Re: [Samba] [PATCH] Workaround very slow nss_winbind, fix crash on the AD DC (particularly for backups)

2013-06-21 Thread Philippe.Simonet
Hi Andrew, many thanks for you patch, i tested it on 2 different systems but without success (the crash is always happening). before applying the patch, I had a strange problem : I couldn't reproduce the problem (with wbinfo --uid-info 300) on one of the machine. no chance even if I

[Samba] Provision new domain from Windows AD

2013-06-21 Thread Alex Ferrara
Hi everyone, What I want to achieve is to provision a new domain with the users, groups and group policy of an existing AD domain. Is this what I would use the vampire function for? Am I on the wrong track? Alex Ferrara Director Receptive IT Solutions -- To unsubscribe from this list go to

[Samba] samba4 missing group membership with getent group

2013-06-21 Thread Philippe.Simonet
Hi Samba users using samba 4.0.6, having /etc/nsswitch.conf that use winbind, getent group does not display the group members. to reproduce that : (my domain is test3.ch) samba-tool user add u1 samba-tool group add g1 samba-tool group addmembers g1 u1 id u1 returns : uid=326(TEST3\u1)

Re: [Samba] [PATCH] Workaround very slow nss_winbind, fix crash on the AD DC (particularly for backups)

2013-06-21 Thread Andrew Bartlett
On Fri, 2013-06-21 at 05:58 +, philippe.simo...@swisscom.com wrote: Hi Andrew, many thanks for you patch, i tested it on 2 different systems but without success (the crash is always happening). before applying the patch, I had a strange problem : I couldn't reproduce the problem

Re: [Samba] [PATCH] Workaround very slow nss_winbind, fix crash on the AD DC (particularly for backups)

2013-06-21 Thread Philippe.Simonet
Hi Andrew, sorry (my English...) I was not clear. I tried to say that the patch does not change anything for me, the crash is still here. best regards Philippe -Original Message- From: Andrew Bartlett [mailto:abart...@samba.org] Sent: Friday, June 21, 2013 9:18 AM To: Simonet

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread steve
On Fri, 2013-06-21 at 06:23 +, philippe.simo...@swisscom.com wrote: Hi Samba users but getent group does not return group/user membership : TEST3\g1:*:327: any advices ? It doesn't work for groups:( use: getent group TEST\g1 hth Steve -- To unsubscribe from this list go to

Re: [Samba] [PATCH] Workaround very slow nss_winbind, fix crash on the AD DC (particularly for backups)

2013-06-21 Thread Andrew Bartlett
On Fri, 2013-06-21 at 07:23 +, philippe.simo...@swisscom.com wrote: Hi Andrew, sorry (my English...) I was not clear. I tried to say that the patch does not change anything for me, the crash is still here. Which (named) patch did you try? I've attached both patches which I proposed.

Re: [Samba] Samba+LDAP: NT_STATUS_UNSUCCESSFUL because of primary group SID mismatch

2013-06-21 Thread Andrew Bartlett
On Thu, 2013-06-20 at 10:26 +0200, Philipp Lies wrote: Hi, I'm trying to get my new samba server running for a few days now and I start losing my mind over not figuring out what I'm doing wrong. Here's my setup: OpenLDAP 2.4.21 server with ~15 groups and 100 users, all having a unix and

Re: [Samba] [PATCH] Workaround very slow nss_winbind, fix crash on the AD DC (particularly for backups)

2013-06-21 Thread Philippe.Simonet
I tried both, and I get still crashes : 0001-gensec-work-around-nested-event-loops-by-ensuring-th.patch 0002-s4-winbind-Add-special-case-for-BUILTIN-domain.patch - samba version 4.0.6 started. Copyright Andrew Tridgell and the Samba Team 1992-2012 samba: using 'single' process model

Re: [Samba] Samba+LDAP: NT_STATUS_UNSUCCESSFUL because of primary group SID mismatch

2013-06-21 Thread Daniel Müller
For me the better way would be, to run serveral openldap servers in master master replication on your DC and several BDC. And no headache about anything. Or just point your BSCs to authenticate against the DCs openldap. But when your DC is down your authentication is gone. Greetings Daniel

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread Philippe.Simonet
Hi Steve getent group TEST3\g1 give an empty result, and getent group TEST3\\g1 with the same result as getent group g1, without user/group membership. in fact my problem goes further : shares access control (write list, ...) does not work for @g1, only with u1 ... Philippe -Original

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread Rowland Penny
Hi, well yet another reason to use sssd instead of winbind. When I turned on winbind in /etc/nsswitch.conf on my test S4 server, I get: id user uid=3001106(HOME\user) gid=20513(HOME\Domain Users) groups=20513(HOME\Domain Users),21110(HOME\linuxusers) getent group linuxusers

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread steve
On Fri, 2013-06-21 at 08:36 +, philippe.simo...@swisscom.com wrote: Hi Steve getent group TEST3\g1 give an empty result, and getent group TEST3\\g1 with the same result as getent group g1, without user/group membership. in fact my problem goes further : shares access control (write

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread steve
On Fri, 2013-06-21 at 10:12 +0100, Rowland Penny wrote: Hi, well yet another reason to use sssd instead of winbind. When I turned on winbind in /etc/nsswitch.conf on my test S4 server, Also I would suggest forgetting using @group in smb.conf and use ACL's instead. Didn't see this, but

Re: [Samba] Provision new domain from Windows AD

2013-06-21 Thread Marc Muehlfeld
Hello Alex, Am 21.06.2013 08:22, schrieb Alex Ferrara: What I want to achieve is to provision a new domain with the users, groups and group policy of an existing AD domain. Is this what I would use the vampire function for? Am I on the wrong track? First you setup a new Samba DC, according

Re: [Samba] Fix the Issue Windows 8 cannot join if a example.com domain

2013-06-21 Thread Daniel Müller
No it is not working! My domain is named example.com and windows 8 is not able to join this domain. My other domain named test windows 8 can join without any problem. It seems dotted domains old style are lost for ever. --- EDV Daniel Müller Leitung

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread Ali Bendriss
On Friday, June 21, 2013 10:12:26 AM Rowland Penny wrote: Hi, well yet another reason to use sssd instead of winbind. [...] Hi, An other option is to use samba AD in one server and the file server (smbd + winbindd) in an other. Since I've done that (last year I think) I've got no problem at

Re: [Samba] samba4 missing group membership with getent group

2013-06-21 Thread steve
On Fri, 2013-06-21 at 15:39 +0200, Ali Bendriss wrote: On Friday, June 21, 2013 10:12:26 AM Rowland Penny wrote: Hi, well yet another reason to use sssd instead of winbind. [...] Hi, An other option is to use samba AD in one server and the file server (smbd + winbindd) in an other.

[Samba] samba4 and (pseudo) LDAP backend for users, groups and rights

2013-06-21 Thread Marcus Mundt
Dear List, I am used to Samba 3 and LDAP. But since Samba 4 I'm struggeling hard to understand what has to be done and how a possible solution might look like for our scenario. I already found out that Samba 4 comes with its own LDAP Server and if I want to use a slapd on the same system, it

Re: [Samba] samba4 and (pseudo) LDAP backend for users, groups and rights

2013-06-21 Thread Marc Muehlfeld
Hello Marcus, Am 21.06.2013 17:27, schrieb Marcus Mundt: Environtment: - LDAP-Master-Server with all the information needed - mostly Windows XP and Windows 7 Clients They should auto mount network drives after login (user, pass and rights from LDAP-Master) Here is what I want to achieve: A

[Samba] Mac Os 10.6 - 10.8 and Samba 3.6.9

2013-06-21 Thread Terre Porter
Hello, I have a very odd issue happening, that I hope someone else might be able to give me pointers. I have two different networks running in two different locations, connected by a network vpn. In each network I have a test smb virtual machine. - Smb Machine 1: (smbtest1) (remote

Re: [Samba] Mac Os 10.6 - 10.8 and Samba 3.6.9

2013-06-21 Thread Jeremy Allison
On Fri, Jun 21, 2013 at 03:03:33PM -0400, Terre Porter wrote: socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=65536 SO_SNDBUF=65536 Not to comment on any other thing in your post bue please remove this line from your smb.conf. It's voodoo bullshit from the long-ancient past :-).

