Re: [Samba] NFS locking ...maybe?

2007-05-24 Thread Don Meyer
min / Websmith . 800.441.3873 x130 Photo Craft Imaging . 3550 Arapahoe Ave. #6 http://www.pcraft.com . . .. Boulder, CO 80303, U.S.A. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba

Re: [Samba] Possible problem w/ 'idmap restore' under 3.0.25rc3 (the sequel)

2007-05-11 Thread Don Meyer
At 11:22 AM 5/11/2007, Don Meyer wrote: At 07:17 AM 5/11/2007, simo wrote: > Afterward, testing the UID mappings that should have been established > (by 'getent passwd {username}' results in allocation of a new number. I need to know what error you get, I have no errors in

Re: [Samba] Possible problem w/ 'idmap restore' under 3.0.25rc3 (the sequel)

2007-05-11 Thread Don Meyer
redhat conference. Jerry has shown me the proper way to build fresh RPMs from the SVN tree with *all* the patches -- I'll plan on building fresh from this and also tearing down and starting the LDAP fresh, so I can get clean results later this afternoon/evening. We

Re: [Samba] Possible problem w/ 'idmap restore' under 3.0.25rc3 (the sequel)

2007-05-10 Thread Don Meyer
At 04:40 PM 5/9/2007, simo wrote: On Fri, 2007-05-04 at 19:14 -0500, Don Meyer wrote: > At 06:00 PM 5/4/2007, simo wrote: > >Sorry for the problem, this slipped through during recent patches to fix > >the sid checking layer violation and the idmap offline code. > > No pr

Re: [Samba] Possible problem w/ 'idmap restore' under 3.0.25rc3

2007-05-04 Thread Don Meyer
s not. (Cached) Running 'getent passwd user2' opens another session, etc. This occurs whether the UID is already present, or if it needs to be added new. If you need more information on any of this, just let me know. It seems so close... ;-) Cheers, -D Don Meyer

[Samba] Possible problem w/ 'idmap restore' under 3.0.25rc3

2007-05-04 Thread Don Meyer
mp file I had just created, and received the same long string of errors. Thus, I suspect there is something not quite right in the 'net idmap restore' functionality... Cheers, -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academ

Re: [Samba] Group permission problems with winbind & NFS

2007-05-03 Thread Don Meyer
At 08:30 AM 5/3/2007, simo wrote: On Mon, 2007-04-30 at 23:35 -0500, Don Meyer wrote: [..] > This system NFS mounts the remote file storage resource on a backend > RHEL4 server. The public facing web frontends also mount these same > resources. Here is where things get hinky -- s

[Samba] Problem with Samba-3.0.25rc3 & idmap_ldap (winbind dumps core)

2007-05-01 Thread Don Meyer
n = cn=sambaadmin,dc=aces-web idmap config ALLDOMAINS:ldap_base_dn = ou=idmap,dc=aces-web idmap config ALLDOMAINS:backend = ldap idmap config ALLDOMAINS:default = yes create mask = 0664 directory mask = 02775 inherit permi

[Samba] Group permission problems with winbind & NFS

2007-04-30 Thread Don Meyer
one can offer will be extremely welcome. (Frankly, even just hearing that someone else is seeing a similar problem would be welcome at this point... ;-) Thanks, -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility

RE: [Samba] Joining an 2003 AD

2007-04-30 Thread Don Meyer
ads join' with Domain Admin credentials...(Even up through 3.0.25rc3) Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES TeleNet System UIUC College of ACES, Information Technology an

Re: [Samba] Joining an 2003 AD

2007-04-30 Thread Don Meyer
he 3.0.23c level, IIRC. (maybe 3.0.23b?)That explains the version differences you are seeing. The gotcha is that I get this failure despite attempting the 'net ads join' with Domain Admin credentials...(Even up through 3.0.25rc3) -D Don Meyer

Re: [Samba] Samba-3.0.23c kernel lock problems with new Redhat kernel 2.6.9-42.0.8

2007-02-02 Thread Don Meyer
ers, but a real solution to the problem would be most welcome ! -- Ole Holm Nielsen Department of Physics, Technical University of Denmark Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES Tel

RE: [Samba] AD integration checklist

2006-12-09 Thread Don Meyer
ficient/lib/security/$ISA/pam_unix.so likeauth nullok use_first_pass authrequired /lib/security/$ISA/pam_deny.so Cheers, -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manage

RE: [Samba] AD integration checklist

2006-12-08 Thread Don Meyer
ers = @"BENCHCAN\domain users" Although this will give all your users access to / which doesn't seem like a good idea, but I assume this is just for testing. Don't forget the necessary modifications to nsswitch.conf: passwd: files winbind

Re: [Samba] Windows Vista RC2 can't delete Samba Directories

2006-10-23 Thread Don Meyer
by searching the samba list archives for "SELinux". Cheers, -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES TeleNet System UIUC College of ACES, Information Technology and Com

Re: [Samba] restrict ssh login by Win2K AD group SOLVED!

2006-09-19 Thread Don Meyer
le AD groups to this group. Winbind should do the magic beyond this point. Adjust your pam_succeed_if.so line for this new gid once it propagates through winbind, and you should be all set... Cheers, -D Don Meyer <[EMAIL PROTECTED]> Netw

Re: [Samba] Rev #2 of the 3.02.3c patch

2006-08-31 Thread Don Meyer
LzlUk2Pjcfk= =Ggf7 -END PGP SIGNATURE- -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing F

Re: [Samba] Problem with 3.0.23 upgrade from 3.0.22 with rfc2307 patch

2006-07-18 Thread Don Meyer
y know why? Howard. Don Meyer wrote: Well, I didn't see the last bit you describe, but I don't run RFC2307 (yet). We we bit by very similar behavior when moving from 3.0.22 to the 3.0.23 RC's. Turns out that the use-default-domain option is not being universally applied to groups

Re: [Samba] Problem with 3.0.23 upgrade from 3.0.22 with rfc2307 patch

2006-07-18 Thread Don Meyer
Sid +cohtech does not start with 'S-'. and the users get rejected. If I declare the user directly then access is allowed. This server gets its group database from the AD controllers via RFC2307. Anybody know why group expansion may be broken in 3.0.23? Don Meyer

RE: [Samba] Fedora packages or Enterprise packages of Samba on RHEL4?

2006-07-14 Thread Don Meyer
based packages, and as long as it is documented somewhere, is trivial/easy to undo for someone who wants to modify their SELinux config later. This also reminds me that I've been wanting to write up a similar patch to handle the selinux chcons for the /var/cache/samba/

Re: [Samba] Fedora packages or Enterprise packages of Samba on RHEL4?

2006-07-13 Thread Don Meyer
At 01:15 PM 7/13/2006, Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Don Meyer wrote: > Were it up to me, I'd post the RPMs for RHEL with > a prominent disclaimer on the support issue. (But > then I'd probably want to separate builds > for

Re: [Samba] Fedora packages or Enterprise packages of Samba on RHEL4?

2006-07-12 Thread Don Meyer
't aware of the improved ability to build RHEL packages from the tarball, and they only see the complete lack of RHEL binary packages as non-support for RHEL. And I think a CentOS "branch" symlinked to the RHEL branch, or vice-versa, would be a nice recognition of

Re: [Samba] Fedora packages or Enterprise packages of Samba on RHEL4?

2006-07-12 Thread Don Meyer
-- * cd ../.. (should be /etc/selinux/targeted/src/policy/ ) * run the command: "make load" This will load some additional rules that will allow winbindd to run without any (significant) AVC errors. This should only need to be done once. Don Meyer

RE: [Samba] I want to use CNAMES for my SAMBA server, how?

2006-07-10 Thread Don Meyer
tations of this "fix"... Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES TeleNet System UIUC College of ACES, Information Technology and Communication Services "They that c

Re: [Samba] I want to use CNAMES for my SAMBA server, how?

2006-07-10 Thread Don Meyer
At 08:15 PM 7/10/2006, Gerald (Jerry) Carter wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Don Meyer wrote: > My question though is what are the ramifications of > a similar situation: Where the CNAME might be > dynamically moved to point to another system's base >

Re: [Samba] I want to use CNAMES for my SAMBA server, how?

2006-07-10 Thread Don Meyer
ffected from a Samba-based system, in order to avoid the need for commands run at the DC? (I suppose if the setting(s) could be safely preloaded for each server/object that might host a particular service address, then this remote capability might not be quite so necessary...) I look forward

Re: [Samba] Print Cost Capture

2006-07-05 Thread Don Meyer
ace that displays a user's queued jobs and allows release & selection of billing code, etc. should also be do-able with enough time and resources.) Cheers, -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facili

[Samba] Setting AD user's home dir/logon script from Samba?

2006-05-23 Thread Don Meyer
using the NET [ADS|RPC] utility. But I don't see a way to either create the user with home directory / logon script preset, or to change these settings after user creation. Am I missing something? TIA, -D Don Meyer <[EMAIL PROTECTED]> N

RE: [Samba] AD users from different AD domains - update

2006-05-10 Thread Don Meyer
27;t wait for this to be fixed. Volker -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facilit

Re: [Samba] SElinux and Samba

2006-05-05 Thread Don Meyer
I can shut down the smb & winbind services, run "setenforce 1" to re-enable SElinux enforcing mode, and then restart smb & winbind. If all goes well, this should not generate any AVC errors... Hope this helps someone... -D Don Meyer

RE: [Samba] samba 4 winbind feature set

2006-03-16 Thread Don Meyer
they are even in SVN code for the next version at this point. Perhaps someone in the know could fill in the blanks and correct anything that I've mis-recalled above... -D Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Comput

Re: [Samba] AD users from different AD domains

2006-03-09 Thread Don Meyer
heck the membership of a user in a group of another AD domain ? I hope it is clear enough :) This sounds like the same situation that has been discussed here a bit in the past week or so. You probably want to follow bug#3530 on https://bugzilla.samba.org. Cheers, -D D

Re: [Samba] Problem with Universal Groups

2006-03-04 Thread Don Meyer
At 09:26 PM 3/3/2006, Gerald (Jerry) Carter wrote: Don Meyer wrote: > As far as trying to at least get Domain Local group handling fixed in > winbind, I would suggest looking at Bug 3530 on bugzilla.samba.org. > The more people that can show similar failure cases, the more likely

RE: [Samba] Problem with Universal Groups

2006-03-03 Thread Don Meyer
n't work at all unless the user is in the same domain as the group. How do we get this escalated? -Original Message- From: Don Meyer [mailto:[EMAIL PROTECTED] Sent: Thursday, March 02, 2006 6:06 PM To: Trimble, Ronald D; samba@lists.samba.org Subject: Re: [Samba] Problem with Universa

Re: [Samba] Problem with Universal Groups

2006-03-02 Thread Don Meyer
EU\\inblr-auth1 not in required group(s). Does anyone else have something like this working? What am I doing wrong? Thanks, Ron -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listin

Re: [Samba] Public shares in FC4 (update)

2006-02-25 Thread Don Meyer
ect_r:samba_share_t /data drwxrwsrwx root root system_u:object_r:samba_share_t /data/public I think this is a better solution then to have samba have access to any new dir with default_t. What do you think? -Louis On Sat, 2006-02-25 at 23:43 -0600, Don Meyer wrote: > Look at your AVC error (below) -- to

Re: [Samba] Public shares in FC4 (update)

2006-02-25 Thread Don Meyer
but doesn't work. I still get: type=AVC msg=audit(1140923608.645:86): avc: denied { search } for pid=3338 comm="smbd" name="/" dev=hda5 ino=2 scontext=root:system_r:smbd_t tcontext=system_u:object_r:default_t tclass=dir ... why does smbd_t

Re: [Samba] Public shares in FC4 (update)

