Re: [Samba] ldbedit syntax problem

2013-09-22 Thread Gémes Géza
2013-09-22 21:09 keltezéssel, steve írta: On Sun, 2013-09-22 at 13:36 +0100, Rowland Penny wrote: On 22/09/13 13:04, steve wrote: Hi How do I ldbedit this dn? CN=*,OU=auto.users,ou=automount,DC=bar,DC=foo It's the * that I can't get. Cheers, Steve Hi Steve, how about 'ldbedit -e nano

Re: [Samba] moodle + samba4 authentication

2013-08-15 Thread Gémes Géza
2013-08-14 20:50 keltezéssel, Darek Frączkiewicz írta: hello, has anyone tried to log in from Moodle to samba4 AD users? I can't config LDAP authentication. Through MS ActiveDirectory doesn't work. Pozdrowienia -- Darek Frączkiewicz daf...@gmail.com

Re: [Samba] Remote linux auth vs samba4: winbind or nslcd + openldap.

2013-08-15 Thread Gémes Géza
2013-08-15 18:45 keltezéssel, Andres Tello Abrego írta: I'm lost in documentation. I setup a samba4 AD, and configured winbind so I can have local authentification using pam, I can now login to AD users vía ssh. I want to achieve the Holy Gria of 1 source of users and password, for both, linux

Re: [Samba] Samba4 Using AD/UNIX attributes for home directory and shell not possible?

2013-08-10 Thread Gémes Géza
Hi, Hi, I'm would like to use the attributes in AD for home directory (homeDirectory) and the login shell (loginShell) for users logging in via ssh to a linux box. Samba 4.x has (from the point of view of domain membership) two modes: 1. Active directory domain controller 2. Standalone,

Re: [Samba] Debian Package Updates

2013-08-08 Thread Gémes Géza
2013-08-08 02:11 keltezéssel, Andrew Bartlett írta: On Wed, 2013-08-07 at 17:58 +0100, Dominic Evans wrote: On 5 August 2013 01:28, Andrew Bartlett abart...@samba.org wrote: On Fri, 2013-08-02 at 14:41 +0100, Dominic Evans wrote: The debian package of samba4 is still sitting at 4.0.3 in

Re: [Samba] Logon scripts, home directories, and Samba4 AD

2013-07-03 Thread Gémes Géza
Hi, This could do the job Identify the home share on your samba3 fileserver (certain it is member of your samba4 domain?!) as dfs root Ex: msdfs root= yes On samba4 ads [home] msdfs proxy= \your-samba3-server\homes read only = No with rsat point to \your-samba3-server\homes

Re: [Samba] samba4 pdc: Import sudoers active directory schema to ldb

2013-06-29 Thread Gémes Géza
2013-06-29 11:00 keltezéssel, george Nopicture írta: Hi guys and congrats for bringing a fantastic project to the open source world. I' ve setup a samba4 pdc succefully and i am able to do domain logins. I was also able to add the automount schema into the ldb. But when it comes to sudoers

Re: [Samba] SAMBA4 vs Windows 2008 AD

2013-06-05 Thread Gémes Géza
2013-06-05 09:29 keltezéssel, Mario Almeida írta: Thanks Geza, We only need for centralist authentication and for deploying group policies. Using windows XP I create group policy and keep in sysvol folder and sync the sysvol folder on BDC (samba) everything should work fine? Regards, Remy

Re: [Samba] SAMBA4 vs Windows 2008 AD

2013-06-03 Thread Gémes Géza
2013-05-26 10:46 keltezéssel, Mario Almeida írta: Hi All, Is there any answer? On Sat, May 25, 2013 at 7:43 PM, Mario Almeida malme...@isa.ae wrote: Hi All, I am planning to covert our company's AD server to Samba4, need to know if Samba4 is complete replacement for Windows 2008 AD. Is

Re: [Samba] Winbind strip domain from username?

2013-04-16 Thread Gémes Géza
= No Thanks for your help! Cheers! On 2013-04-16, at 12:09 AM, Gémes Géza g...@kzsdabas.hu wrote: 2013-04-15 23:12 keltezéssel, Luc Lalonde írta: Hello Folks, This directive works with Samba3 but does not seem to work with Samba-4.0.5: winbind use default domain = Yes I want to get a username

Re: [Samba] file share necessary?

2013-04-15 Thread Gémes Géza
2013-04-15 06:21 keltezéssel, Geoff Crompton írta: On 15/04/13 14:07, Marc Muehlfeld wrote: Am 15.04.2013 04:23, schrieb Geoff Crompton: On https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO#Setup_a_basic_File_Share the instructions says For the server to be useful you, will need to

Re: [Samba] samba4 rfc2307 practice and confuse

2013-04-15 Thread Gémes Géza
2013-04-15 11:51 keltezéssel, d tbsky írta: 2013/4/15 steve st...@steve-ss.com Yes. To get the rfc2307 info out from the directory you can use winbind, nslcd or sssd on the client. If you want to get all of the rfc2307 attributes on the DC, your choice is narrowed down to the latter two. As

Re: [Samba] Winbind strip domain from username?

2013-04-15 Thread Gémes Géza
2013-04-15 23:12 keltezéssel, Luc Lalonde írta: Hello Folks, This directive works with Samba3 but does not seem to work with Samba-4.0.5: winbind use default domain = Yes I want to get a username that does not contain the domain (GIGL). Instead here's what I get: [root@roquefort ~]# getent

Re: [Samba] python scripting samba

2013-04-15 Thread Gémes Géza
2013-04-16 01:30 keltezéssel, Geoff Crompton írta: Can someone point me to some documentation on scripting samba user and group management from python? I'd much rather not do this via calls out to samba-tool, and if I could do this remotely (via LDAP like calls) I'd be even happier. Cheers,

Re: [Samba] file share necessary?

2013-04-14 Thread Gémes Géza
2013-04-15 04:23 keltezéssel, Geoff Crompton írta: On https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO#Setup_a_basic_File_Share the instructions says For the server to be useful you, will need to update it to have at least one share What do you need a file share for the server to be

Re: [Samba] samba4 rfc2307 practice and confuse

2013-04-13 Thread Gémes Géza
2013-04-13 18:49 keltezéssel, d tbsky írta: hi: I setup a small samba 4.0.5 AD DC server. my client is windows 7 and linux. and I use windows 7 with remote managment tools to manage rfc2307 account seetings of samba4 DC. I hope my users can use the same account to use windows and linux.

Re: [Samba] Samba4 member of an another « Samba4 » domain

2013-04-11 Thread Gémes Géza
2013-04-11 01:14 keltezéssel, François Lafont írta: Le 10/04/2013 06:59, Gémes Géza a écrit : You should check rfc2307 on the samba AD, if your users do not have uidNumber gidNumber attributes they are going to be ignored by the winbind daemon if you specify rfc2307 schema mode on the domain

Re: [Samba] LDAP (Schemas,Users) to Samba4 migration

2013-04-09 Thread Gémes Géza
2013-04-09 14:56 keltezéssel, alxgrb írta: Thank you for support. OK. If one has 10 users, it goes by hand, but we have ca. 110 users. Maybe there for it an automatic solution? -- View this message in context:

Re: [Samba] Samba4 member of an another « Samba4 » domain

2013-04-09 Thread Gémes Géza
2013-04-10 01:32 keltezéssel, François Lafont írta: Le 09/04/2013 09:34, Matthieu Patou a écrit : Le 08/04/2013 01:37, Matthieu Patou a écrit : Then, in the DC server, I have done: --- samba-tool domain provision # I keep the default answers each

Re: [Samba] ClassicUpgrade = EpicFail

2013-04-06 Thread Gémes Géza
2013-04-05 21:47 keltezéssel, Jon Detert írta: ClassicUpgrade of my samba3 data to samba4 fails, with this error: ERROR(class 'passdb.error'): uncaught exception - Unable to get id for sid Full log of the classicupgrade is at the end of this email. Project member on this list, Andrew

Re: [Samba] SAMBA4: pdbedit not changing SID

2013-04-01 Thread Gémes Géza
2013-04-01 02:36 keltezéssel, simon+sa...@matthews.eu írta: Since I don't seem to be having any luck with the classicupgrade, I decided to try starting from scratch and then adding users. I ran the command: /usr/local/samba/bin/samba-tool domain provision --realm=my realm \ --domain=mydomain

Re: [Samba] SAMBA4: pdbedit not changing SID

2013-04-01 Thread Gémes Géza
2013-04-02 05:35 keltezéssel, simon+sa...@matthews.eu írta: On Mon, 1 Apr 2013, simon+sa...@matthews.eu wrote: On Tue, 2 Apr 2013, Andrew Bartlett wrote: On Mon, 2013-04-01 at 09:26 +0200, Gémes Géza wrote: 2013-04-01 02:36 keltezéssel, simon+sa...@matthews.eu írta: Since I don't

Re: [Samba] Samba4 Dc Winbind and uidNumbers

2013-03-27 Thread Gémes Géza
Hi, On Wed, Mar 27, 2013 at 6:14 AM, Jim Potter jimchuf...@googlemail.com wrote: Hi all, I'm trying to get the unix extensions working in AD. I'm obviously missing something, but I can't see what... I've just created user Jim (using ADUC) and added a uidnumber (using ADSIEdit). From this and

Re: [Samba] Samba4 home share problem

2013-03-24 Thread Gémes Géza
Hi, Hi, I have installed Samba4 and the home share functionality is not working. Samba version: 4.0.1 OS: Debian Squeeze Kernel: 2.6.32-5-amd64 The smb.conf: [global] workgroup = TESZT realm = TESZT.HU netbios name = FILESERVER server role = active

Re: [Samba] Fwd: kerberos

2013-03-09 Thread Gémes Géza
2013-03-09 15:49 keltezéssel, Saad Benateigha írta: Sorry - Forwarded Message - From: Saad Benateigha sbenatei...@geomega.com To: Andrew Bartlett abart...@samba.org Sent: Friday, March 8, 2013 4:09:36 PM Subject: Re: [Samba] kerberos Andrew: I have found some information in the Samba

Re: [Samba] Samba4: Extending the Schema

2013-02-13 Thread Gémes Géza
2013-02-14 06:42 keltezéssel, Fabian von Romberg írta: Hi Bob, could you please share the link where you found in google how to enable it. Regards, Fabian Hi, You are probably looking for: http://technet.microsoft.com/en-us/library/cc737499%28v=ws.10%29.aspx Regards Geza Gemes -- To

Re: [Samba] Extend Samba4 Schema Scope

2013-02-12 Thread Gémes Géza
2013-02-13 06:20 keltezéssel, Vijay Thakur írta: Hi All Experts, I am about to extend our production Samba4 schema to add a few intra-organizational attributes (Employee ID,Passport No., Date of Joining, Date of Leaving) . How can I make change in my samba4 schema. I have already make a post

Re: [Samba] Samba4: Extending the Schema

2013-02-11 Thread Gémes Géza
2013-02-11 20:04 keltezéssel, Varoujan Avanessians írta: Hi We are thinking of Developing a corporate Directory application the would pull user information from Samba4 Ad. However for our needs we need some additional User attributes that don't seem to be available as part of the AD-schema,

Re: [Samba] generate keytab

2013-01-28 Thread Gémes Géza
Hi, Hi, does not http.keytab. exported thus: $samba-tool domain exportkeytab http.keytab --principal=HTTP/ ejbca.nisled@nisled.org ouput line: # klist -ke http.keytab Keytab name: WRFILE:http.keytab KVNO Principal

Re: [Samba] Samba4 Winbind - is it really not possible to be sensible?

2013-01-25 Thread Gémes Géza
2013-01-25 20:43 keltezéssel, Rob McCorkell írta: Samba3 allowed for the setting of idmaps and passdb backends to configure how users were pulled in. This made integrating with existing LDAP databases, other other forms of authentication easy, since Samba could be configured to present the

Re: [Samba] [Samba 4] Issues with uidNumber and gidNumber in AD for Linux clients

2013-01-22 Thread Gémes Géza
2013-01-22 15:52 keltezéssel, Fred F írta: Hi, I am still experimenting with Samba 4 and I'd like to serve both Windows and Linux clients with Samba (standalone AD server). The Windows-side is already working well. For serving Linux-clients I need to store the users' uidNumber and gidNumber in

Re: [Samba] Samba4 Key Management Server; DNS Failure To Register

2013-01-04 Thread Gémes Géza
2013-01-04 21:18 keltezéssel, Adam Tauno Williams írta: I have Microsoft Key Management server on a Windows 2003 server - joined to my new Samba4 AD domain. But the KMS is not available. In the event log it says: Event Type: Error Event Source: Software Licensing Service Event Category:

Re: [Samba] Samba4 - Bind Config with DHCP

2012-12-03 Thread Gémes Géza
First: please keep discussion on list. 2012-12-03 02:24 keltezéssel, Jorell írta: On 12/2/2012 7:32 AM, Hleb Valoshka wrote: On 11/23/12, Joubert, Dawie dawie.joub...@rhdhv.com wrote: My question is thus: How can I make Samba4 update the DNS entries and allow DHCP to update the entries?

Re: [Samba] Samba4 Classicupgrade Failed

2012-12-03 Thread Gémes Géza
2012-12-04 05:46 keltezéssel, Mario Codeniera írta: Uprading on a New Server (Running on Centos 6.3, OpenLDAP 2.4.23 migrated the data from existing server). I dunno know where to fix it, or someone gave some idea how it works? [root@gaara samba]# /usr/local/samba/bin/samba-tool domain

Re: [Samba] Samba4 - Bind Config with DHCP

2012-12-02 Thread Gémes Géza
2012-12-03 02:24 keltezéssel, Jorell írta: On 12/2/2012 7:32 AM, Hleb Valoshka wrote: On 11/23/12, Joubert, Dawie dawie.joub...@rhdhv.com wrote: My question is thus: How can I make Samba4 update the DNS entries and allow DHCP to update the entries? Somebody should add this link to howto :)

Re: [Samba] NIS to SAMBA4 Migration

2012-11-24 Thread Gémes Géza
Hi, I am also struggling to find up to date information on using Samba 4 with linux clients. I have managed to get the RFC 2307 fields by installing the 'NIS tools' feature on a W2k8 DC, and creating a 'NIS domain'. Previously I could see the fields, but could not select a NIS domain in the ADUC

Re: [Samba] NIS to SAMBA4 Migration

2012-11-23 Thread Gémes Géza
Hi, Hello Steve, The only way I have found to enable those options is to provision with --use-rfc2307. We are performing an upgrade from Samba3 and I noticed that the options were not grayed out after performing a classicupgrade, but were grayed out after a clean provision. I finally figured

Re: [Samba] Samba4 logon server against windows server 2003

2012-11-22 Thread Gémes Géza
2012-11-21 23:47 keltezéssel, Innocent Yevide írta: Hello, does any one knows how I can force samba4 to be the logon server against windows server 2003? I have below in my smb.conf but it doesn't help: domain logons = Yes domain master = Yes preferred master = Yes os level = 255

Re: [Samba] Samba4 logon server against windows server 2003

2012-11-22 Thread Gémes Géza
Adjusting the Weight and Priority for DNS SRV Records in the Registry on the Windowsserver so that the samba4 will be prioritized... but it doesn't help. Best Regards, Innocent. *De :* Gémes Géza g...@kzsdabas.hu *À

Re: [Samba] Migrating from windows server 2003 to SAMBA4

2012-11-02 Thread Gémes Géza
2012-11-02 15:30 keltezéssel, Innocent Yevide írta: Hello, I have an existing basic DC configured on windows server 2003, and would like to move/migrate it to Samba4. Is that possible, if so, could anyone tell me way to do it? Thanks beforehand. Inno. 1. Join samba4 with samba-tool domain

Re: [Samba] cant find provision

2012-10-31 Thread Gémes Géza
2012-10-31 22:35 keltezéssel, samba.to.anomal...@xoxy.net írta: The wiki and most of the how-to web sites reference this command to set up a new ad domain, but I can find this command anywhere in the file system, only a directory with .py commands. samba_upgradeprovision does not seem to support

Re: [Samba] PDC and BDCs : net rpc testjoin

2012-10-23 Thread Gémes Géza
:) My samba version is 3.5.10-116.el6_2. OS: Red Hat Enterprise Linux Server release 6.2 / Linux 2.6.32-131.6.1.el6.x86_64 Best regards, Marcio Oliveira. 2012/10/23 Gémes Géza g...@kzsdabas.hu 2012-10-22 20:10 keltezéssel, Marcio Oli írta: I think the question is simple, so anybody

Re: [Samba] PDC and BDCs : net rpc testjoin

2012-10-22 Thread Gémes Géza
2012-10-22 20:10 keltezéssel, Marcio Oli írta: I think the question is simple, so anybody could help me with this? The questions are: 1. The samba PDCs and BDCs have obligation to be joined to domain? In a samba3 (aka classic domain not) 2. The net rpc testjoin command must to

Re: [Samba] DNS Domain Name vs Samba4 Domain Name vs NT4 Domain Name

2012-10-21 Thread Gémes Géza
Hi, See inline: I am unclear on the relationship between the hostname, DNS domain, server's FQDN, NT4 domain name, etc. Quoting the HOWTO: For the rest of the HOWTO we will assume that your DNS domain name is samdom.example.com, your short (also known as NT4) domain name is samdom, your

Re: [Samba] How can I switch from internal dns server to bind9

2012-10-12 Thread Gémes Géza
2012-10-12 14:34 keltezéssel, fe...@epepm.cupet.cu írta: On Tue, 2012-10-09 at 17:18 -0400, fe...@epepm.cupet.cu wrote: On 10/9/12, fe...@epepm.cupet.cu fe...@epepm.cupet.cu wrote: How can I switch from internal dns server to bind9??? Add into [global] section of smb.conf server services =

Re: [Samba] [PATCH] allow to create Unix-UID/SID mapping in samba-tool user create

2012-09-25 Thread Gémes Géza
a UID/SID mapping when creating a new user. As Gémes Géza mentions this really needs to honour idmap_ldb:use rfc2307 = yes and set it in the sam.ldb if that is set, and while useful in the general case, for the case you are targeting, the classicupgrade will work better. Classicupgrade would only

Re: [Samba] samba4: samba-tool and (unix) uids

2012-09-24 Thread Gémes Géza
2012-09-24 22:52 keltezéssel, Thomas Karmann írta: Hello, at my universities CS computer pools we're trying to migrate our samba3 based NT domain to AD with samba4-rc1. In the past we had a little script which our users could run on their own from their linux account which created a samba user

Re: [Samba] Samba4, DHCP, BIND DLZ

2012-09-20 Thread Gémes Géza
2012-09-21 01:55 keltezéssel, Jeff írta: Hello, I have recently compiled, installed and configured samba4 to run on a FreeBSD server. samba -V reports the version to be Version 4.1.0pre1-GIT-57990cb. The server has working BIND 9.9 and ISC-DHCP services running on it. I have provisioned

Re: [Samba] Sysvol Replication in Samba4

2012-08-29 Thread Gémes Géza
2012-08-29 02:31 keltezéssel, Matthieu Patou írta: On 08/26/2012 10:24 PM, Gémes Géza wrote: Hi Matthieu! Thank you for the script. Could you also attach /usr/local/etc/ecv/list_dcs which is sourced? Well no :-( But this is defining the variable LIST_DC a bit like this: LIST_DC=dc1name

Re: [Samba] Support for Linux Authentication with Samba4's Internal LDAP Server

2012-08-28 Thread Gémes Géza
2012-08-28 10:32 keltezéssel, Andrew Bartlett írta: On Mon, 2012-08-27 at 16:42 -0500, Andrew Martin wrote: Hello, This topic has been touched on in the past, but I'd like to ask for additional clarification on the structure of the internal LDAP server that Samba4 provides. I currently am

Re: [Samba] Sysvol Replication in Samba4

2012-08-26 Thread Gémes Géza
Hi Matthieu! Thank you for the script. Could you also attach /usr/local/etc/ecv/list_dcs which is sourced? Thank you in advance! Cheers Geza Gemes -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] XP Administrator has no access to shares

2012-08-21 Thread Gémes Géza
2012-08-21 10:32 keltezéssel, steve írta: On 20/08/12 21:17, Gémes Géza wrote: 2012-08-20 11:09 keltezéssel, steve írta: On 20/08/12 10:45, steve wrote: On 20/08/12 09:42, Gémes Géza wrote: setfacl -R -m u:Administrator:rwx,d:u:Administrator:rwx /home2/home Hi Géza Sorry to be a pain

Re: [Samba] XP Administrator has no access to shares

2012-08-20 Thread Gémes Géza
Hi Steve, Answers below Hi Géza Thanks for your patience. Lets take this share: [home] path = /home2/home read only = No 1. Could you tell me what I need to add to enable Administrator to have full control over it? The most probable cause of not having access is that Administrator has no

Re: [Samba] XP Administrator has no access to shares

2012-08-20 Thread Gémes Géza
2012-08-20 11:09 keltezéssel, steve írta: On 20/08/12 10:45, steve wrote: On 20/08/12 09:42, Gémes Géza wrote: setfacl -R -m u:Administrator:rwx,d:u:Administrator:rwx /home2/home Hi Géza Sorry to be a pain but there is a slight problem with the acl All folders under /home2/home now have e.g

Re: [Samba] XP Administrator has no access to shares

2012-08-18 Thread Gémes Géza
2012-08-18 08:48 keltezéssel, steve írta: On 17/08/12 13:17, Gémes Géza wrote: 2012-08-17 11:44 keltezéssel, steve írta: Hi S4 DC with S3 fileserver. smb.conf on the fileserver: [global] workgroup = ALTEA realm = HH3.SITE security = ADS kerberos method = secrets and keytab

Re: [Samba] XP Administrator has no access to shares

2012-08-17 Thread Gémes Géza
2012-08-17 11:44 keltezéssel, steve írta: Hi S4 DC with S3 fileserver. smb.conf on the fileserver: [global] workgroup = ALTEA realm = HH3.SITE security = ADS kerberos method = secrets and keytab winbind enum users = Yes winbind enum groups = Yes idmap config

Re: [Samba] About s3fs in samba4

2012-08-17 Thread Gémes Géza
2012-08-17 17:31 keltezéssel, fe...@epepm.cupet.cu írta: Reading Whatsnew.txt in samba I understand that If I use s3fs, as it is set by default in the provision step, I won't be able to modify GPOs later, right? So I have a couple of questions: - What's the advantage of using s3fs over ntvfs in

Re: [Samba] Domain Admin cannot access files

2012-08-16 Thread Gémes Géza
2012-08-16 13:48 keltezéssel, steve írta: On 15/08/12 23:51, Rowland Penny wrote: On 15/08/12 22:10, Gémes Géza wrote: 2012-08-15 18:59 keltezéssel, steve írta: Hi I just joined a Samba 3.6.3 machine as a file server for a Samba4 domain. Normal users can login and reach the shares apart from

Re: [Samba] S4 DC S3 file server: samba-tool and net ads user problems

2012-08-16 Thread Gémes Géza
2012-08-16 18:53 keltezéssel, steve írta: Hi everyone I have a S4 DC with a S3 fileserver. I want to create users and their UninxHomeDirecory on the fileserver. I can do this with a script which uses ldapmodify. Fine so far. The user shows in getent passwd on the DC and in wbinfo -u on the

Re: [Samba] S4 DC S3 file server: samba-tool and net ads user problems

2012-08-16 Thread Gémes Géza
2012-08-16 20:07 keltezéssel, steve írta: On 16/08/12 19:32, Gémes Géza wrote: 2012-08-16 18:53 keltezéssel, steve írta: Hi everyone I have a S4 DC with a S3 fileserver. I want to create users and their UninxHomeDirecory on the fileserver. I can do this with a script which uses ldapmodify

Re: [Samba] Samba4 DC with Samba3 file-server howto

2012-08-15 Thread Gémes Géza
2012-08-15 13:02 keltezéssel, steve írta: Hi I have a Samba4 DC (hh30.hh3.site, 192.168.1.30) and a Samba3 VM on the same box (hh33.hh3.site, 192.168.1.33). How do I tell XP and 7 clients to look at the S4 DC for authentication and the S3 fileserver for files? It already does the

Re: [Samba] Domain Admin cannot access files

2012-08-15 Thread Gémes Géza
2012-08-15 18:59 keltezéssel, steve írta: Hi I just joined a Samba 3.6.3 machine as a file server for a Samba4 domain. Normal users can login and reach the shares apart from the domain Administrator. After Administrator has logged in, any attempt to reach the file server results in a

Re: [Samba] Samba4: rfc2307 compatibility with Samba3

2012-08-14 Thread Gémes Géza
2012-08-14 23:15 keltezéssel, steve írta: On 12/08/12 17:45, Gémes Géza wrote: 2012-08-12 16:26 keltezéssel, steve írta: On 12/08/12 15:28, Gémes Géza wrote: 2012-08-12 09:31 keltezéssel, steve írta: On 08/11/2012 01:10 PM, Andrew Bartlett wrote: On Sat, 2012-08-11 at 11:21 +0200, Helmut

Re: [Samba] RFC2307, AD, and Samba 3.6

2012-08-12 Thread Gémes Géza
Hi, Hi all, I'm still struggling with getting samba 3.6 to use the uids and gids from my Active Directory 2008 R2 setup. I can see the users, I just can't get their UIDs mapped onto my linux machine. I've configured AD to use it's services for unix feature, and through that, I got a Unix

Re: [Samba] Samba4: rfc2307 compatibility with Samba3

2012-08-12 Thread Gémes Géza
2012-08-12 09:31 keltezéssel, steve írta: On 08/11/2012 01:10 PM, Andrew Bartlett wrote: On Sat, 2012-08-11 at 11:21 +0200, Helmut Hullen wrote: Hallo, Andrew, Du meintest am 11.08.12: In Samba3, I have full rfc2307 compliance via winbind where all attributes can be obtained from AD. In

Re: [Samba] Samba4: rfc2307 compatibility with Samba3

2012-08-12 Thread Gémes Géza
2012-08-12 16:26 keltezéssel, steve írta: On 12/08/12 15:28, Gémes Géza wrote: 2012-08-12 09:31 keltezéssel, steve írta: On 08/11/2012 01:10 PM, Andrew Bartlett wrote: On Sat, 2012-08-11 at 11:21 +0200, Helmut Hullen wrote: Hallo, Andrew, Du meintest am 11.08.12: In Samba3, I have full

Re: [Samba] idmap confusion

2012-08-04 Thread Gémes Géza
2012-08-04 12:07 keltezéssel, steve írta: On 03/08/12 21:54, Gémes Géza wrote: 2012-08-03 18:46 keltezéssel, steve írta: On 03/08/12 13:39, Gémes Géza wrote: 2012-08-03 13:07 keltezéssel, steve írta: Three unfathormable questions: 1. What's the difference between: idmap_ldb : use rfc2307

Re: [Samba] winbind: uid range is ignored

2012-08-03 Thread Gémes Géza
2012-08-03 10:22 keltezéssel, steve írta: On 03/08/12 09:01, NdK wrote: Il 03/08/2012 08:01, steve ha scritto: getent passwd/group works fine. I get the names and coresponding uid:gid numbers within the range specified in smb.conf but all I get when I list files on the nfs share, are

Re: [Samba] idmap confusion

2012-08-03 Thread Gémes Géza
2012-08-03 13:07 keltezéssel, steve írta: Three unfathormable questions: 1. What's the difference between: idmap_ldb : use rfc2307 = Yes It is a samba4 winbind setting, so you need it on the Samba4 AD controller only and idmap config * : backend = ad the correct form is: idmap config

Re: [Samba] idmap confusion

2012-08-03 Thread Gémes Géza
2012-08-03 18:46 keltezéssel, steve írta: On 03/08/12 13:39, Gémes Géza wrote: 2012-08-03 13:07 keltezéssel, steve írta: Three unfathormable questions: 1. What's the difference between: idmap_ldb : use rfc2307 = Yes It is a samba4 winbind setting, so you need it on the Samba4 AD controller

Re: [Samba] Samba4: net ads join fails: Host is not configured as a member server.

2012-08-02 Thread Gémes Géza
2012-08-02 09:01 keltezéssel, steve írta: Hi everyone I'm trying to join an Ubuntu 12.04 client to a 12.04 Samba4 DC. xp and win7 clients can join fine. Here is my minmal smb.conf realm = POLOP.SITE workgroup = POLOP security = ADS Kerberos is working: kinit Administrator Password for

Re: [Samba] winbind: uid range is ignored

2012-08-02 Thread Gémes Géza
2012-08-02 17:45 keltezéssel, steve írta: On 02/08/12 17:14, Bjoern Baumbach wrote: Hi Steve, please use idmap config * : range = ... instead of idmap uid/gid. Thanks Jonathan and Bjoern I have that now. I chose: idmap config * : range = 3-4 I have deleted the winbind files from

Re: [Samba] Fwd: Fwd: Fwd: Fwd: Re: Fwd: Re: Samba 4 Smart card logon

2012-07-12 Thread Gémes Géza
2012-07-12 10:47 keltezéssel, Charalampos Anargyrou írta: I have finally found out that my problems had to do with wrong certificates. The commands I used to generate the certificates where taken from http://k5wiki.kerberos.org/wiki/Pkinit_configuration I downloaded and built heimdal 1.5.2

Re: [Samba] splitting services in samba4

2012-07-11 Thread Gémes Géza
Hi Quinn, Thanks for the quick response. So I guess if you wanted high availability, you would either have to implement a PDC/BDC solution with samba4 or use samba4 on top of a corosync/pacemaker cluster. Is this correct? br, Quinn On Wed, Jul 11, 2012 at 10:43 AM, Gémes Géza g

Re: [Samba] Samba help?

2012-07-11 Thread Gémes Géza
Hi Miklós, Hello everyone, I have just joined this group (discussion board) and would like to know how it works. Can I just put questions out there about my Samba difficulties and hope someone can help me? Sorry to sound naïve, but I do need help with my Samba config and I have spent

Re: [Samba] Samba help?

2012-07-11 Thread Gémes Géza
Hi Miklos, Hello Geza, I stand chastised and apologize. I didn't mean to hijack someone's thread. I also didn't plan to ask for help in Hungarian, and this is just a coincidence. However, if you can help me I'll take whatever I can get, so thank you. My question/problem is that I have no

Re: [Samba] Samba4 Multi-Master replication

2012-06-13 Thread Gémes Géza
On 2012-06-13 17:10, steve wrote: On 12/06/12 19:19, Gémes Géza wrote: On 2012-06-12 12:16, Morten Kramer wrote: Hi guys, I'm trying to get the Samba4 multi-master replication to work. With your setup DNS is the single point of failure, because with the (default) DLZ setup bind9 is able

Re: [Samba] Samba4 Multi-Master replication

2012-06-12 Thread Gémes Géza
On 2012-06-12 12:16, Morten Kramer wrote: Hi guys, I'm trying to get the Samba4 multi-master replication to work. I set up the primary domain controller using this howto (under CentOS 6.2 x64): http://wiki.samba.org/index.php/Samba4/HOWTO I installed bind 9.8.3 and enabled

Re: [Samba] Samba4 for AD using existing LDAP, Kerberos, and Bind Setup.

2012-05-18 Thread Gémes Géza
it! On Wed, May 16, 2012 at 1:26 AM, Gémes Géza g...@kzsdabas.hu mailto:g...@kzsdabas.hu wrote: On 2012-05-16 04:28, David Minard wrote: We run Apple's OD to support our Linux, Mac, and Windows clients and servers. We are under pressure to use AD because more and more software

Re: [Samba] Samba4 for AD using existing LDAP, Kerberos, and Bind Setup.

2012-05-15 Thread Gémes Géza
On 2012-05-16 04:28, David Minard wrote: We run Apple's OD to support our Linux, Mac, and Windows clients and servers. We are under pressure to use AD because more and more software coming out for Windows requires it. We don't want to use AD, so Samba4 looks good. However, we don't want

Re: [Samba] Samba4 Localization

2012-04-11 Thread Gémes Géza
2012-04-10 17:28 keltezéssel, German Molano írta: Hi there, there is any way to add self localization names to the default groups and users created by provision at the initial setting up of samba4, if so let me know how to work about it I want to add spanish localization to the default setup.

Re: [Samba] windows and nfs4 acls

2012-02-28 Thread Gémes Géza
2012-02-28 08:27 keltezéssel, steve írta: Hi everyone We're really struggling with nfs4 -- windows acls. Scenario Samba4 share -- cifs -- win7. No problem Samba4 share -- nfs4 -- Linux. acls not inherited Neither is there inheritance vica versa. e.g. It is not possible to create files

Re: [Samba] Samba4 xidNumber and idmap.ldb

2012-02-26 Thread Gémes Géza
2012-02-26 10:28 keltezéssel, steve írta: Hi everyone The s4 Domain Users group has xidNumber: 100 and the Linux users group has gidNumber=100. I've been mapping xidNumber -- gidNumber for s4 posix groups I've added myself, but this causes a name collision for Domain Users. This also has

Re: [Samba] Samba4 gid-to-sid question

2012-02-16 Thread Gémes Géza
2012-02-16 11:39 keltezéssel, steve írta: On 02/16/2012 06:58 AM, Gémes Géza wrote: 2012-02-16 02:01 keltezéssel, steve írta: Hi. We used info from a SID created using samba-tool group add to posix-ify it and then add a posix-ifed domain user to it. The AD doco defines two sorts of SID. Ones

Re: [Samba] Samba4 gid-to-sid question

2012-02-15 Thread Gémes Géza
2012-02-16 02:01 keltezéssel, steve írta: Hi. We used info from a SID created using samba-tool group add to posix-ify it and then add a posix-ifed domain user to it. The AD doco defines two sorts of SID. Ones that change, and ones that don't. Here is a search on our posix-ified group:

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-13 Thread Gémes Géza
Hi, See comments/questions below: Hi When I type this: getent passwd steve6 steve6:*:315:316:steve6:/home/CACTUS/steve6:/bin/bash I can see that the info is coming from LDAP by looking at the ldif for cn=steve6 What is your /etc/nsswitch.conf file like? When I type this: wbinfo

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-13 Thread Gémes Géza
Hi On 02/13/2012 07:53 PM, Gémes Géza wrote: Hi, See comments/questions below: Hi When I type this: getent passwd steve6 steve6:*:315:316:steve6:/home/CACTUS/steve6:/bin/bash I can see that the info is coming from LDAP by looking at the ldif for cn=steve6 What is your /etc

Re: [Samba] samba-tool set default group

2012-02-10 Thread Gémes Géza
2012-02-10 12:11 keltezéssel, steve írta: On 02/10/2012 12:08 PM, steve wrote: On 02/09/2012 07:17 PM, Gémes Géza wrote: 2012-02-09 14:21 keltezéssel, steve írta: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve

Re: [Samba] latest Samba 4 does not look in keytab

2012-02-10 Thread Gémes Géza
2012-02-10 17:58 keltezéssel, steve írta: Hi After upgrading to Version 4.0.0alpha18-GIT-24ed8c5 on Ubuntu 11.10, Samba 4 no longer looks in the keytab for my nfs server entry: mount -t nfs4 foo bar --o sec=krb5 Kerberos: AS-REQ nfs/hh3.hh3.s...@hh3.site from ipv4:192.168.1.3:53213 for

Re: [Samba] Samba 4 and new Kerberos version

2012-02-09 Thread Gémes Géza
2012-02-08 09:29 keltezéssel, steve írta: On 07/02/12 20:52, Gémes Géza wrote: 2012-02-07 16:07 keltezéssel, steve írta: On 07/02/12 12:01, Andrew Bartlett wrote: On Tue, 2012-02-07 at 10:24 +0100, steve wrote: I just got this from the mit list: quote DES transition

Re: [Samba] samba-tool set default group

2012-02-09 Thread Gémes Géza
2012-02-09 14:21 keltezéssel, steve írta: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve But steve's default group is still Users. I'm looking for soething like this: 'samba-tool group setdefaultgroup steve

Re: [Samba] Samba 4 and new Kerberos version

2012-02-07 Thread Gémes Géza
2012-02-07 16:07 keltezéssel, steve írta: On 07/02/12 12:01, Andrew Bartlett wrote: On Tue, 2012-02-07 at 10:24 +0100, steve wrote: I just got this from the mit list: quote DES transition == The krb5-1.8 release disables single-DES cryptosystems by default. As a result, you

Re: [Samba] Samba 4 posixGroup mapping

2012-02-06 Thread Gémes Géza
2012-02-06 09:29 keltezéssel, steve írta: On 02/06/2012 07:19 AM, Gémes Géza wrote: 2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called suseusers and mixed in posixGroup and gidNumber using samba-tool group add as a basis. It works, e.g. when I added an existing

Re: [Samba] Samba 4 posixGroup mapping

2012-02-06 Thread Gémes Géza
2012-02-06 23:58 keltezéssel, steve írta: On 02/06/2012 08:10 PM, Gémes Géza wrote: 2012-02-06 09:29 keltezéssel, steve írta: On 02/06/2012 07:19 AM, Gémes Géza wrote: 2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called suseusers and mixed in posixGroup

Re: [Samba] Samba 4 posixGroup mapping

2012-02-05 Thread Gémes Géza
2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called suseusers and mixed in posixGroup and gidNumber using samba-tool group add as a basis. It works, e.g. when I added an existing user to the group: getent group suseusers suseusers:*:2000: and getent passwd

Re: [Samba] samba 4 PAM and xscreensaver

2012-02-01 Thread Gémes Géza
2012-02-01 19:07 keltezéssel, steve írta: On 01/09/2012 08:42 AM, steve wrote: Hi I have a Linux client running XFCE and authenticating against Samba 4. When trying to return to the session after xscreensaver has kicked in, authentication fails. Sorry to bump, but I've just seen this in the

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread Gémes Géza
2012-01-28 10:40 keltezéssel, steve írta: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 openSUSE 12.1 Conventional nfs4 export works fine, but I'm having trouble kerberizing it for Samba 4 for my Samba 4 users. I've setup the nfs4 pseudo stuff like this: hh3:/ # mkdir /export hh3:/ #

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread Gémes Géza
2012-01-28 12:21 keltezéssel, steve írta: On 28/01/12 11:03, Gémes Géza wrote: 2012-01-28 10:40 keltezéssel, steve írta: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 openSUSE 12.1 Conventional nfs4 export works fine, but I'm having trouble kerberizing it for Samba 4 for my Samba 4 users

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread Gémes Géza
2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: Summary: 1. kerberized /etc/exports /exportgss/krb5(rw,fsid=0,insecure,no_subtree_check,async) /export/homegss/krb5(rw,nohide,insecure,no_subtree_check,async

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread Gémes Géza
2012-01-28 21:44 keltezéssel, steve írta: On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: Summary: 1. kerberized /etc/exports /exportgss/krb5(rw,fsid=0,insecure,no_subtree_check

  1   2   3   4   >