Re: [Samba] valid users = +group doesn't work

2008-04-22 Thread Leonid Zeitlin
Hi Jerry, I guess my question now boils down to the following: when I access a share as domain user DOMAIN\lz, is there a way to apply "valid users" check based on the Unix group membership of the Unix user "lz". From what you are saying I am getting the impression that the asnwer is no; is this

Re: [Samba] valid users = +group doesn't work

2008-04-22 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leonid Zeitlin wrote: > I guess my question now boils down to the following: when I access a > share as domain user DOMAIN\lz, is there a way to apply "valid users" > check based on the Unix group membership of the Unix user "lz". From > what you are

Re: [Samba] valid users = +group doesn't work

2008-04-21 Thread Leonid Zeitlin
Hi Jerry, Please see below. The supplementary groups are determined by mapping the Windows group to a gid. I'm having to remember what we already convered so apoligies fotr asking again. Are you running winbindd? or just manually mapping groups to SIDs ? Seems to be the former. Winbind is

Re: [Samba] valid users = +group doesn't work

2008-04-21 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leonid Zeitlin wrote: >> DOMAIN\lz has a different SID and token than the local >> user "lz". Therefore the search for the local group SID >> of "webdev" will not be found in the domain user's (DOMAIN\lz) >> token. You can view the user's complete

Re: [Samba] valid users = +group doesn't work

2008-04-17 Thread Leonid Zeitlin
Hi Jerry, Thanks a lot for your quick reply. Please see below. Hi all, I seem to be having a problem identical to this bug: https://bugzilla.samba.org/show_bug.cgi?id=3940 in Samba 3.0.28, however the bug is supposed to be fixed by now. I have a Fedora 7 box joined as a member to Windows 2003

Re: [Samba] valid users = +group doesn't work

2008-04-17 Thread Leonid Zeitlin
Hi Jerry, Please see below. -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leonid Zeitlin wrote: Is webdev in the local gtroup mapping table ? If I understand your question correctly, initally it wasn't. Then I did "net sam mapunixgroup webdev", but this didn't seem to have any effect. Cor

Re: [Samba] valid users = +group doesn't work

2008-04-16 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leonid Zeitlin wrote: >> Is webdev in the local gtroup mapping table ? > > If I understand your question correctly, initally it > wasn't. Then I did "net sam mapunixgroup webdev", but > this didn't seem to have any effect. Correct. That was my que

Re: [Samba] valid users = +group doesn't work

2008-04-16 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leonid Zeitlin wrote: > Hi all, > I seem to be having a problem identical to this bug: > https://bugzilla.samba.org/show_bug.cgi?id=3940 in Samba 3.0.28, however the > bug is supposed to be fixed by now. > > I have a Fedora 7 box joined as a member

[Samba] valid users = +group doesn't work

2008-04-16 Thread Leonid Zeitlin
Hi all, I seem to be having a problem identical to this bug: https://bugzilla.samba.org/show_bug.cgi?id=3940 in Samba 3.0.28, however the bug is supposed to be fixed by now. I have a Fedora 7 box joined as a member to Windows 2003 domain. All my Windows users have accounts on the Samba machine,