2006-02-24 Thread Don Meyer
about /data/public access. -Louis On Fri, 2006-02-24 at 16:54 -0600, Don Meyer wrote: > [Caveat: My systems are mostly RHEL4 based, I don't have a FC4 > system handy to verify paths & package names. But they should be > somewhat close...] > > First, you need to identify w

Re: [Samba] Public shares in FC4 (update)

2006-02-24 Thread Don Meyer
t; path = /data/public > > >> public = Yes > > >> read only = No > > >> browseable = Yes > > >> guest ok = Yes > > >> create mask = 2777 > > >> > > >> I am able to browse the s

[Samba] Effect of disabling LM/NTLMv1 auth on an AD?

2006-02-21 Thread Don Meyer
Mv1 on the domain controllers?"Can anyone speak to this? Thanks much, -Don Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES TeleNet System UIUC College of ACES, Infor

Re[2]: [Samba] Domain User access control in the smb.conf

2006-02-17 Thread Don Meyer
mins, I can't even access those share folder. Do I have to chagne to [Test2] comment = Test path = /usr/tmp/ valid users = "@Domain Admins", myaccount readonly = Yes write list = myaccount Thanks Alex On Fri, 17 Feb 2006 13:29:50 -0600 Don M

Re: [Samba] Domain User access control in the smb.conf

2006-02-17 Thread Don Meyer
s a domain separator, you need to be very cognizant of where you need to properly escape it. (I.E., use "\\" instead of just "\") I'm pretty sure that "valid users =" is one of those places... Cheers, -D Don Meyer

Re: [Samba] Samba version and ports

2006-02-16 Thread Don Meyer
m. Thank you. * -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing

Re: [Samba] kerberos error when users in trusted win2k domain try to browse samba server

2006-02-16 Thread Don Meyer
be appreciated. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager,

Re: [Samba] Joining a trusted domain

2006-02-16 Thread Don Meyer
ps://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES TeleNet System UIUC College of ACES, Information Technology and Communication Services "

RE: [Samba] Authenticating another domain

2006-02-16 Thread Don Meyer
out. That is the key. Does "getent passwd 'EU\inblr-auth1'" return anything? What does wbinfo --sequence show? Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Computing Facility Technical System Manager, ACES Tele

Re: [Samba] Samba rpm and /var/*/samba directory for .tdb files

2006-02-16 Thread Don Meyer
At 04:06 PM 2/15/2006, Craig White wrote: On Wed, 2006-02-15 at 14:42 -0600, Gerald (Jerry) Carter wrote: > Don Meyer wrote: > > At 08:24 AM 2/15/2006, Gerald (Jerry) Carter wrote: > >> Oliver Schulze L. wrote: > >> > Hi, > >> > I use CentOS4 (RHEL4) an

Re: [Samba] Samba does not work with new AD groups

2006-02-16 Thread Don Meyer
ed via inclusion in the set specified on your "valid users=" line.) E.g. valid users = "@Domain Users" write list = "@Subset_of_users" Don Meyer <[EMAIL PROTECTED]> Network Manager, ACES Academic Compu

RE: [Samba] samba setup in win2k A.D.

2006-02-15 Thread Don Meyer
ng URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba Don Meyer <[EMAIL PROTECTED]>

Re: [Samba] Samba rpm and /var/*/samba directory for .tdb files

2006-02-15 Thread Don Meyer
/samba/. Does this change in the packaging reflect a "sea change" towards use of /var/lib/samba/ for the future?(I.E. Can we "expect" future RHEL-distributed packagings to adopt use of /var/lib/samba/ as well?) -D Don Meyer

[Samba] Winbind problem w/ ADS domain local group and other-domain members

2006-02-13 Thread Don Meyer
No create mask = 0664 directory mask = 02770 inherit permissions = Yes veto oplock files = /*.TTF/*.XLS/*.DOC/ [prod-W] path = /export/prod/W valid users = "@ITCS CSS Team", "@Domain Admins", IUSR_ACESWEB admin users = &quo