[Samba] UNIX vs. AD group permissions

2007-05-14 Thread David Pullman
. I'd be glad to create level 10 logs to show what's happening (as I did in the previous posts and the bugzilla entry 4348). If anyone has any suggestions I'd greatly appreciate it. We're still running 3.0.14 and can't update production until we can sort this out. -- David Pullman

[Samba] Re: 3.0.23d UNIX vs. AD group permissions

2007-05-03 Thread David Pullman
maintain in AD. We have to maintain the groups in NIS/LDAP. So if we try to use the system like this all of our group definitions are broken. -- David Pullman -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

[Samba] Re: 3.0.23d UNIX vs. AD group permissions

2007-02-03 Thread David Pullman
Status: NEW Severity: major Priority: P3 Component: winbind AssignedTo: [EMAIL PROTECTED] ReportedBy: [EMAIL PROTECTED] QAContact: [EMAIL PROTECTED] -- David Pullman Systems Administrator Manufacturing Engineering Laboratory National

[Samba] Re: 3.0.23d UNIX vs. AD group permissions

2007-01-19 Thread David Pullman
Posted bug for this as I do think it is a serious issue: https://bugzilla.samba.org/show_bug.cgi?id=4348 Summary: UNIX groups not honoured for access to filesystem Product: Samba 3.0 Version: 3.0.23d Platform: Sparc OS/Version: Solaris

[Samba] 3.0.23d UNIX vs. AD group permissions

2007-01-11 Thread David Pullman
be listed in AD, but also populated? Thanks very much. -- David Pullman Systems Administrator Manufacturing Engineering Laboratory National Institute of Standards Technology Mail Stop 8203 100 Bureau Drive Gaithersburg, MD 20899-8260 Tel: (301) 975-5385 Fax: (301) 926-3842 E-mail: [EMAIL PROTECTED

[Samba] Re: 3.0.23d UNIX vs. AD group permissions

2007-01-11 Thread David Pullman
In some subsequent testing it seems to be in winbind: by commenting out the ldap, idmap, and winbind params in smb.conf and not starting winbindd, the authorization is as expected: When I access the share, I get the slew of groups that I belong to in UNIX mapped to the S-1-22 sid:

Re: [Samba] Compile error: libsmbclient on 12rc1 on Solaris 9

2005-03-17 Thread David Pullman
Thanks very much. Will update and rebuild on the test box later today! --David Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 David Pullman wrote: | snip from make.log: | Compiling libsmb/libsmbclient.c with -KPIC | libsmb/libsmbclient.c, line 3249: warning: argument

[Samba] Compile error: libsmbclient on 12rc1 on Solaris 9

2005-03-16 Thread David Pullman
=no it builds successfully. I haven't run into an acomp failure before. Any suggestions? Thanks very much. -- David Pullman -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

[Samba] Is it possible to specify read only by netgroup for hostname entries?

2004-10-13 Thread David Pullman
? It seems that hosts allow can specify a netgroup of machines, but there does not seem to be any way to specify a read list or something like that for machines, only for user names or netgroups of usernames. Any chance I'm missing something that could make this work? Thanks very much. -- David

[Samba] Solaris ACLs, the mask parameter on directories disappears

2004-02-17 Thread David Pullman
for group and the default group work as listed, but not as the #effective entry shows, which is how it normally does. This is a case of everything is working, but it looks funny under the covers :) Makes one a bit nervous. -- David Pullman NIST - Gaithersburg -- To unsubscribe from this list go

[Samba] Any approaches to server usage reporting/metrics

2004-01-29 Thread David Pullman
of connections, etc. As you can imagine, I'd like to find a way to show what we get for the investment in time and equipment, as part of an overall report on services by my group. Thanks very much for any input. David Pullman -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Another Samba+ACLs thread

2002-11-27 Thread David Pullman
On Wed, Nov 27, 2002 at 12:08:12PM +0800 or thereabouts, Andrew Furey wrote: (recipient list getting longer...) Via username mapping, yes (we're a member server in a 2k mixed domain, but that side of things seems to be working). On further investigation, it appears that I _can_ modify

Re: [Samba] Another Samba+ACLs thread

2002-11-26 Thread David Pullman
Andrew Furey wrote: The problem arises when I try to change them from W2k. It silently fails (from 2k's point of view), but in the log files I see something like unable to map SID [blah] to uid or gid. Is the win2k user the owner (in the unix sense) of the file. ? Even though you have

[Samba] acls unable to map SID solaris w2k

2002-11-25 Thread David Pullman
much. Dave -- David Pullman Systems Administrator Manufacturing Engineering Laboratory National Institute of Standards Technology Mail Stop 8203 Gaithersburg, MD 20899-8260 Tel: (301) 975-5385 Fax: (301) 926-3842 E-mail: [EMAIL PROTECTED] -- To unsubscribe from this list go to the following URL