Re: [Samba] Winbind Authentication on Redhat Home Directories

2005-02-24 Thread Christian Merrill
Dave Morrow wrote: Hi all, I have Winbind authentication up and running properly (thanks to new, easy to use features of Redhat Ent 4). My question is this. I know that I can, by massaging /etc/pam.d files manually, have Winbind/Samba automatically create a home directory for each user that

Re: [Samba] Samba Best Practices -- Integration with Active Directory

2005-02-22 Thread Christian Merrill
Tim Holmes wrote: ood Morning Everyone: This question is a bit different from the run of the mill -- HELP ME I GOT TROUBLE questions here on the list, however I am interested in getting this situation working correctly and also need to understand the basis behind the process so that I can

Re: [Samba] Samba Upgrade...

2005-01-31 Thread Christian Merrill
Brent Smith wrote: Sorry if this is a dup. I sent right before I subscribed to the list, so I'm not sure if it made it. I have just taken over a redhat system with Samba 3.0.0 configured with security = user, and domain logins enabled. I've included the smb.conf at the end of this message. I

Re: [Samba] disappointed with complete lack of help.

2005-01-28 Thread Christian Merrill
forth in regard to the product, but to what extent they *do* monitor this list and help others. Christian Merrill -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

[Samba] Curious timestamp bug in samba???

2005-01-18 Thread Christian Merrill
Testing indicates that when a file located on a linux samba share is modified from a windows client, the creation date is modified along with the modification date. It appears that samba doesn't differentiate between the two? I know it's relatively minor in the great scheme of things, but we

Re: [Samba] Curious timestamp bug in samba???

2005-01-18 Thread Christian Merrill
Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Christian Merrill wrote: | Testing indicates that when a file located on a linux | samba share is modified from a windows client, the creation | date is modified along with the modification date. It | appears that samba

Re: [Samba] winbind authentication with fallback

2005-01-11 Thread Christian Merrill
Pau Capdevila wrote: Hi, We use Active Directory users to login into our GNU/Linux workstations. If the network is down, is there any way to use a fallback method to login with the same profile (user, homedir, etc)? Thank you, Pau On windows you can do this because the domain account

Re: [Samba] Samba 3.0.9 doesn't remove printjobs ?

2004-12-21 Thread Christian Merrill
Collins, Kevin wrote: We just upgraded to Samba 3.0.9 (RedHat Enterprise 3 packages) this weekend and are now seeing similar issues on our workstations. I do not see any printing related errors in our logs however. I do however see these backed up print queues on every workstation. We run a mix

Re: [samba] Adding Domain Groups to local Groups Crashed XP

2004-12-17 Thread Christian Merrill
Daniel Wilson wrote: Hi, Im using samba 3.0.9 with LDAP (Sun Iplanet 5.2 directory Server). On an XP client, im trying to add Domain Users group to the Local Power Users group (For windows updates etc...) However when i try to add the group it just crashed the windows. Also if i use the usrmgr.exe

[Samba] RHEL3 3.0.9 Release Active Directory Membership

2004-12-17 Thread Christian Merrill
Some preliminary testing indicates that there may be problems in the newly released Red Hat 3.0.9 packages (not samba.org's) in regard to joining an AD as a full member (w/kerberos). This may also affect maintaining current membership in such an environment. If anyone has already upgraded

Re: [Samba] RHEL3 3.0.9 Release Active Directory Membership

2004-12-17 Thread Christian Merrill
in our domain. Let me know if you need any more help or testing or whatever. Thanks, Ben Vaughan Ben Vaughan Engineering Computing Support Services CLUE Network SysAdmin Iowa State University -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Christian

Re: [Samba] smbd hung processes - Samba 3.0.7

2004-12-03 Thread Christian Merrill
[EMAIL PROTECTED] wrote: We've seen Samba crash and burn twice in the last 48 hours - it just started happening, and we have no idea what might be causing it. I'm hoping that someone will recognize this problem. Platform: we are running RedHat Enterprise Server, with Samba 3.0.7. We're using

Re: [Samba] AD Domain member not authenticating

2004-12-01 Thread Christian Merrill
John Stile wrote: I had samba working, then I tried (unsuccessfully) to setup ssh pam auth. Now users are prompted for a password when accessing shares, but no password works. I am using Redhat AS 3, samba-3.0.9-1, and krb5-1.3. I forgot to backup pam file system-auth before modifying things,

Re: [Samba] AD Domain member not authenticating

2004-12-01 Thread Christian Merrill
John Stile wrote: On Wed, 2004-12-01 at 11:06 -0800, John Stile wrote: I had samba working, then I tried (unsuccessfully) to setup ssh pam auth. Now users are prompted for a password when accessing shares, but no password works. I am using Redhat AS 3, samba-3.0.9-1, and krb5-1.3. I forgot

[Samba] XP/PDC/Directory Server

2004-11-22 Thread Christian Merrill
Alright, I promise I won't put in any more threads regarding this nightmare. Let me rephrase my previous question. Is there *anyone* out there who has XP Pro systems successfully logging into Samba PDC's with Netscape Directory backends? I've rebuilt all components a few times and still I

Re: [Samba] Re: authentication against win2k3 server

2004-11-19 Thread Christian Merrill
Kevin Kobb wrote: Carissa Srugis wrote: I've been trying to setup Samba to authenticate users against accounts existing on a Windows 2003 Server without any backwards capability. Ideally, this needs to be done without any changes to the Windows 2003 Server. Users will not be logging into the

Re: [Samba] Re: authentication against win2k3 server

2004-11-19 Thread Christian Merrill
will then be passed through to squid for proxy authentication. Thanks! Carissa On Fri, 19 Nov 2004 09:42:22 -0500, Christian Merrill [EMAIL PROTECTED] wrote: Kevin Kobb wrote: Carissa Srugis wrote: I've been trying to setup Samba to authenticate users against accounts existing on a Windows 2003

Re: [Samba] Running Samba 3 as PDC

2004-11-19 Thread Christian Merrill
Irene Sakellarakis wrote: I am investigating options for using Samba 3.0.7.2.FC1 (Red Hat Fedora Core 1 basic installation, currently updating via yum) as a primary and only domain controller. We have a Windows user environment, and I'm trying to connect the user machines (XP fully patched as

[Samba] XP SP2/Samba3.0.8 PDC/Directory Server 5.2 backend

2004-11-19 Thread Christian Merrill
Would anyone care to offer any theories (at this point I'll take whatever I can get) as to why the following happens: 1. w2k boxes can join the domain perfectly, users can logon, life is wonderful. 2. winXP boxes can join the domain perfectly, users authenticate fine, the screen goes blue as

Re: [Samba] Re: net ads join fails using Red Hat samba 3.0.7-1.3E.1 (Re: Samba 3 as domain member of w2k realm)

2004-11-18 Thread Christian Merrill
Matt Seitz wrote: Resending with corrected subject line Matt Seitz wrote: R.B. wrote: i've a problem joining a samba 3.0.7-1.3E.1 in a w2k domain: [EMAIL PROTECTED] squid]# net ads join -U myuser myuser's password: [2004/11/18 13:29:32, 0] utils/net_ads.c:ads_startup(183) ads_connect: Program

RE: [Samba] iplanet ldap and samba

2004-11-18 Thread christian merrill
I am not aware of a good guide that takes iplanet into account. I am almost finished working through this with a customer and should hopefully have some documentation put together soon. In this case the customer is running Directory Server 5.2 in a solaris environment with Samba 3.0.7 on

[Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
For whatever reason I am trying to configure the following environment and am running into trouble towards the end of things. Hopefully I am overlooking something basic, any assistance would be greatly appreciated. 1. Redhat AS 2.1 server running Netscape Directory Server 5.2 2. RHEL3 system

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Christian Merrill wrote: For whatever reason I am trying to configure the following environment and am running into trouble towards the end of things. Hopefully I am overlooking something basic, any assistance would be greatly appreciated. 1. Redhat AS 2.1 server running Netscape Directory

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Andreas wrote: On Tue, Nov 16, 2004 at 11:20:06AM -0500, Christian Merrill wrote: Ok, managed to fix most of this...however something appears to be goofy with the Administrator account...I cannot access shares with it directly and it won't allow me to join a machine to the domain

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Daniel Wilson wrote: Christian Merrill wrote: Daniel Wilson wrote: try setting your admin account with uidNumber=0 gidNumber=512 primarygroupsid = X-512 the uidnumber=0 is the important one i think! Regards Dan Here's what I have -- it all looks good, no idea what I'm missing. I'm thinking

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Andreas wrote: On Tue, Nov 16, 2004 at 12:02:21PM -0500, Christian Merrill wrote: Thanks, one more problem out of the way. Now on a windows system I can manually net use to a share with Administrator, however attempting to join the domain still fails with a bad username/pw. The user you

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Andreas wrote: On Tue, Nov 16, 2004 at 01:25:56PM -0500, Christian Merrill wrote: Regarding what you are saying, from the RHEL3 Samba server a getent passwd displays Administrator and root both with uid=0 along with the other available local remote ldap accounts. Yes, that's what I

