[Samba] Samba 3.0.20b - still getting "Winbind Dead but subsys locked"

2005-10-15 Thread PC
I can remove the /var/locl/subsys/winbindd file to clear the subsys locked 
message but this does not chnage the winbind crash problem.

I originally noticed this problem on 20a and thought that 20b had a fix for 
the winbind crash.

Any clues?

I am running RH ES 4.0 64 bit with samba packages downlaoded from 
enterprisesamba.com.

PC

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Samba Speed versus Netatalk from OS X

2005-10-15 Thread Andrew Morgan


On Sat, 15 Oct 2005 [EMAIL PROTECTED] wrote:


Does anyone know why, when transferring data via  Gigabit Ethernet from OS X
to Linux (or vice versa), you get about 50-60 MB/sec  with Samba 3.0.X (all
versions I've tried, the rate depending on whether you use  Jumbo Frames) but
you get about 105-110 MB/sec with Apple File Sharing Protocol  and Netatalk
2.03? Is there any inherent reason why Samba goes at about half the  speed?

By the way,  I'm talking about connecting with OS X (10.4.2  -- Tiger)'s
native SMB/CIFS client.


This has been my experience with OS X clients against Netatalk and Samba. 
I think it is a fault in the OS X smb client.


Andy
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] wbinfo not looking up groups in mixed MS NT/2k AD

2005-10-15 Thread John H Terpstra
On Friday 14 October 2005 12:25, Andre Fernando Goldacker wrote:
> Upgraded to samba-3.0.20b and it's working fine now.
>
> I've noticed that, when I add / remove someone to / from the group
> "internet", which in my case is the one I give internet access, it is
> taking a while for the user appear / be removed in the group, when I do
> getent group the user only appears after a while, more or less 10
> minutes. Is there a setting or something in which it updates quicker??

Pleae check that nscd is not running. It sounds like it may be.

- John T.

>
> Thanks in advance,
>
> André
>
> On Fri, 2005-10-14 at 10:14 -0300, Felipe Augusto van de Wiel wrote:
> > -BEGIN PGP SIGNED MESSAGE-
> > Hash: SHA1
> >
> > Andre Fernando Goldacker escreveu:
> > [...]
> >
> > > wbinfo -n 'EARTH\testgroup'
> > > Could not lookup name EARTH\testgroup
> > >
> > > I think that's the reason why my squid can't match users / groups.
> > > My winbind log file reports me the following lines when I try to
> > > match user/group from squid:
> > >
> > > [2005/10/13 16:46:48, 0] lib/util_sid.c:string_to_sid(301)
> > >   string_to_sid: Sid Could not lookup name internet does not start
> > > with 'S-'.
> > > [2005/10/13 16:46:48, 1]
> > > nsswitch/winbindd_sid.c:winbindd_sid_to_gid(241)
> > >
> > >   Could not cvt string to sid Could not lookup name internet
> > > Any clues why I can lookup users, but not goups?
> > > My AD has about 1100 users and 150 groups.
> > > Any help will be much appreciated,
> >
> > Never saw this problem before, but looking at the logs,
> > looks like your group entry does not have the proper field set,
> > or the field is not right, in other words, it does not start
> > with a "S-" like all the SID's.
> >
> > It is not much help, but perhaps could be a start,
> > good luck! Kind regards,
> >
> > - --
> > //
> > // Felipe Augusto van de Wiel <[EMAIL PROTECTED]>
> > // CTI/Suporte - SEDU/PARANACIDADE
> > // http://www.paranacidade.org.br/
> > //
> > -BEGIN PGP SIGNATURE-
> > Version: GnuPG v1.4.1 (GNU/Linux)
> > Comment: Using GnuPG with Debian - http://enigmail.mozdev.org
> >
> > iD8DBQFDT69HCj65ZxU4gPQRAud7AKCXdp+qPvaiyDX10VuqO3WpftM5MgCfQ4rN
> > t1bixV+pGNo1N9MTvz9SfsA=
> > =AqZF
> > -END PGP SIGNATURE-

-- 
John H Terpstra
Samba-Team Member
Phone: +1 (650) 580-8668

Author:
The Official Samba-3 HOWTO & Reference Guide, 2 Ed., ISBN: 0131882228
Samba-3 by Example, 2 Ed., ISBN: 0131882221X
Hardening Linux, ISBN: 0072254971
Other books in production.
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] help needed for samba 3.0

2005-10-15 Thread Sunil Kumar
Hi all,

when I am tring to connect to my linux
share using linux for
ex: smbclient //linuxspan/kerberos -U suneel  - where as linuxspan is host
name and kerberos is a share name and suneel is ads user.
I am getting this error : tree connect failed : NT_STATUS_BAD_NETWORK_NAME.

pls help me on this.

Thanks in advance.

Best regards,
Sunny.
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Active Directory to OpenLDAP+Kerberos on Linux

2005-10-15 Thread Akshay Guleria
> No, although Samba can interact with Kerberos, it can't actually control
> an AD domain.  That's what Samba 4 is for.
>

ok. so finally, when is samba 4 coming !? :)
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Patch: FC4 spec file

2005-10-15 Thread S Murthy Kambhampaty


--- "Gerald (Jerry) Carter" <[EMAIL PROTECTED]> wrote:

> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
> S Murthy Kambhampaty wrote:
> 
> | 2.)  The Fedora project's samba RPMS install
> | mount.cifs;   it would help to have samba.org's
> RPMS
> | do the same.
> |
> | It would be nice to see these patched incorporated
> | into the next version.
> 
> 
> This one will be in 3.0.20b

Thanks.




__ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] SAMBA password sync

2005-10-15 Thread Sérgio A P Ferreira
Hello list,

 

I´m trying to synchronize NT password and Unix passwords at LDAP directory
through Samba. I want to know if I only to do is to configure “ldap password
sync = yes” ? If don´t,  what more is necessary to make this work?

 

Thanks,

 

Sergio Ferreira.

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] makepkg.sh for samba 3.0.20

2005-10-15 Thread xuan van

Hi,

I downloaded 3.0.20 from samba.org, ran makepkg.sh to create
samba pkg for Solaris. The install base for the new version
locates in /opt/samba and the smbd locates in /etc/samba.
I tried to modify the makepkg.sh to put everything under
/usr/local/samba as follow:

Delete:

   --localstatedir=/var/lib/samba \
   --with-piddir=/var/run \
   --with-logfilebase=/var/log/samba \
   --with-privatedir=/etc/samba/private \
   --with-configdir=/etc/samba \

Add:

   --localstatedir=/usr/local/samba/lib \
   --with-piddir=/var/run \
   --with-logfilebase=/usr/local/samba/var/log \
   --with-privatedir=/usr/local/samba/private \
   --with-configdir=/usr/local/samba/lib \

Replaced INSTALL_BASE=/opt/samba with INSTALL_BASE=/usr/local/samba

makepkg.sh completed with no error. However pkgadd gives me the 
following errors:

# pkgadd -d . samba

Processing package instance  from 

CIFS File and Print server
(sparc) 3.0.20
Copyright (C) 2001 Samba Team
Using  as the package base directory.
## Processing package information.
pkgadd: ERROR: duplicate pathname 
pkgadd: ERROR: unable to process pkgmap

Installation of  failed (internal error).
No changes were made to the system.

What am I missing?

Thanks,

Xuan




--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] wbinfo not looking up groups in mixed MS NT/2k AD

2005-10-15 Thread Andre Fernando Goldacker
Upgraded to samba-3.0.20b and it's working fine now.

I've noticed that, when I add / remove someone to / from the group
"internet", which in my case is the one I give internet access, it is
taking a while for the user appear / be removed in the group, when I do
getent group the user only appears after a while, more or less 10
minutes. Is there a setting or something in which it updates quicker??

Thanks in advance,

André


On Fri, 2005-10-14 at 10:14 -0300, Felipe Augusto van de Wiel wrote:

> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
> Andre Fernando Goldacker escreveu:
> [...]
> > wbinfo -n 'EARTH\testgroup'
> > Could not lookup name EARTH\testgroup
> 
> > I think that's the reason why my squid can't match users / groups.
> > My winbind log file reports me the following lines when I try to 
> > match user/group from squid:
> 
> > [2005/10/13 16:46:48, 0] lib/util_sid.c:string_to_sid(301)
> >   string_to_sid: Sid Could not lookup name internet does not start 
> > with 'S-'.
> > [2005/10/13 16:46:48, 1]
> > nsswitch/winbindd_sid.c:winbindd_sid_to_gid(241)
> 
> >   Could not cvt string to sid Could not lookup name internet
> > Any clues why I can lookup users, but not goups?
> > My AD has about 1100 users and 150 groups.
> > Any help will be much appreciated,
> 
>   Never saw this problem before, but looking at the logs,
> looks like your group entry does not have the proper field set,
> or the field is not right, in other words, it does not start
> with a "S-" like all the SID's.
> 
>   It is not much help, but perhaps could be a start,
> good luck! Kind regards,
> 
> - --
> //
> // Felipe Augusto van de Wiel <[EMAIL PROTECTED]>
> // CTI/Suporte - SEDU/PARANACIDADE
> // http://www.paranacidade.org.br/
> //
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.4.1 (GNU/Linux)
> Comment: Using GnuPG with Debian - http://enigmail.mozdev.org
> 
> iD8DBQFDT69HCj65ZxU4gPQRAud7AKCXdp+qPvaiyDX10VuqO3WpftM5MgCfQ4rN
> t1bixV+pGNo1N9MTvz9SfsA=
> =AqZF
> -END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] PRoblem with ntlm_auth

2005-10-15 Thread Tilo Lutz
Hi

I use suse 10.0. I want to use ntlm_auth
to authenticated users in squid.
Unfortunatly when I try to test the helper
I get this error:

proxy:~ # /usr/local/sbin/ntlm_auth --helper-protocol=squid-2.5-basic 
--debuglevel=3
tilo *password*
[2005/10/14 18:10:58, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
  NT_STATUS_INVALID_HANDLE: Invalid handle (0xc008)
ERR

I have googled a bit but I didn't found a hint what this error means.

Other logfiles, e.g. log.smbd on the server doesn't change anything

This is the smb.conf:
[global]
workgroup = WMS-NET
netbios name = proxy
username map = /etc/samba/smbusers
map to guest = Bad User
include = /etc/samba/dhcp.conf
security = domain
password server = home
wins server = 192.168.0.7
encrypt passwords = yes
idmap uid = 9-10
idmap gid = 9-10
winbind use default domain = yes



Any ideas what is wrong?

Cheers, Tilo
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba Server for Embedded System, Network-Storage and Print-Serve r

2005-10-15 Thread
Hi,

I am new to the mailing list, if any thing is wrong please excuse me in
advance. 

We are running Linux-2.4.20 on the MIPS32 architecture. We have USB2.0 host
and various network interfaces on the board and we want to support "USB
Network-Storage" and "USB Print-Server". Until now I am able the make
"USB-Storage" and "USB-Printer" working locally. 

Please let us know HOWTO make it network. I read that Samba can enable these
devices to be shared with other machines in the network. Is there any other
way to support this feature? In case of Samba, what is the memory footprint
required? Is there any tiny version of Samba for Embedded System? For your
information, we have 16MB RAM and 4MB FLASH.

Really appreciate any help and comment!

Regards,
Ranjeet



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba ignores write and read list

2005-10-15 Thread stingray

Hi everybody,

I have problem with samba and really don't know how to solve it.

Seems as if samba ignored write list and read list options in smb.conf. 
Because when I have

writeable = yes
read list = dummy
user dummy can still write/delete. When I try to do it opposite, i.e.
read only = yes
write list = dummy
then dummy cannot write.

The point is, I have bunch of users specified by valid users (works ok) 
and few of them will have read-only access, the rest read-write access. 
I need to do it on samba level, not by unix rights.


Version of samba: 3.0.20
System: FreeBSD 4.9-RELEASE

Config file:

==
[global]
netbios name = FreeBSD
server string = "FreeBSD Server"
workgroup = GROUP
security = share
log file = /var/log/samba.log
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
encrypt passwords = yes
wins support = yes
local master = yes
domain master = yes
preferred master = yes
os level = 50
force create mode = 0766

[ALL]
path = /data/all
public = yes
guest ok = yes
writeable = yes

[SEC1]
path = /data/SEC1
public = no
writeable = yes
valid users = mike bill

[SEC2]
path = /data/SEC2
public = no
valid users = mike john
writeable = yes
read list = john
==

SEC1 works ok, SEC2 has problems described above. Testparm passes with 
no problems.


Thank you in advance for any idea how to solve it.

