Re: [Samba] winbindd/idmap_ldap.c:472(idmap_ldap_allocate_id) Cannot allocate gid above 20000!

2011-12-23 Thread Charles Weber
I feel your pain. we are up to 1275000, but have been running idmap/ldap for many years. I have considered going to RID or full AD integration, but have organizational issues either way. On Dec 22, 2011, at 3:50 AM, Jelle de Jong wrote: On 19/12/11 19:10, Jelle de Jong wrote: On 19/12/11

Re: [Samba] filesystem of choice?

2011-06-25 Thread Charles Weber
I have a ~100 TB multi server multi SAN XFS/Samba deployment and have been using it since early fedora core days. EXT4 is now where I would consider using it instead of XFS. But with XFS and LVM I have trivial and very quick formatting, partition resizing and partition duplicating. It has been

Re: [Samba] Connecting to AD and OpenLDAP

2011-05-04 Thread Charles Weber
security = ADS realm = REALM.COM idmap backend = ldap:ldap://ldap.realm.com idmap uid = 15000-675000 idmap gid = 15000-675000 This does most but not all of what you want. ldap provides sid mapping. Issues are idmap gid constantly increases if set to automatically map, doesn't sound like you

Re: [Samba] Share mounts as read-only on MacOSX client

2011-04-26 Thread Charles Weber
Try this unix extensions = no On Apr 25, 2011, at 5:01 PM, Kyle Kniepkamp wrote: I have a user with an older Mac Mini, running MacOSX 10.4.11 When she mounts the share from my Samba server it is mounted Read Only. I am able to mount it using her credentials on my Win7 computer and it is

Re: [Samba] Winbind user authentication (-a) fails, but kerberos authentication succeeds

2010-10-23 Thread charles weber
Is AD set for ntlmv2 only? On Oct 22, 2010, at 8:45 AM, Robert Freeman-Day wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/21/2010 09:36 PM, Gaiseric Vandal wrote: What kind of domain - samba PDC or Windows Active Directory ? Maybe the samba version is just too old.

Re: [Samba] mac client and inherited permissions

2009-11-20 Thread charles weber
Cool it worked. Thanks, Chuck On Nov 20, 2009, at 1:38 AM, Eero Volotinen wrote: Adam Nielsen wrote: Problem: Windows clients honor SGID and inherit/create mask statements. Mac 10.6.2 or 10.5.8 clients do not seem to. Do the Mac clients themselves use the Samba code? If so they probably

[Samba] mac client and inherited permissions

2009-11-19 Thread Charles Weber
Hi everyone, We are a longtime samba/win desktop shop but are getting more Macs. Samba sernet rpms 3.3.9 on CentOS 5.4 test box (started to test 3.43 but will wait) and I confirmed a problem I have been having in production. Server is ADS member with ldap stored idmap. All AD auth and idmap are

Re: [Samba] Problem: LDAP as idmap backend

2009-08-14 Thread charles weber
A big change in ldap usage documented only in the man pages. For 3.3.7 I had to change from this idmap backend = ldap:ldap://niairpfiler1.grc.nia.nih.gov ldap:ldap:// niairpfiler2.grc.nia.nih.gov to this ldap ssl = no idmap backend = ldap:ldap://ldapserv1 idmap alloc backend = ldap idmap

[Samba] re Trouble with idmap_ldap in 3.3.6

2009-08-03 Thread Charles Weber
We also have been using samba 2 and 3 for years with ldap idmap. This occurs whether I use sernet 3.3.7 rpms or build my own from samba.org3.3.7 tgz. I increased logging and here is what I get in log.winbindd-idmap. [r...@niairphome2 ~]# tail -f /var/log/samba/log.winbindd-idmap [2009/08/03

Re: [Samba] re Trouble with idmap_ldap in 3.3.6

2009-08-03 Thread Charles Weber
= dc=xxx,dc=xxx ldap ssl = no idmap backend = ldap:ldap://x.x.x ldap:ldap://y.x.x; And ldap idmap works just fine for 3.3.7. thanks, chuck On Mon, Aug 3, 2009 at 11:35 AM, William Jojo w.j...@hvcc.edu wrote: Charles Weber wrote: We also have been using samba 2 and 3 for years with ldap idmap

[Samba] Samba Compile Error on 3.0.7 and 3.0.8 Pre 1 on X64 Fedora Core 3 Test 2

2005-06-08 Thread Charles Weber
For my opterons, I added --with-libdir=/usr/lib64/samba to spec file config line and it worked just fine. -- Charles Weber [EMAIL PROTECTED] -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

[Samba] x86_64 fedora 2-3 rpmbuild

2005-04-26 Thread Charles Weber
When I try to compile samba.org 3.0.10-14a rpms on Fedora Core 2 and 3 x86_64, I get the following errors. The missing files are in /var/tmp/samba-3.0.14a-root/usr/lib/samba/ and there are just 2 files in lib64. So what is the secret incantation here? Thanks, Chuck + cp -pr README COPYING

[Samba] maintaining samba uid and gid in nt to ad migration

2004-12-20 Thread Charles Weber
we used tdbedit and perl to script our domain consolidation sid to uid mappings. The other possibility is to use getfacl and setfacl to store your file rights to a text file and replay them once you are migrated. since getfacl and setfacl use names and not uid's the moved system should resolve the

[Samba] Samba 3.0.x in ADS mode in a Windows Krb AD forest domain, does it work?

2004-12-20 Thread Charles Weber
I have just put in service our first AD member samba server and am replacing, like many of us, samba 2 servers. Our setup is HHS AD tree, with NIH users in ou's under NIH domain and servers in attached division domain (NIA in our case). Our NIH users have no problems so far other than the usual of