[Samba] (no subject)

2004-12-11 Thread Don
Do you want a cheap Watch?
http://oqb.hensi.com

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Copying between physical drives within samba mount - veryslow.

2004-12-11 Thread david rankin
when I move files from /master/drive1 to /master/drive2 the copy process
is very slow.
why does samba send the whole file across the network and back?  is there
a way to avoid this?
why not rsync from /master/drive1 to /master/drive2?
--
David C. Rankin, J.D., P.E.
RANKIN LAW FIRM, PLLC
510 Ochiltree Street
Nacogdoches, Texas 75961
(936) 715-9333
(936) 715-9339 fax
www.rankin-bertin.com
--
- Original Message - 
From: "Panos Koutsoyannis" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Saturday, December 11, 2004 3:10 PM
Subject: [Samba] Copying between physical drives within samba mount - 
veryslow.



I have a situation with a linux box that has several drives mounted under
/master
say /master/drive1 and /master/drive2 ..etc.
I mount /master on my windows machine or os x machine using samba.
Here is my config
red hat 9
samba 3.0.x
system drive = /
data drive 1= /master/drive1
data drive 2 = /master/drive2
mounted system on pc under /master  so I see on my pc drive1 folder and
drive2 folder.
Dragging from drive1 to drive2 seems to pass the whole file across the
network from drive1 to drive2.
If I create folders ... say /master/folder1 and /master/folder2. these
folders are not seperate drives.  Then movign files between them is
lightening fast as expected.
Hope someone can help.
panos
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] can you automatically add a DNS entry when using "net" to join AD

2004-12-11 Thread Lucas Machado
I looked through the net man page and googled with no luck...I was
wondering if it is possible to have a DNS entry created for the
machine I add using "net ads join" without me having to manually add
it to the DNS.

-- 
Cheers,
--Lucas Machado
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Group permissions not working on 3.0.8

2004-12-11 Thread Rodrigo Severo
Taso Hatzi wrote:
Rodrigo Severo wrote:
I saw some messages about group permission related problems down in 
Samba 3.0.2. Could these issues be related to this same problem?

Does "getent group" show the groups that are defined in the LDAP
database?
Yes. I get the groups with all the expected users.
Rodrigo Severo
--
Rodrigo Severo
Fábrica de Idéias
SBS - Ed. Empire Center - Sala 1301 - Cobertura
Fone: (61) 321 1357
Fax: (61) 223 1712
--
It's easier to fight for one's principles than to live up to them.
   -- fortune cookie
--
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] post_exec issues

2004-12-11 Thread Jim Potter
Hi all,
 I've been trying to write scripts that are triggered by the post_exec 
command, and`I've found it doesn't act like it sounds like its meant 
to... it seems that diffrent operating systems let a session with a 
share close at different points:
- Windows keeps my documents and user profile sessions open until ~15 
seconds after the user logs out (don't know about suspend/hibernate)
- windows closes other sessions after ~15 seconds of not having an 
explorer window/file open in the share
- unix mounts keep session open until share is dismounted

Is there any reliable way of triggering a script to run on the server to 
run when a user logs out? Maybe when an IPC$ share closes?
Is there any way of affecting the above behaviour at all, from the 
server's point of view? It would be nice to know when a (windows) user 
logs out on a machine that isn't the DC for that session, and does not 
host the user's home directory 

any thoughts on this would be very welcome
cheers
JimChu
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Samba (old) and shared printers on MS Win 2003 SBS

2004-12-11 Thread Tom Peters
This might be a rube question; if so I apologize in advance. Someone asked 
me to help and I don't have much info, but I have a limited window and have 
to be forearmed with as much information as possible before I set foot in 
the door.

The guy that asked for help runs a Red  Hat 6.2 box with the version of 
Samba that came with RH 6.2. I asked him what version of Samba it was. He 
didn't know. He's going to check Monday.

He has this uneasy relationship with the IT people at the place. His apps 
on the RH box run a main mission function, but the windows boxes do 
everything else. Last week the IT folks decided they were going to sweep 
out all the Win98 and NT boxen and replace all the workstations with XP Pro 
and all the server(s) with Win2003 Small Biz.

Prior to that, his Linux apps printed to shared printers connected to NT 
and maybe even Win98 workstations with ease. Now his stuff can't reach any 
shared printers.

My first thought was that old versions of Samba don't know about Active 
Directory, but I don't know 1. if that's true or 2. if the presence of 
Win2003 server SBS necessarily implies AD.

My second thought was that the arrogant twits just didn't bother to give 
his box required permissions to use the shared printers.

Who'd design a business network with printers on the workstations anyhow?
Whatever, any ideas where to begin?
Can someone tell me how recent a version of Samba he could upgrade to, 
given that he's stuck with the kernel he's using now because of his apps?

TIA,
Tom


[Computing] Minsky and I require every graduate student to take an
oath at the grave of E.E. "Doc" Smith before he can receive a PhD in
AI. --John McCarthy, Computer Science Department, Stanford, CA 94305
--... ...--  -.. .  -. . --.- --.- -...
[EMAIL PROTECTED]   (remove "nospam") N9QQB (amateur radio)
"HEY YOU" (loud shouting)  WEB ADDRESS http//www.mixweb.com/tpeters
43° 7' 17.2" N by 88° 6' 28.9" W,  Elevation 815',  Grid Square EN53wc
WAN/LAN/Telcom Analyst, Tech Writer, MCP, Cisco Certified CCNA

--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Copying between physical drives within samba mount - veryslow.

2004-12-11 Thread Mitch (WebCob)


> -Original Message-
> From: panos [mailto:[EMAIL PROTECTED]
> Sent: December 11, 2004 4:07 PM
> To: 'Mitch (WebCob)'; [EMAIL PROTECTED]
> Subject: RE: [Samba] Copying between physical drives within samba mount -
> veryslow.
> 
> Thanks for the response.  Yeah I saw the same behavior with NFS.  It
> would be nice to have an rpc.move.
> 
> However, if I use netatalk the does not copy across the wire.  I have
> not looked into the detail of the protocol.  However, it has its own
> limitations.
> 
> 
> Do you know of any movement in this area?  Logging in directly is not an
> option for our clients.  I have looked at netatalk, samba, nfs and
> webdav stuff.
> 
> Panos
> 
[Mitch says:] That's an interesting note about netatalk... Apple was often
advanced in their ideas and then crippled cause they wanted to own the ball,
the field, make the rules, and hire the referee ;-)

I am not aware of any movement - if there is a forum or study group for the
protocol, someone here or maybe a reference in samba docs might guide you -
Samba didn't invent the protocol, and as far as I know doesn't contribute to
it - it "just" implements the "standard" (no slight against samba intended!)

You could perhaps provide the function through a web interface or other if
it's used that often? Or maybe just upgrade your server link to gigabit?

m/

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Copying between physical drives within samba mount - veryslow.

2004-12-11 Thread panos
Thanks for the response.  Yeah I saw the same behavior with NFS.  It
would be nice to have an rpc.move.  

However, if I use netatalk the does not copy across the wire.  I have
not looked into the detail of the protocol.  However, it has its own
limitations.


Do you know of any movement in this area?  Logging in directly is not an
option for our clients.  I have looked at netatalk, samba, nfs and
webdav stuff.

Panos


-Original Message-
From: Mitch (WebCob) [mailto:[EMAIL PROTECTED] 
Sent: Saturday, December 11, 2004 3:56 PM
To: [EMAIL PROTECTED]; [EMAIL PROTECTED]
Subject: RE: [Samba] Copying between physical drives within samba mount
- veryslow.



> -Original Message-
> From: [EMAIL PROTECTED] [mailto:samba-
> [EMAIL PROTECTED] On Behalf Of Panos
Koutsoyannis
> Sent: December 11, 2004 1:11 PM
> To: [EMAIL PROTECTED]
> Subject: [Samba] Copying between physical drives within samba mount -
> veryslow.
> 
> I have a situation with a linux box that has several drives mounted
under
> /master
> say /master/drive1 and /master/drive2 ..etc.
> I mount /master on my windows machine or os x machine using samba.
> 
> when I move files from /master/drive1 to /master/drive2 the copy
process
> is very slow.
> 
> it seems samba actually sends the file over he network from the linux
> machine to the pc on which it is mounted and back to the linux
machine.
> 
> This only happens when there are different drives involved.  however
if i
> move files within the same drive it is fast as expected.
> 
[Mitch says:] This is similar to Linux itself - if you were moving
within an
NFS mount point, you would move... which I believe is commonly
implemented
as a hardlink to the second location OR a copy if on a different
physical
location, then an unlink from the old location...

Windows / SMB has the same limitation in the protocol - There is no "rpc
move" used (or even existing I think?) so it does what it has to do
within
the protocol - you will of course see much faster throughput by doing
these
major moves locally on the server box through a shell if that is an
option
for you.

m/

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Copying between physical drives within samba mount - veryslow.

2004-12-11 Thread Mitch (WebCob)


> -Original Message-
> From: [EMAIL PROTECTED] [mailto:samba-
> [EMAIL PROTECTED] On Behalf Of Panos Koutsoyannis
> Sent: December 11, 2004 1:11 PM
> To: [EMAIL PROTECTED]
> Subject: [Samba] Copying between physical drives within samba mount -
> veryslow.
> 
> I have a situation with a linux box that has several drives mounted under
> /master
> say /master/drive1 and /master/drive2 ..etc.
> I mount /master on my windows machine or os x machine using samba.
> 
> when I move files from /master/drive1 to /master/drive2 the copy process
> is very slow.
> 
> it seems samba actually sends the file over he network from the linux
> machine to the pc on which it is mounted and back to the linux machine.
> 
> This only happens when there are different drives involved.  however if i
> move files within the same drive it is fast as expected.
> 
[Mitch says:] This is similar to Linux itself - if you were moving within an
NFS mount point, you would move... which I believe is commonly implemented
as a hardlink to the second location OR a copy if on a different physical
location, then an unlink from the old location...

Windows / SMB has the same limitation in the protocol - There is no "rpc
move" used (or even existing I think?) so it does what it has to do within
the protocol - you will of course see much faster throughput by doing these
major moves locally on the server box through a shell if that is an option
for you.

m/

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread Adam Tauno Williams
> >> As a consequence, this also means, that on each server there has to be 
> >> a copy of a profile of a given user, right? 
> > No, not right. The user roaming profile is stored only on one server.
> So what is the sense of having BDCs? 

So distribute the profiles.  Where the user's profile is located is just
an attribute of the user object (when using an LDAP SAM).

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] (no subject)

2004-12-11 Thread Craig White
On Sat, 2004-12-11 at 17:09 -0500, alton bailey wrote:
> when I issue a command to populate my ldap directory I receive an erro cant 
> find Net/SSleay.pm how can I find an Net:SSleay rpm to install on FC3

---
what does this have to do with samba?

perl -MCPAN -e shell
install Net::SSLeay
exit

Craig

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread John H Terpstra
On Saturday 11 December 2004 13:06, Tomasz Chmielewski wrote:
> gints neimanis wrote:
> > Tomasz Chmielewski wrote:
> >> As a consequence, this also means, that on each server there has to be
> >> a copy of a profile of a given user, right?
> >
> > No, not right. The user roaming profile is stored only on one server.
>
> So what is the sense of having BDCs? I guess the biggest load happens
> when the profiles are copied; when there are hundreds of users, one PDC
> (on which the profiles are stored) would be much overloaded.

Tomasz,

An NT4 PDC is a master authentication database server. It is undesirable to 
have network logon traffic run over a routed network. The purpose of the BDC 
is to permit a single security domain (context) and still permit all network 
logon traffic to be handled on the local network segment.

At some time in the future Samba me be able to handle full authentication 
datebase synchronization (like NT4 PDC/BDC combinations can do). At this time 
it does not, however there can be only on PDC per domain (security context). 
The benefit of a single domain is that it helps keep to a minimum the number 
of interdomain trusts required.

Authentication is entirely orthogonal to MS Windows client profile handling.
Both in NT4 as well as with Samba, the location of the use desktop profile is 
set in the user account record in the authentication database. NT4 does not 
replicate or synchronize desktop profiles - nor does Samba. Where on earth 
did you obtain the idea that this ought to happen?

>
> Besides, Samba Guide chapter 7 ("Distributed 2000 users network")
> describes a setup when users are located in New York, London etc.
> different locations, which sounds just silly if roaming profiles were
> stored for example in New York only.

The notion that all roaming profiles are stored on a central server and that 
profiles are transferred over a wide-area link at login time is not one I 
have created. Where did you get such a notion? I would not call that silly, 
I'd call that insane and completely unworkable.

Windows NT4/2KX profiles can be many gigabytes in size, particularly if 
network administrators have not attempted to manage the network environment. 
Microsoft's ZAW (Zero Administration Windows) program was designed to show 
network administrators how to lock down the desktop profile so that logins 
involve a minimum of network traffic and users get good network 
responsiveness.

>
> > Maybe you may rename the each SAMBA server in each location in the same
> > NetBIOS name, but the profile directory on each server is fetched from
> > the central server over NFS.
>
> I don't think giving the same NetBIOS name for different machines is a
> good idea.

Agreed.

>
> Fetching profiles each time from a central server when user logs in /
> logs out doesn't seem to be good idea for me - what if company/school
> etc. has two or more buildings, and they are connected only by a slow
> VPN over internet/wireless etc.?

The answer is: Practice good account management. Locate the users' profile on 
a server close to where the user is - preferably on the same network segment.
I a user roams across multiple network segments and the wide-area bandwith can 
not handle the roaming profile then do exempt that user from having a roaming 
profile and instead store the profile locally on the workstation (or 
notebook) that is used by this user.

Cheers,
John T.
-- 
John H Terpstra
Samba-Team Member
Phone: +1 (650) 580-8668

Author:
The Official Samba-3 HOWTO & Reference Guide, ISBN: 0131453556
Samba-3 by Example, ISBN: 0131472216
Hardening Linux, ISBN: 0072254971
Other books in production.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] (no subject)

2004-12-11 Thread alton bailey
when I issue a command to populate my ldap directory I receive an erro cant 
find Net/SSleay.pm how can I find an Net:SSleay rpm to install on FC3[EMAIL PROTECTED] ~]# smbldap-populate
Using builtin directory structure
Can't locate Net/SSLeay.pm in @INC (@INC contains: /usr/local/sbin// 
/usr/lib/perl5/5.8.5/i386-linux-thread-multi /usr/lib/perl5/5.8.5 
/usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.4/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.3/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.2/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.1/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.0/i386-linux-thread-multi 
/usr/lib/perl5/site_perl/5.8.5 /usr/lib/perl5/site_perl/5.8.4 
/usr/lib/perl5/site_perl/5.8.3 /usr/lib/perl5/site_perl/5.8.2 
/usr/lib/perl5/site_perl/5.8.1 /usr/lib/perl5/site_perl/5.8.0 
/usr/lib/perl5/site_perl 
/usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.4/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.3/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.2/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.1/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi 
/usr/lib/perl5/vendor_perl/5.8.5 /usr/lib/perl5/vendor_perl/5.8.4 
/usr/lib/perl5/vendor_perl/5.8.3 /usr/lib/perl5/vendor_perl/5.8.2 
/usr/lib/perl5/vendor_perl/5.8.1 /usr/lib/perl5/vendor_perl/5.8.0 
/usr/lib/perl5/vendor_perl .) at 
/usr/lib/perl5/site_perl/5.8.5/IO/Socket/SSL.pm line 17.
BEGIN failed--compilation aborted at 
/usr/lib/perl5/site_perl/5.8.5/IO/Socket/SSL.pm line 17.
Compilation failed in require at /usr/lib/perl5/vendor_perl/5.8.5/Net/LDAP.pm 
line 920.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

[Samba] Contribution to the docs. Was: Loglevel question

2004-12-11 Thread Jim C.
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Jim C. wrote:
| What are the different classes?  The docs list only 3 but are there more?
According to smbclient set to debug level 10:
INFO: Current debug levels:
~  all: True/10
~  tdb: False/0
~  printdrivers: False/0
~  lanman: False/0
~  smb: False/0
~  rpc_parse: False/0
~  rpc_srv: False/0
~  rpc_cli: False/0
~  passdb: False/0
~  sam: False/0
~  auth: False/0
~  winbind: False/0
~  vfs: False/0
~  idmap: False/0
~  quota: False/0
~  acls: False/0
This info sure would be handy to know.  I've been looking for it since I
first started using Samba 3.x  Anybody know where I can find out what
each of these relates to?
Jim C.
- --
- -
| I can be reached on the following Instant Messenger services: |
|---|
| MSN: j_c_llings @ hotmail.com  AIM: WyteLi0n  ICQ: 123291844  |
|---|
| Y!: j_c_llingsJabber: jcllings @ njs.netlab.cz|
- -
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFBu2/A57L0B7uXm9oRAmjNAJ97kDavFLVthwWNntiQ5LxepR21cQCgg0hE
33Zw42RuaLwl1o0p5JfTVLc=
=pVS8
-END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread Tomasz Chmielewski
Tomasz Chmielewski wrote:
| Jim C. wrote:
|
|> -BEGIN PGP SIGNED MESSAGE-
|> Hash: SHA1
|>
|> | Or perhaps I don't understand something?
|>
|> Just a guess but a BDC is probably going to do the same thing with the
|> files that the LDAP backend would do.  I.E. replicate the data from the
|> server.
| But how should it be done?
OK, real quick.  I don't have time to read the rest of this email but
try this:
http://linsec.ca/bin/view/Main/LdapAdvanced
NO, this article is about LDAP mainly, and says nothing about 
replicating/synchronizing profiles/data/files.

Tomek
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Group permissions not working on 3.0.8

2004-12-11 Thread Taso Hatzi
Rodrigo Severo wrote:
I saw some messages about group permission related problems down in 
Samba 3.0.2. Could these issues be related to this same problem?

Does "getent group" show the groups that are defined in the LDAP
database?
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Copying between physical drives within samba mount - very slow.

2004-12-11 Thread Panos Koutsoyannis
I have a situation with a linux box that has several drives mounted under
/master
say /master/drive1 and /master/drive2 ..etc.
I mount /master on my windows machine or os x machine using samba.

when I move files from /master/drive1 to /master/drive2 the copy process
is very slow.

it seems samba actually sends the file over he network from the linux
machine to the pc on which it is mounted and back to the linux machine.

This only happens when there are different drives involved.  however if i
move files within the same drive it is fast as expected.

why does samba send the whole file across the network and back?  is there
a way to avoid this?

Here is my config
red hat 9
samba 3.0.x
system drive = /
data drive 1= /master/drive1
data drive 2 = /master/drive2
mounted system on pc under /master  so I see on my pc drive1 folder and
drive2 folder.
Dragging from drive1 to drive2 seems to pass the whole file across the
network from drive1 to drive2.

If I create folders ... say /master/folder1 and /master/folder2. these
folders are not seperate drives.  Then movign files between them is
lightening fast as expected.

Hope someone can help.

panos

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread Tomasz Chmielewski
gints neimanis wrote:
Tomasz Chmielewski wrote:
As a consequence, this also means, that on each server there has to be 
a copy of a profile of a given user, right?

No, not right. The user roaming profile is stored only on one server.
So what is the sense of having BDCs? I guess the biggest load happens 
when the profiles are copied; when there are hundreds of users, one PDC 
(on which the profiles are stored) would be much overloaded.

Besides, Samba Guide chapter 7 ("Distributed 2000 users network") 
describes a setup when users are located in New York, London etc. 
different locations, which sounds just silly if roaming profiles were 
stored for example in New York only.


Maybe you may rename the each SAMBA server in each location in the same 
NetBIOS name, but the profile directory on each server is fetched from 
the central server over NFS.
I don't think giving the same NetBIOS name for different machines is a 
good idea.

Fetching profiles each time from a central server when user logs in / 
logs out doesn't seem to be good idea for me - what if company/school 
etc. has two or more buildings, and they are connected only by a slow 
VPN over internet/wireless etc.?

Tomek
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread gints neimanis
Tomasz Chmielewski wrote:
As a consequence, this also means, that on each server there has to be a 
copy of a profile of a given user, right?
No, not right. The user roaming profile is stored only on one server.
Maybe you may rename the each SAMBA server in each location in the same 
NetBIOS name, but the profile directory on each server is fetched from 
the central server over NFS.

Gints
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Logon Script

2004-12-11 Thread Norman Zhang
Hi,
Is [netlogon] only applicable for Samba Domain Controllers? I like to 
create use root preexec script to create home folders for first time 
users. I'm currently running ADS mode, and using KiXtart logon script. 
Would this work?

Regards,
Norman Zhang
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Group permissions not working on 3.0.8

2004-12-11 Thread Rodrigo Severo
Hi,
I have just tried Samba 3.0.9 and got the same results. Sadly.
What should I do now?
Rodrigo Severo
Rodrigo Severo wrote:
I believe group permissions are not working well on Samba 3.0.8.
I have two different problems that seems to be group permission related:
1. I have the following file:
-r--rw  1 apache_user developers_group 13285 Dec  9 12:53 index.html
I am a member of developers_group (not my primary group) and I can't 
edit this file. If I give apache_user (the file's owner) the write 
right then I can edit the file. Why?

This only happens when I access the file through Samba, on the machine 
itself these rights work as I expect, i.e., no need of write right to 
the owner.

2. I have the following directory:
dr-xrws---  1 apache_user developers_group 0 Mar 18  2004 userimages/
Again I, as a member of developres_group, should be able to create a 
new file. But I can't: permission denied. Again I ask why?

I saw some messages about group permission related problems down in 
Samba 3.0.2. Could these issues be related to this same problem?

BTW I using ldap based authentication.
---
Rodrigo Severo
Fábrica de Idéias
SBS -Ed. Empire Center Sala 1301 - Cobertura
Fone: (61) 321 1357
Fax: (61) 223 1712
Brasília/DF
---
Nothing is foolproof to a sufficiently talented fool. -- Tom Eastep
-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: Group permissions not working on 3.0.8

2004-12-11 Thread Rodrigo Severo
Danny Paul wrote:
Try removing these lines from the share definition and see what you get.
 

force group = +developers_group
   

...
 

force directory mode = 070
write list = @developers_group
   

Hi,
Took the three out. No change. Both problems remain.
Are samba permission policies so different from unix by design or by 
mistake?

I understood that, specially with
"unix extensions = yes", samba permissions behaviour should be exactly 
the same as the underlying unix systems. Am I wrong?

Thanks again,
Rodrigo Severo

---
Rodrigo Severo
Fábrica de Idéias
SBS -Ed. Empire Center Sala 1301 - Cobertura
Fone: (61) 321 1357
Fax: (61) 223 1712
Brasília/DF
---
It's easier to fight for one's principles than to live up to them.
 -- fortune cookie
-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Strange Samba Problem

2004-12-11 Thread L. Mark Stone
Running SuSE 9.2. This problem happens with both the SuSE-supplied Samba on 
the DVD, as well as the SuSE update rpms to 3.0.9. We even removed all the 
*.tdb files and recreated the installation from scratch, as always carefully 
following the steps in S3BE. FWIW, this same config worked previously on this 
and earlier systems; we did not change anything on this system (other than 
applying YOU patches), and since we fire the Windows VM infrequently, we 
can't correlate when this problem started with any specific YOU patches..

Basically, we use Samba on a host to make printers and shares available to 
Windows running on the same host in a VMware VM. We don't want anyone else on 
the LAN to see shares on this host.

The problem manifests itself in several ways: 

1. MS Office applications complain a file is either locked by another user and 
can be opened read-only, or that a file no longer exists.

2. Using the MS Explorer window to CTRL-C and CTRL-V a file in the same folder 
generates no errors, but the copied file has a file size of 0 bytes.

3. RMB'ing in the MS Explorer window to choose Create New > Folder winds up 
creating the New Folder correctly, but generating a dialog box that reads: 
"Unable to create the folder "New Folder." Cannot create a file when that 
file already exists."

I've run a level 10 debug and didn't see anything intuitively obvious, but I'm 
not a Samba developer!  :-)  Here's smb.conf below. Any ideas? Things to try? 
Printing works fine BTW, if that's helpful.

# smb.conf file.  Created By L. Mark Stone for SuSE 9.2 installation.
# Version 1.0 - Migrated from SuSE 8.2 version in use.

[global]
workgroup = RNOME
printing = cups
printcap name = cups
printcap cache time = 750
printer admin = @ntadmin, root, administrator
username map = /etc/samba/smbusers
passdb backend = tdbsam
use sendfile = no
large readwrite = no
log level = 10
syslog = 0
log file = /var/log/samba/%m
max log size = 50
#   socket options = TCP_NODELAY IPTOS_LOWDELAY SO_KEEPALIVE SO_SNDBUF=8192 
SO_RCVBUF=8192
interfaces = vmnet8 172.16.8.1/24 127.0.0.1
bind interfaces only = yes

#[homes]
#   comment = Home Directories
#   valid users = %S
#   browseable = no
#   read only = no
#   inherit acls = yes

[pdf]
comment = PDF creator
path = /var/tmp
printable = yes
print command = /usr/bin/smbprngenpdf -J '%J' -c %c -s %s -u '%u' -z %z
create mask = 0600

[printers]
comment = All Printers
path = /var/tmp
printable = yes
create mask = 0600
browseable = no

[print$]
comment = Printer Drivers
path = /var/lib/samba/drivers
write list = @ntadmin root
force group = ntadmin
create mask = 0664
directory mask = 0775

[data]
comment = Data Directory
path = /home/data/
public = yes
force user = lmstone
force group = users
inherit permissions = yes
writeable = yes
oplocks = no
level2 oplocks = no


-- 
___
A Message From...  L. Mark Stone

Reliable Networks of Maine, LLC

"We manage your network so you can manage your business."

477 Congress Street
Portland, ME 04101
Tel: (207) 772-5678
Web: http://www.RNoME.com


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: Cannot get DOMAIN ADMINS to work

2004-12-11 Thread Heinrich Rebehn
Jim C. wrote:
| After reading a lot in the mailing list and the official Samba 3 howto,
| i am still unable to give domain admin rights to a user, so that he gets
| admin rights on all workstations in the domain.
|
| Here is what i have:
1. If you are using ldap, you should know that the posixgroup
objectClass is out of date and that you will need a different
objectClass to provide Administrative access to the LDAP database
itself. Specifically, groupOfNames.
LDAP is only used by the Unix system. Samba does not use LDAP, it is 
even compiled w/o LDAP support. So, as long as getgrent(3) shows that a 
user is in the ntadmin group, the user should get admin rights.

--Heinrich
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread Tomasz Chmielewski
Jim C. wrote:
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
| Or perhaps I don't understand something?
Just a guess but a BDC is probably going to do the same thing with the
files that the LDAP backend would do.  I.E. replicate the data from the
server.
But how should it be done?
I have read the whole Samba Guide, and I think I didn't find a clue on 
that - it seems for me that using configurations similar to these 
presented in Samba Guide would result in different roaming profiles on 
each domain controller.

File replication is a different thing than LDAP replication:
- files are big, LDAP queries are just a hundred bytes each,
- file operations are read and write, LDAP are read mostly,
- LDAP is one read/write master server and multiple read-only slaves,
- with PDC and BDCs files can be read from and written to each server 
(PDC, BDC1, BDC2 etc.) - there is no "central" server which takes care 
of everything.

So, now imagine this situation:
We have a university/school facility with two buildings. Additionally, 
there is a campus nearby with 4 buildings. So 6 buildings in total.
They are connected together using VPN over internet link - 1 Mbit 
down/upload in each building.

Students have classes in each building, which means they should be able 
to log in and use their roaming profiles in each building, and also in 
each building in a campus.

To keep traffic to the minimum, there is a domain controller + LDAP 
slave in each building: from 09.00-11.00 student Joe has classes in 
building A, so he uses domain controller (DC-A) in that building, and 
from 11.15-14.00 he has classes in building B (and therefore, uses 
DC-B). After that he makes his homework in the campus - so after each 
logout, his profile should be immediately replicated to other domain 
controllers in other buildings.

With LDAP it is easy: master controlls everything: for example when user 
changes his/her password, slave gives this change to the master, which 
replicates the data to other slaves. When master is unavailable (link 
down or master server down) user will be notified that the password 
can't be changed.

This is not the case with files.
Even if I use some handmade scripts which use rsync to upload files to 
other DCs after user logs out, this will obviously fail when one DC is 
down for some time or internet link/VPN is down:

- at 11.00 user Joe finishes his classes in building A, logs out, 
profile with important data is uploaded to other DCs,
- as there is no connection between building A and B (roadwork workers 
just broke the internet link between buildings), this results in 
different profiles in building A and B,
- at 11.15 logs in in building B, notices (or not), that his important 
data is incomplete,
- at 14.00 he logs out in building B, internet link is back, so his 
incomplete data from building B overwrites important, complete data in 
building A,
- we have data corruption, user confusion, students and staff loosing 
their data, admins fired etc. etc.

So here comes my question again: how should the profiles be synchronized 
between domain controllers? What are the best ways to do it? What are 
your experiences?

Hope the post wasn't too long :) but I think that the problem is not a 
trivial one, too.

Tomek
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Compiling Samba 3.0.9 on Solaris 2.6 gives conflicts :-(

2004-12-11 Thread Jimmy Störbäck
Hi,
I have to build Samba 3.0.9 on a customers Sun E3500 with Solaris 2.6. 
They recently upgraded to Windows 200x domain with AD.
When i try to compile with Heimdal or MIT Kerberos i get the following 
error:

Using FLAGS =  -I/usr/heimdal/include 
-I/usr/local/BerkeleyDB.4.2/include -I/usr/local/ssl/include 
-I/usr/heimdal/include -L/usr/local/BerkeleyDB.4.2/lib 
-L/usr/local/ssl/lib -L/usr/heimdal/lib -I./popt -Iinclude 
-I/opt/tmp/samba-3.0.9/source/include 
-I/opt/tmp/samba-3.0.9/source/ubiqx 
-I/opt/tmp/samba-3.0.9/source/smbwrapper  -I. -I/usr/heimdal/include 
-I/usr/local/BerkeleyDB.4.2/include -I/usr/local/ssl/include 
-I/usr/heimdal/include -L/usr/local/BerkeleyDB.4.2/lib 
-L/usr/local/ssl/lib -L/usr/heimdal/lib -D_LARGEFILE_SOURCE -D_REENTRANT 
-D_FILE_OFFSET_BITS=64 -I/opt/tmp/samba-3.0.9/source
 LIBS = -lsec -lgen -lresolv -lsocket -lnsl -ldl -liconv
 LDSHFLAGS = -G  -L/usr/heimdal/lib 
-I/usr/local/BerkeleyDB.4.2/include -I/usr/local/ssl/include 
-I/usr/heimdal/include -L/usr/local/BerkeleyDB.4.2/lib 
-L/usr/local/ssl/lib -L/usr/heimdal/lib -lthread
 LDFLAGS = -L/usr/heimdal/lib -I/usr/local/BerkeleyDB.4.2/include 
-I/usr/local/ssl/include -I/usr/heimdal/include 
-L/usr/local/BerkeleyDB.4.2/lib -L/usr/local/ssl/lib -L/usr/heimdal/lib 
-lthread
Compiling dynconfig.c
In file included from include/includes.h:457,
from dynconfig.c:21:
/usr/heimdal/include/gssapi.h:76: error: conflicting types for 
'gss_ctx_id_t'
/usr/include/rpc/rpcsec_gss.h:59: error: previous declaration of 
'gss_ctx_id_t' was here
/usr/heimdal/include/gssapi.h:103: error: conflicting types for 
'gss_cred_id_t'
/usr/include/rpc/rpcsec_gss.h:60: error: previous declaration of 
'gss_cred_id_t' was here
/usr/heimdal/include/gssapi.h:116: error: conflicting types for 
'gss_channel_bindings_t'
/usr/include/rpc/rpcsec_gss.h:61: error: previous declaration of 
'gss_channel_bindings_t' was here
make: *** [dynconfig.o] Error 1

Is there somebody out there that can give me a hint please ... i need to 
get my Samba running quick.

Regards
Jimmy Jonsson
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Re: %a - Supporting Multiple Windows OS's

2004-12-11 Thread Jim C.
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Gerald (Jerry) Carter wrote:
| Craig White wrote:
|
| | can we now use %u and/or %U in LDAP sambaHomePath
| | and sambaProfilePath ?
| Not currently.
What about %USERNAME% instead?
Jim C.
- --
- -
| I can be reached on the following Instant Messenger services: |
|---|
| MSN: j_c_llings @ hotmail.com  AIM: WyteLi0n  ICQ: 123291844  |
|---|
| Y!: j_c_llingsJabber: jcllings @ njs.netlab.cz|
- -
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFButhi57L0B7uXm9oRAmgOAJ0bDq8rz0ARsRkOQYAvzTQQKfygBACZAa5N
fgcVdrXA1xsS/0TJwSAFK90=
=fQ8E
-END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Loglevel question

2004-12-11 Thread Jim C.
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
What are the different classes?  The docs list only 3 but are there more?
Jim C.
- --
- -
| I can be reached on the following Instant Messenger services: |
|---|
| MSN: j_c_llings @ hotmail.com  AIM: WyteLi0n  ICQ: 123291844  |
|---|
| Y!: j_c_llingsJabber: jcllings @ njs.netlab.cz|
- -
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFButiq57L0B7uXm9oRAg3kAJ9P2T7vJofLZ9zeGM1KxgQLDxRrgACdEdZ2
089Wy7cVuaS6c5PxTiSfl14=
=ljG1
-END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Re: PDC, BDCs - how do you synchronize roaming profiles?

2004-12-11 Thread Jim C.
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
| Or perhaps I don't understand something?
Just a guess but a BDC is probably going to do the same thing with the
files that the LDAP backend would do.  I.E. replicate the data from the
server.
Jim C.
- --
- -
| I can be reached on the following Instant Messenger services: |
|---|
| MSN: j_c_llings @ hotmail.com  AIM: WyteLi0n  ICQ: 123291844  |
|---|
| Y!: j_c_llingsJabber: jcllings @ njs.netlab.cz|
- -
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFButk657L0B7uXm9oRAm4TAJ9FbHfSVOMwBXgmLNe+2d3/hDP6kwCeONlC
hejNa02+f9eAkCGwyERz15I=
=csYH
-END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba