[Samba] Anything like nss_updatedb for ldapsam account information backend?

2012-02-28 Thread Jack Bates
Is there anything like nss_updatedb [1] for ldapsam account information backend? nss_updatedb caches unix account information, so it is available even when the LDAP directory isn't available But ldapsam stores additional account information. How can I cache this additional account

[Samba] New Windows 7 PC in samba network sees itself as logonserver respectively can not access subdirectories

2012-02-28 Thread Andreas Moroder
Hello, we are preparing a new image for our windows 7 computers. We can connect to the domain, we also see all of our samba servers. On one server we can logon, see also the directories in the share, but when we try to open subdirectories explorer hangs for a long time and then a dialog

Re: [Samba] Samba4 xidNumber and idmap.ldb

2012-02-28 Thread Kai Blin
On 2012-02-26 18:15, steve wrote: Hi Steve, Sorry. Just one more thing. Could you point me at the code which finds the next free xid when e.g. you create a new user? That's not how samba4 id mapping works at the moment I'm afraid. It will ignore the Posix attributes that might exist in the AD.

Re: [Samba] Anything like nss_updatedb for ldapsam account information backend?

2012-02-28 Thread Adam Tauno Williams
On Tue, 2012-02-28 at 00:31 -0800, Jack Bates wrote: Is there anything like nss_updatedb [1] for ldapsam account information backend? nss_updatedb caches unix account information, so it is available even when the LDAP directory isn't available But ldapsam stores additional account

Re: [Samba] Samba domain member server using only nss ldap

2012-02-28 Thread Adam Tauno Williams
On Sat, 2012-02-25 at 19:49 +0100, steve wrote: one little problem. When I execute ls -la in the directory there is a delay about 1-2 seconds. Is it normal? nscd deamon solves this problem, there is no delay. Is there any solution without using nscd? nss-ldapd with nslcd. Much quicker

Re: [Samba] Proposal to change security=share in Samba 4.0

2012-02-28 Thread Mike Rambo
Andrew Bartlett wrote: On Mon, 2012-02-27 at 19:45 -0500, simo wrote: On Tue, 2012-02-28 at 10:16 +1100, Andrew Bartlett wrote: On Mon, 2012-02-27 at 17:53 -0500, David Collier-Brown wrote: Am I correct in thinking this would make all shares have the same password as the guest user, or do

Re: [Samba] Samba4 xidNumber and idmap.ldb

2012-02-28 Thread steve
On 28/02/12 11:14, Kai Blin wrote: On 2012-02-26 18:15, steve wrote: Hi Steve, Sorry. Just one more thing. Could you point me at the code which finds the next free xid when e.g. you create a new user? That's not how samba4 id mapping works at the moment I'm afraid. It will ignore the Posix

[Samba] Samba4 error? A global catalog (GC) cannot be contacted

2012-02-28 Thread steve
Hi everyone Every so often we get this error: http://dl.dropbox.com/u/45150875/samba-list.png The error disappears around 5 minutes after Admin has logged in, Meanwhile the user can logon and none of his group acls seem to be affected. Nothing unusual appears at d3 level either. Anyone

Re: [Samba] windows and nfs4 acls

2012-02-28 Thread Gémes Géza
2012-02-28 08:27 keltezéssel, steve írta: Hi everyone We're really struggling with nfs4 -- windows acls. Scenario Samba4 share -- cifs -- win7. No problem Samba4 share -- nfs4 -- Linux. acls not inherited Neither is there inheritance vica versa. e.g. It is not possible to create files

Re: [Samba] Fwd: STATUS_ACCESS_DENIED with NTCreateAndX if Access Mask has System Security bit set

2012-02-28 Thread Jeremy Allison
On Mon, Feb 27, 2012 at 04:55:29PM -0800, Jeremy Allison wrote: On Mon, Feb 27, 2012 at 03:12:49PM -0700, Tom Lee wrote: -- Forwarded message -- From: Tom Lee tlee2...@gmail.com Date: Mon, Feb 27, 2012 at 3:10 PM Subject: Re: [Samba] STATUS_ACCESS_DENIED with NTCreateAndX

Re: [Samba] windows and nfs4 acls

2012-02-28 Thread Jeremy Allison
On Tue, Feb 28, 2012 at 06:37:21PM +0100, Gémes Géza wrote: 2012-02-28 08:27 keltezéssel, steve írta: Hi everyone We're really struggling with nfs4 -- windows acls. Scenario Samba4 share -- cifs -- win7. No problem Samba4 share -- nfs4 -- Linux. acls not inherited Neither is

Re: [Samba] Fwd: STATUS_ACCESS_DENIED with NTCreateAndX if Access Mask has System Security bit set

2012-02-28 Thread Tom Lee
I have tested with this fix and it looks like it does take care of the problem. We'll look forward to seeing this update in the latest 3.6.x codebase. Thanks a lot. On Tue, Feb 28, 2012 at 10:42 AM, Jeremy Allison j...@samba.org wrote: On Mon, Feb 27, 2012 at 04:55:29PM -0800, Jeremy Allison

Re: [Samba] Fwd: STATUS_ACCESS_DENIED with NTCreateAndX if Access Mask has System Security bit set

2012-02-28 Thread Jeremy Allison
On Tue, Feb 28, 2012 at 01:22:38PM -0700, Tom Lee wrote: I have tested with this fix and it looks like it does take care of the problem. We'll look forward to seeing this update in the latest 3.6.x codebase. Thanks a lot. Thanks ! It's tracked as bug #8784

Re: [Samba] Proposal to change security=share in Samba 4.0

2012-02-28 Thread Andrew Bartlett
On Tue, 2012-02-28 at 07:30 -0500, Mike Rambo wrote: From what I saw in the rest of the thread it looks like there will still be a way to do this but I thought I'd chime in since the subject has come up and we do use security=share to accomplish this at present. There will always be a way

Re: [Samba] Proposal to change security=share in Samba 4.0

2012-02-28 Thread Volker Lendecke
Andrew, On Wed, Feb 29, 2012 at 10:53:47AM +1100, Andrew Bartlett wrote: On Tue, 2012-02-28 at 07:30 -0500, Mike Rambo wrote: From what I saw in the rest of the thread it looks like there will still be a way to do this but I thought I'd chime in since the subject has come up and we do

Re: [Samba] Proposal to change security=share in Samba 4.0

2012-02-28 Thread Jeremy Allison
On Wed, Feb 29, 2012 at 01:00:00AM +0100, Volker Lendecke wrote: Andrew, On Wed, Feb 29, 2012 at 10:53:47AM +1100, Andrew Bartlett wrote: On Tue, 2012-02-28 at 07:30 -0500, Mike Rambo wrote: From what I saw in the rest of the thread it looks like there will still be a way to do

Re: [Samba] Proposal to change security=share in Samba 4.0

2012-02-28 Thread Andrew Bartlett
On Tue, 2012-02-28 at 16:34 -0800, Jeremy Allison wrote: On Wed, Feb 29, 2012 at 01:00:00AM +0100, Volker Lendecke wrote: Andrew, On Wed, Feb 29, 2012 at 10:53:47AM +1100, Andrew Bartlett wrote: On Tue, 2012-02-28 at 07:30 -0500, Mike Rambo wrote: From what I saw in the rest of

Re: [Samba] samba 4 how to enable winbindd

2012-02-28 Thread Kai Blin
On 2012-02-27 14:13, Alain Toussaint wrote: Hi Alain, I configured a domain controller on a ubuntu server using samba 4 alpha 15 using ubuntu's distribution packages and followed this howto: https://wiki.samba.org/index.php/Samba4/Winbind to have unix account for domain users but

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Amitay Isaacs
The branch, master has been updated via 0c4d1d6 upgradedns: Missing rename from upgradedns to samba_upgradedns from d92b955 s4:torture:smb2:durable-open: fix a silly access-after-free panic http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

autobuild: intermittent test failure detected

2012-02-28 Thread autobuild
The autobuild test system has detected an intermittent failing test in the current master tree. The autobuild log of the failure is available here: http://git.samba.org/autobuild.flakey/2012-02-28-1127/flakey.log The samba3 build logs are available here:

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Andrew Bartlett
The branch, master has been updated via d12bad7 torture: added samba4-ntvfs target via e2e2e60 s3fs: when samba is logging to stdout, ask smbd to also do so via 1da318d smbd: detect EOF on stdin in --foreground mode via 645fcc5 selftest: added a pipe on stdin in s3

[SCM] Samba Shared Repository - branch v3-6-test updated

2012-02-28 Thread Karolin Seeger
The branch, v3-6-test has been updated via 9902744 s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path from 4d60392 Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER but has no

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Jeremy Allison
The branch, master has been updated via 6081fab Fix problem reported by Tom Lee tlee2...@gmail.com - when calculating the share security mask, take priviliges into account for the connecting user. from d12bad7 torture: added samba4-ntvfs target

[SCM] Samba Shared Repository - branch v3-6-test updated

2012-02-28 Thread Karolin Seeger
The branch, v3-6-test has been updated via a0d5194 s3: Add sys_statvfs() wrapper support for OpenBSD/FreeBSD/DragonFly. from 9902744 s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path

[SCM] Samba Shared Repository - branch v3-6-test updated

2012-02-28 Thread Karolin Seeger
The branch, v3-6-test has been updated via 01747a5 s3-winbindd: set the can_do_validation6 also for trusted domain from a0d5194 s3: Add sys_statvfs() wrapper support for OpenBSD/FreeBSD/DragonFly. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-6-test - Log

[SCM] Samba Shared Repository - branch v3-5-test updated

2012-02-28 Thread Karolin Seeger
The branch, v3-5-test has been updated via 6c1501a s3-winbindd: set the can_do_validation6 also for trusted domain from 12b60f9 s3:loadparm: fix the reload of the configuration: also reload activated registry shares http://gitweb.samba.org/?p=samba.git;a=shortlog;h=v3-5-test -

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Volker Lendecke
The branch, master has been updated via c5c67ca s3: Add a test that makes a chained open break an oplock via e916778 s3: More fix for smbd -i from 6081fab Fix problem reported by Tom Lee tlee2...@gmail.com - when calculating the share security mask, take priviliges into

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Volker Lendecke
The branch, master has been updated via de870e9 s3: Introduce req helper var in reply_lockingX_success via adac885 s3: Fix a const warning from c5c67ca s3: Add a test that makes a chained open break an oplock http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] CTDB repository - branch 1.2.39 updated - ctdb-1.9.1-499-gf053a6d

2012-02-28 Thread Ronnie Sahlberg
The branch, 1.2.39 has been updated via f053a6d2948a1933d38d6cdd4cae55349e71b7d4 (commit) from 6f6dac21f93c38c3abcbebc1b786b4da2ef9f563 (commit) http://gitweb.samba.org/?p=ctdb.git;a=shortlog;h=1.2.39 - Log - commit

[SCM] CTDB repository - branch 1.2.40 updated - ctdb-1.9.1-542-gfd33e6f

2012-02-28 Thread Ronnie Sahlberg
The branch, 1.2.40 has been updated via fd33e6ff1e349e3d6d1d2e78ab14942c97aba731 (commit) from a02fa85678cc5061042ab6d448b8a3f5993f2d70 (commit) http://gitweb.samba.org/?p=ctdb.git;a=shortlog;h=1.2.40 - Log - commit

[SCM] CTDB repository - branch master updated - ctdb-1.12-223-g5ae94c6

2012-02-28 Thread Ronnie Sahlberg
The branch, master has been updated via 5ae94c6b9b3000a6c79fccaaea1e007ebd5be1a9 (commit) from 49791db7dc74cffd7e88bd73091590cdc1909328 (commit) http://gitweb.samba.org/?p=ctdb.git;a=shortlog;h=master - Log - commit

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Stefan Metzmacher
The branch, master has been updated via c9219fe libcli/smb/smbXcli: use smb2_key_deviration() to setup SMB 2.24 keys via 39ae473 libcli/smb/smb2_signing: implement aes_cmac_128 based signing for SMB 2.24 via 7f5e569 libcli/smb/smb2_signing: add smb2_key_deviration()

[SCM] CTDB repository - branch master updated - ctdb-1.12-224-g7417d99

2012-02-28 Thread Ronnie Sahlberg
The branch, master has been updated via 7417d994c2a159f71d27d4bcd2f53684862eece3 (commit) from 5ae94c6b9b3000a6c79fccaaea1e007ebd5be1a9 (commit) http://gitweb.samba.org/?p=ctdb.git;a=shortlog;h=master - Log - commit

[SCM] Samba Shared Repository - branch master updated

2012-02-28 Thread Stefan Metzmacher
The branch, master has been updated via 65d42ab s3:torture/test_smb2: test path based calls during reauth in SMB2-MULTI-CHANNEL via 300ab04 s3:torture/test_smb2: test handle based calls during reauth in SMB2-MULTI-CHANNEL via 2fced53 s3:torture/test_smb2: do a reauth over