Re: [Samba] Samba StartTLS

2011-11-13 Thread Volker Lendecke
On Sat, Nov 12, 2011 at 05:39:18PM -0300, zoolook wrote: > 2011/11/12 steve : > > > Nearly understood it but I'm missing this: How does the username and > > password that is typed in on the win client travel over the network to the > > samba (and in my case also ldap) server? It must be sent as pl

Re: [Samba] Samba StartTLS [SOLVED]

2011-11-12 Thread steve
On Saturday 12 Nov 2011 21:34:05 you wrote: > Hi Steve, > > 2011/11/12 steve : > > My smb conf looks like this: > > > > passdb backend = ldapsam:ldap://hh1.site > > idmap backend = ldap:ldap://hh1.site > > ldap ssl = start tls > > Looks right. > > > hh1.site is my FQDN and is also the CN for t

Re: [Samba] Samba StartTLS

2011-11-12 Thread zoolook
2011/11/12 steve : > Nearly understood it but I'm missing this: How does the username and > password that is typed in on the win client travel over the network to the > samba (and in my case also ldap) server? It must be sent as plain text no? > Cheers, Steve. Yup... more or less. I don't know t

Re: [Samba] Samba StartTLS

2011-11-12 Thread zoolook
Hi Steve, 2011/11/12 steve : > My smb conf looks like this: > > passdb backend =  ldapsam:ldap://hh1.site > idmap backend = ldap:ldap://hh1.site > ldap ssl = start tls Looks right. > > hh1.site is my FQDN and is also the CN for the CA and servercerts. > Good > But I'm wondering. Since the sam

Re: [Samba] Samba StartTLS

2011-11-12 Thread steve
On 11/12/2011 06:52 PM, zoolook wrote: 2011/11/11 steve: So, On a win 7 client, where do I put the CA cert? You don't :-) Win will talk to samba. Samba talks to OpenLDAP over a tls conection. Nearly understood it but I'm missing this: How does the username and password that is typed in on

Re: [Samba] Samba StartTLS

2011-11-12 Thread steve
On 11/12/2011 06:52 PM, zoolook wrote: 2011/11/11 steve: So, On a win 7 client, where do I put the CA cert? You don't :-) Win will talk to samba. Samba talks to OpenLDAP over a tls conection. > From my experience (since -from my pov- it is not clear in the docs), Samba needs: pass

Re: [Samba] Samba StartTLS

2011-11-12 Thread zoolook
2011/11/11 steve : > So, On a > win 7 client, where do I put the CA cert? You don't :-) Win will talk to samba. Samba talks to OpenLDAP over a tls conection. >From my experience (since -from my pov- it is not clear in the docs), Samba needs: passdb backend = ldapsam:ldaps://ldap.yourdo

Re: [Samba] Samba StartTLS

2011-11-11 Thread steve
On 11/11/2011 08:23 PM, zoolook wrote: 2011/11/11 steve: On 11/11/2011 08:31 AM, steve wrote: Hi Scenario: Lan with opensuse 11.4 Samba and LDAP server. Linux, win-xp and win7 clients. Nov 10 11:20:16 hh1 smbd[6066]: [2011/11/10 11:20:16.268556, 0] lib/smbldap.c:731(smb_ldap_start_tls) Nov

Re: [Samba] Samba StartTLS

2011-11-11 Thread zoolook
2011/11/11 steve : > On 11/11/2011 08:31 AM, steve wrote: >> >> Hi >> Scenario: >> Lan with opensuse 11.4 Samba and LDAP server. Linux, win-xp and win7 >> clients. >> >> >> >> Nov 10 11:20:16 hh1 smbd[6066]: [2011/11/10 11:20:16.268556,  0] >> lib/smbldap.c:731(smb_ldap_start_tls) >> Nov 10 11:20:1

Re: [Samba] Samba StartTLS

2011-11-11 Thread steve
On 11/11/2011 08:31 AM, steve wrote: Hi Scenario: Lan with opensuse 11.4 Samba and LDAP server. Linux, win-xp and win7 clients. Nov 10 11:20:16 hh1 smbd[6066]: [2011/11/10 11:20:16.268556, 0] lib/smbldap.c:731(smb_ldap_start_tls) Nov 10 11:20:16 hh1 smbd[6066]: Failed to issue the StartTLS

[Samba] Samba StartTLS

2011-11-10 Thread steve
Hi Scenario: Lan with opensuse 11.4 Samba and LDAP server. Linux, win-xp and win7 clients. The Linux clients can login fine under TLS: Nov 10 11:31:22 hh1 slapd[1727]: conn=1243 op=0 STARTTLS Nov 10 11:31:22 hh1 slapd[1727]: conn=1243 op=0 RESULT oid= err=0 text= Nov 10 11:31:22 hh1 slapd[1727]: