, Vol 110, Issue 27

2012-02-26 Thread Alex Domoradov
> Hi > I can't answer the question definitively, but nss-ldapd solves the delay > you are describing. Without nscd. > Thanks, now (with nslcd) all works fine and quickly -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/sam

Re: [Samba] samba Digest, Vol 110, Issue 26

2012-02-25 Thread Alex Domoradov
> > nss-ldapd with nslcd. Much quicker mappings. > http://arthurdejong.org/nss-**pam-ldapd/ > HTH > Steve > It seems that it's only other implementation of nss-ldap from PADL. So, my question is the following - will there always be a delay (without using any

Re: [Samba] Samba domain member server using only nss ldap

2012-02-25 Thread Alex Domoradov
ue, Feb 21, 2012 at 10:13 AM, Alex Domoradov wrote: > Thanks, I'll try your solution > > > On Mon, Feb 20, 2012 at 10:56 AM, Angel Bosch wrote: > >> Hi, >> >> not sure if you solved this. I'll give my advice anyway. >> >> >> if y

Re: [Samba] Samba domain member server using only nss ldap

2012-02-21 Thread Alex Domoradov
ssword server = mypdc.example.com > > [prova3] >comment = proves de membre samba >path = /tmp/prova3 >read only = No >guest ok = Yes > > > > > this is the simplest way i've found to do it. > > regards, > > abosch &g

Re: [Samba] Samba domain member server using only nss ldap

2012-02-15 Thread Alex Domoradov
> On a member server, the ldap backend should not be needed for user and group look up. You do need some sort of idmapping for the unix level to see the UID's and GID's assigned to the samba users, and use those uid's and gid's to set file permissions. I need to do idmapping via winbind or someth

[Samba] Samba domain member server using only nss ldap

2012-02-15 Thread Alex Domoradov
I have NT4 domain on samba-3.x integrated with LDAP. I need to use domain users in the shares permissions On the domain member server I have the following smb.conf [global] workgroup = W3 server string = File server netbios name = FS1 security = domain load printers = no

Re: [Samba] Samba member server creates sambaDomainName LDAP entry

2012-01-29 Thread Alex Domoradov
sambaForceLogoff: -1 sambaNextRid: 1281 sambaAlgorithmicRidBase: 1000 gidNumber: 1353 sambaMaxPwdAge: -1 sambaPwdHistoryLength: 0 uidNumber: 1878 On Sun, Jan 29, 2012 at 10:31 PM, Andrew Bartlett wrote: > On Sun, 2012-01-29 at 14:45 +0200, Alex Domoradov wrote: > > I have the following b

[Samba] Samba member server creates sambaDomainName LDAP entry

2012-01-29 Thread Alex Domoradov
I have the following box setup as a file server # cat /etc/redhat-release CentOS release 6.2 (Final) # uname -r 2.6.32-220.4.1.el6.x86_64 # rpm -qa | grep samba samba-3.5.10-114.el6.x86_64 samba-winbind-clients-3.5.10-114.el6.x86_64 samba-client-3.5.10-114.el6.x86_64 samba-winbind-3.5.10-114.el6

Re: [Samba] LDAP issues

2012-01-28 Thread Alex Moen
that was done, all the smbldap group commands worked. I was able to add the groups that my user needed. Then, it was just a matter of changing (syncing? updating? creating?) the samba user password, and everything was working. So, the combination of using a usermap (email_address = windows_userna

Re: [Samba] LDAP issues

2012-01-26 Thread Alex Moen
I didn't go too deeply on your issue, but it seems to me that since you have: ldap user suffix = ou=People You cannot simply have: dn: uid=testu...@mydomain.com,ou=mydomain,o=ndtc But should have instead: dn: uid=testu...@mydomain.com,ou=People,ou=mydomain,o=ndtc Am I wrong? Nope. Yo

Re: [Samba] LDAP issues

2012-01-26 Thread Alex Moen
On Jan 26, 2012, at 12:42 PM, Jorge Concha C. wrote: On Thu, 26 Jan 2012 14:59:24 -0300, Alex Moen wrote: ldap usersuffix = ou=People maybe the problem is: this line must be ldap user suffix = ou=People Sorry, my english is not good. -- Jorge C. OK, fixed that, but it didn't

Re: [Samba] LDAP issues

2012-01-26 Thread Alex Moen
On Jan 26, 2012, at 10:55 AM, Jürgen Echter wrote: Am 26.01.2012 17:51, schrieb Alex Moen: Forgot to add... If I create a Unix account, and add it to the local smbpasswd subsystem, it works fine. I can log in using the credentials that I create. So, samba is working, and linux/ldap is

Re: [Samba] LDAP issues

2012-01-26 Thread Alex Moen
Forgot to add... If I create a Unix account, and add it to the local smbpasswd subsystem, it works fine. I can log in using the credentials that I create. So, samba is working, and linux/ldap is working, but samba/ldap has issues... Alex Moen Network Services Technician

[Samba] LDAP issues

2012-01-26 Thread Alex Moen
, command outputs, etc. to get this solved. TIA! Alex Moen Network Services Technician II North Dakota Telephone Company 701-662-6481 -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba on FreeNAS permissions

2012-01-03 Thread Alex Ferrara
s inherit permissions = yes vfs objects = zfsacl recycle recycle:repository = .recycle/%U recycle:keeptree = yes recycle:versions = yes recycle:touch = yes recycle:directory_mode = 0777 recycle:subdir_mode = 0700 inherit acls = Yes map archive = No map readonly = no nfs4:mode = sp

[Samba] Samba4 DNS Update failing and crashing Bind

2011-12-14 Thread Alex MacCuish
auth-nxdomain no;# conform to RFC1035 listen-on-v6 { any; }; tkey-gssapi-keytab "/usr/local/samba/private/dns.keytab"; }; Any help would be greatly appreciated, Alex -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] 3.6.0 Domain trusts broken

2011-10-14 Thread Alex Crow
On 11/10/11 22:16, Jeremy Allison wrote: On Tue, Oct 11, 2011 at 06:44:18PM +0100, Alex Crow wrote: Hi all, Since the winbind refactoring in Samba 3.6.0, interdomain trusts between Samba servers seem to be broken in that being able to resolve or modify file permissions on the other domain work

[Samba] 3.6.0 Domain trusts broken

2011-10-11 Thread Alex Crow
rvers is as follows, the other server is the same apart from the domain being "TESTDOM2" and wins server = PDC> rather than "wins support=yes". Any help is much appreciated. Thanks, Alex [global] workgroup = TESTDOM1 netbios name = PDC interfaces = eth0, lo passd

Re: [Samba] How to check the password complexity in samba

2011-09-12 Thread Alex Domoradov
>Who changed users' password? >"check password script" affects only for normal user. I run smbldap-passwd as root dn and gui (srvtools) as domain admins 2011/9/12 TAKAHASHI Motonobu > From: Alex Domoradov > Date: Mon, 12 Sep 2011 17:09:29 +0300 > > > Hi all

  1   2   3   4   5   6   7   >