[Samba] cifs mounts fail after kernel upgrade

2013-06-21 Thread Dale Schroeder
Upgrading Debian testing's linux-image from 3.2.46-1 to 3.9.6-1 causes cifs mounts via fstab or command line to fail with return code -38 function not implemented. Reverting back to the old kernel yields working cifs mounts. The only option I use is a credentials file. Attempting the mount

Re: [Samba] Mac Os 10.6 - 10.8 and Samba 3.6.9

2013-06-21 Thread Bob Miller
Hi, On the mac, connected to the remote (smbtest1) machine, when I double click on the finder to enter the test directory that has about 200 files in it, the finder just sits there... for at least two or more minuets before showing anything. I tried to connect to the smbtest1 machine

Re: [Samba] Samba+LDAP: NT_STATUS_UNSUCCESSFUL because of primary group SID mismatch

2013-06-21 Thread Philipp Lies
Thanks for the recommendations! I was hoping that there'd be a simple solution/config parameter to force the samba server trust the LDAP (it's still puzzling me why the other machines I have do work like that). I'll try to set up my new servers as DCs and see how this goes. The idea with

Re: [Samba] DNS replication and BDCs

2013-06-21 Thread David González Herrera - [DGHVoIP]
Hi Marc, comments below. On 6/20/2013 5:26 PM, Marc Muehlfeld wrote: Hello David, Am 20.06.2013 19:55, schrieb David González Herrera - [DGHVoIP]: I would like youi to point me or tell me how do I create a fail-over or high availability system so that when one of the DCs is down the other

Re: [Samba] Mac Os 10.6 - 10.8 and Samba 3.6.9

2013-06-21 Thread Terre Porter
On 6/21/2013 3:44 PM, Jeremy Allison wrote: On Fri, Jun 21, 2013 at 03:03:33PM -0400, Terre Porter wrote: socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=65536 SO_SNDBUF=65536 Not to comment on any other thing in your post bue please remove this line from your smb.conf. It's

Re: [Samba] Mac Os 10.6 - 10.8 and Samba 3.6.9

2013-06-21 Thread Terre Porter
On 6/21/2013 4:24 PM, Bob Miller wrote: Hi, On the mac, connected to the remote (smbtest1) machine, when I double click on the finder to enter the test directory that has about 200 files in it, the finder just sits there... for at least two or more minuets before showing anything. I tried to

Re: [Samba] Samba rejecting Machine account auth requests

2013-06-21 Thread Julien Savoie
On 13/06/13 12:37 AM, Julien Savoie wrote: On 21/08/12 11:46 AM, John Drescher wrote: I have a samba domain with over 100 machines in it. For some reason every 30-35 days, 2 of the machines fail the trust relationship at login and need to be removed from the domain and rejoined. In the logs

Re: [Samba] DNS replication and BDCs

2013-06-21 Thread Marc Muehlfeld
Hello David, Am 21.06.2013 23:42, schrieb David González Herrera - [DGHVoIP]: root@bdc:~# dig @10.10.10.20 AXFR example.local . example.local. 900 IN A 10.10.10.5 example.local. 900 IN A 21x.xxx.xxx.xxx example.local. 900 IN A

[SCM] Samba Shared Repository - branch v4-0-test updated

2013-06-21 Thread Karolin Seeger
The branch, v4-0-test has been updated via 4b25860 docs: Avoid mentioning a possibly misleading option. from a46a6be tevent: Fix Coverity ID 989236 Operands don't affect result http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v4-0-test - Log

[SCM] Samba Shared Repository - branch master updated

2013-06-21 Thread Michael Adam
The branch, master has been updated via ad86e2a s3:passdb/pdb_util make pdb_create_builtin consider whether backend deals with BUILTIN via 2d2d13e s3:passdb add a gid argument to pdb_create_builtin_alias via 212baed s3:utils/net_sam make use of pdb_create_builtin helper

[SCM] Samba Shared Repository - branch master updated

2013-06-21 Thread Amitay Isaacs
The branch, master has been updated via d2642cb dns: Fix CID 1034969 Uninitialized scalar variable from ad86e2a s3:passdb/pdb_util make pdb_create_builtin consider whether backend deals with BUILTIN http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2013-06-21 Thread Volker Lendecke
The branch, master has been updated via b96cea4 Fix some blank line endings from d2642cb dns: Fix CID 1034969 Uninitialized scalar variable http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log - commit

[SCM] Samba Shared Repository - branch master updated

2013-06-21 Thread Jeremy Allison
The branch, master has been updated via bbe09b3 Add missing SMB2/SMB3 share capability flag define via 06e5401 lsa4: Fix a set but unused variable warning via 7d5daaa lsa4: Remove an unused variable via 2448fe3 lsa4: Remove an unused variable via 720b4d3