Re: [Samba] 3.6.12 winbind problem

2013-02-14 Thread Christopher Chan
On Thursday, February 14, 2013 03:33 PM, Christopher Chan wrote: On Thursday, February 14, 2013 03:09 PM, Christopher Chan wrote: On Thursday, February 14, 2013 02:19 PM, Christopher Chan wrote: winbind has problems resolving gid sids. I get cli_rpc_pipe_open_schannel_with_key failed

[Samba] 3.6.12 winbind problem

2013-02-13 Thread Christopher Chan
winbind has problems resolving gid sids. I get cli_rpc_pipe_open_schannel_with_key failed: NT_STATUS_UNSUCCESSFUL in the debug output each time I try to look up a group name. e.g. wbinfo -n domain\ users wbinfo -s of group SIDs will fail with: failed to call wbcLookupSid:

Re: [Samba] 3.6.12 winbind problem

2013-02-13 Thread Christopher Chan
On Thursday, February 14, 2013 02:19 PM, Christopher Chan wrote: winbind has problems resolving gid sids. I get cli_rpc_pipe_open_schannel_with_key failed: NT_STATUS_UNSUCCESSFUL in the debug output each time I try to look up a group name. e.g. wbinfo -n domain\ users wbinfo -s of group

Re: [Samba] 3.6.12 winbind problem

2013-02-13 Thread Christopher Chan
On Thursday, February 14, 2013 03:09 PM, Christopher Chan wrote: On Thursday, February 14, 2013 02:19 PM, Christopher Chan wrote: winbind has problems resolving gid sids. I get cli_rpc_pipe_open_schannel_with_key failed: NT_STATUS_UNSUCCESSFUL in the debug output each time I try to look up

Re: [Samba] Problems accessing Windows shares 3.5.8 vs 3.6.3

2012-04-16 Thread Christopher Chan
samba 3.5.14 runs fine on OpenIndiana. samba 3.5.4-8 have issues on any platform in certain cases like using winbind + rid/ldap backend. On Monday, April 16, 2012 10:15 PM, Rob LaRose wrote: As I recall, Win2008 was the end of the line for Samba-on-Solaris10 for us. We adopted a product

Re: [Samba] samba authenticating users via kerberos failure

2012-04-02 Thread Christopher Chan
On Monday, April 02, 2012 12:45 PM, Christopher Chan wrote: On Friday, March 30, 2012 05:40 PM, Christopher Chan wrote: What does this mean? A configuration problem? Yep. thanks to Andrew Barlett, the problem was identified as kerberos method = system tab. Switching back to default solved

Re: [Samba] samba authenticating users via kerberos failure

2012-04-01 Thread Christopher Chan
On Friday, March 30, 2012 05:40 PM, Christopher Chan wrote: When users try to access the samba server via \\shortname, they get a dialog prompting them for their username and password. Access via \\ip.addr does not exhibit that though. samba 3.5.13 + winbind + idmap_ldap backend Logs from

[Samba] samba authenticating users via kerberos failure

2012-03-30 Thread Christopher Chan
When users try to access the samba server via \\shortname, they get a dialog prompting them for their username and password. Access via \\ip.addr does not exhibit that though. samba 3.5.13 + winbind + idmap_ldap backend Logs from samba during attempts to access via \\shortname: From

[Samba] winbind in 3.5.x does not automatically allocate uids

2012-01-30 Thread Christopher Chan
hi all, I am using samba 3.5.5 with ldap as the backend for winbind. It will create entries in ou=Idmap,dc=bradbury,dc=lan if I run wbinfo --set-u/gid-mapping but it won't do it automatically. What gives? What's different about idmap_ldap in 3.5.x compared to previous versions of samba?

Re: [Samba] samba 3.5.6, winbindd and getent/id

2010-12-09 Thread Christopher Chan
On Thursday, December 09, 2010 06:13 PM, Eugene M. Zheganin wrote: Hi. On 04.12.2010 01:18, Volker Lendecke wrote: You are not the first to say that. Many others, including me, are having winbind problems after upgrading to 3.5.x. Interestingly enough, the problems are quite disparate between

[Samba] winbind with ldap backend on samba 3.5.4

2010-12-08 Thread Christopher Chan
Hi list, Okay, I have mostly got the disabling errors of samba 3.5.4 on Openindiana sorted. Things like child smbd processes core dumping/dying (max groups set to 16 only by default in opensolaris kernel) and being unable to create sid-uid/sid-gid mappings. What remains is finding out why

Re: [Samba] samba 3.5.6, winbindd and getent/id

2010-12-02 Thread Christopher Chan
On Thursday, December 02, 2010 03:38 PM, Eugene M. Zheganin wrote: Hi. I'm using samba to authenticate squid users in Windows AD, and to provide 'em some statistics on the Internet usage. As this requires the existence of windows users in Unix environment, I use nsswitch.conf and nss_winbind.so

Re: [Samba] samba 3.5.6, winbindd and getent/id

2010-12-02 Thread Christopher Chan
On Thursday, December 02, 2010 10:09 PM, Eugene M. Zheganin wrote: Hi. On 02.12.2010 15:02, Christopher Chan wrote: wbinfo -u/-g should work if the configuration is correct. At least they work for me on 3.5.4. Yeah, at least for me it used to work on 3.0.x and 3.4.9. So the configuration

Re: [Samba] [ob...@samba.org: 3.6:idmap:Q2: get rid of (all/most) idmap alloc parameters for idmap_ldap ?]

2010-11-30 Thread Christopher Chan
. If I loose track due to being busy with other topics, I am thankful for any reminder to fix my bugs... :-) Cheers - Michael Christopher Chan wrote: Hi Michael, I, for one, am using config alloc because that is how things were done on 3.0.xx before I migrated data to a new box that uses 3.5.4. I do

Re: [Samba] [ob...@samba.org: 3.6:idmap:Q2: get rid of (all/most) idmap alloc parameters for idmap_ldap ?]

2010-11-28 Thread Christopher Chan
Hi Michael, I, for one, am using config alloc because that is how things were done on 3.0.xx before I migrated data to a new box that uses 3.5.4. I do not care very much about the configuration changes. But I beg you that documentation regarding idmap_ldap is updated including how idmap_ldap

Re: [Samba] Active directory in Ubuntu

2010-10-31 Thread Christopher Chan
On Friday, October 29, 2010 01:53 AM, Dale Schroeder wrote: Tommie, To emulate an Active Directory DC, you will have to use Samba 4. Note that Samba 4 is still in alpha, but some have reported using it successfully in production environments. http://wiki.samba.org/index.php/Samba4 Does

Re: [Samba] Kerberos5 ticket renewal 'net ads join' w/o authentication

2010-10-31 Thread Christopher Chan
On Friday, October 29, 2010 07:58 AM, Philipoff, Andrew wrote: However I do not know how to enable the execution the 'net ads join' command without supplying a password. Get a ticket first? -- To unsubscribe from this list go to the following URL and read the instructions:

Re: [Samba] Samba 3.5.6, Solaris 10, pam_winbind.so will not link

2010-10-31 Thread Christopher Chan
On Friday, October 29, 2010 11:34 PM, Robert M. Martel - CSU wrote: On 10/27/2010 06:04 PM, Christopher Chan wrote: On Wednesday, October 27, 2010 09:50 PM, Robert M. Martel - CSU wrote: Still no progress trying to get Samba 3.5.6 built on Solaris 10, using gcc 3.4.6. Isn't it bad to use

Re: [Samba] Samba 3.5.6, Solaris 10, pam_winbind.so will not link

2010-10-27 Thread Christopher Chan
On Wednesday, October 27, 2010 09:50 PM, Robert M. Martel - CSU wrote: Greetings, Still no progress trying to get Samba 3.5.6 built on Solaris 10, using gcc 3.4.6. Isn't it bad to use gcc for this? pam_winbind and nss_winbind would be using gcc ABI while the rest of the system using Sun

[Samba] samba 3.5.4 on openindiana 147 - kerberos spnego issues

2010-10-26 Thread Christopher Chan
hi all, I am having a problem with the samba packaged by Openindiana 147. It is setup to use winbind, a ldap backend and to be an AD member. Computers trying to authenticate themselves fail when samba negotiates ntlmv2 authentication which apparently does not use winbind. Just about