Re: [Samba] Need support

2013-08-10 Thread Scott Lovenberg

On Aug 5, 2013, at 0:09, ketut.nur...@dexagroup.com wrote:

 dear Samba team,
 
 Today we have used samba ver. 3 as primary domain controller at my 
 company. To improve the Samba technology and feature to support our 
 business , we want to upgrade to Samba 4. 
 
 Is there any tools or support to provide upgrade solution from Samba 3 to 
 samba 4 ?
 
 For the information current Samba version we are used and running on 
 Mandriva :
 samba-common-3.0.23b-7mdv2007.0
 samba-server-3.0.23b-7mdv2007.0
 samba-smbldap-tools-3.0.23b-7mdv2007.0
 samba-client-3.0.23b-7mdv2007.0
 samba-doc-3.0.23b-7mdv2007.0
 
 Any suggestion or support please contact me.
 

Although no longer technically supported, the upgrade provision script has done 
well for many people. Have you considered trying it in a virtual environment?
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Need support

2013-08-10 Thread Andrew Bartlett
On Sat, 2013-08-10 at 03:19 -0400, Scott Lovenberg wrote:
 On Aug 5, 2013, at 0:09, ketut.nur...@dexagroup.com wrote:
 
  dear Samba team,
  
  Today we have used samba ver. 3 as primary domain controller at my 
  company. To improve the Samba technology and feature to support our 
  business , we want to upgrade to Samba 4. 
  
  Is there any tools or support to provide upgrade solution from Samba 3 to 
  samba 4 ?
  
  For the information current Samba version we are used and running on 
  Mandriva :
  samba-common-3.0.23b-7mdv2007.0
  samba-server-3.0.23b-7mdv2007.0
  samba-smbldap-tools-3.0.23b-7mdv2007.0
  samba-client-3.0.23b-7mdv2007.0
  samba-doc-3.0.23b-7mdv2007.0
  
  Any suggestion or support please contact me.
  
 
 Although no longer technically supported, the upgrade provision script has 
 done well for many people. Have you considered trying it in a virtual 
 environment?

The upgradeprovision script is not for upgrades from Samba 3.x or
classic domains, it is about old (very old) databases from the 4.0 alpha
series.  Use of the samba-tool domain classicupgrade command remains and
will remain fully supported.

Andrew Bartlett

-- 
Andrew Bartletthttp://samba.org/~abartlet/
Authentication Developer, Samba Team   http://samba.org


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Upgrading Samba 3 DC to a Samba 4.0 AD DC

2013-08-10 Thread Andrew Bartlett
On Mon, 2013-08-05 at 11:09 +0700, ketut.nur...@dexagroup.com wrote:
 dear Samba team,
  
 Today we have used samba ver. 3 as primary domain controller at my 
 company. To improve the Samba technology and feature to support our 
 business , we want to upgrade to Samba 4. 
  
 Is there any tools or support to provide upgrade solution from Samba 3 to 
 samba 4 ?

See
https://wiki.samba.org/index.php/Samba4/samba-tool/domain/classicupgrade/HOWTO

Thanks,

Andrew Bartlett
-- 
Andrew Bartletthttp://samba.org/~abartlet/
Authentication Developer, Samba Team   http://samba.org


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Need support

2013-08-10 Thread Scott Lovenberg

On Aug 10, 2013, at 4:22, Andrew Bartlett abart...@samba.org wrote:

 On Sat, 2013-08-10 at 03:19 -0400, Scott Lovenberg wrote:
 On Aug 5, 2013, at 0:09, ketut.nur...@dexagroup.com wrote:
 
 dear Samba team,
 
 Today we have used samba ver. 3 as primary domain controller at my 
 company. To improve the Samba technology and feature to support our 
 business , we want to upgrade to Samba 4. 
 
 Is there any tools or support to provide upgrade solution from Samba 3 to 
 samba 4 ?
 
 For the information current Samba version we are used and running on 
 Mandriva :
 samba-common-3.0.23b-7mdv2007.0
 samba-server-3.0.23b-7mdv2007.0
 samba-smbldap-tools-3.0.23b-7mdv2007.0
 samba-client-3.0.23b-7mdv2007.0
 samba-doc-3.0.23b-7mdv2007.0
 
 Any suggestion or support please contact me.
 
 Although no longer technically supported, the upgrade provision script has 
 done well for many people. Have you considered trying it in a virtual 
 environment?
 
 The upgradeprovision script is not for upgrades from Samba 3.x or
 classic domains, it is about old (very old) databases from the 4.0 alpha
 series.  Use of the samba-tool domain classicupgrade command remains and
 will remain fully supported.

Sorry, Andrew,  you are correct. I meant classicupgrade instead of 
upgradeprovision (to be fair,  it's 4:30 AM on this side of the pond :))  

Although I thought that classic upgrade still had some issues to be worked out, 
IIRC from the mailing list/IRC discussions. Am I mistaken?
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Need support

2013-08-10 Thread Andrew Bartlett
On Sat, 2013-08-10 at 04:37 -0400, Scott Lovenberg wrote:
 On Aug 10, 2013, at 4:22, Andrew Bartlett abart...@samba.org wrote:
 
  On Sat, 2013-08-10 at 03:19 -0400, Scott Lovenberg wrote:
  On Aug 5, 2013, at 0:09, ketut.nur...@dexagroup.com wrote:
  
  dear Samba team,
  
  Today we have used samba ver. 3 as primary domain controller at my 
  company. To improve the Samba technology and feature to support our 
  business , we want to upgrade to Samba 4. 
  
  Is there any tools or support to provide upgrade solution from Samba 3 to 
  samba 4 ?
  
  For the information current Samba version we are used and running on 
  Mandriva :
  samba-common-3.0.23b-7mdv2007.0
  samba-server-3.0.23b-7mdv2007.0
  samba-smbldap-tools-3.0.23b-7mdv2007.0
  samba-client-3.0.23b-7mdv2007.0
  samba-doc-3.0.23b-7mdv2007.0
  
  Any suggestion or support please contact me.
  
  Although no longer technically supported, the upgrade provision script has 
  done well for many people. Have you considered trying it in a virtual 
  environment?
  
  The upgradeprovision script is not for upgrades from Samba 3.x or
  classic domains, it is about old (very old) databases from the 4.0 alpha
  series.  Use of the samba-tool domain classicupgrade command remains and
  will remain fully supported.
 
 Sorry, Andrew,  you are correct. I meant classicupgrade instead of 
 upgradeprovision (to be fair,  it's 4:30 AM on this side of the pond :))  
 
 Although I thought that classic upgrade still had some issues to be worked 
 out, IIRC from the mailing list/IRC discussions. Am I mistaken?

Due to the range of possible source configurations the classicupgrade
code may fail.  Most of these failures are due to what I consider
invalid configuration of the old classic domain, but which were not
detected previously, as we had not validation tool in the past.  

That said, we can and should work around these and the other remaining
issues, and patches are very much welcome.

Andrew Bartlett

-- 
Andrew Bartletthttp://samba.org/~abartlet/
Authentication Developer, Samba Team   http://samba.org


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Samba4 Using AD/UNIX attributes for home directory and shell not possible?

2013-08-10 Thread Markus Gillmeister
Hi,

I'm would like to use the attributes in AD for home directory
(homeDirectory) and the login shell  (loginShell) for users logging in via
ssh to a linux box.

I added the following parameters in the global-Section of
/etc/samba/smb.conf:
   winbind nss info = rfc2307
   idmap_ldb:use rfc2307 = yes

Also I set the attributes for a test-user (called tim) with some values.

But when calling getent passwd I got the following result:
...
SHADOW\tim:*:317:100:Tim Testinger:/home/SHADOW/tim:/bin/false

So it seems that winbind is ignoring AD attributes. Is this a bug or did I
misconfigure my samba installation?

Best Regards
Markus

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Samba4 Using AD/UNIX attributes for home directory and shell not possible?

2013-08-10 Thread Gémes Géza

Hi,

Hi,

I'm would like to use the attributes in AD for home directory
(homeDirectory) and the login shell  (loginShell) for users logging in via
ssh to a linux box.

Samba 4.x has (from the point of view of domain membership) two modes:

1. Active directory domain controller
2. Standalone, domain member or classic (NT4-like) domain controller

In the first case only the samba binary should run, which takes care of 
the winbind task (mapping user attributes) too. Unfortunately it can't 
retrieve homedir and shell attributes from the directory.


In the second case a separate winbind instance is/should be running 
which is able to use those mapping from the directory, so if you are not 
running an AD DC on the box in question, please send your whole config 
to be able to help debugging it.

I added the following parameters in the global-Section of
/etc/samba/smb.conf:
winbind nss info = rfc2307
idmap_ldb:use rfc2307 = yes

Also I set the attributes for a test-user (called tim) with some values.

But when calling getent passwd I got the following result:
...
SHADOW\tim:*:317:100:Tim Testinger:/home/SHADOW/tim:/bin/false

So it seems that winbind is ignoring AD attributes. Is this a bug or did I
misconfigure my samba installation?

Best Regards
Markus


Regards

Geza Gemes
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] [CIFS] mount error(13): Permission denied

2013-08-10 Thread Felix Miata

On 2013-08-09 00:20 (GMT-0400) Felix Miata composed:


This is from



mount mountpoint



on openSUSE 13.1m3 running 3.10.1 desktop kernel. The mountpoint and fstab
entries are identical and working in openSUSE 12.3 on same system. I just
spent several hours on IRC and elsewhere trying to figure this out before
thinking to try booting something other than 13.1. :-(



Fstab entry (redacted):
//HOST/share /mountpoint cifs
guest,nounix,uid=,gid=,dir_mode=0777,file_mode=0664,noauto 0 0



The host is a Linux satellite receiver, running kernel 3.3.1 and sambaserver
3.0.37-r8. It's configuration options are crippled. Security = user seems not
to be an option, but since the device runs on FOSS and there is no manual,
whether that is in fact the case is unclear. I simply haven't been able to
make it work except with security = share.



A developer on IRC told me how to get extra debug info:
http://fm.no-ip.com/Tmp/Linux/messages-suse131CIFSfailure7proc-fs-cifs-cifsFYI.txt



He said it smells like regression/fallout from removal of security = share
and will look at it more after sleeping. Anyone else want to comment? Is this
the right place to discuss?


Found a solution in option sec=none.
--
The wise are known for their understanding, and pleasant
words are persuasive. Proverbs 16:21 (New Living Translation)

 Team OS/2 ** Reg. Linux User #211409 ** a11y rocks!

Felix Miata  ***  http://fm.no-ip.com/
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


autobuild: intermittent test failure detected

2013-08-10 Thread autobuild
The autobuild test system has detected an intermittent failing test in 
the current master tree.

The autobuild log of the failure is available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1020/flakey.log

The samba3 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1020/samba3.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-1020/samba3.stdout

The source4 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1020/samba.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-1020/samba.stdout
  
The top commit at the time of the failure was:

commit d944841211a407c3587ccabd3615df55fba72aaf
Author: David Disseldorp dd...@samba.org
Date:   Wed Aug 7 17:16:12 2013 +0200

torture: add smb2 FSCTL_[GET/SET]_COMPRESSION test

This test simply creates a file and checks the compression state before
and after FSCTL_SET_COMPRESSION(COMPRESSION_FORMAT_DEFAULT).

The test expects the compression state to be COMPRESSION_FORMAT_LZNT1
after set, conforming to Windows Server behaviour.

If the server responds to the first FSCTL_GET_COMPRESSION request with
NT_STATUS_NOT_SUPPORTED or NT_STATUS_INVALID_DEVICE_REQUEST, then the
test is skipped. This allows it to run during selftest.

Signed-off-by: David Disseldorp dd...@samba.org
Reviewed-by: Jeremy Allison j...@samba.org

Autobuild-User(master): Jeremy Allison j...@samba.org
Autobuild-Date(master): Fri Aug  9 22:03:39 CEST 2013 on sn-devel-104


[SCM] Samba Shared Repository - branch master updated

2013-08-10 Thread Stefan Metzmacher
The branch, master has been updated
   via  9177a0d libcli/auth: add more const to 
spnego_negTokenInit-mechTypes
   via  f1e6014 libcli/auth: avoid possible mem leak in read_negTokenInit()
   via  966faef auth/gensec: treat struct gensec_security_ops as const if 
possible.
   via  c81b6f7 auth/gensec: use 'const char * const *' for function 
parameters
   via  e81550c auth/gensec: make it possible to implement async backends
   via  6a7a44d auth/gensec: avoid talloc_reference in 
gensec_security_mechs()
   via  3e3534f auth/gensec: avoid talloc_reference in 
gensec_use_kerberos_mechs()
   via  71c63e8 auth/gensec: introduce gensec_internal.h
   via  57bcbb9 libcli/auth/schannel: remove unused schannel_position
   via  4c978b6 libcli/auth/schannel: make struct schannel_state private
   via  e90e1b5 s4:gensec/schannel: only require librpc/gen_ndr/dcerpc.h
   via  9b9ab1a s4:gensec/schannel: there's no point in having 
schannel_session_key()
   via  a07049a s4:gensec/schannel: GENSEC_FEATURE_ASYNC_REPLIES is not 
supported
   via  b510476 s4:gensec/schannel: use the correct computer_name from 
netlogon_creds_CredentialState
   via  49f347e s4:gensec/schannel: simplify the code by using 
netsec_create_state()
   via  4cad5dc s4:gensec/schannel: remove unused dcerpc_schannel_creds()
   via  2ea3a24 s4:torture: avoid usage of dcerpc_schannel_creds()
   via  c014427 s4:libnet: avoid usage of dcerpc_schannel_creds()
   via  a36ccdc s3:dcerpc_helpers: remove unused DEBUG message of 
schannel_state-seq_num.
   via  a964309 s3:rpc_server: make use of netsec_create_state()
   via  af4dc30 s3:cli_pipe.c: return NO_USER_SESSION_KEY in 
cli_get_session_key() for schannel
   via  838cb53 s3:cli_pipe: pass down creds-computer_name to 
NL_AUTH_MESSAGE
   via  e96142f s3:cli_pipe: make use of netsec_create_state()
   via  3321539 libcli/auth: add netsec_create_state()
   via  9f2e81a libcli/auth: maintain the sequence number for the NETLOGON 
SSP as 64bit
   via  59b0956 auth/gensec: add gensec_security_by_auth_type()
   via  45c74c8 auth/gensec: first check GENSEC_FEATURE_SESSION_KEY before 
returning NOT_IMPLEMENTED
   via  04938cb s3:rpc_client: remove unused 
cli_rpc_pipe_open_ntlmssp_auth_schannel()
   via  3302356 s3:rpc_client: remove netr_LogonGetCapabilities check from 
rpc_pipe_bind*
   via  eecb5ba s3:rpc_client: add netr_LogonGetCapabilities to 
cli_rpc_pipe_open_schannel_with_key()
   via  e9c8e3f s3:rpc_client: use netlogon_creds_copy before rpc_pipe_bind
   via  90e28c1 s3:rpc_client: fix/add AES downgrade detection to 
rpc_pipe_bind_step_two_done()
   via  e77a64f s3:rpcclient: try to use NETLOGON_NEG_SUPPORTS_AES
   via  0460063 s3:rpc_client: try to use NETLOGON_NEG_SUPPORTS_AES
   via  beba326 s3:libnet_join: try to use NETLOGON_NEG_SUPPORTS_AES
   via  d82ab705 s3:auth_domain: try to use NETLOGON_NEG_SUPPORTS_AES
   via  11e0be0 s3:libsmb: remove unused cli_state-is_guestlogin
  from  d944841 torture: add smb2 FSCTL_[GET/SET]_COMPRESSION test