Best regards

Roman
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: what's the best filesystem

2005-10-15 Thread ch4os
I like the speed of ReiserFS, excellent!... but use ext3 for /boot and
/backup
as I can boot the ext3 from my OSX
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] samba shutdown script

2005-10-15 Thread Robert Schetterer

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Software Groups schrieb:
| Hi,
|
| I see following samba shutdown script line in the smb.conf file. Do
| you know where can I get this shutdown.sh script?
|
| shutdown script = /var/lib/samba/scripts/shutdown.sh
|
| Thanks
| --
| Software Groups (SFG)
| http://www.sfgroups.com
Hi, this means sombody has written his own script, so you can do too

- --
Mit freundlichen Gruessen
Best Regards
Robert Schetterer

robert_at_schetterer.org
Munich / Bavaria / Germany
https://www.schetterer.org

\**
\* gnupgp
\* public key:
\* https://www.schetterer.org/public.key
\**
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDUVXsb0iqzJq+0MgRAhvuAJ4tpj707WyJdy6SOnnNJGfOEuUrWACeLeLy
BESqP8DyC2Ca3ebrWWD7VAQ=
=XOr5
-END PGP SIGNATURE-
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

[Samba] samba shutdown script

2005-10-15 Thread Software Groups
Hi,

I see following samba shutdown script line in the smb.conf file. Do
you know where can I get this shutdown.sh script?

shutdown script = /var/lib/samba/scripts/shutdown.sh

Thanks
--
Software Groups (SFG)
http://www.sfgroups.com
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba Speed versus Netatalk from OS X

2005-10-15 Thread AndyLiebman
Does anyone know why, when transferring data via  Gigabit Ethernet from OS X 
to Linux (or vice versa), you get about 50-60 MB/sec  with Samba 3.0.X (all 
versions I've tried, the rate depending on whether you use  Jumbo Frames) but 
you get about 105-110 MB/sec with Apple File Sharing Protocol  and Netatalk 
2.03? Is there any inherent reason why Samba goes at about half the  speed? 

By the way,  I'm talking about connecting with OS X (10.4.2  -- Tiger)'s 
native SMB/CIFS client. 

Andy Liebman  

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Low Latency and Samba

2005-10-15 Thread AndyLiebman

I'm trying to optimize some servers for "low  latency" and "low jitter". Do 
you have a reasonable ideas about specific Samba  options that might affect 
those attributes? 

In specific, I'm wondering  about the "socket options". I would think 
"TCP_NODELAY" would be helpful in  reducing latency. 

However, I would also think that increasing the size  of the SO_RCVBUF and 
SO_SNDBUF would increase latency (because you would tend to  fill up larger 
buffers before writing incoming data to the filesystem, or you  would delay 
confirmation of writes going back out to the network). 

What  does the "jury of Samba experts" say about TCP_NODELAY and SO_RCVBUF 
and  SO_SNDBUF these days? Most documents and default smb.conf files that come 
with  distributions have 

socket options = TCP_NODELAY SO_RCVBUF=8192  SO_SNDBUF=8192

Are these considered "magic numbers"? 

I just  loaded up the most recent SUSE distribution, SUSE 10, and ITS default 
smb.conf  file does not set any socket options at all. 

Andy Liebman  

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Printing Delays - What's to blame?

2005-10-15 Thread Michael Lueck

Environment...
Client OS Win2K SP4
Corel WordPerfect Suite 12 SP2
Joined to Samba PDC 3.0.14a / Debian Sarge
CUPS printing
HP LaserJet 4000 on server LPT1

Delay...
Corel Presentations
File / Print / Current View to get one page printed / OK
Select another page
File / Print / wait wait wait...
The dialog will not pop until the paper has come out of the printer for the 
previous job

Any suggestions of what direction to head in for locating the program / code 
with the waiting problem?

--
Michael Lueck
Lueck Data Systems
http://www.lueckdatasystems.com/

Remove the upper case letters NOSPAM to contact me directly.

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] smbcacls add acl fails 3.0.20

2005-10-15 Thread Henrik Zagerholm

Hi all!

I have a problem setting ACLs on a remote file on a Windows XP Pro  
SP2 box.


I issue the following command:
smbcacls -a 'ACL:BBI-DEV\beakid:ALLOWED/0/0x00100116' -U 'BBI-DEV 
\Admin' //BBI-DEV/Data /Niva.txt


And I get this response from debug level 3.

Password:
Connecting to host=BBI-DEV
Connecting to 192.168.1.124 at port 445
Doing spnego session setup (blob length=16)
server didn't supply a full spnego negprot
Got challenge flags:
Got NTLMSSP neg_flags=0x628a0215
NTLMSSP: Set final flags:
Got NTLMSSP neg_flags=0x60080215
NTLMSSP Sign/Seal - Initialising with flags:
Got NTLMSSP neg_flags=0x60080215
Connecting to host=BBI-DEV
Connecting to 192.168.1.124 at port 445
Doing spnego session setup (blob length=16)
server didn't supply a full spnego negprot
Got challenge flags:
Got NTLMSSP neg_flags=0x628a0215
NTLMSSP: Set final flags:
Got NTLMSSP neg_flags=0x60080215
NTLMSSP Sign/Seal - Initialising with flags:
Got NTLMSSP neg_flags=0x60080215
lsa_io_sec_qos: length c does not match size 8
NT_TRANSACT_SET_SECURITY_DESC failed
ERROR: secdesc set failed: NT_STATUS_ACCESS_DENIED

Any help will be appreciated!


PS I can easily retrieve ACLs so it works one way :D

//Henrik

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] sambaLogonHours and timezones

2005-10-15 Thread David Wilson

Hi guys/girls,

How are you keeping ?

A while ago I mentioned a problem that I'm picking up with Samba with 
OpenLDAP and the "logon hours" restrictions which are implemented via the NT 
4.0 User Manager.


Basically my problem was that users were unable to login 2 hours before the 
actual restriction should kick in.
At the time I thought that perhaps the problem was caused by Slackware Linux 
and it's timezone implementation of SAST (GMT+2).

Since then I've experienced the same problem on SLES9 and Suse Linux 9.3.

From what I can see, the "sambaLogonHours" value is always set with GMT in 

mind.
Because in South Africa we are at GMT+2 Samba enforces restrictions 2 hours 
before it should.
For example if users should only denied login access at 16:00, Samba is 
denying them access at 14:00.


I've looked all over and cannot find a solution to the problem other than 
adding two hours to the logon hours restrictions for each user when using 
the NT User Manager tool.


Does anyone know of a workaround for this ? Is there a way to get Samba to 
check the time zone on the server first and make calculations before writing 
values for the "sambaLogonHours" attribute ?


Links/references:
Explanation of feature: http://www.archive-two.com/new-2794385-2895.html
http://lists.samba.org/archive/samba-technical/2004-December/038271.html
http://archives.free.net.ph/message/20051006.181854.4d7c50dc.en.html
http://archives.free.net.ph/message/20050701.071531.eeffd7e5.en.html
http://lists.samba.org/archive/samba/2005-February/099778.html

Thanks in advance.

Kind regards

David Wilson
CNS, CLS, Linux+
033 3427003
082 4147413
0860-1-LINUX

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Gerhard Schaller/HOL_DV/Kuester/DE ist außer Hau s. ['Watchdog': checked]

2005-10-15 Thread gerhard . schaller
Ich bin außer Haus ab 15.10.2005 und für Sie wieder erreichbar ab
23.10.2005.

I'm not in the office on 15.10.2005 and will be available to you on
23.10.2005.


Ich werde Ihre Nachricht nach meiner Rückkehr beantworten.
Diese E-mail ist nur für den bezeichneten Adressaten bestimmt und kann
vertrauliche und/oder rechtlich geschützte Informationen enthalten. Sollten
Sie diese E-mail irrtümlich erhalten haben, informieren Sie bitte sofort
den Absender und vernichten Sie diese E-mail. Wenn Sie nicht der
vorgesehene Adressat dieser E-mail sein sollten, so beachten Sie bitte,
dass jede Überarbeitung, Weiterleitung, Verbreitung oder jeder weitere
Gebrauch dieser E-mail ausdrücklich untersagt ist.

This e-mail is intended solely for the addressee and may contain
confidential and/or privileged information. If you are not the intended
recipient, please notify the sender immediately and destroy this e-mail. In
this case any form of reproduction, disclosure, distribution or any action
taken or refrained from in reliance on it, is strictly prohibited.




.


--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Samba vs ADS problems

2005-10-15 Thread Daniel Jensen

Thank you for your help again :)

I have managed to fix the problem and still using 3.0.13 version of samba...
It apperas that my nsswitch.conf wasnt setup correctly... was missing 
some winbind entrys

Now the group lookups is working nicely

Im sorry for taking your time :) Now im sure I have explored most of 
what can be explored of samba and its components by a normal user :D So 
some good came of this :)


I look forward to see the next releases of samba... Keep up the nice 
work on this project, a nice alternative to rather expensive MS products 
that my boss wanted me to explore, and I must say with ACL included it 
is very nice :)


Gerald (Jerry) Carter wrote:


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Daniel Hindbo Jensen wrote:

| After installing SuSE 10.0 on another desktop PC which
| is running samba 3.0.20 (not 3.0.20a) it made the same error
| as the older samba version running on the live server
|
| However some small changes have occured in the
| wbinfo feedback... I can now lookup:
|
| # wbinfo --user-sids=S-1-5-21-220523388-1957994488-854245398-2749
...
| # wbinfo --user-domgroups=S-1-5-21-220523388-1957994488-854245398-2749
...
|
| However the groupname lookup for the user still returns the same
|
| IT02:/var/log/samba # wbinfo -r tarp+dhj
| 17000

...
| So is this all down to the version of samba I use?

winbindd itself was rewritten drastically in Samba 3.0.20
in order to providing more scalability.  There are rpc
infrastructure changes coming in 3.0.21 (pre1 is due out
on Monday) for better interoperabilty with newer MS
updates

| I have attached all the log files in the directory
| /var/log/samba + the samba smb.conf

Unfortunately, you didn't run winbindd at level 10.  That
is the critical one.  Run winbindd -d 10 manually.  And
then grab /var/log/samba/log.{winbindd,wb-*}





cheers, jerry
=
Alleviating the pain of Windows(tm)  --- http://www.samba.org
GnuPG Key- http://www.plainjoe.org/gpg_public.asc
"There's an anonymous coward in all of us."   --anonymous
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDT7osIR7qMdg1EfYRAq3nAJoCalg19lxR8WLvPPktocgXV1BrCQCff0jd
d+1yMomkIeD8Y8++xM4sawM=
=qqrM
-END PGP SIGNATURE-



--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Re: Dangling MS Access DB Lock Files *.ldb

2005-10-15 Thread Stéphane Purnelle
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Dragan Krnic a écrit :

> I might have unwittingly made the impression that the
> problem only came with 3.0.20. The same problem was present
> in 3.0.14 as well as 3.0.4. It's a very intermittent
> problem which has been haunting me for months now.

 Then it's not this particular bug.
>>>
>>> No, it ain't. There's a dangling *.ldb file there write now.
>>> But now there are 2 PIDs listed as holding the *.MDB file open
>>> with "DENY_DOS" and "RDWR" sharing both with the same timestamp
>>> "Fri Oct 14 19:58:09 2005", whereas formerly it used to be only
>>> one open of *.mdb and one of *.ldb file. The *.ldb file was
>>> opened "RDONLY" about 10 minutes earlier by one of the 2
>>> contestants. Can I do some more forensic on the logs?
>>
>> Ok, if you can reproduce this bug with 3.0.20b then refresh me
>> with the problem and then let's look at it closer.
>
>
> Yes. Of course. I've just compiled and installed 3.0.20b and set a
> watchdog to observe it.
>
> I was thinking of adding a repair action to the watchdog script
> that would identify the smbd PID keeping the *.ldb MS Access DB
> lock file open for so long and kill it, but the command "net rpc
> file" never lists what I can easily see on the status page of SWAT
> if I continuously refresh it until by chance one of the clients
> opens it. The "net rpc file
>
> only lists "0 \PIPE\samr 0x35 0 dummy user
>
> all the time. Is there another CLI utility which lists the same
> thing as SWAT does?
>
> Regards Dragan
>
> PS.: I've severely edited the verbosity of a samba log for the
> previous incident, so that the MS Access rain-dance can easily be
> followed to the point where the offending client for some reason
> reopens the lock file after once successfully opening it with
> numopen=1, meaning that nobody else claims it until he reopens it,
> when numopen increments to =2 for obvious readons, and then never
> remembers to close it the same number of times. It might be one of
> those MS tricks to scare the users off Samba?
>
> Would you like to take a look at it, if I send it to you
> off-samba-list?
>
smbstatus list all connection and open file

- --
Stéphane Purnelle <[EMAIL PROTECTED]>
Site Web : http://www.linuxplusvalue.be
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDUN428tswkE3d0ecRAsQYAJ0TaShcH/nSt6QYS70ePxFRvmRlNwCeJ8hV
nROnK0ZPy5fQ/q7H+Dsnvw8=
=J8Gu
-END PGP SIGNATURE-

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Problem with ntlm_auth

2005-10-15 Thread Tilo Lutz
Hi

> Tilo Lutz schrieb:
> | I use suse 10.0 and have problems to set up ntlm_auth for squid.
> | It uses samba 3.0.20 and squid 2.5.stable10

Am Samstag 15 Oktober 2005 09:46 schrieb Robert Schetterer:
> perhaps you should change to 3.0.20b latest version of samba
> cause of winbind errors suse 10 rpms are for download at ftp.suse.com or
> samba mirrors

I have installed the latest rpm and now it seems to work.
Any idea why those patches not reported by "you"?

Cheers, Tilo
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Dangling MS Access DB Lock Files *.ldb

2005-10-15 Thread Dragan Krnic
 I might have unwittingly made the impression that the problem only came 
 with 3.0.20. 
 The same problem was present in 3.0.14 as well as 3.0.4. It's a very 
 intermittent 
 problem which has been haunting me for months now.
>>> Then it's not this particular bug.
>>
>> No, it ain't. There's a dangling *.ldb file there write now. But now there 
>> are 2 PIDs
>> listed as holding the *.MDB file open with "DENY_DOS" and "RDWR" sharing 
>> both with the
>> same timestamp "Fri Oct 14 19:58:09 2005", whereas formerly it used to be 
>> only one open
>> of *.mdb and one of *.ldb file. The *.ldb file was opened "RDONLY" about 10 
>> minutes
>> earlier by one of the 2 contestants. Can I do some more forensic on the logs?
> 
> Ok, if you can reproduce this bug with 3.0.20b then refresh me with the 
> problem
> and then let's look at it closer.

Yes. Of course. I've just compiled and installed 3.0.20b and set a watchdog to
observe it.

I was thinking of adding a repair action to the watchdog script that would 
identify
the smbd PID keeping the *.ldb MS Access DB lock file open for so long and kill 
it,
but the command "net rpc file" never lists what I can easily see on the status 
page
of SWAT if I continuously refresh it until by chance one of the clients opens 
it.
The "net rpc file

   only lists "0   \PIPE\samr   0x35   0  dummy user

all the time. Is there another CLI utility which lists the same thing as SWAT 
does?

Regards
Dragan

PS.: I've severely edited the verbosity of a samba log for the previous 
incident,
so that the MS Access rain-dance can easily be followed to the point where the
offending client for some reason reopens the lock file after once successfully
opening it with numopen=1, meaning that nobody else claims it until he reopens
it, when numopen increments to =2 for obvious readons, and then never remembers 
to close it the same number of times. It might be one of those MS tricks to 
scare 
the users off Samba? 

Would you like to take a look at it, if I send it to you off-samba-list?

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] SAN

2005-10-15 Thread test ya
What advise would people have on using setting up a
storage area network to store user files on. This SAN
would be used by some linux clients directly but
primarily by a samba pdc. I was going to use nbd or
enbd. I know that these are for direct control of the
harddrive partition so the clients are out if i do
that. However nfs seems to be the best for what i
need. My Problem is also figuring how I would export
the directories to the samba servers and the few linux
clients. Should i do it per user or the whole /home
directory? Not this is a large SAN separated into
groups and user folders on multiple servers. Please
Help!

Chris 
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Gerhard Schaller/HOL_DV/Kuester/DE ist außer Hau s. ['Watchdog': checked]

2005-10-15 Thread gerhard . schaller
Ich bin außer Haus ab 15.10.2005 und für Sie wieder erreichbar ab
23.10.2005.

I'm not in the office on 15.10.2005 and will be available to you on
23.10.2005.


Ich werde Ihre Nachricht nach meiner Rückkehr beantworten.
Diese E-mail ist nur für den bezeichneten Adressaten bestimmt und kann
vertrauliche und/oder rechtlich geschützte Informationen enthalten. Sollten
Sie diese E-mail irrtümlich erhalten haben, informieren Sie bitte sofort
den Absender und vernichten Sie diese E-mail. Wenn Sie nicht der
vorgesehene Adressat dieser E-mail sein sollten, so beachten Sie bitte,
dass jede Überarbeitung, Weiterleitung, Verbreitung oder jeder weitere
Gebrauch dieser E-mail ausdrücklich untersagt ist.

This e-mail is intended solely for the addressee and may contain
confidential and/or privileged information. If you are not the intended
recipient, please notify the sender immediately and destroy this e-mail. In
this case any form of reproduction, disclosure, distribution or any action
taken or refrained from in reliance on it, is strictly prohibited.




.


--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Problem with ntlm_auth

2005-10-15 Thread Robert Schetterer

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Tilo Lutz schrieb:
| Hi
|
| I use suse 10.0 and have problems to set up ntlm_auth for squid.
| It uses samba 3.0.20 and squid 2.5.stable10
|
| I have set up winbind and everyhting seems to work.
| I've changes groupownerchip of /var/lib/samba/winbindd_privileged
| to squid. squid runs as group squid.
|
| Everyhting is working fine for several minutes.
| After a while it doesn't work anymore
|
| proxy:/var/log/samba # /usr/local/sbin/ntlm_auth
| --helper-protocol=squid-2.5-basic --debuglevel=3
| tilo *secret*
| [2005/10/15 09:25:11, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
|   NT_STATUS_INVALID_HANDLE: Invalid handle (0xc008)
| ERR
|
| After restarting winbindd it works again:
|
| proxy:/var/log/samba # /usr/local/sbin/ntlm_auth
| --helper-protocol=squid-2.5-basic --debuglevel=3
| tilo *secret*
| [2005/10/15 09:26:49, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
|   NT_STATUS_OK: Success (0x0)
| OK
|
| log.winbindd (log level=3) doesn't show anything interessting:
| [2005/10/15 09:31:12, 3]
| nsswitch/winbindd_misc.c:winbindd_interface_version(460)
|   [0]: request interface version
| [2005/10/15 09:31:12, 3]
nsswitch/winbindd_misc.c:winbindd_priv_pipe_dir(493)
|   [0]: request location of privileged pipe
| [2005/10/15 09:31:12, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth(202)
|   [0]: pam auth tilo
|
| Any idea how to keep it running?
|
| Cheers, Tilo
Hi
perhaps you should change to 3.0.20b latest version of samba
cause of winbind errors suse 10 rpms are for download at ftp.suse.com or
samba mirrors
Regards

- --
Mit freundlichen Gruessen
Best Regards
Robert Schetterer

robert_at_schetterer.org
Munich / Bavaria / Germany
https://www.schetterer.org

\**
\* gnupgp
\* public key:
\* https://www.schetterer.org/public.key
\**
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDULPlb0iqzJq+0MgRAmDTAJ9MEAmCQIzBdlXwAbbO5Xw8cBm0hACfQRsN
HvzRRdOptLKHQmsDB3zzHRs=
=oFdx
-END PGP SIGNATURE-
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

[Samba] Problem with ntlm_auth

2005-10-15 Thread Tilo Lutz
Hi

I use suse 10.0 and have problems to set up ntlm_auth for squid.
It uses samba 3.0.20 and squid 2.5.stable10

I have set up winbind and everyhting seems to work.
I've changes groupownerchip of /var/lib/samba/winbindd_privileged
to squid. squid runs as group squid.

Everyhting is working fine for several minutes.
After a while it doesn't work anymore

proxy:/var/log/samba # /usr/local/sbin/ntlm_auth 
--helper-protocol=squid-2.5-basic --debuglevel=3
tilo *secret*
[2005/10/15 09:25:11, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
  NT_STATUS_INVALID_HANDLE: Invalid handle (0xc008)
ERR

After restarting winbindd it works again:

proxy:/var/log/samba # /usr/local/sbin/ntlm_auth 
--helper-protocol=squid-2.5-basic --debuglevel=3
tilo *secret*
[2005/10/15 09:26:49, 3] utils/ntlm_auth.c:check_plaintext_auth(292)
  NT_STATUS_OK: Success (0x0)
OK

log.winbindd (log level=3) doesn't show anything interessting:
[2005/10/15 09:31:12, 3] 
nsswitch/winbindd_misc.c:winbindd_interface_version(460)
  [0]: request interface version
[2005/10/15 09:31:12, 3] nsswitch/winbindd_misc.c:winbindd_priv_pipe_dir(493)
  [0]: request location of privileged pipe
[2005/10/15 09:31:12, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth(202)
  [0]: pam auth tilo

Any idea how to keep it running?

Cheers, Tilo
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba