[SCM] Samba Shared Repository - branch master updated

2017-09-29 Thread Marc Muehlfeld
- commit 0e9fcc3e7506dff01c3062893eace6beef5781a1 Author: Marc Muehlfeld <mmuehlf...@samba.org> Date: Fri Sep 29 18:34:25 2017 +0200 vfs_snapper man page: Fixed typo This commit corrects a small typo in vfs_snapper manpage. Signed-off-by: Yvan Masson <y.

[SCM] Samba Shared Repository - branch master updated

2017-07-26 Thread Marc Muehlfeld
er - Log - commit 4b56f803793a2da847b8d8bb65c8173691ab0244 Author: Marc Muehlfeld <mmuehlf...@samba.org> Date: Wed Jul 26 08:00:24 2017 +0200 Set log level for "Not authorative for" from 2 to 5 Signed-off-by: Marc Muehlfeld <mmuehlf...@samba.org> Rev

[SCM] Samba Website Repository - branch master updated

2015-09-16 Thread Marc Muehlfeld
- commit a478eabf6d129182071901b3bcd88a2ce0b1de00 Author: Marc Muehlfeld <mmuehlf...@samba.org> Date: Wed Sep 16 08:57:33 2015 +0200 Remove note about FTP from the download page Signed-off-by: Marc Muehlfeld <mmuehlf...@

[SCM] Samba Website Repository - branch master updated

2015-03-04 Thread Marc Muehlfeld
99783831ed8dcf13c550e1c4d133e0c5e0c755c5 Author: Marc Muehlfeld mmuehlf...@samba.org Date: Wed Mar 4 23:04:16 2015 +0100 News: Fix link to release notes in 4.2.0 announcement Signed-off-by: Marc Muehlfeld mmuehlf...@samba.org

[SCM] Samba Shared Repository - branch master updated

2015-02-03 Thread Marc Muehlfeld
- commit 362cac25a744d2d5c6e01495d341969b863d7f12 Author: Marc Muehlfeld mmuehlf...@samba.org Date: Sat Jan 31 19:44:26 2015 +0100 samba-tool: Create NIS enabled users and unixHomeDirectory attribute Allow to create NIS enabled user

[Samba] File share permissions act different on member server than on DC

2013-10-13 Thread Marc Muehlfeld
Hello, a while ago I wrote the http://wiki.samba.org/index.php/Setup_and_configure_file_shares HowTo. When I wrote the HowTo, I setup and configured the share on a DC - what still works like described. Today I tried the first time to do exactly the same on a 4.0.10 and 4.1.0 _member

Re: [Samba] [Announce] Samba 4.1.0 Available for Download

2013-10-11 Thread Marc Muehlfeld
Hello Szymon, Am 11.10.2013 21:53, schrieb Szymon Życiński: Any infos about update from 4.0.9? Regular way: - download - ./configure - make - make install Yes. If there are other steps required, it is mentioned in the release notes. Regards, Marc -- To unsubscribe from this list go to the

Re: [Samba] Point'n Print setup on Samba4 failing to install drivers

2013-10-08 Thread Marc Muehlfeld
Hello Pablo, Am 08.10.2013 17:41, schrieb Pablo T. Virgo: If I attempt to load the driver with the [print$] share permissions set as per the howto, (755 server side, samba config includes 'writeable = yes') I get an access denied error. - Can you show the output of getfacl on the directory?

Re: [Samba] Samba4 as AD member local rights problem...

2013-10-08 Thread Marc Muehlfeld
Am 24.09.2013 09:13, schrieb Thomas Besser: Like described here (http://geekyprojects.com/ubuntu/getting-windows-printer-drivers-from-cups/) I enabled 'root' for short and granted the 'SePrintOperator' right to a normal account and switched back to security = ads Now the next problem arises: I

Re: [Samba] Point'n Print setup on Samba4 failing to install drivers

2013-10-08 Thread Marc Muehlfeld
Am 08.10.2013 18:53, schrieb Pablo T. Virgo: - Can you show the output of getfacl on the directory? - What filesystems is this share on? - Is it mounted with user_xattr? Details on the share: /var/samba/print_drivers is on the /var partition, which is mounted with user_xattr, as per the

Re: [Samba] Folder disappears on rename

2013-10-06 Thread Marc Muehlfeld
Hello Jones, Am 06.10.2013 09:02, schrieb Jones: Sometimes this symptom happened in my environment, and found this link: SMB2 Client Redirector Caches Explained http://technet.microsoft.com/zh-tw/library/ff686200(v=ws.10).aspx Here is one test case, during Windows 7 and Samba are negotiated

Re: [Samba] Folder disappears on rename

2013-10-06 Thread Marc Muehlfeld
Am 06.10.2013 23:27, schrieb Charles Marcus: Fyi... this is a known problem (with both renames and newly created files/folders, and even deleted foles/folders) on Windows 7, even with a real Windows Server... never seen it on XP, but it happens all the time on Windows 7 here. It's a SMB2

Re: [Samba] Folder disappears on rename

2013-10-05 Thread Marc Muehlfeld
Hello Jeremy, I did an intensive testing this morning to reproduce and find out the circumstances. My results I put on a bug report (incl. wireshark capture, level 10 debug log, etc.): https://bugzilla.samba.org/show_bug.cgi?id=10184 Maybe the other people in this thread, who have also

Re: [Samba] Folder disappears on rename

2013-10-05 Thread Marc Muehlfeld
Hello, after spending my saturday afternoon with digging into the problem and comparing smb.conf files of servers where this problem occurs and where not, I found out the following: When I remove max protocol = SMB2 from my smb.conf and restart Samba, the problem seems to be gone (but I

Re: [Samba] Folder disappears on rename

2013-10-04 Thread Marc Muehlfeld
Hello, Am 03.10.2013 20:57, schrieb Brian Martin: I have Samba 4.0.9 installed under Ubuntu 12.04. It's configured as a domain member, with a Windows 2008R2 server being the DC. All workstations are running Windows 7. One of my users is reporting problems in the following scenario: 1) She

Re: [Samba] Use LDAP for passwords ONLY

2013-10-03 Thread Marc Muehlfeld
Hello, Am 03.10.2013 18:17, schrieb Garey: I am trying to figure out if I can setup samba to verify only passwords against LDAP and keep everything else local. Can you be a bit more specific what you intend to do? Regards, Marc -- To unsubscribe from this list go to the following URL and

Re: [Samba] Understanding the difference of lock/state/cache directory

2013-09-30 Thread Marc Muehlfeld
Hello Andrew, Am 30.09.2013 21:55, schrieb Andrew Bartlett: *Question 1*: The manpage says state directory is for persistent and cache directory for non-persistent data. Ok. That's clear. But what is stored in the lock directory and what is the reason why its content isn't placed in one of the

Re: [Samba] Host Cannot Access Samba

2013-09-28 Thread Marc Muehlfeld
Hello Amanda, Am 27.09.2013 21:56, schrieb Hicks, Amanda: Answers as follows: - The linux VB is on a different network than the server Does the VB host do NAT for his guest? - I have a log file generated for that VB ipaddress with errors: getpeername failed. Error was Transport

Re: [Samba] Must Samba4 AD be provisionned with rfc2307 to use winbind ?

2013-09-28 Thread Marc Muehlfeld
Hello, Am 28.09.2013 10:11, schrieb Rowland Penny: Without the rfc2307 domain provision, will I have to add manually uidNumber and guiNumber each time a new user is created from Windows Management Console ? Even with RFC2307 domain provision, you will have to add the uidNumber gidNumber

[Samba] Understanding the difference of lock/state/cache directory

2013-09-28 Thread Marc Muehlfeld
Hello, in Samba 3 I had all TDBs on one place configured through lock directory. Now I saw that Samba 4 split the location of the database files into lock/state/cache directory. *Question 1*: The manpage says state directory is for persistent and cache directory for non-persistent data.

Re: [Samba] Host Cannot Access Samba

2013-09-27 Thread Marc Muehlfeld
Hello Amanda, Am 25.09.2013 19:57, schrieb Hicks, Amanda: Our windows clients can access samba but we have a user using linux in a virtual box that is getting permission errors when trying to access the share. Can someone give direction to samples with Linux client smb.conf? You are

Re: [Samba] Samba4 as AD member local rights problem...

2013-09-24 Thread Marc Muehlfeld
Hello Thomas, Am 24.09.2013 09:13, schrieb Thomas Besser: Like described here (http://geekyprojects.com/ubuntu/getting-windows-printer-drivers- from-cups/) I enabled 'root' for short and granted the 'SePrintOperator' right to a normal account and switched back to security = ads I'm not

Re: [Samba] smbd 3.6.9-151 Red Hat EL 6 crashes from time to time

2013-09-20 Thread Marc Muehlfeld
Hello Götz, Am 20.09.2013 08:54, schrieb Götz Reinicke - IT Koordinator: we still run a Red Hat EL 6.x samba-3.6.9-151 PDC with domain login, roaming profiles, Windws 7 clients and LDAP back end. In the last couple of weeks we notice some unregular crashes with abrt reports. But as an

Re: [Samba] Samba4 as AD member local rights problem...

2013-09-19 Thread Marc Muehlfeld
Hello Thomas, Am 19.09.2013 16:27, schrieb Thomas Besser: have a samba4 server as AD member (security =ADS). I have no account with Domain Admin rights, only a normal account with delegated privilege to managing GPO and for domain join. I can not manage the printserver resp. upload the win

Re: [Samba] Windows 7 and Samba

2013-09-17 Thread Marc Muehlfeld
Hello Geoffrey, Am 17.09.2013 17:45, schrieb Geoffrey Myers: After researching win7 and samba issues we upgraded to 3.5.22. We still can not connect to shares on the RHEL 5.9 box. Odd thing is, when attempting to connect we never see anything in the logs, which makes me think its a

Re: [Samba] Fwd: Samba4 DC with multiple IPs

2013-09-16 Thread Marc Muehlfeld
Hello Rafael, Am 16.09.2013 17:18, schrieb Rafael Steiner: Is there a way to limit dynamic updates to a specific interface or can I disable it altogether on the DC? Do you want to listen Samba on any interface and only limit dynamic updates to a defined interface? In this case I don't think

Re: [Samba] Upgrading samba 2.2.8a to 3.6.15 on Solaris 9 -- 3.6.15 brings all inetd services down

2013-09-16 Thread Marc Muehlfeld
Hello Jordan, Am 17.09.2013 01:28, schrieb Jordan Verschuer: However, after rebooting I can log on to swat and see that the smbd and nmbd services are running and I can make quick changes to the configuration, like adding a new user or updating the password, and I can even map to the share...

Re: [Samba] NT_STATUS_CONNECTION_REFUSED with smbclient and samba 4.0.6

2013-09-03 Thread Marc Muehlfeld
Hello, Am 03.09.2013 17:55, schrieb GUEI née worou noee: I'm trying to install samba 4 as a DC following this tutorial https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO. ... Samba 4 has started successfully Your netstat output doesn't look like a successfull start. Here is a list of

Re: [Samba] How to allow users to be local admin

2013-09-02 Thread Marc Muehlfeld
Hello Götz, Am 02.09.2013 14:43, schrieb Götz Reinicke - IT Koordinator: it's some time that I had to touch our samba installation and may be somewon can point me to the right direction. We run a samba-3.6.9 PDC with ldap backend and windows 7 clients. Everything for normal users is working

Re: [Samba] [samba]wrong record for connetcting share

2013-09-01 Thread Marc Muehlfeld
Hello Ming, Am 29.08.2013 10:08, schrieb ming: I have some question about smbcontrol reload-config ,please explain it to me.Thanks! Connecting samba share by windows,and modify the smb.conf(EX:modify the share record rw to ro). After that,execute smbcontrol -d 10 all

Re: [Samba] Samba setup

2013-09-01 Thread Marc Muehlfeld
Am 25.08.2013 18:12, schrieb Keller Racing: Hi all. I am a truly new to Samba so please bear with me while I ask a few questions. I am running a Pentium 366 Celeron, 128meg memory, Red Hat Linux 7.2, Linux 2.4.7-10, Samba 2.2.1a. I am running this much older version as the best book I

Re: [Samba] objectClass:posixAccount missing

2013-08-31 Thread Marc Muehlfeld
Am 31.08.2013 00:14, schrieb Luca Olivetti: I'm not still 100% convinced that I need to migrate from samba 3 to samba 4, and once I am I have to explain it to my boss. Samba 4 != AD only Samba 4 is the the next version after the 3.6 tree and contains everything + AD DC functionality.

Re: [Samba] Where is the DLZ zone file with the bind dns backend?

2013-08-31 Thread Marc Muehlfeld
Am 31.08.2013 11:35, schrieb Sense Zeng: I'm testing the samba4 with bind. Samba: 4.0.9 Bind: 9.9.3-P2 I configured with the document http://wiki.samba.org/index.php/Dns-backend_bind and seems dns update completed. I trying to find out where is the DLZ zone file. Is there? Or it's just the ldb

Re: [Samba] Where is the DLZ zone file with the bind dns backend?

2013-08-31 Thread Marc Muehlfeld
Am 31.08.2013 13:58, schrieb Sense Zeng: I hope to manual edit the zone file, like adding an A host record. I test the bind backend was wish it has a DLZ zone file like the nomal bind zone file. But it's the ldb file. It seems I‘d use samba-tool. Thx. Yes, you need to use samba-tool for doing

Re: [Samba] objectClass:posixAccount missing

2013-08-30 Thread Marc Muehlfeld
Am 30.08.2013 23:44, schrieb steve: That's a good idea. Often, when we've been in production for while without errors, we lose sight of what it was like at the beginning. If there's anything here or in my sssd howto you would change it would be great if you could let us have it as a real user

Re: [Samba] sambaLMPassword

2013-08-29 Thread Marc Muehlfeld
Hello Michelangelo, Am 29.08.2013 10:12, schrieb Michelangelo Rezzonico: I have a Samba-PDC installation (version is 3.6.3) with openLDAP. When I change the password from a client (Windows/XP and Windows/7) the attribute sambaNTPassword is changed and I can log-in with the new pssword. The

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-29 Thread Marc Muehlfeld
Am 29.08.2013 12:31, schrieb steve: The first 4 bullets of 'Method 2' are unnecessary. Why don't we use what we already have? How about this instead? 1. For a client joined to the domain, please skip to (3) below. 2. On the DC: Extract the machine key: samba-tool domain exportkeytab

Re: [Samba] Change default GID of users

2013-08-29 Thread Marc Muehlfeld
Hello Bruno, Am 29.08.2013 16:11, schrieb Bruno Vane: I had this mapping in nslcd.conf map passwd gidNumber primaryGroupID I need the gidNumber to be 100 because this is gidnumber of group users in my Ubuntu servers. I will disable this mapping and test if everything is OK.

[Samba] nslcd: kerberos vs. simple bind

2013-08-28 Thread Marc Muehlfeld
Hello, I took this out of the OpenSSH auth in SAMBA4 LDAP thread, because it was drifting away from it's origin question :-) I played this afternoon a bit with nslcd and kerberos for extending my Wiki HowTo. But as more as I read, one question comes bigger and bigger: What are the

Re: [Samba] nslcd: kerberos vs. simple bind

2013-08-28 Thread Marc Muehlfeld
Am 28.08.2013 19:11, schrieb steve: If you're happy with plain text passwords being passed over the network then use them. There may be some admins that will not be able to do that though, so. . . Ok. This is an good argument I haven't tought about. In production I have used LDAPS. But the

Re: [Samba] objectClass:posixAccount missing

2013-08-28 Thread Marc Muehlfeld
Am 29.08.2013 00:10, schrieb Luca Olivetti: Yeah, nslcd works well, but for AD funcionality and speed, sssd is the only way to go for nss on Samba4 or any m$ server. Just my €0.02 I'll try it. I only used nslcd because that's what was suggested in the samba wiki. The Winbind and sssd Howto

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-28 Thread Marc Muehlfeld
Am 27.08.2013 10:52, schrieb Marc Muehlfeld: I had a short search for 0.8 and it seems that since that, some comfortable changes where done for AD. If I have time tonight, I'll compile the latest version and try to find out the differences and comment my examples accordingly. Then the users can

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-27 Thread Marc Muehlfeld
Am 27.08.2013 10:38, schrieb Luca Olivetti: http://support.microsoft.com/kb/921913/en Thank you, I was missing idmu.exe Now I can see the unix tab, but, whenever I click accept, it tells me Unable to modify the object property values. Check your credentials. There could be a network problem.

Re: [Samba] nslcd / pam_ldap HowTo

2013-08-27 Thread Marc Muehlfeld
Am 27.08.2013 10:11, schrieb steve: Your distro must be still using the 0.7 series. Yes. RHEL ships 0.7.5. I had a short search for 0.8 and it seems that since that, some comfortable changes where done for AD. If I have time tonight, I'll compile the latest version and try to find out

[Samba] objectClass:posixAccount missing

2013-08-27 Thread Marc Muehlfeld
Hello, I start a new thread, because the other one meanwhile drifted far away from what the OP asked. :-) Am 27.08.2013 17:02, schrieb Luca Olivetti: If you provisioned your domain with --use-rfc2307, then in Win7 ADUC you can see the posixAccount (UNIX Attributes) of the users. I did a

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Hello Bruno, Am 25.08.2013 22:26, schrieb Bruno Vane: Yes I read these sections, but I want something different. Users will join on AD domain (Samba 4) and will connect to an entry SSH server, and from this server they can access other SSH servers on the network. All SSH servers are configured

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 26.08.2013 14:10, schrieb Bruno Vane: I will try this configuration. For this to work I need openLDAP proxy? No. You can access AD via LDAP direclty. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 26.08.2013 16:11, schrieb Bruno Vane: Marc, sorry to bother you with this, but I can not access a SSH server using these settings. Could you take a look if you have time to find out if my settings are wrong? When I do a ssh -l nslcd-connect (or any other user) to the server, i got this in

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 26.08.2013 19:19, schrieb steve: On Mon, 2013-08-26 at 19:09 +0200, Marc Muehlfeld wrote: passwd: files ldap shadow: files ldap group: files ldap @marc Just curious, but why are you trying to pull shadow from the directory? You are right. This is not necessary

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 26.08.2013 20:12, schrieb Luca Olivetti: - Now you should be able to see all accounts (the local and domain accounts), when you type # getent passwd I tried it on a test VM, but it only showed accounts migrated from samba 3+ldap (since they have the posix attributes), new users/groups

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 26.08.2013 21:58, schrieb Bruno Vane: Now i have to research how to auto-create the home dir and change the shell to /bin/bash. For the home auto creation, PAM maybe could help you (pam_mkhomedir). But this won't help you, if use ssh with keyfiles, because someone have to place the public

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-26 Thread Marc Muehlfeld
Am 25.08.2013 09:27, schrieb Bruno Vane: I have some Ubuntu LTS servers running openssh server authenticating to external openldap. I installed a new Ubuntu LTS server with Samba4 to create a domain and is working very well. I managed to make a pfsense firewall authenticate users in this Samba4

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Hello Luca, Am 27.08.2013 00:11, schrieb Luca Olivetti: The problem is, how do I get the posix information into samba4? With samba 3 I could manage users and groups with ldap account manager and they got both samba and posix attributes. I have a windows workstation at work. There I use ADUC.

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 27.08.2013 00:28, schrieb Luca Olivetti: I tried ADUC (again, in a test VM joined to the domain), which could be suitable, but I couldn't see any unix tab (and if I have to manually assign uids/gids there it's not an option). In ADUC on Win7 the tab should be there (on XP you need to

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 27.08.2013 00:56, schrieb Luca Olivetti: ..when I tried to add a user via ADUC I couldn't see it with nslcd. Maybe I didn't really use ADUC? (dsa.msc) Do the users have posix attributes (uid, shell, etc.)? I published my nslcd HowTo some hours ago. Have a look on it. Maybe you missed

Re: [Samba] nslcd / pam_ldap HowTo (was: OpenSSH auth in SAMBA4 LDAP)

2013-08-26 Thread Marc Muehlfeld
Hello Steve, thanks for your suggestions. Am 27.08.2013 00:40, schrieb steve: 1. Nested groups work fine with nslcd. Please use the latest version: man nslcd.conf(5) I use the version Redhat ships. I haven't used that latest version and I think most will use the one shipped with their

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 27.08.2013 01:13, schrieb Luca Olivetti: In ADUC on Win7 the tab should be there (on XP you need to install something additionally if I remember right). Ah, OK, I'm on XP and I installed the tools here: https://wiki.samba.org/index.php/Samba_AD_management_from_windows#Windows_XP_Pro No

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-26 Thread Marc Muehlfeld
Am 27.08.2013 01:19, schrieb Luca Olivetti: https://wiki.samba.org/index.php/Local_user_management_and_authentication/nslcd Yep, I only had to comment the map group uniqueMember member line, though (migrated) groups show the members fine. What didn't work when you have this line in? I have

Re: [Samba] OpenSSH auth in SAMBA4 LDAP

2013-08-25 Thread Marc Muehlfeld
Hello Bruno, Am 25.08.2013 09:27, schrieb Bruno Vane: I have some Ubuntu LTS servers running openssh server authenticating to external openldap. I installed a new Ubuntu LTS server with Samba4 to create a domain and is working very well. I managed to make a pfsense firewall authenticate users

Re: [Samba] [samba]How to config samba4 internal dns?

2013-08-22 Thread Marc Muehlfeld
Hello, Am 22.08.2013 12:30, schrieb Sense Zeng: There are two DC in the domain: 1. win2003. It's created dotest.com http://dotest.com and with dns server too; 2. linux with samba4. It join the domain and being a DC. I can't use samba-tool to query any thing in the internal dns, like:

Re: [Samba] [samba]How to config samba4 internal dns?

2013-08-21 Thread Marc Muehlfeld
Hello, Am 21.08.2013 08:45, schrieb Sense Zeng: I'm new for samba4 and I'm trying to test samba4(Version 4.0.8) with internal dns. Did internal dns can config? Could I just manual add some host(A) in? What do you mean by configure internal DNS? How to setup? The internal DNS is default

Re: [Samba] Problems Implementing roaming profiles with Samba

2013-08-17 Thread Marc Muehlfeld
Hello Jose, Am 16.08.2013 14:46, schrieb Fermin Francisco: In tab Security it shows the follow: the requested security information is either unavailable or cannot be displayed Does your filesystem on which you have the share, supports extended ACLs and are they enabled during mount

Re: [Samba] Trying to Join a Working W2K3 AD

2013-08-15 Thread Marc Muehlfeld
Hello Kevin, hello Eli, Am 15.08.2013 05:48, schrieb Kevin Field: I get to the step /usr/local/samba/bin/samba-tool dns add 192.168.1.252 _msdcs.domain.co.il 2d59ac49-1175-4656-943e-d556baa242cb CNAME DC2.domain.co.il -Uadministrator I get the following error message: ERROR(runtime): uncaught

Re: [Samba] Samba4 Delegation

2013-08-15 Thread Marc Muehlfeld
Hello Andreas, Am 15.08.2013 11:07, schrieb Andreas Krupp: For information, what I was trying to do was: - Create an OU for a group of applications - Delegate control of this OU to a normal user (not helpdesk or domain admin) to be able to create groups and assign domain users to them - What

Re: [Samba] Remote linux auth vs samba4: winbind or nslcd + openldap.

2013-08-15 Thread Marc Muehlfeld
Hello Andres, Am 15.08.2013 18:45, schrieb Andres Tello Abrego: I want to achieve the Holy Gria of 1 source of users and password, for both, linux and windows machines, but I'm lost in documentation. So far I know: samba4 cann't use openldap as backend. Right. samba4 ldap doesn't really is

Re: [Samba] samba 4.0.x : samba_backup wrong path line 54

2013-08-12 Thread Marc Muehlfeld
Hello, Am 12.08.2013 07:33, schrieb m...@electronico.nc: (samba 4.0.8 compiled from git source) Just tried the samba_backup from https://wiki.samba.org/index.php/Backup_and_Recovery line 54 mention : tdbbackup $ldb where it should be /usr/local/samba/bin/tdbbackup $ldb Thanks for this nice

Re: [Samba] Samba 4 with LDAP proxy in DMZ

2013-08-12 Thread Marc Muehlfeld
Hello Julian, Am 08.08.2013 18:14, schrieb Julian Pilfold-Bagwell: I'm setting up a Samba AD domain which works perfectly with the WIn 7 server tools and so far everything is going fine. What has me stumped is setting up an LDAP proxy in our DMZ against which I can authenticate our email and

Re: [Samba] samba4 + winbind did not work

2013-08-12 Thread Marc Muehlfeld
Hello Darek, Am 12.08.2013 20:03, schrieb Darek Frączkiewicz: unfortunately this howto (https://wiki.samba.org/index.php/Samba4/Domain_Member ) did'n work. After configure with options: ./configure --with-ads --with-shared-modules=idmap_ad and change files ktrb.conf and smb.conf samba didn't

Re: [Samba] samba4 + winbind did not work

2013-08-12 Thread Marc Muehlfeld
Hello Darek, Am 12.08.2013 21:09, schrieb Darek Frączkiewicz: I was add in smb.conf log file = /var/log/samba.log and now i see: [2013/08/12 21:02:08, 0] ../source4/smbd/server.c:461(binary_smbd_main) At this time the 'samba' binary should only be used for either: 'server role = active

Re: [Samba] os level permissions for samba 4 share

2013-08-12 Thread Marc Muehlfeld
Hello Eduardo, Am 12.08.2013 20:15, schrieb Eduardo Sotomayor: I read at the samba4 wiki that to setup a samba4 share you need to Create a folder that you want to share # mkdir -p /srv/samba/Demo/ Add a new share to your smb.conf: [Demo] path = /srv/samba/Demo/ read only =

Re: [Samba] samba4 + winbind did not work

2013-08-12 Thread Marc Muehlfeld
Am 12.08.2013 22:04, schrieb Darek Frączkiewicz: I'm testing samba4 (with https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO) since one year and this config: debian + samba4 +bind9+dhcp+ntp+LAMP gives me domain, joining workstations, menage users and GPO. All works good. In this howto I

Re: [Samba] Network browsing in S4

2013-08-12 Thread Marc Muehlfeld
Hello Greg, Am 12.08.2013 22:32, schrieb Gregory Sloop: So, if I understand things correctly, NMBD or network browsing isn't functional under S4 yet. [At least I don't believe it was in 4.03 - and I don't think that's changed.] Currently Samba still doesn't support network neighbourhood.

Re: [Samba] samba4 + winbind did not work

2013-08-12 Thread Marc Muehlfeld
Am 12.08.2013 22:40, schrieb Darek Frączkiewicz: If you require to have the Samba AD accounts local on your Samba DC (not on a member server), then the winbind configuration may be a bit different (haven't done that yet). But you can use nslcd (adapt the config from here:

Re: [Samba] Network browsing in S4

2013-08-12 Thread Marc Muehlfeld
Am 12.08.2013 23:28, schrieb Gregory Sloop: So, we'll assume that nmbd doesn't work properly on an S4 AD. Can I run nmbd alone, on an independent box? (I'd guess not.) Or should I run an S3 server as a member of the AD also running nmbd? [This instance won't do any file sharing, as that will

Re: [Samba] samba4 + winbind did not work

2013-08-11 Thread Marc Muehlfeld
Hello Darek, Am 11.08.2013 23:02, schrieb Darek Frączkiewicz: I have install samba4 on debian whezzy 64-bit All is working OK, but now I try to add qoutas to users and this tutorial did not working https://wiki.samba.org/index.php/Samba4/Winbind have a look at this HowTo

Re: [Samba] samba4 + winbind did not work

2013-08-11 Thread Marc Muehlfeld
Am 12.08.2013 00:29, schrieb Darek Frączkiewicz: thank's Marc i will try tomorow this howto https://wiki.samba.org/index.__php/Samba4/Domain_Member https://wiki.samba.org/index.php/Samba4/Domain_Member I'm going to connect samba4 as AD with 30 windows workstations in my school. After testing

Re: [Samba] Joining Samba4 as DC--Error Failed to find a writeable DC for domain

2013-07-31 Thread Marc Muehlfeld
Hello Daniel Am 31.07.2013 09:39, schrieb Daniel Müller: Just did the trick: Put the nameserver MasterDC in my /etc/resolv.conf on the SlaveDC and all is finished. Please add this hint to http://wiki.samba.org/index.php/Samba4/HOWTO/Join_a_domain_as_a_DC I already had this on my to-do list,

Re: [Samba] Problem to demote samba4 dc

2013-07-31 Thread Marc Muehlfeld
Hello Davy, Am 31.07.2013 15:35, schrieb Davy HUBERT: I recently migrated our samba 3 domain to an AD domain using Samba 4 classic upgrade tool. Well, everything seems to work fine since i'm still alive ;) . I promoted a Windows 2k8 box as a new DC of this domain and I transfer the 5 FSMO

Re: [Samba] Windows 8 pro and Samba 4

2013-07-30 Thread Marc Muehlfeld
Hallo, Am 30.07.2013 14:17, schrieb iss...@aralar.edunet.es: Well, to begin with a BIG THANK YOU!!! win 8 pro joined the samba NT4 style domain. After making the 2 changes, 1) put my dns suffix in computer- properties- computer name- dns suffix 2) add the keys to the registry with the

Re: [Samba] Windows 8 pro and Samba 4

2013-07-30 Thread Marc Muehlfeld
Am 30.07.2013 18:43, schrieb Marc Muehlfeld: I'll try to clarify the Wiki article about the registry changes for that during the next time. I over-worked the Wiki Win7 registry hack page and also renamed it: https://wiki.samba.org/index.php/Registry_changes_for_NT4-style_domains It should now

Re: [Samba] Printer IP

2013-07-30 Thread Marc Muehlfeld
Hello Jimc, Am 31.07.2013 06:34, schrieb jimc: My printer somehow got its IP changed. How do I change my server (Mint linux 13, Samba 4.06) to reflect the change? I suggest not to use IP addresses in your Samba configuration. Use names and make sure, you're having a working DNS to resolve.

Re: [Samba] Windows 8 pro and Samba 4

2013-07-29 Thread Marc Muehlfeld
Hello, Am 29.07.2013 16:10, schrieb iss...@aralar.edunet.es: The win8 machine is able to resolve the netbios name of the server. ping works fine. I ping the netbios name and it returns the ip address. I attach the 4 screenshots. - the first is the message I get on trying to join the domain -

Re: [Samba] Windows 8 pro and Samba 4

2013-07-29 Thread Marc Muehlfeld
Am 29.07.2013 08:00, schrieb Daniel Müller: I have one w8 prof in my Samba AD test environment and it works without problems. Just be sure you did no registry hack on the windows 8 machine!? No registry hack here. Under

Re: [Samba] Consistent Inter-Samba UID/GID Mappings

2013-07-29 Thread Marc Muehlfeld
Hello Chris, Am 30.07.2013 01:36, schrieb chris.ha...@proporta.com: In an attempt to implement RFC2307 in the Samba directory, I rebuilt my test domain (Samba4) using the --use-rfc2307 option in the samba-tool domain provision command. The --use-rfc2307 option enables your Samba AD

Re: [Samba] Windows 8 pro and Samba 4

2013-07-28 Thread Marc Muehlfeld
Hello Emeka, Am 28.07.2013 18:39, schrieb iss...@aralar.edunet.es: I installed opensuse 12.2, and upgraded the samba 3 it came with to samba 4. I successfully joined win xp, win 7 clients to the samba as domain controller but couldn´t join win 8 prof (it keeps displaying domain does not exist

Re: [Samba] Fwd: About samba 3.0.28 trust AD

2013-07-28 Thread Marc Muehlfeld
Hello, Am 06.07.2013 15:26, schrieb Wong siu yu: I had a RedHat 5.2 need to trust domain the Windows Server 2008 R2 (forest level 2003). Which package I need to install first? I am using samba-3.0.28 but I have no samba-winbind. May I know procedures of trust setting in Linux? Please have a

Re: [Samba] Win dcpromo and SysVol Replication

2013-07-25 Thread Marc Muehlfeld
Hello Garth, Am 25.07.2013 13:21, schrieb Garth Keesler: When I DCPROMO a Win2003 server into an existing Samba4.1RC1 domain with two Samba DCs, all appears to be working correctly from the Samba side but the WinDC never starts sharing SysVol as it should. Sites and Services shows all DCs as

[Samba] Samba4 AD SysVol Replication (HowTo + Script)

2013-07-23 Thread Marc Muehlfeld
Hello, as it is often a question here on the lists and by many others on the internet, I wrote a new HowTo for setting up a SysVol replication workaround, until Samba supports this feature by itself: https://wiki.samba.org/index.php/SysVol_Replication For the replication process, I wrote a

Re: [Samba] Samba4 AD SysVol Replication (HowTo + Script)

2013-07-23 Thread Marc Muehlfeld
Hello Dewayne, Am 24.07.2013 01:59, schrieb Dewayne Geraghty: Where you mention in the document PDC role, do you mean PdcEmulationMasterRole, or is there some other meaning? Yes. I thought the DC with the FSMO role PDC would be a good choice to be the Master, because some Microsoft tools,

Re: [Samba] need soms tips for adding samba4 to windows 2008R2 domain

2013-07-17 Thread Marc Muehlfeld
Hello, Am 17.07.2013 11:29, schrieb L.P.H. van Belle: Am 15.07.2013 12:48, schrieb L.P.H. van Belle: 1) keep my existing windows 2008 domain. ( contains dhcp + dns + AD ) its a clean domain, no users yet. dhcp+dns is used already. 2) add samba4 to the windows domain dc as secondairy

Re: [Samba] Classicupgrade set_nt_acl_no_snum: fset_nt_acl returned NT_STATUS_INVALID_OWNER

2013-07-16 Thread Marc Muehlfeld
Am 16.07.2013 09:28, schrieb Stéphane PURNELLE: I have the same problem with classicupgrade (samba 4.0.6) but on S-1-5.21---xxx-500. This is the domain Admin account. What happens if you remove it before the classicupgrade? Regards Marc -- To unsubscribe from this list go to the

Re: [Samba] New ADC configuration

2013-07-16 Thread Marc Muehlfeld
Am 16.07.2013 18:04, schrieb Matthew Daubenspeck: On Tue, Jul 16, 2013 at 04:42:48PM +0100, Rowland Penny wrote: Hi, Have you given your users groups a uidNumber and/or gidNumber on the server? Rowland Is that something that has to be done with ADUC? I have added all the test

Re: [Samba] New ADC configuration

2013-07-16 Thread Marc Muehlfeld
Hello, Am 16.07.2013 19:16, schrieb Matthew Daubenspeck: On Tue, Jul 16, 2013 at 05:22:14PM +0100, Rowland Penny wrote: Yes, you can use ADUC but you need to have provisioned samba4 with --use-rfc2307 You can also add the uidNumber gidNumber with an ldif and ldapmodify or

Re: [Samba] Restore samba4 backup

2013-07-16 Thread Marc Muehlfeld
Hello, Am 16.07.2013 15:45, schrieb TI: Calling DNS name update script Failed to find object (null) for attribute fsmoRoleOwner - Cannot find DN (null) to get attribute fsmoRoleOwner for reference dn: Unsupported critical extension 1.2.840.113556.1.4.529 Failed to find if we are the PDC for

Re: [Samba] New ADC configuration

2013-07-16 Thread Marc Muehlfeld
Am 16.07.2013 20:38, schrieb Matthew Daubenspeck: I re provisioned the whole works, rejoined the member server. Now in ADUC I can see the NIS domain name and UID, as well is being part of a primary group (after I created one). It works perfectly on the DC server, but still nothing seems to

Re: [Samba] Restore samba4 backup

2013-07-16 Thread Marc Muehlfeld
Hello, Am 16.07.2013 21:31, schrieb TI: /usr/local/samba/lib/private/libntvfs.so: version `SAMBA_4.0.7' not found (required by /usr/local/samba/sbin/samba) Ok, my bad. I have compiled the version 4.0.7 for the new server and the crashed one was probably 4.0.1. This was what I ment with

Re: [Samba] Restore samba4 backup

2013-07-16 Thread Marc Muehlfeld
Hello Edison, Am 16.07.2013 22:53, schrieb TI: Through the strings command (on the library from backup files), I saw that correct version is 4.0.3. So I've compiled and installed samba 4.0.3. I've restored all backup files and renamed the .bak ones. The samba has started without error,

Re: [Samba] Restore samba4 backup

2013-07-16 Thread Marc Muehlfeld
Hello, Am 17.07.2013 07:25, schrieb TI: Hi Marc, In the samba logs, I saw these errors: /usr/local/samba/sbin/samba_dnsupdate: Error reading smb_krb5 reply packet: NT_STATUS_CONNECTION_REFUSED from 10.1.1.12 /usr/local/samba/sbin/samba_dnsupdate: Error reading smb_krb5 reply packet:

Re: [Samba] need soms tips for adding samba4 to windows 2008R2 domain

2013-07-15 Thread Marc Muehlfeld
Hello Louis, Am 15.07.2013 12:48, schrieb L.P.H. van Belle: 1) keep my existing windows 2008 domain. ( contains dhcp + dns + AD ) its a clean domain, no users yet. dhcp+dns is used already. 2) add samba4 to the windows domain dc as secondairy DC. ( this server wil be my zarafa mail

Re: [Samba] Invalid listing, samba 3.6.6

2013-07-15 Thread Marc Muehlfeld
Hello Simon, Am 15.07.2013 08:33, schrieb Traugott Simon: i do have a problem with Amanda and Smbclient again. Im trying to backup some shares and I do get some errors which i cannot fix: ? smbclient: Error reading file \Dtel\El\2009-11 u TEST\2009-11\Logos\meeting, England\P1020272.MOV :

  1   2   3   >