Re: [Samba] The boss will discharge me, I spoiled the system. HELP!

2003-11-17 Thread Fernando Fonseca
Ferreto,

Give more information about your problem, your configuration, message errors, 
logs,  etc.

There are a new version of Samba, released at November 14. I will try to solve 
some of my problems installing it.

[ ]'s
Fernando Fonseca
Network Administrator
Tel: +55(11)4039-9260
Triaton do Brasil 



On Monday 17 November 2003 10:25, Ferretero Herraduras Clavo wrote:
 I have a mixture network with WinXP machines and IRIX (UNIX of Silicon
 Graphics) machines. In the machine with IRIX (O2) there was an old version
 of samba. It worked well. But recently I've downloaded. I installed this
 new version, and I spoiled the system. Now I don't know if I have to
 reconfigure the smb.conf only or if I have to install more pakages or if I
 have to reconfigure several files... CAN ANYONE HELP ME???

 Ferretero


 -

 Antivirus • Filtros antispam • 6 MB gratis
 ¿Todavía no tienes un correo inteligente?

-- 

--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] ADS with Kerberos trust

2003-11-17 Thread Fernando Fonseca
Hi Fergus,

Look at the PDF included in the /doc directory source package of Samba caled 
HOWTO Collection, in the section 4.3.5 and 7.4 you will see how to do it.

I understand that just seting the 2 following parameters you say to AD to use 
Kerberos:
security = ADS
encrypt password = yes

To test your kerberos conection you can use kinit and klist, usualy placed in 
/usr/kerberos/bin.

[ ]'s


On Saturday 15 November 2003 01:42, Fergus wrote:
 Hi Fernando,
 We are using Samba 3 and I got it to authenticate to ADS.. But the key
 is to try and get it to authenticate to ADS using the alternative
 kerberos mapping.  When you do thi mapping in AD you can login using
 kerberos credentials.  I'm just not sure how to tell Samba to do this.

 Fergus

 -Original Message-
 From: Fernando Fonseca [mailto:[EMAIL PROTECTED]
 Sent: Friday, 14 November 2003 9:31 PM
 To: Fergus McKenzie-Kay; [EMAIL PROTECTED]
 Subject: Re: [Samba] ADS with Kerberos trust


 Fergus,

 What version of Samba are you using?

 With the version 3.0 if you set ¨encrypt password = yes¨ in smb.conf you
 will
 tell it to use Kerberos, but I think that you already do it.

 Other parameter is the ¨security = ADS¨ that enable the search in ADS.

 On Friday 14 November 2003 04:18, Fergus McKenzie-Kay wrote:
  Hi,
  We have an environment where we use LDAP and Kerberos and we are
  having trouble setting up Samba with both of these. We also have a
  win2k Active Directory server that has all the users mapped to our
  kerberos realm.  Unfortunately when we try and configure to use the
  Active Directory server for authentication it tries to use the native
  win2k password and not the kerberos realm mapping. I have tried to set
 
  the smb.conf to the kerberos realm and the password server to the KDC
  but I get: session setup failed: NT_STATUS_NO_LOGON_SERVERS
 
  Does anyone have any ideas how to make samba either use active
  directory with the username mappings to kerberos?  Or simply use
  kerberos authentication while and LDAP authorisation? I believe the
  first solution would be easier as then AD would look after all the
  details.. whereas when we tried to setup samba talking to kerberos and
 
  ldap, the ldap config needed changing and samba had to know how to
  create users in kerberos and ldap.
 
  Any ideas would be appreciated.
 
  --
  Fergus McKenzie-Kay [EMAIL PROTECTED]

-- 
Fernando Fonseca
Network Administrator
Tel: +55(11)4039-9260
Triaton do Brasil 
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] ADS with Kerberos trust

2003-11-14 Thread Fernando Fonseca
Fergus,

What version of Samba are you using?

With the version 3.0 if you set encrypt password = yes in smb.conf you will 
tell it to use Kerberos, but I think that you already do it.

Other parameter is the security = ADS that enable the search in ADS.








On Friday 14 November 2003 04:18, Fergus McKenzie-Kay wrote:
 Hi,
 We have an environment where we use LDAP and Kerberos and we are having
 trouble setting up Samba with both of these.
 We also have a win2k Active Directory server that has all the users
 mapped to our kerberos realm.  Unfortunately when we try and configure
 to use the Active Directory server for authentication it tries to use
 the native win2k password and not the kerberos realm mapping.
 I have tried to set the smb.conf to the kerberos realm and the password
 server to the KDC but I get:
 session setup failed: NT_STATUS_NO_LOGON_SERVERS

 Does anyone have any ideas how to make samba either use active directory
 with the username mappings to kerberos?  Or simply use kerberos
 authentication while and LDAP authorisation?
 I believe the first solution would be easier as then AD would look after
 all the details.. whereas when we tried to setup samba talking to
 kerberos and ldap, the ldap config needed changing and samba had to know
 how to create users in kerberos and ldap.

 Any ideas would be appreciated.

 --
 Fergus McKenzie-Kay [EMAIL PROTECTED]

-- 
Fernando Fonseca
Network Administrator
Tel: +55(11)4039-9260
Triaton do Brasil 
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Autenticating SQUID in ADS

2003-11-13 Thread Fernando Fonseca
Hi, 

I have to install a SQUID in my company and autenticate the users in a Active 
Directory, I have some questions about it:

1) The Better way to do it is diretct with a LDAP helper or using SAMBA 3.0. I 
don't need to do a trasparent autentication, the user will have to introduce 
login and password to use the brouser.

2) Trying do do it with a SAMBA I'm with a follow error message whem testing 
the wbinfo (wbinfo -u or -g) Error looking up domain users.

3) Security is needed here, what's the most secure way to autenticate the 
users? 

4) We use QMAIL too and I want to autenticate the user in AD too, it will be 
good if I found a unique solution to both problems.

Thanks a lot!



-- 
Fernando Fonseca
Network Administrator
Tel: +55(11)4039-9260
Triaton do Brasil 
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba