[Samba] BDC needs a [profile] and [netlogon] share ?

2013-05-24 Thread ?icro MEGAS
Hi all, I have a BDC which uses the LDAP backend of my PDC. Unfortunately all the users who log-in in the morning and who are processed by this BDC, do not get their logon script executed. The BDC logs this error message: [2013/05/24 07:28:11.946577, 2] auth/auth.c:304(check_ntlm_password)

Re: [Samba] (force) defau­lt security ­mask

2013-05-22 Thread ?icro MEGAS
with many users, perhaps several thousand, to allow a single [homes] share to be used flexibly by each user. Default: inherit permissions = no On 05/20/2013 3:24 PM, ?icro MEGAS wrote: That was a type error in my previous

Re: [Samba] (force) default security ­mask

2013-05-20 Thread ?icro MEGAS
That was a type error in my previous post, the line in my smb.conf is of course: read only = No Вск 19 Май 2013 14:58:39 +0400, ?icro MEGAS написал: Hello folks, Samba 3.5.6 running and I have following share: [public] path = /data/public read onlyXSSCleaned

[Samba] (force) default security mask

2013-05-19 Thread ?icro MEGAS
Hello folks, Samba 3.5.6 running and I have following share: [public] path = /data/public read only = No create mask = 0777 directory mask = 0777 directory security mask = 0750 vfs object = acl_xattr nt acl support = yes

[Samba] Fwd: Re: Re: Cannot ad­d/mo­dify ACL through win­dows ­client

2013-05-15 Thread ?icro MEGAS
Hi Denis, on both samba hosts (donald and pluto) these commands work great: id johndoe getent group getent passwd My pluto:/etc/nsswitch.conf looks like that: [...] passwd: compat ldap group: compat ldap shadow: compat ldap [...] I want to add, that the described

Re: [Samba] Fwd: Re: Re: ­ Cannot ad­d/mo­dify ACL ­through win­dows ­client

2013-05-15 Thread ?icro MEGAS
Hi Denis, my smb.conf on PDC (hostname=donald) looks like that: [global] workgroup = MYDOM server string = Fileserver interfaces = 172.16.0.1/16, 127.0.0.1 update encrypted = Yes map to guest = Bad User passdb backend = ldapsam:ldap://172.16.0.1

[Samba] Cannot add/modify ACL through windows client

2013-05-14 Thread ?icro MEGAS
Dear all, I am struggling around with Windows ACLs and cannot find a solution nor how to troubleshoot that. I have two samba3 hosts. Hostname donald is my domain controller with samba 3.x + OpenLDAP server running. Hostname pluto is my other samba 3.x server which was joined to my domain. I

Re: [Samba] Using Windows­­­­ ACL on a samba3 share

2013-05-09 Thread ?icro MEGAS
Unfortunately it didn't help either. The strange thing is that when I open the security tab for a directory on the windows client, I only see the SID numbers of users. The groups are displayed well with names, but the usernames are not displayed, I only see the SIDs. Seems that samba somehow

[Samba] Using Windows ACL on a samba3 share

2013-05-08 Thread ?icro MEGAS
Hello folks, I have some directories within a samba 3.x share which I want to give granulated security settings for various users and groups. I could use of course setfacl and POSIX ACLs to accomplish that, but some of these ACL should be also able to be set by some users. These users of

Re: [Samba] Using Windows­­­ ACL on a samba3 share

2013-05-08 Thread ?icro MEGAS
Hello again, I am using samba 3.5.6. I have another though maybe this problem occurs due to my OpenLDAP service? My /etc/openldap/slapd.conf is using: [...] access to dn.base= by * read access to dn.base=cn=Subschema by * read access to attrs=userPassword,userPKCS12 by

[Samba] Samba4: W2k clients cannot set / sync time with samba4 AD DC

2013-04-25 Thread ?icro MEGAS
here -- http://paste.ubuntu.com/5600267/ Hope to get some feedback of the devs, it seems that this is related to SMB and not to NTP itself ? Any feedback appreciated, thanks and greetings... Lucas Пнд 22 Апр 2013 19:17:03 +0400, ?icro MEGAS написал: @samba-devs: Could this be related to samba4

Re: [Samba] Samba4: W2k c­lients cannot set / sync ­time with samba4 AD DC

2013-04-25 Thread ?icro MEGAS
Hello, I HAVE sniffed the network traffic for this w2k client and provided the link via paste.ubuntu.com, so everybody can look inside that without the need of extra-tools like wireshark. And as I realized you have looked into that sniffed result output. I did it this way, because I work on

[Samba] Samba4: W2k clients cannot perform dynamic updates (TSIG failure)

2013-04-22 Thread ?icro MEGAS
Hi all, I am running samba 4.0.5 as Active-Directory Domain Controller with bind9 9.8 and I am using the BIND9_DLZ mech. I have setup my DNS quite exactly as described on the samba4_dns HowTo, but I am facing following problems: Win2000 clients are NOT ABLE to update/add/delete dynamic dns

[Samba] NTP doesnt work for Win2000 clients + Samba 4.0.4 (see tcpdump)

2013-04-09 Thread ?icro MEGAS
Hi all, I am using Samba 4.0.4 as AD DC on my test environment and realized that all my W2k clients (default installation, no special setups made on the clients) cannot receive the correct time of my samba 4.0.4 AD domain controller. Windows XP and 7 work fine though. The problem occurs at

[Samba] Samba4 issue: roaming profile mismatch betweens W2k/XP machines due to enabled o

2013-03-27 Thread ?icro MEGAS
Samba 4.0.4 installed, provisioned by classicupgrade, running on Debian Squeeze: The issue is, that changes to the roaming profile is not transferred after log ins/outs between Win2K and XP machine. In example: I log

[Samba] ADUC tool cannot creates users home directory

2013-03-27 Thread ?icro MEGAS
Hello everybody, if I use Microsoft's Active Directory Users tool to add a home drive mapping to a users profile, I encounter the problem that ADUC tool cannot create automatically the home directory for the desired user. ADUC tool fails with the message, that the share cannot be accessed.