[Samba] member server and groups

2013-04-04 Thread Neil Price
I have a samba 3 member server joined to a samba pdc using ldap. Join is OK. Version is from debian wheezy: 3.6.6 With servers that are bdc's I have no problems with authentication, with the member server I cannot get group file permissions to work. User file permissions work fine Samba share u

Re: [Samba] wbinfo ok, but getent nothing

2011-02-07 Thread Neil Price
On 2011/02/07 02:39 PM, Jean-Yves Avenard wrote: After wasting 2 days on this ; I removed 3.5.6 then installed 3.4.9... And getent passwd properly shows everything :( I had the same experience.. for me the problem is only on member servers, and only with getent group (getent passwd works) S

[Samba] getent group fails on member server after upgrade to 3.5.5

2010-10-21 Thread Neil Price
I have a member server joined to a samba 3 domain. It was working fine with 3.4.8 but after an upgrade to 3.5.5 (debian lenny with backports) getent group no longer works. getent passwd works fine, wbinfo -u and wbinfo -g work fine I upgraded some other servers which are DC's and those work f

Re: [Samba] samba 3.4.7 as NT4 domain member and win9x

2010-10-06 Thread Neil Price
On 2010/10/05 10:44 PM, Chris Weiss wrote: I can connect win9x using local accounts, just not domain accounts. the same domain accounts work from all other OS's, and on older Samba versions. I had a problem with a dos login to a domain account that worked with 3.2.x but not with 3.4.x and 3.5.x

Re: [Samba] NT4 Migration

2010-09-22 Thread Neil Price
Quoting Dermot : sid S-1-5-21-1979685110-1467996072-351907979-500 does not belong to our domain sid S-1-5-21-1979685110-1467996072-351907979-2998 does not belong to our domain sid S-1-5-21-1979685110-1467996072-351907979-3010 does not belong to our domain Are you using idmap? I had this w

[Samba] wbinfo_group.pl and spaces in group names

2010-08-27 Thread Neil Price
Hi, I;m using wbinfo_group.pl from samba 3.4.8 for squid ntlm authentication because I'm using multiple samba groups squid version is 2.7 from debian Lenny squid.conf contains: external_acl_type nt_group ttl=0 children=5 %LOGIN /usr/lib/squid/wbinfo_group.pl -d acl AuthorizedUsers proxy_aut

Re: [Samba] Is "samba3_vscan" compiled anymore, by anyone?

2010-08-23 Thread Neil Price
On 2010/08/22 06:15 PM, Nico Kadel-Garcia wrote: I'm looking at the RPM's over at http://ftp.sernet.de/pub/samba/3.5/, and noticing that the "samba3-vscan" package is not being built for any OS. Is this deliberate? If so, perhaps it can be deleted from the SRPM? It no longer builds correctly for

[Samba] gecos?

2010-06-15 Thread Neil Price
This has always bothered me.. wtf does gecos mean (in the samba ldap)? -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Debian Lenny 3.5.3 packages pam-auth-update

2010-06-09 Thread Neil Price
I hope it is relevant to report this here. The debian lenny samba 3.5.3 packages at http://pkg-samba.alioth.debian.org have this problem: Setting up winbind (2:3.5.3~dfsg-1~unoff50+1) ... /var/lib/dpkg/info/winbind.postinst: line 16: pam-auth-update: command not found dpkg: error processing w

Re: [Samba] Winbind 3.5.2 caching issues under SLES11???

2010-04-26 Thread Neil Price
On 2010/04/23 10:58 PM, Chris Smith wrote: Don't know if it's related but on 2 systems with 3.5.2 I could not get the new idmap backend (moved from tdb to rid) to work without deleting the gencache* tdb's in addition to the winbind ones. I had the same problem on 3.4.7 moving from tdb to ld

[Samba] samba as a trusting domain

2010-04-20 Thread Neil Price
I'm establishing a trust to an NT domain (a real NT domain with a real NT servers) I set up the trusting domain on the NT server then on the samba server # net rpc trustdom establish lawco Enter GIBB.LOCAL$'s password: Could not connect to server CAPETOWN-2 Trust to domain LAWCO established It

[Samba] idmap with member servers

2010-04-13 Thread Neil Price
I'm using a member server joined to my primary domain. I'm using winbind because I have a trusted domain. both pdc and member server has idmap uid = 8-9 idmap gid = 8-9 idmap backend = ldap:ldap://my.pcd member server has security=domain password server = * (and no p