Re: [Samba] Force user permission in specific folders

2013-08-29 Thread TAKAHASHI Motonobu
27;m wondering if it's possible to force folders/files to be > created with certain user/group owner in just that specific folder. > I not I can force so that everything is created with a specific user/group, > but I want it specific to folders. Please use "force user" and

Re: [Samba] samba4wins install

2013-05-25 Thread TAKAHASHI Motonobu
ce I get samba4wins installed, how does one add static > WINS entries to the database? You can add an entry with ldbedit forexample, # ldbedit -H /usr/local/samba4wins/private/wins_config.ldb -a --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To

Re: [Samba] Problems adding domain policies in samba4.0.4

2013-05-06 Thread TAKAHASHI Motonobu
mba-tool domain passwordsettings". Samba4 can provide GPO but cannot be a client. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Passwording a simple anonymous share

2013-04-10 Thread TAKAHASHI Motonobu
on the network. > But I want it to be password protected. Try these settings: [sharename] path=/sharedfiles users = root read only = yes And to set password to "root" with smbpasswd command. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.m

Re: [Samba] Samba Upgrade 3.0.33 to 3.6.13.

2013-04-03 Thread TAKAHASHI Motonobu
efault domain = yes > restrict anonymous = 2 > passdb backend = tdbsam Because you use default idmap (tdb) in Samba 3.0.33 and use idmap_rid for "domain" domain in Samba 3.6.13. If you use same mappings, use same winbindd_idmap.tdb file or manually set the mapping with using wbinfo

Re: [Samba] SaMBa 4 - authenticate ftp server

2013-03-12 Thread TAKAHASHI Motonobu
From: Celso Viana Date: Fri, 8 Mar 2013 23:14:59 -0300 > Does anyone know if it is possible to authenticate an ftp server > (proftpd or vsftpd) based LDAP Samba 4? No. But you can authenticate an ftp server via pam_winbind feature included in Samba4 (or order version of Samba). --- TAK

Re: [Samba] Win 7 - Rejecting auth request from client

2013-03-09 Thread TAKAHASHI Motonobu
cate3: netlogon_creds_server_check failed. Rejecting > auth request from client MACHINE machine account MACHINE$ Does your issue meet this article? https://lists.samba.org/archive/samba/2013-January/171085.html --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.m

Re: [Samba] Cannot logon Samba 4 via plaintext password

2013-03-08 Thread TAKAHASHI Motonobu
At last I filed a bug: https://bugzilla.samba.org/show_bug.cgi?id=9705 From: Benjamin Huntsman Date: Sun, 3 Feb 2013 19:52:02 + So then basically plaintext passwords (and by extension authentication against local UNIX accounts) is completely broken in Samba 4? Want to file a bug, or shall

Re: [Samba] OpenLDAP Samba4 Password Sync

2013-03-05 Thread TAKAHASHI Motonobu
As far as I read, this python script can export the Hash. -- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 DFS Support

2013-03-05 Thread TAKAHASHI Motonobu
e DFS. This similar config is working in Samba v. 3.5.6. I >>spent some time Googling and didn't find much. Do these articles help you? https://lists.samba.org/archive/samba-technical/2013-February/090403.html https://lists.samba.org/archive/samba/2012-October/

Re: [Samba] Making Linux and domain users the same

2013-03-02 Thread TAKAHASHI Motonobu
y other way to map the name to a Unix >> UID - it needs to get that information from somewhere. Use idmap_nss instead of idmap_tdb (default). idmap_nss picks uid/gid from /etc/passwd or its altinatives (such as NIS), instead of generating its own value. --- TAKAHASHI Motonobu / @damemo

Re: [Samba] SaMBa 4.0.3 - permissions in mapping

2013-03-02 Thread TAKAHASHI Motonobu
ot;, reports that the default value of the options > "create mask" and "directory mask" are respectively "0744" and "0755." > The command "testparm" [3] reports that the two values are valued > "0777". If you set up Samba4 as a

Re: [Samba] Cross-subnet browsing with LMBs + remote browse sync + samba4WINS

2013-02-26 Thread TAKAHASHI Motonobu
workgroup name (for example SAMBA01 and SAMBA02) >> >> Then, each Samba box exchanges its browse list. >> >> --- >> TAKAHASHI Motonobu / @damemonyo >>facebook.com/takahashi.motonobu > > Hi Takahashi, > > thats very interesting and i

Re: [Samba] Cross-subnet browsing with LMBs + remote browse sync + samba4WINS

2013-02-25 Thread TAKAHASHI Motonobu
From: vagy Date: Mon, 25 Feb 2013 23:20:31 +0200 > On Mon, 25 Feb 2013 17:40:32 +0200, TAKAHASHI Motonobu > wrote: > > looking the SAMBA docs[1] i realized that remote browse sync > means that an LMB will sync its browse list with another > LMB. Thus this "trick"

Re: [Samba] Cross-subnet browsing with LMBs + remote browse sync + samba4WINS

2013-02-25 Thread TAKAHASHI Motonobu
From: vagy Date: Sun, 24 Feb 2013 18:28:03 +0200 > On Sun, 24 Feb 2013 17:36:56 +0200, TAKAHASHI Motonobu > wrote: > >> From: vagy >> Date: Sun, 24 Feb 2013 13:34:37 +0200 >> >>> i am about to implement cross subnet browsing/sharing >>> and I

Re: [Samba] Samba4 as a classic DC

2013-02-25 Thread TAKAHASHI Motonobu
retain as DC hoping it is still supported, isn't it? As far as I examined, smbd/nmbd of Samba4 can act as a classic domain controller. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read

Re: [Samba] access based shared enum = yes

2013-02-24 Thread TAKAHASHI Motonobu
From: Fabian von Romberg Date: Sat, 16 Feb 2013 17:32:43 -0500 > Actually I tried that under the share definition. Please see my smb.conf: Hmmm, as far as I examined, "access based share enum" does not work against "samba" binary... > [global] > workgroup = MYDOMAIN > realm = MYDOM

Re: [Samba] Cross-subnet browsing with LMBs + remote browse sync + samba4WINS

2013-02-24 Thread TAKAHASHI Motonobu
= yes remote browse sync = x.x.x.x - Samba has to be WINS server and DMB. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] access based shared enum = yes

2013-02-16 Thread TAKAHASHI Motonobu
smb.conf is: - [global] # access based share enum = yes [tmp] writeable = yes path = /tmp - Remember that you set "tmp" share's access rights via Windows GUI (not via Samba parameters such as "valid users"). -- TAKAHASHI Motonobu / @damemonyo

Re: [Samba] Samba 4 DC log.smd flooded with Conversion error

2013-02-11 Thread TAKAHASHI Motonobu
UAdministrator%'verysecurepasswd' -c 'ls' > > The same error in my log floods…… No, you have to set 'dos charset' parameter correctly. In my Japanese environment, same errors occur unless I set "dos charset = CP932", which means Japanese.

Re: [Samba] Append/delete permissions

2013-02-10 Thread TAKAHASHI Motonobu
I have been playing with create mode/mask, directory mode/mask, force > user/group, inherit owner, inherit permissions, chattr, etc but didn't > make any success. I am using Samba 3.5.6 on Linux Debian machine. No, you cannot archive with these parameters. These parameters work in U

Re: [Samba] removing local policies

2013-02-10 Thread TAKAHASHI Motonobu
ike to remove that policies without having to reinstall or recreate > users, has anyone managed to do that? I think you are using 'System Policy' feature on Samba 3 domain. The settings applied by 'System Policy' are tatooed. It's by design. To search "system policy

Re: [Samba] Trouble with user who has mixed case login (upper and lower)

2013-02-10 Thread TAKAHASHI Motonobu
nd our version is 3.5.10-125.el6.x86_64. > > Any help that anyone can provide would be awesome. Have you tried to set "username level" parameter? Also you may use "usename map" or "username map script" for this purpose. See smb.conf(5) for the detail. --- TAKAHASH

Re: [Samba] Password Expiration Notice

2013-02-09 Thread TAKAHASHI Motonobu
ound an answer. Windows 7 does not tell the password expiration date. This is Windows 7's matter, not Samba's. See: http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/fce9e485-67a4-47df-a649-f92632fb6132/ --- TAKAHASHI Motonobu / @damemonyo faceboo

Re: [Samba] Samba 4 DC log.smd flooded with Conversion error

2013-02-09 Thread TAKAHASHI Motonobu
You had better set 'dos charset' parameter correctly and 'unix charset' parameter if you do not use UTF-8 on Linux. From: Jeremy Allison Date: Sat, 9 Feb 2013 09:04:47 -0800 On Sat, Feb 09, 2013 at 11:54:26PM +0800, Kinglok, Fong wrote: My machine is running samba 4.0.3 inside a DomU of Debian

Re: [Samba] Cannot logon Samba 4 via plaintext password

2013-02-06 Thread TAKAHASHI Motonobu
-ad-dc option. Also if you compile Samba4 with same method as Samba3, then you can not see samba-tool. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Cannot logon Samba 4 via plaintext password

2013-02-03 Thread TAKAHASHI Motonobu
mba replies to enable plaintext password, Windows client sends a plaintext password, and at last Samba replies logon failure to client. My smb.conf is: - [global] encrypt passwords = no server max protocol = nt1 ntlm auth = yes [tmp] path = /tmp writeable = yes - Hm

Re: [Samba] SaMBa 4 - homedir mapping

2013-02-03 Thread TAKAHASHI Motonobu
0 mapping works. What is your expected behavior? I examined on my Samba 4.0.1 and Samba 4.0.0rc5 env and got same result. And to run pdbedit, I saw the home directory setting was applied. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsub

Re: [Samba] require_membership_of is ignored

2013-01-26 Thread TAKAHASHI Motonobu
mh: 0x7f2a6c630f40] LEAVE: pam_sm_authenticate returning 7 (PAM_AUTH_ERR) - To join the user to samba01g, the user can login. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read

Re: [Samba] ldap users with users samba

2013-01-22 Thread TAKAHASHI Motonobu
.conf. If you set a parameter twice in smb.conf, latter one is enabled. So you use tdbsam now. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Use backends

2013-01-22 Thread TAKAHASHI Motonobu
From: rodrigo tavares Date: Tue, 22 Jan 2013 05:08:40 -0800 (PST) > Can I have two passdb backend in my smb.conf ? > > Thanks ! After Samba 3.0.23, only one passdb backend is allowed. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To un

Re: [Samba] How to debug SID problems

2013-01-21 Thread TAKAHASHI Motonobu
command there either. Sorry, whoami command appears at Windows Vista / Windows Server 2003. >> - On Samba side >> pdbedit (an user's) >> profiles (a profile file's) > > What is the name of a profile file? is it NTUSER.DAT? Yes, but as I answered at an

Re: [Samba] How to debug SID problems

2013-01-21 Thread TAKAHASHI Motonobu
-5-12 ACL for $$$PROTO.HIV\AppEvents Owner SID: S-1-5-32-544 Group SID: (NULL SID) DACL: 8 entries: ... - But now, I tried the same command and get errors... I examined profiles bundled in Samba 3.5.6. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi

Re: [Samba] How to debug SID problems

2013-01-19 Thread TAKAHASHI Motonobu
he users > SIDs. But I'm new to windows and samba so I find it dificult to > navigate through this windows mess. You can see SID: - On Windows side whoami /user (an user's) - On Samba side pdbedit (an user's) profiles (a profile file'

Re: [Samba] Users and groups without Winbind

2013-01-19 Thread TAKAHASHI Motonobu
And if you see those Linux users from programs other than Samba, you have to configure Winbind correctly. --- TAKAHASHI Motonobu / @damemonyo facebook.com/takahashi.motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://list

Re: [Samba] ldap users with users samba

2013-01-19 Thread TAKAHASHI Motonobu
nge LDAP users's password, you need to configure pam_smbpass.so correctly. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Users and groups without Winbind

2013-01-19 Thread TAKAHASHI Motonobu
s integrated in it and is always enabled. If you do not use users created by Samba for programs other than Samba, you do not need to configure Winbind to show those uses from programs other than Samba. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the ins

Re: [Samba] .recycle folder not showing up

2013-01-02 Thread TAKAHASHI Motonobu
anyone have experience with such an issue??? Much appreciated. AFAIK, Samba recycle bin only affects to files only, not directories. If you set "recycle:keeptree = yes", the parent directories on a deleted file are also copied to .recycle when the file is deleted. --- TAKAHASHI Motonobu -

Re: [Samba] Permissions problem

2012-12-31 Thread TAKAHASHI Motonobu
ve=mode' copy. >> >> Is there a way to forbid this behaviour ? Or is there something >> wrong in my configuration ? Does "unix extensions = no" help your problem? --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4, Winbind & RFC2307

2012-12-16 Thread TAKAHASHI Motonobu
member. You may manually set these attributes on S4 DC with the script: http://lists.samba.org/archive/samba-technical/2012-November/089119.html --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba3 and crackcheck

2012-12-12 Thread TAKAHASHI Motonobu
could compile/link. It should be compiled on Ubuntu..., but I do not know why you cannot, sorry. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 and permissions of SYSVOL and NETLOGON

2012-12-11 Thread TAKAHASHI Motonobu
mba-tool ntacl sysvolreset"? To run that, ACLs are correctly set and normal users cannot write into these shares. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba3 and crackcheck

2012-12-11 Thread TAKAHASHI Motonobu
From: Dominique Date: Tue, 11 Dec 2012 16:08:06 +0100 > > On 11/12/2012 15:43, TAKAHASHI Motonobu wrote: >> From: Dominique >> Date: Tue, 11 Dec 2012 13:45:51 +0100 >> >>> I've got samba3 on ubuntu 12 up and running with one exception. I try to >>&

Re: [Samba] Samba3 and crackcheck

2012-12-11 Thread TAKAHASHI Motonobu
ackage, and tried to compile crackcheck with a > simple make, but all it returns is failure with the following error: > crackcheck.c:6:19: fatal error: crack.h: No such file or directory You need to install the library of cracklib. For ubuntu, libcrack2-dev is its package name. --- TAK

Re: [Samba] Samba Permissions

2012-12-10 Thread TAKAHASHI Motonobu
" and put permissions to that account helps you? "security = share" is too old. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] samba4 rc6 join win2k3 domain failed

2012-12-09 Thread TAKAHASHI Motonobu
In my environment, joining to W2K8R2 domain failed on same error. From: TAKAHASHI Motonobu Date: Sun, 09 Dec 2012 23:39:01 +0900 (JST) I have same problem. Hmmm... From: Innocent Yevide Date: Fri, 7 Dec 2012 22:56:12 + (GMT) Hello, I am trying to join samba4 rc6 to win2k3 server, and

Re: [Samba] samba4 rc6 join win2k3 domain failed

2012-12-09 Thread TAKAHASHI Motonobu
I have same problem. Hmmm... From: Innocent Yevide Date: Fri, 7 Dec 2012 22:56:12 + (GMT) Hello, I am trying to join samba4 rc6 to win2k3 server, and failing with: "descriptor_sd_propagation_recursive: DC=DomainDnsZones,DC=office,DC=local not found under DC=office,DC=local" full log belo

Re: [Samba] Samba Permissions

2012-12-08 Thread TAKAHASHI Motonobu
From: "Baird, Josh" Date: Fri, 7 Dec 2012 20:58:22 + > I thought I had this working correctly, but sometimes it randomly breaks. > Here is an example of a share's configuration: > > [testshare] > comment = Test Share > path = /test/testshare > writeable = yes > create mask = 770 >

Re: [Samba] ower and group at linux

2012-12-08 Thread TAKAHASHI Motonobu
he creates a file, > doesn't appears the username owner of the file, instead of this, always > appears root how the owner. > How can I, solve this issue? Because of the setting: > [global] > ... > admin users = @PGT\pgt.cxt This setting always set the accessing use

Re: [Samba] samba4 and dns + dhcp on windows.

2012-12-08 Thread TAKAHASHI Motonobu
addition to these you have to manually configure DNS/DHCP server for your machines belonging to B domain to receive B as its domain name. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba3 PDC and Windows 8 RTM

2012-12-03 Thread TAKAHASHI Motonobu
l] workgroup = SAMBA366 domain logons = yes passdb backend = tdbsam add machine script = /usr/sbin/useradd -d /dev/null -s /bin/false %u [homes] writeable = yes browseable = no - --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lis

Re: [Samba] Samba3 PDC and Windows 8 RTM

2012-12-03 Thread TAKAHASHI Motonobu
ameResolutionRequired value is not applied... --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 3.x Windows 8

2012-11-19 Thread TAKAHASHI Motonobu
ndows 8 Pro box can join with "max protocol = smb2", try: - max protocol = nt1 min protocol = nt1 - as mentioned at: https://lists.samba.org/archive/samba/2012-September/169213.html --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the

Re: [Samba] Windows 8 Pro no domain logon possible

2012-09-24 Thread TAKAHASHI Motonobu
O_RCVBUF=65536 > add machine script = /usr/local/samba/bin/createSambaMachineAccount.php > "%u" (snip) Perhaps "smb ports = 139" causes your problem. Port 139 is a port for old services. Recent services use port 445 instead. Adding "smb pors = 139" to my simpl

Re: [Samba] Windows 8 Pro no domain logon possible

2012-09-23 Thread TAKAHASHI Motonobu
SMB2... My Windows 8 box runs Windows 8 Professional 32bit modified registries same as Windows 7. If you could, please test same smb.conf? --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Windows 8 Pro no domain logon possible

2012-09-20 Thread TAKAHASHI Motonobu
course I examined that after rebooting some domain accounts can logon into Samba domain on Windows 8 box. -- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] security level = user

2012-09-09 Thread TAKAHASHI Motonobu
private-share" in the example above) with the input username/password. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] net ads user add: Can we prompt for a password?

2012-08-21 Thread TAKAHASHI Motonobu
sword is never expired, not never disabled. AFAIK, any user created by "net ads user add" always becomes disabled at first. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] samba 3.0.14a works with ldapsam backend but not 3.5.10-125.el6

2012-08-21 Thread TAKAHASHI Motonobu
bldap_search_paged: search was successful > sid S-1-5-21-3516781642-1962875130-3438800523-41232 does not belong to our > domain > Skipping entry uid=qchang,cn=users,cn=accounts,dc=sri,dc=utoronto,dc=ca > = --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] samba ADS security mode not accesible by work group computer

2012-05-07 Thread TAKAHASHI Motonobu
assword, you would access without any security changes. See "map untrusted to domain" parameter in smb.conf(5) --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Login Attempt Resets Password in smbpasswd

2012-05-04 Thread TAKAHASHI Motonobu
ient and try to connect to the Samba server after changing password string to X... Why I say "reboot" is that it is the easiest way to clear authentication cache. Basically "reboot" is not required. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] template homedir and idmap_ad

2012-05-04 Thread TAKAHASHI Motonobu
ing wrong. > > JAB. What version of Samba do you use? And how have you set "winbind nss info" parameter. In recently Samba3, this parameter determines if "template homedir" parameter is used or not. idmap_ad module determines where the UID and GID are retrieved. --- TAKAHASH

Re: [Samba] configuring a backup domain server

2012-05-04 Thread TAKAHASHI Motonobu
s PDC and BDC are completely different servers at the view of a file server. If you want to synchronize/share files on both server, you have to do outside Samba. 2012/5/4 TAKAHASHI Motonobu > From: deconya > Date: Fri, 4 May 2012 13:46:23 +0200 > > > Im looking to config a BDC with l

Re: [Samba] configuring a backup domain server

2012-05-04 Thread TAKAHASHI Motonobu
new folders putted inside BDC servers the > steps are: > > include folders in BDC smb.conf. > windows XP clients will use the path \\domain-pdc\sharedfolder > > is correct? So you can access to shared folders on BDC like \\domain-bdc\sharedfolder. --- TAKAHASHI Motonobu -

Re: [Samba] Unix users/groups and the Windows ACL editor

2012-02-27 Thread TAKAHASHI Motonobu
From: Victor Sudakov Date: Sun, 26 Feb 2012 23:23:04 +0700 > TAKAHASHI Motonobu wrote: > > > > > > > > > There is a samba compiled --without-winbind --with-acl-support; the > > > > > Windows GUI ACL editor Security tab shows multiple users and groups

Re: [Samba] samba ldap domain member server with cifs and nfs

2012-02-27 Thread TAKAHASHI Motonobu
ame that those in the USERS OU because i have some entry that > are correct and i had domain member server in this samba version. > > Is there a way to synchronize unix uids with idmap uids? (snip) > winbind trusted domains only = Yes "winbind trusted domains only" is som

Re: [Samba] Unix users/groups and the Windows ACL editor

2012-02-26 Thread TAKAHASHI Motonobu
From: Victor Sudakov Date: Sun, 26 Feb 2012 22:18:40 +0700 > TAKAHASHI Motonobu wrote: > > > > > There is a samba compiled --without-winbind --with-acl-support; the > > > Windows GUI ACL editor Security tab shows multiple users and groups > > > as "U

Re: [Samba] Unix users/groups and the Windows ACL editor

2012-02-26 Thread TAKAHASHI Motonobu
> and groups from the GUI if I wish to. > > Is there a way to _add_ Unix groups and users via the ACL editor? If your file system has ACL feature, you can manupulate these groups to map them to Samba groups with "net groupmap add". Also you can add users who map to Samba user.

Re: [Samba] rpoblem: after renaming a directory permissions are changed

2012-02-18 Thread TAKAHASHI Motonobu
directory mask = 0770 > inherit acls = Yes I re-produced your issue at my lab. You set "directory mask = 0770" at "sys". "directory mask" or such parameters is applied not only when creating directories but when manuplating directories. --- TAKAHASHI Motono

Re: [Samba] Set primary group of file on samba share from windows

2012-01-09 Thread TAKAHASHI Motonobu
ity tab, Advanced button, Owner). You had better discuss samba-technical ML about improving Samba feature. In Samba4, group ownership is supported because Samba4 abandoned to keep interoperability with permission/ACL of UNIX filesystem in order to get full-compatibility with Windows NTFS. --- TAKAHASHI

Re: [Samba] Set primary group of file on samba share from windows

2012-01-08 Thread TAKAHASHI Motonobu
From: Hubert Kario Date: Sun, 8 Jan 2012 19:42:54 +0100 > On Sunday 08 of January 2012 08:41:18 TAKAHASHI Motonobu wrote: > > From: Hubert Kario > > Date: Thu, 5 Jan 2012 23:36:58 +0100 > > > > > Unfortunately, I'm unable to set the primary group using windo

Re: [Samba] Set primary group of file on samba share from windows

2012-01-07 Thread TAKAHASHI Motonobu
p list" or other method? Have you correctly set "set primary group script"? And your Samba joined AD and run Winbind? As far as I examined we can change primary group via Samba under certain environment. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the followin

Re: [Samba] samba share permission

2012-01-07 Thread TAKAHASHI Motonobu
00 Samba can restrict access per share/per user using writable/write list/..., but not per files/directories. If your jobs are running on RHEL server, you have to set correctly permissions in your jobs. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read th

Re: [Samba] The Group Policy Client service failed the logon. Access is denied.

2012-01-04 Thread TAKAHASHI Motonobu
give > correct owner and group of files. I do not create the Samba users I have it > set so when I create a new Linux user the Samba user is created. If it where > the tdb wouldn't their be problems when logging in to an XP machine. --- TAKAHASHI Motonobu -- To unsubscribe fr

Re: [Samba] The Group Policy Client service failed the logon. Access is denied.

