Re: [Samba] Mystery Samba (3.4.1) and Win7

2009-09-16 Thread Martin Hochreiter
Have you tried following the steps on http://wiki.samba.org/index.php/Windows7 ? 3.4.1 is really known to work as long as you do not start to modify your netlogon registry settings. Guenther Hi Guenther! I followed Joss instructions ... [HKEY_LOCAL_MACHINE\SYSTE

[Samba] smb.conf(5) format meaning question

2009-09-16 Thread Linda Walsh
In the smb.conf manpage, there is a notation used, (G) or (S) for global or share. Does (S) mean it can only be used in a Share section (i.e. - will be ignored in the global section), or is that they *can* be applied at the share level, and, possibly set a default in the 'G'lobal section? exam

Re: [Samba] Share authentication via AD

2009-09-16 Thread Adam Nielsen
> The problem I'm experiencing is that I'm unable to authenticate to the > share and thus browse it. What do you mean by 'authenticate to the share'? Normally you only authenticate with a server. > As far as the basics, the server is joined successfully to the domain > and I can browse to it fro

[Samba] [samba] Share authentication via AD

2009-09-16 Thread Matt Delves
Hey folks, I've got a server setup that uses samba to join to the Windows 2k3 Active Directory. I've also created a shared folder on that server. The problem I'm experiencing is that I'm unable to authenticate to the share and thus browse it. The smb.conf file is: == [global] workgroup = s

Re: [Samba] locking down ssh when using winbind

2009-09-16 Thread Philipoff, Andrew
You shouldn't need to define a domain, sshusers should be sufficient. Did you restart sshd? Andrew Philipoff Infrastructure Coordinator Information Systems Department of Medicine, UCSF From: samba-boun...@lists.samba.org [samba-boun...@lists.samba.org] On

Re: [Samba] Can winbind authenticate users from two AD groups?

2009-09-16 Thread Joel Therrien
On the windows box, it doesn't display an error, it just shows the username and password prompt again. The samba log for the windows box is attached. I am noting that the student is correctly trying to log in using the STUDENT\Username form to identify that he belongs to the student do

Re: [Samba] locking down ssh when using winbind

2009-09-16 Thread Luv Linux
Thanks Andrew, The file didn't have the line = accountrequired pam_stack.so service=system-auth so changed it to the following, group's name in AD is domain\sshusers btw so I'm not sure if I have to input it as domain\sshusers or sshusers. But doesn't seem to work... What did I do wrong

Re: [Samba] Samba server masquerading as another...

2009-09-16 Thread Adam Nielsen
> [2009/09/14 17:35:14, 1] smbd/sesssetup.c:reply_spnego_kerberos(316) > Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE! I think this means that when the client sent Samba the kerberos ticket (to prove it had authenticated) Samba was unable to verify it with the server that

Re: [Samba] smbclient -M

2009-09-16 Thread Adam Nielsen
> Thank you very much, I'm quite surprised the messenger service is not > running on the clients of that LAN, but I take it and check ASAP. The service is turned off on all our PCs, so I'm not sure if that's just our environment or the default. Since there's no authentication it could cause a lo

Re: [Samba] locking down ssh when using winbind

2009-09-16 Thread Philipoff, Andrew
You can restrict access to specific local and domain groups: #accountrequired pam_stack.so service=system-auth accountsufficient pam_succeed_if.so user ingroup users accountsufficient pam_succeed_if.so user ingroup webdevelopers Check here for more info: http://linux.die.net/m

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Miguel Medalha
All files/dirs are 666 or 777. According to my reading, since there are no POSIX extended ACLs, if the VFS layer "passes" an access, then it only should be compared against the standard UGO permissions. That's correct - but the problem isn't access, it's when the incoming ACL is "set" o

[Samba] locking down ssh when using winbind

2009-09-16 Thread Luv Linux
Hi all, I'm using samba with winbind which has been integrated with Active Directory. In the smb.conf file, I have template shell = /bin/bash winbind use default domain = yes to allow ssh but I don't want all the domain users to be able to ssh. Is there a way to only allow for example) domain\ss

Re: [Samba] Help needed: valid users

2009-09-16 Thread Gary Dale
Chris Osicki wrote: Hi I'm using Samba 3.0.33 on Solaris10 and have the following problem. In the smb.conf I have workgroup = CORPROOT security = domain and users authenticated to CORPROOT domain can connect shares w/o problems, [homes] for example. Now I would like to create a shar

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Jeremy Allison
On Wed, Sep 16, 2009 at 07:20:11PM +0100, Miguel Medalha wrote: > > All files/dirs are 666 or 777. According to my reading, since there are > no POSIX extended ACLs, if the VFS layer "passes" an access, then it only > should be compared against the standard UGO permissions. That's correct - but

Re: [Samba] Can I use net ads join without DNS

2009-09-16 Thread Volker Lendecke
On Wed, Sep 16, 2009 at 06:01:04PM +0100, andy.m...@bt.com wrote: > Cheers Volker > > I used your option and I've also found the password server option in the > smb.conf. Im running both and seem to have got a bit further. > > But now I'm getting a different error. I'm not sure if the problem is

[Samba] How to create a new share

2009-09-16 Thread Ingraham, Kim, DOH
This is a simple problem, I'm sure, but it's stumped me so far. I am using Samba version 2.2.3a on an IBM AIX server and I need to create a new share and cannot find how to do that from the documentation I have. The shares I have were set up by a person that is no longer employed with us an

Re: [Samba] 2.6.31-rc8: CIFS with 5 seconds hiccups

2009-09-16 Thread Christoph Lameter
On Tue, 15 Sep 2009, Jeff Layton wrote: > Yow, that version of mount.cifs is really old. I wonder if it may be > passing bad mount options to the kernel? Might be interesting to strace > that. Something like: > > # strace -f -s 256 -e mount mount -t cifs //chiprodfs2/company /mnt > -ouser=clamete

[Samba] (64 bit dump) Re: 2.6.31-rc8: CIFS with 5 seconds hiccups

2009-09-16 Thread Christoph Lameter
64 bit one-- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] 2.6.31-rc8: CIFS with 5 seconds hiccups

2009-09-16 Thread Christoph Lameter
On Thu, 10 Sep 2009, Jeff Layton wrote: > In any case, I think we need to look closely at what's happening at > mount time. First, I'll need some other info: > > 1) output of "/sbin/mount.cifs -V" from both machines The 32 bit machine #/sbin/mount.cifs -V mount.cifs version: 1.5 mount -t cifs /

Re: [Samba] Still problems with samba 3.4.1 / ldap and search for users ans machines

2009-09-16 Thread Rob Shinn
John H Terpstra - Samba Team wrote: Of over 100 LADP Samba installation I have completed over 80% successfully use: uid='username',ou=People,ou=Users, uid='machine',ou=Computers,ou=Users, Same here, though I use uid='username', ou=people, cn='machine', ou=hosts, and make the object str

[Samba] station can t join domain due to wins cache

2009-09-16 Thread Stephane Durieux
Hello, A problem that might be usefull to mention (or not). Sometimes, I encountered a problem with some stations that couldn t join the samba domain. It was due to the wins cache. (the samba conf was configured to provide wins service) I had already joined the domain with those stations be

Re: [Samba] Problem with net rpc .

2009-09-16 Thread Wes Deviers
On Wednesday 16 September 2009 08:46:31 am Bruno Steven wrote: > Hi guys ... > I have samba Version 3.0.33-3.7.el5_3.1 integrated with Openldap I have > trying run the command *net rpc join -U root , * but show message > Creation of workstation account failedUnable to join domain TEST.COM. ... H

Re: [Samba] Help needed: valid users

2009-09-16 Thread Gary Dale
Chris Osicki wrote: Hi I'm using Samba 3.0.33 on Solaris10 and have the following problem. In the smb.conf I have workgroup = CORPROOT security = domain and users authenticated to CORPROOT domain can connect shares w/o problems, [homes] for example. Now I would like to create a shar

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Miguel Medalha
Dear Jeremy Since I once thought about doing the same, I would like to know your views on the method that Wes describes. I quote: ยป What I've been doing, which is dangerous but effective, is setting file creation mode to 666 and letting the Samba VFS ACL layer take care of everything. That

[Samba] Help needed: valid users

2009-09-16 Thread Chris Osicki
Hi I'm using Samba 3.0.33 on Solaris10 and have the following problem. In the smb.conf I have workgroup = CORPROOT security = domain and users authenticated to CORPROOT domain can connect shares w/o problems, [homes] for example. Now I would like to create a share and restrict access t

[Samba] Domain Trusts

2009-09-16 Thread Charlie Clark
Hi, I am trying to get two Samba4 domain's linked in a trust over an openvpn tunnel. Everything seems to be setup fine and each domain recognizes the other domain when starting to create the trust. I am unable to get this to work though as when I go through the wizard and it creates the trust, the

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Jeremy Allison
On Wed, Sep 16, 2009 at 01:38:13PM -0400, Wes Deviers wrote: > > Or, alternately, "Does Samba, with vfs object = acl_xattr, store ACLs both as > a user_xattr AND an ext3 ACL at the same time?" My limited testing shows > that > *not* to be the case, but I'm certainly not the expert. Yes it doe

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Wes Deviers
On Wednesday 16 September 2009 12:56:11 pm Jeremy Allison wrote: > On Wed, Sep 16, 2009 at 11:18:58AM -0400, Wes Deviers wrote: SNIP > > > > How can I insist that Samba use the vfs object ACL module, instead of the > > POSIX acls? > > You can't at the moment. Samba still requires the incoming >

Re: [Samba] Can I use net ads join without DNS

2009-09-16 Thread andy.marr
Also found in the debug output the following [2009/09/16 18:20:09, 8] libsmb/namequery.c:(1644) get_sorted_dc_list: attempting lookup for name FGPREPROD.COM (sitename NULL) using [ad s] Which I'm guessing is where its getting the: Bad option: ads Failed to join domain: Invalid parameter Erro

Re: [Samba] Can I use net ads join without DNS

2009-09-16 Thread andy.marr
Cheers Volker I used your option and I've also found the password server option in the smb.conf. Im running both and seem to have got a bit further. But now I'm getting a different error. I'm not sure if the problem is still DNS. The ADS server is not in DNS and in a different domain to my SAMB

Re: [Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Jeremy Allison
On Wed, Sep 16, 2009 at 11:18:58AM -0400, Wes Deviers wrote: > List, > > I had Samba 3.0 running on Debian Lenny configured to use POSIX ACLs on ext3. > > They worked fine, or at least as fine as NT -> POSIX mapping ever did. After > testing 3.3 with acl_xattr on using a different machine, I

Re: [Samba] Can I use net ads join without DNS

2009-09-16 Thread Volker Lendecke
On Wed, Sep 16, 2009 at 03:10:38PM +0100, andy.m...@bt.com wrote: > Hi Samba people > > I'm trying to join a Solari10 server using Samba Version 3.0.33 server > to an ADS. But the ADS is not in DNS. > > I thought I could get round this by putting the ADS IP in the servers > local hosts file, and

[Samba] Printing queues not clearing after server crash

2009-09-16 Thread bdehn
We had a server crash last night and now the print queues (from the Windows clients) are not clearing after the job prints. I'm using Samba version 3.0.26a-0.9-1787-SUSE-SLES9 and CUPS cups-1.1.20-108.44. I'm thinking I've got a corrupt tdb file but not sure which one(s) to check. Advice / sug

Re: [Samba] Mystery Samba (3.4.1) and Win7

2009-09-16 Thread Guenther Deschner
Hi Martin, On Wed, Sep 16, 2009 at 01:37:33PM +0200, Martin Hochreiter wrote: > Hi! > > I read many threads and tried many "solutions" but > I can't get Win7 (RTM, 64 bit) and Samba 3.4.1 to work together. > > I am still failing with the "trusteeship" problem during > the first logon after domain

[Samba] ACL misbehavior moving from POSIX ACL -> acl_xattr

2009-09-16 Thread Wes Deviers
List, I had Samba 3.0 running on Debian Lenny configured to use POSIX ACLs on ext3. They worked fine, or at least as fine as NT -> POSIX mapping ever did. After testing 3.3 with acl_xattr on using a different machine, I decided to give it a whirl on the production server. And yes, I know it'

[Samba] Can I use net ads join without DNS

2009-09-16 Thread andy.marr
Hi Samba people I'm trying to join a Solari10 server using Samba Version 3.0.33 server to an ADS. But the ADS is not in DNS. I thought I could get round this by putting the ADS IP in the servers local hosts file, and telling the krb5.conf not to use dns but it doesn't seem to work. 1. Can it be

[Samba] Problem with net rpc .

2009-09-16 Thread Bruno Steven
Hi guys ... I have samba Version 3.0.33-3.7.el5_3.1 integrated with Openldap I have trying run the command *net rpc join -U root , * but show message Creation of workstation account failedUnable to join domain TEST.COM. The content my /var/log/messages Sep 15 09:32:08 amblivre smbd[4163]: [2009/

[Samba] Mystery Samba (3.4.1) and Win7

2009-09-16 Thread Martin Hochreiter
Hi! I read many threads and tried many "solutions" but I can't get Win7 (RTM, 64 bit) and Samba 3.4.1 to work together. I am still failing with the "trusteeship" problem during the first logon after domain join. Is there a working solution? regards Martin -- To unsubscribe from this list go to