Re: [Samba] Samba/Netscape Directory Server

2004-11-16 Thread Christian Merrill
Andreas wrote: On Tue, Nov 16, 2004 at 01:49:52PM -0500, Christian Merrill wrote: Will bump up the logging and see what I can find. Sorry for not posting the config portion: I would also take a closer look at the ldap logs to be certain samba is being able to log in as manager. Can you

Re: [Samba] Problem with smbmount

2004-11-03 Thread Christian Merrill
Jerome Tytgat wrote: Hello list, Sorry for the reposting, but I think someone may have an idea, I don't think I'm the only one with this kind of problem. I have a problem with my samba shares. I have a server with samba installed on it (3.0.7-Debian). I have workstations under wxp and workstations

Re: [Samba] Problem with smbmount

2004-11-03 Thread Christian Merrill
Jerome Tytgat wrote: Does something like the following work for you: mount -t smbfs -o username=user1,password=xxx,uid=0,gid=0,dmask=770 //server/Archive /mnt/server/archive it works for the mount point but not for any folder inside. Thanks anyway Christian try adding fmask=770 as well

Re: [Samba] kerberos and/or winbind ??

2004-10-13 Thread Christian Merrill
Mark Le Noury wrote: Hi, I'm getting confused about the role that kerberos authentication plays. What exactly is the point of using kerberos to join a samba server to an AD domain? If using kerberos still requires you to rely on winbindd for all the nsswitch stuff then what is the point? I can

Re: [Samba] NT and XP clients cannot reach Samba PDC

2004-10-13 Thread Christian Merrill
M Middleton wrote: When attempting to join my domain, the NT 4 Workstation and XP Pro clients cannot contact the domain controller. The Samba server is running normally, and can be connected to via IP address, but not by name. Additionally, when I set up a DNS, it still could not contact the

[Samba] Redhat, Samba 4, Kerberos, Netscape Directory Server

2004-09-30 Thread Christian Merrill
As you may have heard Redhat just recently acquired Netscape's Directory Server. I am curious about any potential compatibility issues that we may run into down the road with Samba 4. In particular can any integration be done with Netscapes LDAP and are we going to be facing any major issues

Re: [Samba] Unable to map or view resources by name

2004-09-23 Thread Christian Merrill
[EMAIL PROTECTED] wrote: FYI, I have upgraded to Samba 3.0.7-1.3E and the problem persists. Jon Etkins IT Administration Support Austin Logistics, Inc [EMAIL PROTECTED] wrote on 09/22/2004 01:33:55 PM: Hi, folks. I'm in the process of setting up a RH ES3 box as a samba server in our Active

Re: [Samba] Unable to map or view resources by name

2004-09-23 Thread Christian Merrill
[EMAIL PROTECTED] wrote: Christian Merrill [EMAIL PROTECTED] wrote on 09/23/2004 10:29:33 AM: Sounds like you're running into either the kerberos compatibility errors we see with win2k3 or the newest problem where people upgrade from 3.0.6+ and then start encountering apparent kerberos

Re: [Samba] Which distribution to rollout

2004-09-23 Thread Christian Merrill
Daniel Ramaley wrote: I run Samba on OpenBSD. It isn't Linux, but it is free and works very well. It also isn't likely to go away or move to a less stable development any time soon. On Thursday 23 September 2004 09:44 am, Chris McKeever wrote: we are running an older version of RH (7.3) -

[Samba] username.map limitations

2004-09-22 Thread Christian Merrill
It's looking like there may be a 1024 character limit for each username map? For example: account1 = user1 user2 user3 user4 user5 (etc. etc. etc.) --After a certain point user accounts are not recognized as being part of the map. Is this an intentional limitation, am I coming up against

Re: [Samba] username.map limitations

2004-09-22 Thread Christian Merrill
Paul Gienger wrote: It's looking like there may be a 1024 character limit for each username map? For example: From the smb.conf man page Each line of the map file may be up to 1023 characters long. If you're running up against that maybe you should put all the users you need to map into a

[Samba] Change in smbpasswd in 3.0.6

2004-09-17 Thread Christian Merrill
Hi, we recently had a customer reporting that a script they run that includes an smbpasswd statement was no longer functioning after upgrading. The smbpasswd command was being used to create an account and set a password -- taking the passwd as the second argument. It looks like there has

Re: [Samba] Change in smbpasswd in 3.0.6

2004-09-17 Thread Christian Merrill
Jeremy Allison wrote: On Fri, Sep 17, 2004 at 01:18:16PM -0400, Christian Merrill wrote: Hi, we recently had a customer reporting that a script they run that includes an smbpasswd statement was no longer functioning after upgrading. The smbpasswd command was being used to create an account

[Samba] username map --update dynamically?

