[Samba] Problems with W2K8R2 <-> S4 replication

2010-05-23 Thread Dmitry Khromov
rested in Samba4 AD DC functionality, so I'd like to try it out. Hope you'll help me. Best regards, Dmitry Khromov. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4 internal DNS - how to modify SOA record

2013-08-06 Thread Dmitry Khromov
>> How could one modify a SOA record in rc3? For example, NS part (not NS >> record) of SOA record points to an absent Windows server. This effectively >> breaks DNS updates, since there is no such server and if corresponding A >> record is added, update requests from clients will come unsigned.

[Samba] DRS replication fails with Windows 2003 R2

2012-09-27 Thread Dmitry Khromov
to manually replicate Sysvol, or should I just restore GPOs from backups after taking Windows DC down? Will such approach introduce any AD inconsistence/fuctionality problems? Thanks in advance. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the

[Samba] DRS replication fails with Windows 2003 R2

2012-09-27 Thread Dmitry Khromov
a6-6374-409d-a7e9-4010964e2dca._msdcs.klin.kifato-mk.com[1026,seal,krb5] NT_STATUS_UNSUCCESSFUL Any suggestions? smb_debug.log.xz is attached (sorry for xz, but it's sowemhat long). -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba4 LDAP returns wrong responses in some cases, BIND-DLZ refuses to update

2012-09-28 Thread Dmitry Khromov
renders DNS unmanageable: # bin/samba-tool dns zonelist dc0 Password for [someadminu...@klin.kifato-mk.com]: ERROR(runtime): uncaught exception - (9717, 'WERR_DNS_ERROR_DS_UNAVAILABLE') Any suggestions on getting updates to work? -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] BIND-DLZ refuses to update

2012-09-29 Thread Dmitry Khromov
gt; (metadata partition) ldb: ldb_trace_next_request: (tdb)->search ldb: ldb_trace_response: REFERRAL ref: ldap://klin.kifato-mk.com/CN=Configuration,DC=klin,DC=kifato-mk,DC=com ldb: ldb_trace_response: REFERRAL ref: ldap://klin.kifato-mk.com/DC=DomainDnsZones,DC=klin,DC=kifato-mk,DC=com ldb: ld

[Samba] Samba4 KDC - no such entry found in hdb

2012-09-30 Thread Dmitry Khromov
kifato-mk,DC=com NULL -> 1 ndr_pull_error(11): Pull bytes 2 (../librpc/ndr/ndr_basic.c:103) [] 00 00 00 00 62 00 00 00 00 00 00 00 20 00 20 00 b... . . [0010] 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00. . . . . . . . [0020] 20 00 20 00 20 00 20 00 20 00 20 00 20 0

Re: [Samba] Samba4 KDC - no such entry found in hdb

2012-10-01 Thread Dmitry Khromov
On Mon, 1 Oct 2012 10:43:59 +0400 Dmitry Khromov wrote: > Samba 4.1.0pre1-GIT-aad669b, joined as a DC to an existing domain. At least 6 > accounts behave like this: > Kerberos: AS-REQ techgr...@klin.kifato-mk.com from ipv4:192.168.1.31:33822 > for krbtgt/klin.kifato-mk@klin.k

[Samba] Samba4 KDC Windows 7 clients may fail to get a ticket

2012-10-02 Thread Dmitry Khromov
_recv() - NT_STATUS_CONNECTION_DISCONNECTED' [2012/10/03 09:31:54, 3] ../source4/smbd/process_single.c:104(single_terminate) single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED] -- Best regards, Dmitry Khromov. -- To unsubscribe from this list

Re: [Samba] Samba4 KDC Windows 7 clients may fail to get a ticket

2012-10-02 Thread Dmitry Khromov
Samba DC 5 days ago). By the way, XP stations (we have more XP's than Sevens) are unaffected. Thank you. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba 4 internal DNS - how to modify SOA record

2012-10-23 Thread Dmitry Khromov
sRecord, so one could forge a valid record and just change dnsRecord in DC=@ using some LDAP tool? Thanks in advance. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Unable to create GPO with rc3 and a few authentication problems

2012-10-29 Thread Dmitry Khromov
ase. Try to rename some host using Windows GUI (My Computer -> Properties) and check if CN, sAMAccountName and member for corresponding groups are changed correctly. In my experience, only sAMAccountName is changed. Once again, sorry if this is OK. Thanks in advance. -- Best regards, Dmitry Khrom

Re: [Samba] Unable to create GPO with rc3 and a few authentication problems

2012-10-30 Thread Dmitry Khromov
Policies after samba-tool ntacl sysvolreset). So, should samba-tool really use machine account for GPO operations? -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Unable to create GPO with rc3 and a few authentication problems

2012-10-30 Thread Dmitry Khromov
> On Wed, 2012-10-31 at 03:33 +0400, Dmitry Khromov wrote: > > > I had encountered a few problems with 2 Samba 4 rc3 DCs serving domain > > > migrated from Windows 2003 R2. I post them altogether, since they look > > > related. > > > > > > 1. Un

[Samba] Internal DNS - TTL enforcement for dynamic updates

2012-10-31 Thread Dmitry Khromov
g. Normally, this is done by modifying SOA record (and, as I recall, Samba's internal DNS respects TTLs in SOA). But samba-tool can't edit SOA records, MMC DNS snap-in fails to do it too. Thanks. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
able. Or just pkill samba and use ldbmodify on the .ldb directly. http://msdn.microsoft.com/en-us/library/ee898781(prot.20).aspx describes dnsRecord attribute data format http://msdn.microsoft.com/en-us/library/cc448905(v=prot.20).aspx describes SOA record format Thank you! -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
ave a control of records TTL. P.S. > When Windows DHCP client receives a lease or when you manually issue ipconfig > /renew command Sorry, not /renew, I meant /registerdns. Thanks. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructi

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
need a network capture to see what's > going on with the DNS MMC failing to update the SOA record. Attached (PCAP-formatted). Thanks in advance. -- Best regards, Dmitry Khromov -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

2012-11-01 Thread Dmitry Khromov
record. As you can see, only the first update succeeds, then - SERVFAIL again. P.S. Just in case you're suprised with the updates frequency - it's what we really have in production on "parking" subnets, as a workaround for the Windows 7 DHCPINFORM on non-authoritative subnets