[Samba] session keep alive

2009-01-29 Thread Urs Golla
Hello I have several (40) linux servers and which use winbind for authentication (ads backend). Some of them (6) are behind a load balancer (Big-IP) which acts as an ordinary router at the moment. When I try to logon to one of these servers with my ads account I get permission denied. But if I

[Samba] session keepalive

2009-01-28 Thread Urs Golla
Hello I have several (40) linux servers and which use winbind for authentication (ads backend). Some of them (6) are behind a load balancer (Big-IP) which acts as an ordinary router at the moment. When I try to logon to one of these servers with my ads account I get permission denied. But if I

[Samba] first logon always fails

2008-12-06 Thread Urs Golla
Hi I use winbind on Linux for authentication (using ADS acounts) on many servers and it works very well on all of them. I use the same configuration and the same Domain Controllers etc.. I have 4 new servers which are all in a special network segment (behind a load balancer). On all of them I

Re: [Samba] Stable Samba for AIX5.1

2008-12-04 Thread Urs Golla
Hi I use pware.samba-3.0.23d on AIX 5.3. It works very well for me and I am almost sure I have used it already on 5.1. cheers On Wed, Dec 3, 2008 at 2:58 AM, Ray, Tito [EMAIL PROTECTED] wrote: Hello, I need to upgrade Samba 2.2.2 to a stable Samba version compatible with AIX5.1 . Need to

Re: [Samba] Stable Samba for AIX5.1

2008-12-04 Thread Urs Golla
: Urs Golla [EMAIL PROTECTED] Subject: Re: [Samba] Stable Samba for AIX5.1 To: Ray, Tito [EMAIL PROTECTED] Cc: samba@lists.samba.org Hi I use pware.samba-3.0.23d on AIX 5.3. It works very well for me and I am almost sure I have used it already on 5.1. Hmmm, I do not think that will run

[Samba] Fwd: NT_STATUS_NO_LOGON_SERVERS

2008-11-11 Thread Urs Golla
, but i know that the windows servers in that domain do not have this problem. I also have the impression that it happend much more often on our 64bit RHEL servers (with 64bit samba installed). **any help would be greatly appreciated! -- Forwarded message -- From: Urs Golla [EMAIL

Re: [Samba] Fwd: NT_STATUS_NO_LOGON_SERVERS

2008-11-11 Thread Urs Golla
AM, Urs Golla wrote: Ok. it seems i am not the only one with this problem: http://www.mail-archive.com/samba@lists.samba.org/msg88996.html I did a net ads lookup and net ads info before and after the Problem occurred. The output (DC etc..) was exactly the same. I dont know much about our

[Samba] NT_STATUS_NO_LOGON_SERVERS

2008-11-06 Thread Urs Golla
Every few weeks users are not able to logon anymore until i restart the winbind daemon. The message in winbind.log is NT_STATUS_NO_LOGON_SERVERS. after that PAM (system-auth -- pam_succeed_if.so) is not able to resolve the active directory groups anymore. The quick fix is to create a new situation

Re: [Samba] force user and read only

2008-10-26 Thread Urs Golla
PM, Dennis B. Hopp [EMAIL PROTECTED] wrote: On Fri, 2008-10-24 at 17:08 +0200, Urs Golla wrote: This works only if the samba user is also the owner of the file. Please CC the list so that other users can benefit from this conversation and if I'm mistaken, somebody else can correct me

[Samba] force user and read only

2008-10-24 Thread Urs Golla
Hi I need a share with read-only access for some developers (to read logfiles). the logfiles are owned by the application user and group and have 700 permissions. I have set up the share like this: path = /applicationx/logs read only = Yes valid users =

[Samba] error codes

2008-09-23 Thread Urs Golla
Hi I am wondering if there is a list of all possible error codes/messages for samba and winbind. There are such lists available for OS error codes (e.g. AIX or AS400). Regards Urs -- To unsubscribe from this list go to the following URL and read the instructions:

[Samba] Preauthentication failed

2008-08-08 Thread Urs Golla
Hi We have several RHEL4 and 5 servers with security=ads config and we use winbind for authentication. Today 3 users could not logon to a server. The message in the log was: Aug 8 05:29:56 servername sshd(pam_unix)[7748]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser=

Re: [Samba] Windows Samba problem

2008-07-16 Thread Urs Golla
What do you mean with lose the profile? Is it a Linux server with some shares and you connect to the shares (eg. net use \\myserver\myshare)? On Wed, Jul 16, 2008 at 4:23 PM, [EMAIL PROTECTED] wrote: Hi everyone , I'am new using Linux and SAMBA, so I hope you can help me to solve this

Re: [Samba] DC outage

2008-07-11 Thread Urs Golla
you post your smb.conf here? Cheers - Michael Urs Golla wrote: Hi Michael Thats what I thought after reading the manual again. is this entry needed for joining? as far as i remember, the join was not working when i had no pw server defined. hm... i will test again. cheers

[Samba] DC outage

2008-07-10 Thread Urs Golla
Hello We had an outage of one of our domain controllers today and all Linux servers have lost their connection to the ADS. I always thought winbind should switch to another DC if one is not reachable anymore. The windows servers in the same domain switched to a new one. do i have to specify more

Re: [Samba] DC outage

2008-07-10 Thread Urs Golla
it is the latest stable from sernet for rhel4 32bit On Thu, Jul 10, 2008 at 6:27 PM, Jeremy Allison [EMAIL PROTECTED] wrote: On Thu, Jul 10, 2008 at 05:05:48PM +0200, Urs Golla wrote: Hello We had an outage of one of our domain controllers today and all Linux servers have lost

Re: [Samba] DC outage

2008-07-10 Thread Urs Golla
, you should not set any specific password server in the smb.conf if you want DC failover to work. Instead, leave it at the default, which is *, so that dns lookups of srv records is enabled. Cheers, Michael Urs Golla wrote: it is the latest stable from sernet for rhel4 32bit On Thu, Jul 10

[Samba] libtalloc.so.1()(64bit)

2008-07-07 Thread Urs Golla
Hi I am trying to upgrade to samba 3.2 with the experimental package for rhel5 64 bit from sernet. it tells me i have to install libtalloc.so.1()(64bit) first. where do i get this? yum provides libtalloc.so.1 does not find anything. thanks urs -- To unsubscribe from this list go to the

[Samba] tilde username

2008-07-01 Thread Urs Golla
Hi I use winbind with ADS security for authentication. If I write ls -la ~username in bash or ksh and press TAB or escape to resolve the HOMEDIR the shell hangs until I cancel with Ctrl+C. After that I have to restart winbind! If I press enter after ls -la ~username it works. I use

Re: [Samba] tilde username

2008-07-01 Thread Urs Golla
Hi the problem is, if one of the developers does a cd ~usernameTAB winbind hangs for ALL users and needs to be restartet. I think I will disable the user/group enumeration in smb.conf. cheers On Tue, Jul 1, 2008 at 5:10 PM, Rob Shinn [EMAIL PROTECTED] wrote: On Tue, July 1, 2008 9:49 am, Urs

Re: [Samba] force ntlm

2007-12-13 Thread Urs Golla
responses. please have a look on its man page... thanks, warren On Nov 19, 2007 4:49 PM, Urs Golla [EMAIL PROTECTED] wrote: Is there really no way to tell winbind to use ntlm for security = ads with samba 3.0.26? The man pages say that it should work like that... wrong information

Re: [Samba] force ntlm

2007-11-19 Thread Urs Golla
, sorry I thought it came with 3.0.26. Neal Urs Golla wrote: Hi Neal I get Unknown parameter encountered: winbind rpc only I have samba 3.0.26.a-35 cheers Urs On 11/16/07, Neal A. Lucier [EMAIL PROTECTED] wrote: Urs Golla wrote: Is there a way to force samba to use NTLM

Re: [Samba] force ntlm

2007-11-18 Thread Urs Golla
Hi Neal I get Unknown parameter encountered: winbind rpc only I have samba 3.0.26.a-35 cheers Urs On 11/16/07, Neal A. Lucier [EMAIL PROTECTED] wrote: Urs Golla wrote: Is there a way to force samba to use NTLM (or NTLMv2) instead of kerberos? While the man page doesn't explicitly say

[Samba] force ntlm

2007-11-16 Thread Urs Golla
Hi We have a problem with the one way trusts between the DEV and PROD domains (Windows 2003). Microsoft told me to use NTLM instead of kerberos. Is there a way to force samba to use NTLM (or NTLMv2) instead of kerberos? Regards Urs -- To unsubscribe from this list go to the following URL and

[Samba] Fwd: could not read attribute 'gidNumber' -- seems to work with ldapsearch

2007-10-09 Thread Urs Golla
some known applications or install scripts that may cause problems if usermod is not working? Regards Urs -- Forwarded message -- From: Urs Golla [EMAIL PROTECTED] Date: Oct 5, 2007 5:23 PM Subject: Fwd: could not read attribute 'gidNumber' -- seems to work with ldapsearch

[Samba] Fwd: could not read attribute 'gidNumber' -- seems to work with ldapsearch

2007-10-05 Thread Urs Golla
If I run a normal ldapsearch it gives me the gidnumber and uidnumber attributes. It looks like the AD is set up properly. -- Forwarded message -- From: Urs Golla [EMAIL PROTECTED] Date: Oct 4, 2007 9:47 AM Subject: could not read attribute 'gidNumber' To: samba@lists.samba.org

[Samba] Fwd: could not read attribute 'gidNumber' -- seems to work with ldapsearch

2007-10-05 Thread Urs Golla
. -- Forwarded message -- From: Urs Golla [EMAIL PROTECTED] Date: Oct 5, 2007 1:43 PM Subject: Fwd: could not read attribute 'gidNumber' -- seems to work with ldapsearch To: samba@lists.samba.org If I run a normal ldapsearch it gives me the gidnumber and uidnumber attributes. It looks like the AD

[Samba] could not read attribute 'gidNumber'

2007-10-04 Thread Urs Golla
Hi I am using samba 3.0.23c on RHEL5 with security = ads. If I use idmap backend = ad i can see in the logfile that it gets my uidNumber: ad_idmap_get_id_from_sid mapped SID [S-mysid] to POSIX UID myuid but it is not able to get my gidNumber: [2007/10/04 09:44:17, 1]

Re: [Samba] AD Integrated authentication

2007-06-05 Thread Urs Golla
I think, I know how you feel :-) It seems as if the winbind stuff is not properly configured. I think you should post your smb.conf and nsswitch.conf. cheers On 5/28/07, Michael Cleghorn [EMAIL PROTECTED] wrote: Hello list, i'm going to try very hard not to rant here, but i've been trying

[Samba] net groupmap -- HELP!

2007-06-01 Thread Urs Golla
Hello I still have a problem with the net groupmap add command. If I add a domain group to a lcoal group, the memebers of the domain group should show up as members of the local group. Or am I totaly wrong? cheers -- To unsubscribe from this list go to the following URL and read the

Re: [Samba] net groupmap -- HELP!

2007-06-01 Thread Urs Golla
Hi I mean, if i do a net groupmap add mydomaingroup mylocalgroup. what is exactly the result of this? cheers On 6/1/07, Gerald (Jerry) Carter [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Urs Golla wrote: Hello I still have a problem with the net groupmap add

[Samba] groupmapping impossible?

2007-06-01 Thread Urs Golla
Does someone know how to do this group mapping in samba? why does net groupmap x y has no effect? If I map a domain group to a local group, then the members of the domain group should be treated as members of the local group, or not? On 6/1/07, Urs Golla [EMAIL PROTECTED] wrote: Usage: net

Re: [Samba] net groupmap -- HELP!

2007-06-01 Thread Urs Golla
Display full information -V or --version Print samba version information -P or --machine-passAuthenticate as machine account On 6/1/07, Gerald (Jerry) Carter [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Urs Golla wrote: Hi

[Samba] need help with group mapping!

2007-05-31 Thread Urs Golla
Hello I really need help with the group mapping stuff on AIX! I have domain user A which is member of domain group B. And I have a local group C. What I want to do now is: if A maps a smb-share, he should be a member of group C. Is such a mapping possible? cheers -- To unsubscribe from this

[Samba] group mapping

2007-05-30 Thread Urs Golla
Hi all If i add something like myunixuser = MYDOMAIN+domainuser to my username.map ist works. but if i do the same with groups (myunixgroup = @MYDOMAIN+domaingroup) i can no longer map my samba shares... any idea? what is the difference between ./net groupmap ... and using a username.map?

[Samba] trusted domains

2007-05-21 Thread Urs Golla
Hello I have a security = ads configuration. If i do a ./ntlm_auth --username=MYTRUSTEDDOMAIN+MYUSER It says: NT_STATUS_OK: Success (0x0) -- :-) but if i do a ./wbinfo -i MYTRUSTEDDOMAIN+MYUSER It says: Could not get info for user MYTRUSTEDDOMAIN+MYUSER wbinfo -m gives me a list of all the

[Samba] Re: trusted domains

2007-05-21 Thread Urs Golla
no idea? On 5/21/07, Urs Golla [EMAIL PROTECTED] wrote: Hello I have a security = ads configuration. If i do a ./ntlm_auth --username=MYTRUSTEDDOMAIN+MYUSER It says: NT_STATUS_OK: Success (0x0) -- :-) but if i do a ./wbinfo -i MYTRUSTEDDOMAIN+MYUSER It says: Could not get info for user

Re: R: [Samba] Fwd: SAMBA on AIX -- nsswitch.conf?

2007-05-14 Thread Urs Golla
logfile... wbinfo -i username does also not work anymore... any idea? thanks a lot! On 5/14/07, Gianluca Culot [EMAIL PROTECTED] wrote: -Messaggio originale- Da: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] conto di Urs Golla Inviato: domenica 13 maggio 2007 10.35 A: samba

Re: [Samba] SAMBA on AIX -- nsswitch.conf?

2007-05-14 Thread Urs Golla
thanks a lot for all the support! my samba is now running like a dream! :-) On 5/14/07, Hillel Seltzer [EMAIL PROTECTED] wrote: On Mon, 14 May 2007 10:34:32 +0200, Urs Golla wrote nsswitch.conf does not exist on AIX! It works after changing /etc/security/user and copying WINBIND etc

[Samba] SAMBA on AIX -- nsswitch.conf?

2007-05-13 Thread Urs Golla
Hi I am still trying to run SAMBA on AIX with security = ads and I have a few questions: - on AIX is no such file as /etc/nsswitch.conf -- Do I have to add the configuration somewhere else? - I allways get this User xy is invalid on this system if try to map a share from Windows. What does

[Samba] Fwd: SAMBA on AIX -- nsswitch.conf?

2007-05-13 Thread Urs Golla
it works if i create the user xy on AIX. any ideas? -- Forwarded message -- From: Urs Golla [EMAIL PROTECTED] Date: May 13, 2007 9:26 AM Subject: SAMBA on AIX -- nsswitch.conf? To: samba@lists.samba.org Hi I am still trying to run SAMBA on AIX with security = ads and I have

Re: [Samba] Fwd: SAMBA on AIX -- nsswitch.conf?

2007-05-13 Thread Urs Golla
, May 13, 2007 at 10:34:46AM +0200, Urs Golla wrote: it works if i create the user xy on AIX. any ideas? From nsswitch/winbindd_nss_aix.c: /* To install this module copy nsswitch/WINBIND to /usr/lib/security and add WINBIND in /usr/lib/security/methods.cfg and /etc/security/user Note

[Samba] uid mapping

2007-05-13 Thread Urs Golla
Hi It's me again ;-) I have set idmap uid = 1-4. But my ads users have now uid's starting from 5000. And the new Files from this users have MYDOMAIN:MYDOMAIN as owner. I think this should be MYDOMAINUSERNAME:MYDOMAINGROUP. Any ideas? I think it's almost done... -- To unsubscribe from

[Samba] security = ads -- invalide user

2007-05-10 Thread Urs Golla
Hello I try to run SAMBA with security = ads on AIX 5.3 with SAMBA 3.0.23d. net ads join was successful and the machine is now visible in the Domain with the netbios name. When I try to access the shares on the machine the log.smbd files says: (...) [2007/05/10 08:58:16, 1]

Re: R: [Samba] security = ads -- invalide user

2007-05-10 Thread Urs Golla
] wrote: -Messaggio originale- Da: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] conto di Urs Golla Inviato: giovedì 10 maggio 2007 9.44 A: samba@lists.samba.org Oggetto: [Samba] security = ads -- invalide user Hello I try to run SAMBA with security = ads on AIX 5.3 with SAMBA 3.0.23d

Re: R: R: [Samba] security = ads -- invalide user

2007-05-10 Thread Urs Golla
is 2003 I map now groups AND users. -- It still does not work... any idea? On 5/10/07, Gianluca Culot [EMAIL PROTECTED] wrote: -Messaggio originale- Da: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] conto di Urs Golla Inviato: giovedì 10 maggio 2007 10.04 A: samba@lists.samba.org

Re: R: R: R: [Samba] security = ads -- invalide user

2007-05-10 Thread Urs Golla
Hi Gianluca * *How did you define your shares in the smb.conf? Can you send me an example? thanks Urs * * On 5/10/07, Urs Golla [EMAIL PROTECTED] wrote: If I set client use spnego = no in the smb.conf it says: Requested protocol [LANMAN2.1] [2007/05/10 13:00:57, 3] smbd