2004-09-15 Thread Christian Merrill
My assumption is that that Samba needs to be restarted before it can recognize changes made to a username map file. Is there anyway to have it dynamically recognize changes? Christian -- To unsubscribe from this list go to the following URL and read the instructions:

Re: [Samba] username map --update dynamically?

2004-09-15 Thread Christian Merrill
Eric Boehm wrote: On Sun, Sep 12, 2004 at 06:18:25AM -0400, Christian Merrill wrote: Christian == Christian Merrill [EMAIL PROTECTED] writes: Christian My assumption is that that Samba needs to be restarted Christian before it can recognize changes made to a username map

[Samba] Modifying ACL's from client without using winbind

2004-09-13 Thread Christian Merrill
My situation is pretty simple but I'm not able to figure out this last bit (any help is greatly appreciated). I have a Samba3 server that is a standard NT member of an Active Directory. All domain user's have matching local accounts, and the domain groups that are involved also have matching

[Samba] create_canon_ace_lists: unable to map SID

2004-09-10 Thread Christian Merrill
I know this is probably something very simple but I can't for the life of me figure out what's going on. This is a very basic setup using domain security and joined NT style in an AD running in Mixed Mode. I am *not* using winbind, all user and group accounts are represented locally in

Re: [Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-10 Thread Christian Merrill
.. Tom On Fri, 10 Sep 2004, Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Christian Merrill wrote: | Well from my end (Redhat) the behavior is indicative of | a known issue with the MIT kerberos 1.2.x packages | that we currently support and Win2k3 DC's...however Win2k

Re: [Samba] Problems com password in win2k

2004-09-09 Thread Christian Merrill
Fernando wrote: I have a problem with password in win2k clients Samba run in a HP-UX version 11.11 I connect to a server, map the drive, and give to me to put a login and a password, but when i reboot the client machine, give me again the login and password. I would like to stop the give to me a

Re: [Samba] (no subject)

2004-09-09 Thread Christian Merrill
Tom Skeren wrote: It's a mount command. On FBSD it's mount_smbfs //[EMAIL PROTECTED]/share /(some local directory path) Gerald Hughes wrote: Samba, Is if possible to connect to a C drive on a windows machine from a Unix machine using SAMBA? We can go the other way but have a problem from

[Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-08 Thread Christian Merrill
Running into a lot of people upgrading to the 3.0.6 package that all of a sudden begin to experience the Failed to verify incoming ticket! errors etc., that are generally associated with a kerberos package incompatibility. However many of these people are running later versions of kerberos *and*

Re: [Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-08 Thread Christian Merrill
Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Christian Merrill wrote: | Running into a lot of people upgrading to the 3.0.6 | package that all of a sudden begin to experience | the Failed to verify incoming ticket! errors | etc., that are generally associated

Re: [Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-08 Thread Christian Merrill
Rick Brown wrote: On Sun, 5 Sep 2004, Christian Merrill wrote: Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Christian Merrill wrote: | Running into a lot of people upgrading to the 3.0.6 | package that all of a sudden begin to experience | the Failed to verify

Re: [Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-08 Thread Christian Merrill
Ross, Alex wrote: Christian, FYI: win2k SP4 on AD cause Win3K like behavior of forcing Kerberos Ticket sighning http://support.microsoft.com/default.aspx?scid=kb;en-us;811422 So on win2k ad this breaks krb5 before 1.3.x... -Alex -Original Message- From: Christian Merrill [mailto:[EMAIL

Re: [Samba] Samba 3.0.6 Problems w/AD and Kerberos

2004-09-08 Thread Christian Merrill
Blindauer Emmanuel wrote: Le dimanche 05 Septembre 2004 13:38, Christian Merrill a écrit : Running into a lot of people upgrading to the 3.0.6 package that all of a sudden begin to experience the Failed to verify incoming ticket! errors etc., that are generally associated with a kerberos

Re: [Samba] Best strategy to undo an update

2004-09-08 Thread Christian Merrill
Andrew B. Young wrote: My http authentication through winbind has stopped working with a Fedora Core 2 update of httpd and samba (and others), httpd-2.0.49-4 - httpd-2.0.50-2.1 samba-3.0.3-5 - samba-3.0.6-2.fc2 which I believe is caused by a winbind bug