2012-01-04 Thread TAKAHASHI Motonobu
reated all Samba users? I met same issue when I re-used passdb.tdb from old machine, because old machine's SID and new machine's SID was not same. Or to edit all users' SID manually, the issue will be solved, I think. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to th

Re: [Samba] limiting netbios browsing

2012-01-03 Thread TAKAHASHI Motonobu
From: Chris Smith Date: Mon, 2 Jan 2012 14:29:43 -0500 > Given a DC environment where very few (1-3) hosts actually need to be > discovered via browsing is there a good way to limit what is > browseable? To set "browse list = no" solves your issue? --- TAKAHASHI Motonobu

Re: [Samba] samba file hierarcy issue

2011-12-30 Thread TAKAHASHI Motonobu
r folders w,y,z > inside folder x with password. So users can enter and view x folder content > but cant view w,y,z folder contents without password. (snip) > Is it possible to create a folder hierarcy in samba server for clients No, also can't for Windows. --- TAKAHASHI Motonobu

Re: [Samba] incorrect profiles

2011-12-27 Thread TAKAHASHI Motonobu
= disable > browseable = No Have you tried to set "profile acls = yes" at profiles share? --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] maximum password age question

2011-12-27 Thread TAKAHASHI Motonobu
policy, but unable to set value! > > Does anyone know what the root issue is ? After Samba 3.0.21, those policies are stored in LDAP, but before 3.0.21, they were always stored in local tdb file. I guess that you have to manually create those account policies on your LDAP directory. -

Re: [Samba] question regarding samba permissions

2011-12-18 Thread TAKAHASHI Motonobu
Tue, 13 Dec 2011 16:38:41 +0100, "skull" wrote: > I want to make a subfolder read only for certain users. > for example: /data/pool is public rwx for all users. > and now i would like to make a /data/pool/subfolder only rwx for user1 > and grant read only permissions to us

Re: [Samba] nmblookup failures

2011-12-18 Thread TAKAHASHI Motonobu
round the problem, I have manually added the server into > /var/lib/samba/wins.dat. I am having to add it every day. You can set an entry statically like: "problemserver#20" 0 w.x.y.z 66R #20 means NetBIOS suffix. 66R means: 0x60 (registered by H-node) + 0x04 (active) + 0x02 (st

Re: [Samba] Samba + acl,user_xattr

2011-12-18 Thread TAKAHASHI Motonobu
TXATTR HAVE_LSETXATTR HAVE_SETXATTR --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] All read and write

2011-12-17 Thread TAKAHASHI Motonobu
e manually. And I think that these features are probably not tested with "security = share", so you had better set "security = user" and proper settings. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://l

Re: [Samba] ADS Domain Member smb.conf using idmap_ad

2011-12-11 Thread TAKAHASHI Motonobu
From: Freeman Date: Wed, 23 Nov 2011 10:37:05 -0500 > On 11/23/2011 08:44 AM, TAKAHASHI Motonobu wrote: > > From: Freeman > > Date: Wed, 23 Nov 2011 08:17:55 -0500 > > > >>> Have you already set values into "UNIX attributes" for every user you >

Re: [Samba] Configure samba to not look for domain master browser

2011-12-06 Thread TAKAHASHI Motonobu
browser ? After a while, nmbd will find a master browser (or a domain master browser) or will try to become a master browser by myself? If yes, this is expected behavior. If not, something will be wrong. Can you show the spamming messages? --- TAKAHASHI Motonobu -- To unsubscribe from this li

Re: [Samba] cant access shares on members of samba domain from windows domain

2011-12-03 Thread TAKAHASHI Motonobu
ss a share on domain B, to specify correct user and whose password will make them access. Otherwise, you have to set up domain trustrelationship between domain A and B, and set correct permissions on every share you want to enable access from other domain's users. --- TAKAHASHI Motonobu -- To

Re: [Samba] File names with unusual characters and linux smbfs clients

2011-12-02 Thread TAKAHASHI Motonobu
s mounted via smbfs or cifs that it causes problems. Have you set iocharset (and codepage if smbfs) properly? Both smbfs and cifs are not part of Samba, they are part of Linux kernel. Does the same problem occur when you you access an "U+2014" filename on Windows share via smbfs/cifs?

Re: [Samba] offline logon with AD

2011-11-29 Thread TAKAHASHI Motonobu
his? You need to add pam_winbind.so with "cached_login" parameter to "auth" type. See pam_winbind(8) --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] ADS Domain Member smb.conf using idmap_ad

2011-11-23 Thread TAKAHASHI Motonobu
upon a user log in. If you keep current uid/gids maintained by NIS, you should use idmap_ad(8). If not, idmap_rid(8) is easy to configure. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] ADS Domain Member smb.conf using idmap_ad

2011-11-23 Thread TAKAHASHI Motonobu
id' i get the uid of 1000. When i try to run this command > wbinfo -n flo on the member server, i get some other number: > > [root@moe samba]# wbinfo -n flo > S-1-5-21-344340502-4252695000-2390403120-1236058 SID_USER (1) uid/gid does not have nothing to do with SID/RID. If you w

Re: [Samba] Problem with 3.6 Samba

2011-11-23 Thread TAKAHASHI Motonobu
manner. > Q2 : how I must configured Samba to can start/stop via the command : > /etc/init.d/winbind start > /etc/init.d/winbind start > /etc/init.d/smb start You need to create/modify those scripts suitable for your installation. --- TAKAHASHI Motonobu -- To unsubscribe from thi

Re: [Samba] I can browse but can't modify or create files

2011-11-15 Thread TAKAHASHI Motonobu
means "read only users' list". "write list" means "read and write users' list". To remove "read list" line would solve your problem... --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] user access to samba files

2011-11-14 Thread TAKAHASHI Motonobu
ce enabled Winbind, all group membership that Samba recognizes must be managed on Winbind or Windows. Unix-based group membership (including yp, /etc/group and etc...) is ignored. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba-3.6.1 release IPV6 issue

2011-11-13 Thread TAKAHASHI Motonobu
error : network name is not available. Have you used a global IPv6 address (not link/site local) ? --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba-3.6.1 release IPV6 issue

2011-11-11 Thread TAKAHASHI Motonobu
at's Windows' design. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Problem with kerberos method attribut

2011-11-11 Thread TAKAHASHI Motonobu
wn parameter "kerberos method" > > I works on OpenSuse Linux version 10 and a samba version 3.0.36-0.5.5. > Q : how resolve this problem ? Both "kerberos method" and "dedicated keytab file" are introduced at Samba 3.4.0. You use too old version. --- TAK

Re: [Samba] move to Idmap with ldap

2011-11-11 Thread TAKAHASHI Motonobu
t; user accounts and group listings as expected. If you are building Samba as PDC, Idmap is never used unless you use ldapsam:editposix (with Winbind) instead of smbldap-tools. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists

Re: [Samba] Permissions in printer share

2011-11-07 Thread TAKAHASHI Motonobu
; Try replacing "write list = @group1" > with "valid users = @group1" > > Dale If you use Winbind, you have to specify "@domain\group" style by default. Also you can configure printers' permissions by ACL via Windows. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] win 7 join domain error

2011-11-05 Thread TAKAHASHI Motonobu
Please keep CC to the list. From: steve Date: Sat, 5 Nov 2011 08:33:37 +0100 > On Saturday 05 Nov 2011 04:08:49 you wrote: > > From: steve > > Date: Sat, 5 Nov 2011 01:07:58 +0100 > > > > Use simple "%u" instead of "%m$", see smb.conf(5) f

Re: [Samba] win 7 join domain error

2011-11-04 Thread TAKAHASHI Motonobu
cups > add machine script = /usr/sbin/useradd -c Machine -d /var/lib/nobody > -s /bin/false %m$ (snip) Use simple "%u" instead of "%m$", see smb.conf(5) for details. --- TAKAHASHI Motonobu -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

  1   2   3   4   >