Re: [Samba] Samba 4 logging

2012-11-18 Thread Andrew Bartlett
in the future? It's a worthy feature, but no, I'm not aware of any specific plans. It needs someone to volunteer and implement it, including hooks in Heimdal. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] Samba 4 logging

2012-11-16 Thread Andrew Bartlett
Windows AD servers log it to the security event log? Not at this point, sorry. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL

Re: [Samba] Samba domain member losing membership

2012-11-16 Thread Andrew Bartlett
releases for this (gives a longer timeout). The issue is, this takes longer than we allow, so we think it failed, but it actually succeed, and so we loose our membership. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba

Re: [Samba] config a share named Global, not global

2012-11-16 Thread Andrew Bartlett
. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 - Wins error running samba-tool classicupgrade

2012-11-16 Thread Andrew Bartlett
. The correct fix would be to work out what nmbd does with a duplicate entry (does it just take the first or last entry?) and then do the same in the upgrade code. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] Is it possible to change the root/Administrator user to another username?

2012-11-16 Thread Andrew Bartlett
? As speculation, upgrading to Samba 4.0 might help, as (partly in reaction to this kind of thing) we have tried to reduce how often we ask for a system and root token. It might just happen to reduce the demands on your backend to a level where it doesn't break down. I hope this helps, Andrew Bartlett

[SCM] Samba Shared Repository - branch master updated

2012-11-16 Thread Andrew Bartlett
to smbacl4_fill_ace4 Signed-off-by: Christian Ambach a...@samba.org Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Sat Nov 17 01:11:07 CET 2012 on sn-devel-104 commit

Re: [Samba] dns-backend BIND9_FLATFILE

2012-11-15 Thread Andrew Bartlett
On Thu, 2012-11-15 at 14:38 +, Bruno Fernandes wrote: Hi, I'm still running samba4 beta5 with dns-backend=BIND9_FLATFILE I want to upgrade to samba4 rc5. Can I still use BIND9_FLATFILE ? Yes. Andrew Bartlett -- Andrew Bartletthttp

Re: [Samba] Is it possible to change the root/Administrator user to another username?

2012-11-15 Thread Andrew Bartlett
probably give you some sensible advise. root isn't hard-coded anywhere in Samba, but uid 0 is special in unix and in Samba. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

[SCM] Samba Shared Repository - branch master updated

2012-11-15 Thread Andrew Bartlett
) File /usr/lib/python2.6/dist-packages/samba/netcmd/fsmo.py, line 160, in run self.seize_role(role, samdb, force) File /usr/lib/python2.6/dist-packages/samba/netcmd/fsmo.py, line 119, in seize_role m.dn = ldb.Dn(samdb, self.schema_dn) Reviewed-by: Andrew Bartlett

[SCM] Samba Shared Repository - branch master updated

2012-11-13 Thread Andrew Bartlett
me...@samba.org Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Nov 13 13:53:31 CET 2012 on sn-devel-104 commit 11f5d54cbb10fd5c5f0e1718427609709c3476f4 Author: Stefan Metzmacher me

[SCM] Samba Shared Repository - branch master updated

2012-11-13 Thread Andrew Bartlett
missing newline in the output of ldb_ldif_write_trace() http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log - commit a390a5878db627a7f0147699fff97a39013816dc Author: Andrew Bartlett abart...@samba.org Date: Tue Nov 13

[SCM] Samba Shared Repository - branch master updated

2012-11-12 Thread Andrew Bartlett
is not available. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log - commit c5f53ed580d92088f544a7d66b8b276fef8f3ab7 Author: Andrew Bartlett abart...@samba.org Date: Mon Nov 12 21:49:36 2012 +1100 Revert selftest/skip: add

Re: [Samba] samba4 documentation

2012-11-11 Thread Andrew Bartlett
inside samba-4.0.0rc4/docs-xml like: samba-4.0.0rc4/docs-xml/smbdotconf These are built if you have the correct xsltproc stuff installed. Otherwise, they are included in all release tarballs under docs. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] sambar4: user creation with ldap and initial password

2012-11-11 Thread Andrew Bartlett
On Mon, 2012-11-05 at 12:54 +0200, Michael Wood wrote: On 5 November 2012 09:28, Andrew Bartlett abart...@samba.org wrote: On Mon, 2012-11-05 at 08:18 +0100, Thomas Mueller wrote: Am 05.11.2012 04:31, schrieb Andrew Bartlett: On Thu, 2012-11-01 at 12:44 +, Thomas Mueller wrote: hi

[SCM] Samba Shared Repository - branch master updated

2012-11-11 Thread Andrew Bartlett
- commit 1d81e52bba65f05378db7027537aa27eb5bfa70a Author: Andrew Bartlett abart...@samba.org Date: Sun Nov 11 21:33:41 2012 +1100 selftest: Add tests for expected behaviour on directories as well as files This is important because it covers the codepath which had the talloc error

[SCM] Samba Shared Repository - branch master updated

2012-11-11 Thread Andrew Bartlett
...@samba.org Date: Fri Nov 9 17:23:53 2012 +0100 s4:dsdb/acl_read: make sure confidential attributes require CONTROL_ACCESS (bug #8620) Signed-off-by: Stefan Metzmacher me...@samba.org Signed-off-by: Andrew Bartlett abart...@samba.org Reviewed-by: Andrew Bartlett abart

Re: [Samba] samba4 documentation

2012-11-10 Thread Andrew Bartlett
On Thu, 2012-11-08 at 21:15 -0300, José Neto wrote: Where is the samb4 (nice typo) documentation? Sorry about the question, but I can't find samba4 docs anywhere. Someone, please, help me. Thanks! https://wiki.samba.org/index.php/Samba4/HOWTO -- Andrew Bartlett

Re: [Samba] Question about filtering

2012-11-10 Thread Andrew Bartlett
on the local or on the remote one? Thanks in advance! You would need a network capture to be sure - the client can do either in theory, but the protocol is perfectly capable of doing this remotely. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] SYSVOL ACLs and GPOs

2012-11-10 Thread Andrew Bartlett
On Thu, 2012-11-01 at 14:54 +, Alex Matthews wrote: On 30/10/2012 00:08, Jeremy Allison wrote: On Tue, Oct 30, 2012 at 11:00:31AM +1100, Andrew Bartlett wrote: be a particular trigger - but it shouldn't be able to make a modification that doesn't go via vfs_acl_xattr. For Alex

Re: [Samba] libkdc-policy.so: cannot open shared object file: No such file or directory?

2012-11-07 Thread Andrew Bartlett
. This command will remove *EVERYTHING* that isn't committed to git, which of course includes all our build artefacts. git clean -x -f -d Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Re: [Samba] Samba Active Directory w/ Kerberos Trust

2012-11-05 Thread Andrew Bartlett
to dig in further into why we return LOGON_FAILURE with a higher log level and our debug logs. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] [PATCH] Re: SYSVOL ACLs and GPOs

2012-11-05 Thread Andrew Bartlett
On Mon, 2012-11-05 at 22:02 +0100, Jelmer Vernooij wrote: On Mon, Nov 05, 2012 at 01:10:13PM +1100, Andrew Bartlett wrote: On Thu, 2012-11-01 at 14:54 +, Alex Matthews wrote: On 30/10/2012 00:08, Jeremy Allison wrote: On Tue, Oct 30, 2012 at 11:00:31AM +1100, Andrew Bartlett wrote

Re: [Samba] Provision Samba4 on Macosx snow leopard

2012-11-05 Thread Andrew Bartlett
As the command said: On Sat, 2012-11-03 at 15:02 +, gof wrote: Please remove the smb.conf file and let provision generate it -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe

Re: [Samba] Samba Active Directory w/ Kerberos Trust

2012-11-05 Thread Andrew Bartlett
on the AD DC). You must log in with kerberos - ie kinit first, then sun smbclient -k (for example) or use a windows client already logged in with kerberos credentials. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

[SCM] Samba Shared Repository - branch master updated

2012-11-05 Thread Andrew Bartlett
- commit ab30a8bf0fb9bd4ee3c907183132f3b9abb67c7a Author: Andrew Bartlett abart...@samba.org Date: Mon Nov 5 20:44:14 2012 +1100 provision: Make dsacl2fsacl() take a security.dom_sid, not str Reviewed-by: Jelmer Vernooij jel...@samba.org Signed-off

[SCM] Samba Shared Repository - branch master updated

2012-11-05 Thread Andrew Bartlett
with the system heimdal, as gssapi/gssapi_spnego.h is included. Reviewed-by: Andrew Bartlett abart...@samba.org Signed-off-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Nov 6 05:12:28 CET

[Samba] [PATCH] Re: SYSVOL ACLs and GPOs

2012-11-04 Thread Andrew Bartlett
On Thu, 2012-11-01 at 14:54 +, Alex Matthews wrote: On 30/10/2012 00:08, Jeremy Allison wrote: On Tue, Oct 30, 2012 at 11:00:31AM +1100, Andrew Bartlett wrote: be a particular trigger - but it shouldn't be able to make a modification that doesn't go via vfs_acl_xattr. For Alex

Re: [Samba] provisioning fails

2012-11-04 Thread Andrew Bartlett
, -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] libkdc-policy.so: cannot open shared object file: No such file or directory?

2012-11-04 Thread Andrew Bartlett
. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] sambar4: user creation with ldap and initial password

2012-11-04 Thread Andrew Bartlett
however the userPassword, which is a normal, utf8 unquoted string (ie, sane :-) Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following

Re: [Samba] ldbsearch returning NT_STATUS_INVALID_PARAMETER

2012-11-04 Thread Andrew Bartlett
by name), so we fail if presented with an IP address. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Samba Active Directory w/ Kerberos Trust

2012-11-04 Thread Andrew Bartlett
try and involve PAM or turn off encrypted passwords, because we never get a plaintext password from modern clients anyway. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Re: [Samba] libkdc-policy.so: cannot open shared object file: No (samba: message 2 of 20) such file or directory?

2012-11-04 Thread Andrew Bartlett
binary, or after running 'make' again (as we re-link for installation) run bin/samba-tool in the build directory. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from

Re: [Samba] sambar4: user creation with ldap and initial password

2012-11-04 Thread Andrew Bartlett
On Mon, 2012-11-05 at 08:18 +0100, Thomas Mueller wrote: Am 05.11.2012 04:31, schrieb Andrew Bartlett: On Thu, 2012-11-01 at 12:44 +, Thomas Mueller wrote: hi trying to create a user with ldap from a remote server. The user is created successfully. I'm failing setting the initial

[SCM] Samba Shared Repository - branch master updated

2012-11-04 Thread Andrew Bartlett
- commit c452efe977753a44807dd12a1b2ff8ce1387bfa6 Author: Andrew Bartlett abart...@samba.org Date: Sat Nov 3 09:57:40 2012 +1100 selftest: Add skip for DIR1 test which loops on 64 bit ext4 Reviewed-by: Jelmer Vernooij jel...@samba.org

[SCM] Samba Shared Repository - branch master updated

2012-11-04 Thread Andrew Bartlett
- commit 71e1c080cbd033b3118952c2da05186252fc411a Author: Andrew Bartlett abart...@samba.org Date: Mon Nov 5 09:46:49 2012 +1100 libads: Always free the talloc_stackframe() on error path Reviewed-by: Michael Adam ob...@samba.org Autobuild-User

Re: [Samba] Restricting DC Roles?

2012-11-01 Thread Andrew Bartlett
on it, and lsof reveals that the signed socket is indeed being read by samba. I am not having any other authentication issues with kerberos. Is this a known issue by chance? Thanks! No, it is not, sorry. Please file a bug with network captures etc. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] samba4: audit logs

2012-10-31 Thread Andrew Bartlett
can't find these in the logfile. We don't really have anything like that in an organised fashion right now. Sorry, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe

Re: [Samba] [PATCH] Re: can not change mandatory owner to administrators

2012-10-31 Thread Andrew Bartlett
it to administrators in release notes, I'll try and get that set when we fix the release branch. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] Error installing samba4 on snow leopard OS

2012-10-30 Thread Andrew Bartlett
On Mon, 2012-10-29 at 00:26 +, gof wrote: Support I've downloaded samba 4 on snow leopard and when I compile it I get an error by running 'Make test error: This patch, from master, should fix it. -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] ntlm_auth allowing users which are denied access

2012-10-30 Thread Andrew Bartlett
. There is nothing that ntlm_auth does to indicate to the DC that this is for a remote access server, compared with say, Squid or a CIFS login. That's why it doesn't fail. Perhaps the --require-membership-of option might help, but I don't know what that particular GUI option sets. Andrew Bartlett

Re: [Samba] samba4 rc4 not configure in freebsd 9.1

2012-10-30 Thread Andrew Bartlett
for xattr support. At this point master and v4-0-test have diverged, which is why there are these differences. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org From

Re: [Samba] Unable to create GPO with rc3 and a few authentication problems

2012-10-30 Thread Andrew Bartlett
/Policies after samba-tool ntacl sysvolreset). So, should samba-tool really use machine account for GPO operations? Probably not for write operations. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Re: [Samba] Unable to create GPO with rc3 and a few authentication problems

2012-10-30 Thread Andrew Bartlett
access error will raise (due to the fact machine accounts do not have write permissions on sysvol/fqdn/Policies after samba-tool ntacl sysvolreset). So, should samba-tool really use machine account for GPO operations? Probably not for write operations. Andrew Bartlett

[SCM] Samba Shared Repository - branch master updated

2012-10-30 Thread Andrew Bartlett
s3fs-utils: Free the popt context in smbcacls and smbquotas. http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log - commit a71ad96bd046f1199e67b4fe8fc7783cbd8dd771 Author: Andrew Bartlett abart...@samba.org Date: Tue Oct 30

Re: [Samba] Domain DFS on samba 4

2012-10-29 Thread Andrew Bartlett
Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Joining domain without password?

2012-10-29 Thread Andrew Bartlett
delegate the privilege of joining machines to the domain, which may lessen the impact of the password or kerberos ticket/keytab you forward, but the shared secret needs to be securely set up somehow. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] Samba4 additional schema

2012-10-28 Thread Andrew Bartlett
in your way. Because of that, and out of caution we still disallow them by default. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-26 Thread Andrew Bartlett
On Fri, 2012-10-26 at 00:49 +0100, Alex Matthews wrote: On 26/10/2012 00:34, Alex Matthews wrote: On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-26 Thread Andrew Bartlett
that was generated. (this patch is in master) Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org From 88df69b860c3d503846872d7624cd38f969185a7 Mon Sep 17 00:00:00 2001 From: Andrew Bartlett abart

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-26 Thread Andrew Bartlett
gpmc.msc once seems key), I think I have the steps to reproduce this here, which I'll try tonight or tomorrow. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from

Re: [Samba] Restricting DC Roles?

2012-10-26 Thread Andrew Bartlett
on? This fix I just put in master is almost certainly for this problem. If it doesn't apply, then just run 'sh -c 'umask 0 samba-tool ntacl sysvolreset' to remove the umask for the duration of this operation. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

[SCM] Samba Shared Repository - branch master updated

2012-10-26 Thread Andrew Bartlett
cb50e85a5a054eeb59bf4c27c886679285732548 Author: Andrew Bartlett abart...@samba.org Date: Fri Oct 26 14:23:39 2012 +1100 vfstest: set umask(0) in vfstest Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Fri Oct 26 10:07:03 CEST 2012 on sn-devel-104 commit

[SCM] Samba Shared Repository - branch master updated

2012-10-26 Thread Andrew Bartlett
=samba.git;a=shortlog;h=master - Log - commit 3180a1082a79698a69f6721282cb8c45900f884c Author: Andrew Bartlett abart...@samba.org Date: Sat Oct 27 10:59:43 2012 +1100 sefltest: use TestCaseInTempDir and setUp/tearDown

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Andrew Bartlett
On Thu, 2012-10-25 at 10:01 +0100, Alex Matthews wrote: On 25/10/2012 02:31, Andrew Bartlett wrote: On Wed, 2012-10-24 at 18:36 +0100, Alex Matthews wrote: On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex

Re: [Samba] Compiling samba4 hangs at [1815/3978] Compiling librpc/ndr/ndr_basic.c

2012-10-25 Thread Andrew Bartlett
code. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Andrew Bartlett
'log level = 10' in your smb.conf, then re-run and send me (personally) the result compressed with xz. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list

Re: [Samba] Compiling samba4 hangs at [1815/3978] Compiling librpc/ndr/ndr_basic.c

2012-10-25 Thread Andrew Bartlett
. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options

Re: [Samba] new Win7 security setting broke Samba

2012-10-25 Thread Andrew Bartlett
here. Perhaps they also set a smb signing policy, and you didn't enable smb signing, or you are running 'security=server', which is incompatible with NTLMv2? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Andrew Bartlett
On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews wrote: samba-tool ntacl sysvolcheck shows: sudo /usr/local/samba/bin/samba-tool ntacl sysvolcheck ERROR(class

Re: [Samba] Compiling samba4 hangs at [1815/3978] Compiling librpc/ndr/ndr_basic.c

2012-10-25 Thread Andrew Bartlett
what I'm looking for, I'll go hunting. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] Restricting DC Roles?

2012-10-25 Thread Andrew Bartlett
suggestion is to manually replicate the sysvol share. Sadly we don't have a tool for that either. We know this is not a great situation, but it just hasn't been possible to handle yet. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Andrew Bartlett
On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32 +0100, Alex Matthews wrote: samba-tool ntacl sysvolcheck shows: sudo /usr/local/samba/bin

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-25 Thread Andrew Bartlett
On Fri, 2012-10-26 at 00:34 +0100, Alex Matthews wrote: On 25/10/2012 23:27, Andrew Bartlett wrote: On Thu, 2012-10-25 at 21:48 +1100, Andrew Bartlett wrote: On Thu, 2012-10-25 at 11:41 +0100, Alex Matthews wrote: On 25/10/2012 11:30, Andrew Bartlett wrote: On Thu, 2012-10-25 at 10:32

[SCM] Samba Shared Repository - branch master updated

2012-10-25 Thread Andrew Bartlett
/?p=samba.git;a=shortlog;h=master - Log - commit e9b6b23fbdafff700ceb788dbff2ba69584ff833 Author: Andrew Bartlett abart...@samba.org Date: Thu Oct 25 16:27:19 2012 +1100 selftest: Add many more tests for our posix ACL handling

[SCM] Samba Shared Repository - branch master updated

2012-10-25 Thread Andrew Bartlett
- commit a2d53262e835b0c74282d389b1dd6dad2395f0f1 Author: Andrew Bartlett abart...@samba.org Date: Wed Oct 24 18:24:12 2012 +1100 python-ntacls: Cope with ACL revision 4 This is the new revision with the hash of the posix or system ACL. Andrew

Re: [Samba] Error

2012-10-24 Thread Andrew Bartlett
gives this error, please configure with --abi-check-disable to skip this check -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Compiling samba4 hangs at [1815/3978] Compiling librpc/ndr/ndr_basic.c

2012-10-24 Thread Andrew Bartlett
, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Error

2012-10-24 Thread Andrew Bartlett
On Wed, 2012-10-24 at 11:00 +0200, Michael Wood wrote: Hi Andrew On 24 October 2012 10:06, Andrew Bartlett abart...@samba.org wrote: On Tue, 2012-10-23 at 18:16 -0400, sandy.napo...@eccmg.cupet.cu wrote: [...] See this line: If you have not changed any ABI, and your platform always

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-24 Thread Andrew Bartlett
help me guess as what is going wrong here, and fix it. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Error

2012-10-24 Thread Andrew Bartlett
On Wed, 2012-10-24 at 20:05 +1100, Andrew Bartlett wrote: On Wed, 2012-10-24 at 11:00 +0200, Michael Wood wrote: Hi Andrew On 24 October 2012 10:06, Andrew Bartlett abart...@samba.org wrote: On Tue, 2012-10-23 at 18:16 -0400, sandy.napo...@eccmg.cupet.cu wrote: [...] See

Re: [Samba] SYSVOL ACLs and GPOs

2012-10-24 Thread Andrew Bartlett
On Wed, 2012-10-24 at 18:36 +0100, Alex Matthews wrote: On 24/10/2012 17:25, Alex Matthews wrote: On 24/10/2012 12:09, Andrew Bartlett wrote: On Wed, 2012-10-24 at 10:49 +0100, Alex Matthews wrote: Hi, I have installed a virtual testing network consisting of one samba4 PDC (latest git

Re: [Samba] Compiling samba4 hangs at [1815/3978] Compiling librpc/ndr/ndr_basic.c

2012-10-24 Thread Andrew Bartlett
the ccache package help? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

[SCM] Samba Shared Repository - branch master updated

2012-10-24 Thread Andrew Bartlett
- commit 9dbb64563c35003311d3f3d47e6c4ef0f546ffab Author: Andrew Bartlett abart...@samba.org Date: Wed Oct 24 16:41:52 2012 +1100 dsdb-cracknames: Return DRSUAPI_DS_NAME_STATUS_NO_MAPPING when there is no SID If there is no SID

Re: [Samba] DNS Domain Name vs Samba4 Domain Name vs NT4 Domain Name

2012-10-23 Thread Andrew Bartlett
of interest, why try to keep the same name if you don't want to migrate it, and why don't you want to migrate it? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list

[Samba] machine password change timeout (was: Re: Old, reliable samba 3.5 and Active directory suddenly not reliable)

2012-10-23 Thread Andrew Bartlett
On Tue, 2012-10-23 at 11:14 -0400, Robert M. Martel - CSU wrote: On 10/22/2012 05:10 PM, Andrew Bartlett wrote: On Mon, 2012-10-22 at 14:51 -0400, Robert M. Martel - CSU wrote: [2012/10/22 14:23:07.353280, 0] libads/kerberos.c:333(ads_kinit_password) kerberos_kinit_password

Re: [Samba] Samba4 upgrade compatability

2012-10-23 Thread Andrew Bartlett
Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 upgrade compatability

2012-10-23 Thread Andrew Bartlett
, but we now have a 2sec DNS timeout to reduce the number of open file descriptors. The issue is the default 1024 FD ulimit (and we use a lot - perhaps too many - internally for other things). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication

[SCM] Samba Shared Repository - branch master updated

2012-10-23 Thread Andrew Bartlett
7138b2138ba1f67386c6aa1e1c5ef49fde07cc41 Author: Andrew Bartlett abart...@samba.org Date: Tue Oct 23 17:53:58 2012 +1100 build: Add #define FREEBSD on FreeBSD This makes waf match autoconf Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Oct 23 11

[SCM] Samba Shared Repository - branch master updated

2012-10-23 Thread Andrew Bartlett
. See also https://lists.samba.org/archive/samba-technical/2012-October/087164.html metze Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Oct 23 14:44:21 CEST 2012 on sn-devel-104

[SCM] Samba Shared Repository - branch master updated

2012-10-23 Thread Andrew Bartlett
8697acd4b08354fb4185b05da07f4399bda917bc Author: Andrew Bartlett abart...@samba.org Date: Wed Oct 24 11:56:02 2012 +1100 dsdb-cracknames: Always use talloc_zero() Otherwise, we will return un-initialised values to the caller, which will attempt to push them onto the wire

Re: [Samba] Old, reliable samba 3.5 and Active directory suddenly not reliable

2012-10-22 Thread Andrew Bartlett
the password have been expired? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

Re: [Samba] freebsd + samba4rc3 = 100% CPU

2012-10-21 Thread Andrew Bartlett
. If you can validate the patch, I think we get get it into the RC releases. Note that per the release notes we still have an outstanding issue with FreeBSD rejecting lookup of names containing _. We don't currently have a workaround for this platform limitation. Andrew Bartlett -- Andrew

Re: [Samba] Samba4 - multiple forest hosting?

2012-10-21 Thread Andrew Bartlett
servers for redundancy anyway. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

Re: [Samba] [samba] build samba4 for arm!

2012-10-19 Thread Andrew Bartlett
and patch it up (the code is all under buildtools, being waf and our wrappers on waf), otherwise you may need to build native. Sorry, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

[SCM] Samba Shared Repository - branch master updated

2012-10-18 Thread Andrew Bartlett
64886e312fe76145c2c4bc900b794274594368aa Author: Alexander Wuerstlein a...@arw.name Date: Sun Sep 30 04:32:01 2012 +0200 Warn when setting UID/GID without idmap_ldb:use rfc2307 = Yes Signed-off-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org

Re: [Samba] [PATCH] Re: can not change mandatory owner to administrators

2012-10-17 Thread Andrew Bartlett
On Tue, 2012-10-16 at 18:09 +1100, Andrew Bartlett wrote: On Tue, 2012-10-16 at 13:17 +1100, Andrew Bartlett wrote: On Sat, 2012-10-13 at 19:30 +1100, Andrew Bartlett wrote: On Sat, 2012-10-13 at 09:58 +0330, Mohammad Ebrahim Abravi wrote: Solved Thanks a lot Thanks

[SCM] Samba Shared Repository - branch master updated

2012-10-17 Thread Andrew Bartlett
. Signed-off-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Wed Oct 17 12:55:44 CEST 2012 on sn-devel-104 commit 83d34bb2bbcbc0ebbcb81825590363e996979e08 Author: Andrew Bartlett abart...@samba.org Date: Tue Oct 16 15

Re: [Samba] samba3 to samba4 // logon hours // server role secrets.tdb, secrets.ldb

2012-10-16 Thread Andrew Bartlett
show me the input and output smb.conf files. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions

Re: [Samba] [PATCH] Re: can not change mandatory owner to administrators

2012-10-16 Thread Andrew Bartlett
On Tue, 2012-10-16 at 13:17 +1100, Andrew Bartlett wrote: On Sat, 2012-10-13 at 19:30 +1100, Andrew Bartlett wrote: On Sat, 2012-10-13 at 09:58 +0330, Mohammad Ebrahim Abravi wrote: Solved Thanks a lot Thanks. The root of the issue is this automatically generated entry

[Samba] [PATCH] Re: can not change mandatory owner to administrators

2012-10-15 Thread Andrew Bartlett
On Sat, 2012-10-13 at 19:30 +1100, Andrew Bartlett wrote: On Sat, 2012-10-13 at 09:58 +0330, Mohammad Ebrahim Abravi wrote: Solved Thanks a lot Thanks. The root of the issue is this automatically generated entry in your idmap.ldb: # record 12 dn: CN=S-1-5-32-544 cn: S-1-5-32

Re: [Samba] Change DNS method?

2012-10-15 Thread Andrew Bartlett
On Sun, 2012-10-14 at 15:31 -0700, Matthieu Patou wrote: On 10/14/2012 03:17 PM, Andrew Bartlett wrote: On Sun, 2012-10-14 at 15:02 +, Steve wrote: Is it possible to change from the internal name server to BIND once you've provisioned a domain? I set mine up with the internal since

Re: [Samba] samba3 to samba4 // logon hours // server role secrets.tdb, secrets.ldb

2012-10-15 Thread Andrew Bartlett
;-) Exactly what command did you run? We should upgrade a ROLE_DOMAIN_PDC into an 'server role = active directory domain controller'. Are you sure you are using the smb.conf produced by the upgrade? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] Change DNS method?

2012-10-14 Thread Andrew Bartlett
with the bind9 DLZ side of things, then certainly, this might be practical. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL

Re: [Samba] file sharing issue in samba4

2012-10-14 Thread Andrew Bartlett
things. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] can not change mandatory owner to administrators

2012-10-13 Thread Andrew Bartlett
papered over this issue (didn't deal with file ownership at a unix level), but the smbd file server needs to correctly set posix permissions. I hope this clarifies things. If you can please file a bug, I'll try not to forget this. Thanks, Andrew Bartlett -- Andrew Bartlett

Re: [Samba] can not change mandatory owner to administrators

2012-10-12 Thread Andrew Bartlett
Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[SCM] Samba Shared Repository - branch master updated

2012-10-11 Thread Andrew Bartlett
- commit 1ec5486338772cecf953e150ebb717a8845c98d4 Author: Andrew Bartlett abart...@samba.org Date: Thu Oct 11 22:29:43 2012 +1100 smbd: Always free the talloc_stackframe() before leaving smbd_do_query_security_desc Autobuild-User(master): Andrew

provision: Always create DNS user.

2012-10-11 Thread Andrew Bartlett
it to be removed). Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

<    10   11   12   13   14   15   16   17   18   19   >