[Samba] Server authentication

2013-08-19 Thread Miroslav Prýmek
Hello, I can't find any precise technical information about how the client computer in Windows domain (NT,AD) verifies the identity of the PDC. Can you please point me to any source of relevant information or give me a brief explanation? Situation: I'm going to replace a Windows Server 2003 PDC

Re: [Samba] Server authentication

2013-08-19 Thread Michael Wood
Hi On 19 August 2013 09:58, Miroslav Prýmek m.pry...@gmail.com wrote: Hello, I can't find any precise technical information about how the client computer in Windows domain (NT,AD) verifies the identity of the PDC. Can you please point me to any source of relevant information or give me a

Re: [Samba] /var/lock/samba filling up /run/lock

2013-08-19 Thread Mark Fox
Thanks Achim, especially for pointing out where we can set the size of /run/lock and have it stick after a reboot. We hadn't gotten that far yet, but we did expand the size of /run/lock on Friday by hand and do some testing. We ended up chasing an unrelated wild goose, but realized this morning

[Samba] Samba 4.0.8 on RHEL 6.2 how to grant permissions via Windows to unix users/groups?

2013-08-19 Thread Kristy Kallback-Rose
I have built from source Samba 4.0.8 on RHEL 6.2. I want users to be able to change permissions via Windows, but I don't see how to do that for the unix users and groups in the Windows permission screens. When I create a folder, for example, and right-click to get properties and click on the

Re: [Samba] Samba4 + Winbind + PAM Installation/Configuration

2013-08-19 Thread Thiago Fernandes Crepaldi
I am justs tarting o samba too, but I think it is normal to have lots of not found. You have to pay attention for the features you want, though. You might need libpam0g-dev package for PAM support (At least that is the one for Debian) and you can also consider libacl-dev for ACL support

Re: [Samba] Windows 7 on startup always loads temporary profiles samba 3.4.8

2013-08-19 Thread hussain free
i think it's not samba proble, after long search and trying , thank god, i found the solution the client can't write to it's home profile and read it so you jest give it permission for profile directory chmod 777 -R /home best regards -- To unsubscribe from this list go to the following URL

[Samba] samba-tool classicupgrade throws uncaught exception

2013-08-19 Thread Scott Goodwin
I have a new server running CentOS 6.4 x64, which will serve as our new Samba4 server. It is set up in a test environment, and I've copied over the tdb files and the smb.conf file from our samba3 server (Same OS and version). I'm trying to do an in-place upgrade on the copied files, but keep

[Samba] Is kerberos authentication against AD possible without joining the domain?

2013-08-19 Thread Les Mikesell
On CentOS (and presumably RHEL), the authconfig tool can set up kerberos authentication via PAM so that locally added users can be authenticated at the shell/ssh level if the password they use succeeds for the matching user name in Active Directory - and this works without joining the linux box to

[Samba] rpcclient netshareenum 502 causes SEGV

2013-08-19 Thread pisymbol .
Hello: I have a Windows 2003 Server that is causing rpcclient to SEGV via the following command: $ rpcclient -U Administrator%foobar -c 'netshareenum 502' server ... type: 0x6269: SEC_DESC_OWNER_DEFAULTED SEC_DESC_DACL_DEFAULTED SEC_DESC_SACL_DEFAULTED SEC_DESC_DACL_TRUSTED

Re: [Samba] rpcclient netshareenum 502 causes SEGV

2013-08-19 Thread pisymbol .
On Mon, Aug 19, 2013 at 6:21 PM, pisymbol . pisym...@gmail.com wrote: Hello: I have a Windows 2003 Server that is causing rpcclient to SEGV via the following command: $ rpcclient -U Administrator%foobar -c 'netshareenum 502' server ... type: 0x6269: SEC_DESC_OWNER_DEFAULTED

Re: [Samba] Is kerberos authentication against AD possible without joining the domain?

2013-08-19 Thread Andrew Bartlett
On Mon, 2013-08-19 at 17:17 -0500, Les Mikesell wrote: On CentOS (and presumably RHEL), the authconfig tool can set up kerberos authentication via PAM so that locally added users can be authenticated at the shell/ssh level if the password they use succeeds for the matching user name in Active

[Samba] Samba 4.0.5 User who has same password then Administrator authenticated as Administrator.

2013-08-19 Thread Gigor Szilárd
Hi list! I use samba 4.0.5 as ADDC and I have more shares. Everthing great but I have some share premission problem. There are some users who have same password then Administrator, they authenticated as Administrator on shares. These users don't have premission to these shares. For example:

Re: [Samba] Is kerberos authentication against AD possible without joining the domain?

2013-08-19 Thread Les Mikesell
On Mon, Aug 19, 2013 at 5:40 PM, Andrew Bartlett abart...@samba.org wrote: On CentOS (and presumably RHEL), the authconfig tool can set up kerberos authentication via PAM so that locally added users can be authenticated at the shell/ssh level if the password they use succeeds for the matching

[Samba] Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE

2013-08-19 Thread Gregory Machin
Hi. I we are migrating form domain ad.adc.com to ad.xyz.com , there is a trust between the two domains. Before the move the file server was work perfectly, post migration I get the following in the samba logs [2013/08/19 08:07:15.961679, 1] smbd/sesssetup.c:342(reply_spnego_kerberos) Failed

Re: [Samba] samba-tool classicupgrade throws uncaught exception

2013-08-19 Thread Scott Goodwin
Update: I realized shortly after I sent the email that because I don't use winbind, I can (and should) delete the file winbindd_idmap.tdb. So, the second error is now the stopper. In essence, it's complaining that it can't find the user or group with sid ending in 1057. Adding users to groups

Re: [Samba] rpcclient netshareenum 502 causes SEGV

2013-08-19 Thread Jeremy Allison
On Mon, Aug 19, 2013 at 06:21:02PM -0400, pisymbol . wrote: Hello: I have a Windows 2003 Server that is causing rpcclient to SEGV via the following command: $ rpcclient -U Administrator%foobar -c 'netshareenum 502' server ... type: 0x6269: SEC_DESC_OWNER_DEFAULTED SEC_DESC_DACL_DEFAULTED

Re: [Samba] rpcclient netshareenum 502 causes SEGV

2013-08-19 Thread Jeremy Allison
On Mon, Aug 19, 2013 at 06:21:02PM -0400, pisymbol . wrote: Hello: I have a Windows 2003 Server that is causing rpcclient to SEGV via the following command: $ rpcclient -U Administrator%foobar -c 'netshareenum 502' server ... type: 0x6269: SEC_DESC_OWNER_DEFAULTED SEC_DESC_DACL_DEFAULTED

Re: [Samba] Is kerberos authentication against AD possible without joining the domain?

2013-08-19 Thread Andrew Bartlett
On Mon, 2013-08-19 at 18:22 -0500, Les Mikesell wrote: On Mon, Aug 19, 2013 at 5:40 PM, Andrew Bartlett abart...@samba.org wrote: On CentOS (and presumably RHEL), the authconfig tool can set up kerberos authentication via PAM so that locally added users can be authenticated at the

[SCM] CTDB repository - branch master updated - ctdb-2.3-60-g7b7aa7b

2013-08-19 Thread Amitay Isaacs
The branch, master has been updated via 7b7aa7b599536cd60ebb84d363607bb4e953248a (commit) via 1c9025fdd08d1cea342af7487d0123015e08831b (commit) via f0853013655ac3bedf1b793de128fb679c6db6c6 (commit) via a610bc351f0754c84c78c27d02f9a695e60c5b0f (commit) via

autobuild: intermittent test failure detected

2013-08-19 Thread autobuild
The autobuild test system has detected an intermittent failing test in the current master tree. The autobuild log of the failure is available here: http://git.samba.org/autobuild.flakey/2013-08-19-0935/flakey.log The samba3 build logs are available here:

[SCM] Samba Shared Repository - branch master updated

2013-08-19 Thread Jeremy Allison
The branch, master has been updated via 74829fe Fix bug #10097 - MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba. from 02618cc rpc_server: Fix CID 1063255 Resource leak http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2013-08-19 Thread Jeremy Allison
The branch, master has been updated via 4f96d57 libsmb: Fix a bunch of Coverity IDs from 74829fe Fix bug #10097 - MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log

[SCM] Samba Shared Repository - branch master updated

2013-08-19 Thread Jeremy Allison
The branch, master has been updated via 1808316 docs: Fix variable list in man vfs_crossrename. via 3e11421 Man pages for ntdb tools missing from 4f96d57 libsmb: Fix a bunch of Coverity IDs http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log