[Samba] Samba 4 internal DNS and reverse zones

2013-10-14 Thread Julian Pilfold-Bagwell
Hi All, I currently have another thread open on squid authentication with Samba 4 and am going to try authenticating against kerberos instead of NTLM. According to the docs for the web filter I'm using, it's essential for Kerberos to be able to resolve reverse DNS so I've spent the last

[Samba] Samba 4 and squid ntlm auth

2013-10-10 Thread Julian Pilfold-Bagwell
Hi List, Looking for assistance with a squid authentication problem against Samba 4. The squid proxy we're using worked fine on our old Samba 3 domain with 500+ users but keeps freezing on our new Samba 4 domain. I've joined the proxy using net ads join and the samba 4 network is a clean

[Samba] Samba 4 with LDAP proxy in DMZ

2013-08-11 Thread Julian Pilfold-Bagwell
Hi All, I'm setting up a Samba AD domain which works perfectly with the WIn 7 server tools and so far everything is going fine. What has me stumped is setting up an LDAP proxy in our DMZ against which I can authenticate our email and web services. I've got port 389 open on my main Samba 4

Re: [Samba] Can not logon to domain

2012-01-02 Thread Julian Pilfold-Bagwell
On 02/01/12 12:50, sa...@printflow.eu wrote: Hi all, After new year I started to getting error when trying to logon to domain. On XP machine I get The system connot log you on now because the domain DOMAIN is not available. On Win7 Trust Relationship Between Workstation and Domain Fails

Re: [Samba] Cross subnet browsing + OpenVPN

2010-07-09 Thread Julian Pilfold-Bagwell
Sorry about the delay, family emergency to deal with. browse sync shares the info across them. I tried putting the specific IP addresses of the local master browsers into the browse sync but it still doesn't seem to spread everything across all the subnets. From what I understand, the

[Samba] Cross subnet browsing + OpenVPN

2010-07-06 Thread Julian Pilfold-Bagwell
Hi All, I'm having a problem with cross subnet browsing and name resolution across an openvpn tunnel. i've found quite a few people who've had the same on mail lists but none of their fixes have worked. The spec of the setups at both ends of the tunnel are as follows: OS - CentOS 5.5 Samba

[Samba] Samba multi-site advice request please

2010-01-31 Thread Julian Pilfold-Bagwell
Hi all, I am looking at setting up a multi-site office and need to put a plan forward. The site consists of one head office and several branch office and my plan so far is this: In head office, one Samba PDC. Each branch office will have a local BDC that also stores files local to the branch,

Re: [Samba] One way Samba

2009-12-03 Thread Julian Pilfold-Bagwell
A quick look through shows hosts allow = 127. 192.77.0. and the interface is bound to 192.168.77.0/24. Add the 168 to the entry in the hosts allowed line and it should work. Cheers, Jools On Wed, 2009-12-02 at 22:49 -0800, wino_pilot wrote: I am running Samba 2:3.3.2 on a Kubuntu 9.04

Re: [Samba] Domain Administrator problems - SOLVED

2008-02-07 Thread Julian Pilfold-Bagwell
Nice one. rpc rights sorted it out straight away. Should have RTFM'd a bit more ;) Cheers, Jools On Wed, 2008-02-06 at 09:04 -0600, Adam Williams wrote: you still have to grant toni priviliges. http://us1.samba.org/samba/docs/man/Samba-Guide/happy.html#id353033 Julian Pilfold-Bagwell

[Samba] Domain Administrator problems

2008-02-06 Thread Julian Pilfold-Bagwell
Hi All, I have a tdbsam backend on Samba PDC and am trying to set a user up as a domain admin. I read that instead of the old admin users line in smb.conf you now use net groupmap to map unix groups to NT groups. I have a user called toni in unix group admins and have run: net groupmap add

[Samba] Logging logins with preexec and Samba/LDAP

2007-10-01 Thread Julian Pilfold-Bagwell
the % substitutions for user, machine and time. Has anyone else run into this problem? If so, any help with the solution would be handy. Thanks, -- Julian Pilfold-Bagwell, Network Manager, Borden Grammar School, Sittingbourne, Kent, ME10 1EY. Tel: 01795 424192 -- To unsubscribe from this list go

Re: [Samba] Logging logins with preexec and Samba/LDAP

2007-10-01 Thread Julian Pilfold-Bagwell
Mac wrote: Date: Mon, 01 Oct 2007 13:22:25 +0100 From: Julian Pilfold-Bagwell [EMAIL PROTECTED] To: Samba mail List samba@lists.samba.org Subject: [Samba] Logging logins with preexec and Samba/LDAP I had the following line in my smb.conf with which to log access to the home share when users

Re: [Samba] Logging logins with preexec and Samba/LDAP

2007-10-01 Thread Julian Pilfold-Bagwell
Mac wrote: Hi there, Date: Mon, 01 Oct 2007 14:36:26 +0100 From: Julian Pilfold-Bagwell [EMAIL PROTECTED] Subject: Re: [Samba] Logging logins with preexec and Samba/LDAP Yup, I upgraded to 3.0.24 at the same time. How's it changed? It was documented (just about) in the release notes

Re: [Samba] RE: migrating samba to new hardware and different OS

2007-08-26 Thread Julian Pilfold-Bagwell
Volker Lendecke wrote: On Sun, Aug 26, 2007 at 03:12:30PM +0200, Andrew Jeremy Gargan wrote: write list = @agroup, auser, another user Fedora bug. Change the @ to +. Volker Hiya, It's not just a Fedora bug it's a change in the way that Samba handles permissions. If you check

[Samba] Windows XP joining Samba/LDAP domain problem (User cannot be found) [SOLVED]

2007-08-24 Thread Julian Pilfold-Bagwell
To anyone out there who's having problems joining their Samba/LDAP domain with XP here's a solution. The main symptom is that the XP join domain gui returns a user cannot be found error. The setup that I experienced this on was configured and managed using the smbldap-tools package. Usual

[Samba] smbldap-tools problem

2007-08-23 Thread Julian Pilfold-Bagwell
Hi All, I've been trying to run smbldaptools from a PDC using a seperate LDAP server but can't join new machines to the domain. I've just noticed that the smbldap.conf file has two entries that declare the pathways to slappasswd and smbpasswd. Does anyone with in-depth knowledge of smbldap

[Samba] Profiles with an LDAP backend being overridden

2007-08-09 Thread Julian Pilfold-Bagwell
Hi All, I've got LDAP running as the backend to Samba 3.0.24 and am trying to set the profile directories to mandatory for one group of users and roaming for another. To this end I'm using the sambaProfilePath in LDAP but it's getting overridden by something that's setting it to %u. As a

[Samba] Domain and local user permissions

2007-07-31 Thread Julian Pilfold-Bagwell
Hi all, I have a question regarding the seperation of domain and local permissions. I have a Samba PDC and BDC setup with three member servers authenticating from them. I've set all the boxes up to use nss_ldap for the Posix side so that all the groupmapping between domain and unix groups

Re: [Samba] Correct method to Join Domain ????

2007-06-08 Thread Julian Pilfold-Bagwell
Mike Rushton wrote: I am testing w/ a PC loaded w/ Centos 5 and Samba (whatever version it came with) I have not had any luck with connecting WinXP clients to it (or anything for that matter) I think my problems stem from not joining the domain correctly. What is the proper method for Win XP

Re: [Samba] Re: Join Linux client to Samba PDC domain

2007-06-08 Thread Julian Pilfold-Bagwell
Matt wrote: Now I want the same thing in a different environment CentOS Samba PDC in domain mode and LDAP Windows XP and Vista clients joined to the Samba domain Linux File Server (which I don't know how to configure) So I want all the Windows clients to be able to access the shares on my

[Samba] Domain and Unix permissions

2007-06-07 Thread Julian Pilfold-Bagwell
Hi all, I have a question about setting permissions on files and folders in Samba versions that differentiate between the two. Groups are mapped via net groupmap indicating that setting the UNIX group permissions on a directory will be mapped across to the relevant NT Group but how are UNIX

Re: [Samba] can't create workstation account

2007-05-23 Thread Julian Pilfold-Bagwell
Hi all, Found this thread while searching for the problem you have and have found a cure that works for me. Whenever joining the domain from a Windows XP machine it was only creating the Posix side of the account and not the sambaSamAccount that's required for a successful account creation.

[Samba] Permissions across servers

2007-05-12 Thread Julian Pilfold-Bagwell
Hi all, I have a problem that I stumbled across a solution for on a list while searching for something else but can't find again. It's down to permissions propogating from a Samba PDC across member servers. I'm using 3.0.28c which according to the release notes uses the +Domain\group

Re: [Samba] wbinfo on a PDC

2007-05-03 Thread Julian Pilfold-Bagwell
Hi again, The problem I have is that I have a PDC and a member server but the permissions don't seem to propogate from one to another. If I run getent passwd and group I get all the users and groups from the UNIX/LDAP backend and if I run net groupmap list I get identical group mappings on

[Samba] Samba/LDAP PDC and member servers

2007-04-29 Thread Julian Pilfold-Bagwell
Hi All, I have a problem with permissions following a migration from tdbsam to LDAP. As I understand it from the documentation, each member server on the domain needs to have 2 SIDs, a domain SID and a local machine SID. After migrating the server to ldap, users can still login and desktops

[Samba] LDAP PDC migration gone wrong.

2007-04-17 Thread Julian Pilfold-Bagwell
Hi All, I have a problem following the migration of my PDC's backend from tdbsam to LDAP. We started out with a PDC called SMB1 which ran with a tdbsam backend. I used pdbedit to convert it to LDAP and built a new server onto which the LDIF file was loaded. Samba was then setup to use the

[Samba] wbinfo on a PDC

2007-04-17 Thread Julian Pilfold-Bagwell
Hi all, When running winbind on an LDAP authenticated Samba domain controller should it return lists from wbinfo -u wbinfo or does this not happed on controllers? All I get is Error looking up domain users and I need to know if this a feature or a problem. Cheers, Jools -- To

Re: [Samba] wbinfo on a PDC

2007-04-17 Thread Julian Pilfold-Bagwell
Hiya, My situation is that I have a PDC with LDAP and samba and a member server with samba/winbind. I can get a full NT user and group listing from the member server using wbinfo but the PDC returns the error message. Both give the same results when getent passwd and group are run and net

[Samba] Samba / Winbind / LDAP - Can't access shares

2007-04-17 Thread Julian Pilfold-Bagwell
Hi All, I have the following setup. Samba/LDAP PDC, Samba BDC, Samba member server, Win2K member server, 300 Win XP Client PCs. I can access the shares on the PDC from all Win XP clients. I can access the shares on the Win2K member server from all XP clients, I can't however access any of

[Samba] Permissions on Domain Admin created files

2006-11-22 Thread Julian Pilfold-Bagwell
Hi All, I have a PDC that serves 800 users all of whom have their own home directory. From time to time, members of the Domain Admins group scan pages for the users and save them into the users home directories but the permissions for the file are created with the admin as owner. Is there any

[Samba] cracking smbpasswd

2006-08-04 Thread Julian Pilfold-Bagwell
Hi all, I'm currently migrating from tdbsam to LDAP and want to restructure my setup at the same time. I can get the SIDs for the user and machine accounts using pdbedit -Lv | grep SID but I have 800 users so I don't want to reset their passwords. So far, I've dumped the contents of the

[Samba] tdbsam to LDAP

2006-07-02 Thread Julian Pilfold-Bagwell
Hi All, I've found a script for migrating posix accounts to LDAP but does anyone know of a script for migrating tdbsam to LDAP? Cheers, Julian -- J. Pilfold-Bagwell Borden Grammar School Avenue of Remembrance Sittingbourne Kent ME10 4DB (+44) 1795 424192 -- To unsubscribe from this list

[Samba] Adding machines and machine based logins

2006-05-25 Thread Julian Pilfold-Bagwell
Hi All, I am hoping to set up machine based logins on our Samba server (3.0.21c/RedHat EL4). I have the following lines in the global section to my smb.conf: [global] add group script = /usr/sbin/groupadd %g delete group script = /usr/sbin/groupdel %g add user to group

[Samba] OpenLDAP and Samba - password expiration.

2005-12-31 Thread Julian Pilfold-Bagwell
Hi all, I have a Samba PDC with an LDAP backend. Yesterday, I tried to add a new machine to the network and received the following message: The following error occurred attempting to join the domain: The password of this user has expired Not a problem I thought, and then ran

[Samba] Samba PDC, LDAP and permissions

2005-12-08 Thread Julian Pilfold-Bagwell
Hi all, I have a Samba PDC running on OpenSuSe 10 with LDAP as the backend and am running Mandriva 2006 as a member server with a few shares for users. The PDC seems OK and I've added the member using the instructions in the Samba example documents and I'm at the following point: OpenLDAP is

[Samba] cupsaddsmb

2005-11-30 Thread Julian Pilfold-Bagwell
Hi all, I'm trying to add printers with cupsaddsmb on Samba 3.0.20 (Mandrake Linux) with an LDAP backend. I've followed the howto on the samba page and have the error: result was WERR_INVALID_PRINTER_NAME generated when I run it. So far I've Googled for the solution but

Re: [Samba] Samba SIDs

2005-11-20 Thread Julian Pilfold-Bagwell
, Craig White wrote: On Sat, 2005-11-19 at 23:32 +, Julian Pilfold-Bagwell wrote: Hi all, I need help to clear a bit of confusion regarding SIDs on Samba servers. I had my PDC collapse on Thursday which wasn't too much of a problem as I had everything backed up but I'm now

Re: [Samba] SAMBA PDC Howto LDAP

2005-11-19 Thread Julian Pilfold-Bagwell
More info on Samba/LDA is available here: http://www.idealx.org/prj/samba/smbldap-howto.en.html On Saturday 19 Nov 2005 00:08, Jeff Gamsby wrote: Here is some info on how to setup a SAMBA PDC and BDC with an LDAP backend

[Samba] Samba SIDs

2005-11-19 Thread Julian Pilfold-Bagwell
Hi all, I need help to clear a bit of confusion regarding SIDs on Samba servers. I had my PDC collapse on Thursday which wasn't too much of a problem as I had everything backed up but I'm now in the position that I have a mismatched Domain SID. If I run net getlocalsid I get the sid for the

[Samba] Critical collapse of Samba/LDAP - Help Please

2005-11-17 Thread Julian Pilfold-Bagwell
Hi all, For the last fortnight I've had a Samba PDC running OpenLDAP 2.3.6 and Samba 3.0.20 running without problem on a 700 user network. Today however, we were setting up mandatory profiles when the whole thing ground to halt. I suspect hardware failure and plan to work tonight to restore

[Samba] Multiple Login scripts

2005-11-15 Thread Julian Pilfold-Bagwell
login scripts that would be executed in sequence i.e. run by user is %u, and machine is %m is it possible to say run %u to set up shares followed by %m to set up the right printers for the room their in? Thanks in advance... Cheers, Jpb -- Julian Pilfold-Bagwell Borden Grammar School

[Samba] RPC Vamp + caps

2005-09-01 Thread Julian Pilfold-Bagwell
Hi all, Am using RPC Vampire to pull accounts from an NT4 PDC to a Linux box. The unit is connected as a BDC and vampire succeeds in extracting accounts on the NT box but only those which match the UNIX password parameters e.g. lower case and staring with a letter. Unfortunately, there are

[Samba] Vampire and smbusers map file

2005-09-01 Thread Julian Pilfold-Bagwell
Hi All, I've solved the capital letter NT username problem from the earlier post but still can't get Vampire to pull across accounts with numerical IDs (about 700 of them). Does vampire allow the mapping of UNIX to NT ID's during the transfer or am I stuffed. Thanks, Joolz -- To unsubscribe

[Samba] net rpc vampire

2005-09-01 Thread Julian Pilfold-Bagwell
Ok folks, here goes: We have an old NT4 machine that we wish to replace as the PDC on our network. In it's place, we've got a dual xeon box with Mandrake LE2005 and Samba 3.0.13-2 and I'm currently trying to draw the accounts over with vampire. I'm using tdbsam as a backend. I've been

Re: [Samba] Re: cupsaddsmb problem

2005-05-16 Thread Julian Pilfold-Bagwell
. cupsaddsmb is adding only the NT4/win9x drivers (if they exist in Samba). Using the cupsaddsmb from cups-1.1.20-11.6 works like a charm. -Original Message- From: Julian Pilfold-Bagwell [mailto:[EMAIL PROTECTED] Sent: sexta-feira, 13 de Maio de 2005 11:39 To: samba@lists.samba.org

[Samba] cupsaddsmb problem

2005-05-13 Thread Julian Pilfold-Bagwell
Hi all, I have a problem with adding point and print to a print server. The server details are as follows: 700MHz Celeron + 384MB RAM Mandriva LE2005 (Mandrake 10.2) Samba 3.0.13-2mdk CUPS 1.1.23 cups drivers 10.2-0.11 gimpprint-cups 2-1.1.23-11 foomatic 3.0.2-1 The server is bound to an NT4