http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master


- Log -
commit 9177a0d1c1c92c45ef92fbda55fc6dd8aeb76b6c
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 10:46:47 2013 +0200

libcli/auth: add more const to spnego_negTokenInit-mechTypes

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

Autobuild-User(master): Stefan Metzmacher me...@samba.org
Autobuild-Date(master): Sat Aug 10 11:11:54 CEST 2013 on sn-devel-104

commit f1e60142e12deb560e3c62441fd9ff2acd086b60
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 10:43:38 2013 +0200

libcli/auth: avoid possible mem leak in read_negTokenInit()

Also add error checks.

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

commit 966faef9c61d2ec02d75fc3ccc82a61524fb77e4
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 11:20:21 2013 +0200

auth/gensec: treat struct gensec_security_ops as const if possible.

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

commit c81b6f7448d7f945635784de645bea4f7f2e230f
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 11:10:55 2013 +0200

auth/gensec: use 'const char * const *' for function parameters

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

commit e81550c8117166d0fbf69ba1d3957cb950c42961
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 16:12:13 2013 +0200

auth/gensec: make it possible to implement async backends

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett 

autobuild: intermittent test failure detected

2013-08-10 Thread autobuild
The autobuild test system has detected an intermittent failing test in 
the current master tree.

The autobuild log of the failure is available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1338/flakey.log

The samba3 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1338/samba3.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-1338/samba3.stdout

The source4 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-1338/samba.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-1338/samba.stdout
  
The top commit at the time of the failure was:

commit 9177a0d1c1c92c45ef92fbda55fc6dd8aeb76b6c
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 10:46:47 2013 +0200

libcli/auth: add more const to spnego_negTokenInit-mechTypes

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

Autobuild-User(master): Stefan Metzmacher me...@samba.org
Autobuild-Date(master): Sat Aug 10 11:11:54 CEST 2013 on sn-devel-104


autobuild: intermittent test failure detected

2013-08-10 Thread autobuild
The autobuild test system has detected an intermittent failing test in 
the current master tree.

The autobuild log of the failure is available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-2244/flakey.log

The samba3 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-2244/samba3.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-2244/samba3.stdout

The source4 build logs are available here:

   http://git.samba.org/autobuild.flakey/2013-08-10-2244/samba.stderr
   http://git.samba.org/autobuild.flakey/2013-08-10-2244/samba.stdout
  
The top commit at the time of the failure was:

commit 9177a0d1c1c92c45ef92fbda55fc6dd8aeb76b6c
Author: Stefan Metzmacher me...@samba.org
Date:   Mon Aug 5 10:46:47 2013 +0200

libcli/auth: add more const to spnego_negTokenInit-mechTypes

Signed-off-by: Stefan Metzmacher me...@samba.org

Reviewed-by: Andrew Bartlett abart...@samba.org

Autobuild-User(master): Stefan Metzmacher me...@samba.org
Autobuild-Date(master): Sat Aug 10 11:11:54 CEST 2013 on sn-devel-104