[Samba] AIX and WINBIND

2008-01-12 Thread Michael Gasch
hi, i have to upgrade an AIX 5.3 box (see another thread Problem with old Samba joining AD (migration szenario)) running samba 2.2.7 to samba 3.0.x since the company needs enhanced trusted domains support (for new domain DOMAINB). permissions and sid2uid-mappings have to be kept (for

[Samba] Problem with old Samba joining AD (migration szenario)

2008-01-12 Thread Michael Gasch
hi list, i have a problem joining a samba 2.2.12 linux server to a w2k3 domain (native mode). background: i have to upgrade an AIX box running samba 2.2.x to 3.0.x but want to simulate this under vmware workstation first. i compiled this version w/out any options (no winbind, ldap, ssl etc) -

Re: [Samba] Problem with old Samba joining AD (migration szenario)

2008-01-12 Thread Michael Gasch
Lendecke schrieb: On Sat, Jan 12, 2008 at 06:48:27PM +0100, Michael Gasch wrote: does someone please have a config or tips to join an AD domain with samba 2.x? Will not work unless you disable mandatory smb signing on the DC. Volker -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Heartbeat and secrets.tdb

2007-11-14 Thread Michael Gasch
with local copies of secrets.tdb on the two servers? Is it because the same IP adresses move between two different machines with different secrets.tdb? If so, would it work better if secrets.tdb would be placed on a ocfs2 file system shared between the two servers? regards Henrik -- Michael

Re: [Samba] smbstatus issue with multiple smbd

2007-09-18 Thread Michael Gasch
report which just list all the locks for the users and groups lists altogheter. We would like to have two distinct reports. Is there any ease way to get this or must we perl-script something? Hope it is clear. Thanks Valerio Daelli -- Michael Gasch Max Planck Institute for Evolutionary Anthropology

Re: [Samba] Interdomain Trusts and Winbind

2007-08-31 Thread Michael Gasch
Winbind, one of the steps is to join the PDC domain. Can one PDC join another PDC's domain?? Can someone please tell if i'm configuring this correctly? Thanks. Jason. -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D

Re: [Samba] Mapping domain groups with winbind

2007-06-05 Thread Michael Gasch
) greez Jon Ferguson wrote: I've got several machines authenticating against AD via winbind. What I would like to do is map Domain Users to various local groups, eg. audio, video, cdrom, etc. Is this possible and if so, what is the correct/preferred way? -- Michael Gasch Max Planck Institute

Re: [Samba] Mac - Filesystem Size Limit?

2007-05-04 Thread Michael Gasch
/Jul/msg4.html I couldn't find any other info. Anybody have any ideas? ~Sean -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax

Re: [Samba] 3.0.23 ldapsam:trusted=yes problem

2007-03-19 Thread Michael Gasch
hi, unfortunately no answer to your question but where did you find this parameter and what does it do ldapsam:editposix = yes ??? thx! -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany

[Samba] Samba 3.0.x, GPFS and NFSv4, ACLs and so on... ???

2007-03-15 Thread Michael Gasch
hi list, we have plans to implement GPFS in our heterogeneous environment (win, linux and mac clients; many linux servers) to scale better in file serving and improve availability. are there any recommendations regarding samba and GPFS and samba co-existing with NFSv4 (ACLs!) on GPFS on the same

Re: [Samba] Q: Samba Proxy or SAMBA Cluster?

2007-03-15 Thread Michael Gasch
Hello Volker and List This is exactly the same as discussed a couple of weeks ago: for me it seems that cluster support in samba gets more and more important. i know that there´s already a lot of work done and in progress. and also it´s really a big challenge to implement these HA-services. i

Re: [Samba] vfs_shadow and [homes]

2007-03-02 Thread Michael Gasch
something like: # ls -s /mnt/snapshots/snap1/user1 /home/user1/@GMT-2003.08.05-12.00.00 This gets a bit cumbersome with large numbers of users and snapshots. I've working on some enhancements to the shadow_copy module to address this. Ed Plese -- Michael Gasch Max Planck Institute

Re: [Samba] Samba + Quantum StorNext FS (SNFS)

2007-03-02 Thread Michael Gasch
ok, so i´ll try do this kind of art in the next couple of weeks... :) thx again! micha Volker Lendecke wrote: On Thu, Mar 01, 2007 at 04:52:54PM +0100, Michael Gasch wrote: to speed up performance do you think it´s a good idea to use jumbo frames between the samba server and windows xp

Re: [Samba] Samba + Quantum StorNext FS (SNFS)

2007-03-01 Thread Michael Gasch
. With both sides you hopefully mean NFS and Samba. Multiple Samba servers on the same file space leads to corrupt data, because the locking is not right. See the clustering pages on wiki.samba.org for the development being done in this area. Volker -- Michael Gasch Max Planck Institute

[Samba] Samba + Quantum StorNext FS (SNFS)

2007-02-28 Thread Michael Gasch
already runs SNFS and samba in a large environment?!?! thx for any help! micha -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0

[Samba] vfs_shadow and [homes]

2007-02-28 Thread Michael Gasch
representing different shares (depending on users). has anybody hints about using vfs_shadow with [homes]? thx! -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137

Re: [Samba] Samba + Quantum StorNext FS (SNFS)

2007-02-28 Thread Michael Gasch
3641 57-7705 Am Mi 28.02.2007 16:05 schrieb Michael Gasch [EMAIL PROTECTED]: hi, more a general question: does anyone know about problems running samba on a clustered filesystem like Quantum/ ADIC SNFS??? i know, i´m not allowed to export the same FS/mountpoint on different samba servers. i´m

Re: [Samba] bdc ?

2007-02-18 Thread Michael Gasch
hi I'm afraid that will try to change their password too ;-) clients will never attempt to change a password against BDCs either they're forwarded or the change will fail. micha Dmitry Melekhov wrote: Hello! I configured samba BDC according to howto. PDC is in the same subnet. But I see

Re: [Samba] Domains Trusts

2007-02-18 Thread Michael Gasch
hi, as these users are from different domains and with different SIDs you can distinguish between them. on your fileservers use winbind use default domain = no and an IDMAP backend which supports SID-to-UID-mappings for trusted domains, too (e.g. idmap_ldap in case you have many

Re: [Samba] application 'allway sync' evades sticky bit?!

2007-02-18 Thread Michael Gasch
hi, it's not the first time i see this. especially macs always manage to circumvent the permissions (even if enforced by the filesystem with ACLs)...i never found the time to trace things down with ethereal. micha Rainer Traut wrote: Hi, am running: Redhat EL4.4 i386, Samba 3.0.23d from

Re: [Samba] Connection dropped when copying large files to a SambaServer

2007-02-18 Thread Michael Gasch
hi, just to tell you that we had the same issue 2 years ago and my colleague blamed samba for this. in fact it turned out to be a SCSI HW problem on the system. all stress test on the local storage succeeded but when samba came into the game it broke the system. that's why we thought it's

Re: [Samba] Samba members in NT4.0 to AD upgrade

2007-02-18 Thread Michael Gasch
hi, i never did this (so far), but: 1. Are there any gotchas with this scenario or will the Samba clients just keep working as NT4-esque clients. if you use mixed-mode (incl. PDC emulator) you should be able to continue running samba with security = domain 2. Is it possible to upgrade

Re: [Samba] Connection from WinXP 64 Bit to Samba server broken?

2007-02-18 Thread Michael Gasch
hi andreas, i just can tell you that we migrated from debian (samba 3.0.14 orig debian) to SLES10 (samba 3.0.22 orig novell) last weekend to make winxp64 work with our samba DCs. before that you could join the domain but not authenticate. i know that almost all of your samba versions are

Re: [Samba] PDC appears to be BDC in server manager

2007-02-17 Thread Michael Gasch
where nnn.nnn.nnn.nnn is the IP address of the PDC. Presumably this is correct. yep :) Martin On 2/13/07, Michael Gasch [EMAIL PROTECTED] wrote: you're welcome :) what does nmblookup DOMAIN#1b and DOMAIN#1c give you? since everything is working this seems to be a cosmetic error?!?! micha

Re: [Samba] pdbedit password policy - not updating ldapsam

2007-02-17 Thread Michael Gasch
: No such file or directory Unable to open/create TDB passwd Can't sampwent! -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49

Re: [Samba] PDC appears to be BDC in server manager

2007-02-13 Thread Michael Gasch
the .tdb files from backup). Does it even matter, since everything is working now? Martin On 2/11/07, Michael Gasch [EMAIL PROTECTED] wrote: hi again, 2. I somehow need to rename the server back to BIGSERVER, but I'm not sure how to do this without breaking things again. assuming you have

Re: [Samba] PDC appears to be BDC in server manager

2007-02-11 Thread Michael Gasch
can't. Can anyone offer any suggestions? Thanks in advance. Martin -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550

Re: [Samba] PDC appears to be BDC in server manager

2007-02-11 Thread Michael Gasch
hi again, 2. I somehow need to rename the server back to BIGSERVER, but I'm not sure how to do this without breaking things again. assuming you have a small net work w/ only one DC (samba) and no trusts this should be no problem. - stop all samba processes on the PDC. rename it in

Re: [Samba] bdc ?

2007-02-08 Thread Michael Gasch
hi I'm afraid that will try to change their password too ;-) clients will never attempt to change a password against BDCs either they're forwarded or the change will fail. micha Dmitry Melekhov wrote: Hello! I configured samba BDC according to howto. PDC is in the same subnet. But I see

Re: [Samba] Samba members in NT4.0 to AD upgrade

2007-02-08 Thread Michael Gasch
hi, i never did this (so far), but: 1. Are there any gotchas with this scenario or will the Samba clients just keep working as NT4-esque clients. if you use mixed-mode (incl. PDC emulator) you should be able to continue running samba with security = domain 2. Is it possible to upgrade a

Re: [Samba] Connection dropped when copying large files to a SambaServer

2007-02-08 Thread Michael Gasch
hi, just to tell you that we had the same issue 2 years ago and my colleague blamed samba for this. in fact it turned out to be a SCSI HW problem on the system. all stress test on the local storage succeeded but when samba came into the game it broke the system. that's why we thought it's

Re: [Samba] application 'allway sync' evades sticky bit?!

2007-02-08 Thread Michael Gasch
hi, it's not the first time i see this. especially macs always manage to circumvent the permissions (even if enforced by the filesystem with ACLs)...i never found the time to trace things down with ethereal. micha Rainer Traut wrote: Hi, am running: Redhat EL4.4 i386, Samba 3.0.23d from

Re: [Samba] Domains Trusts

2007-02-08 Thread Michael Gasch
hi, as these users are from different domains and with different SIDs you can distinguish between them. on your fileservers use winbind use default domain = no and an IDMAP backend which supports SID-to-UID-mappings for trusted domains, too (e.g. idmap_ldap in case you have many fileservers).

Re: [Samba] Connection from WinXP 64 Bit to Samba server broken?

2007-02-08 Thread Michael Gasch
hi andreas, i just can tell you that we migrated from debian (samba 3.0.14 orig debian) to SLES10 (samba 3.0.22 orig novell) last weekend to make winxp64 work with our samba DCs. before that you could join the domain but not authenticate. i know that almost all of your samba versions are 3.0.20

Re: [Samba] Cannot change case of existing file names

2007-02-06 Thread Michael Gasch
in older versions. Any ideas? Thanks. -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399 -- To unsubscribe from

Re: [Samba] users via winbind and using @group in smb.conf

2007-01-05 Thread Michael Gasch
IMHO be compared to this scenario...can't it? greez Stefan Froehlich wrote: On Fri, Jan 05, 2007 at 03:50:07PM +0100, Michael Gasch wrote: if private is a group, you have to add @ in front of the valid users entry. according to a post of jerry the syntax with ticks and spaces is correct. Ok

Re: [Samba] users via winbind and using @group in smb.conf

2007-01-05 Thread Michael Gasch
could you please try the latest samba (or at least 3.0.23c) and use valid users = Unix Group\your_local_group ??? thx Stefan Froehlich wrote: On Thu, Jan 04, 2007 at 02:35:30PM +0100, Voelz Alexander wrote: [...] what das NOT work is to assign a samba share on B to this local group. I tried

Re: [Samba] Samba File Shares growing out of control

2007-01-05 Thread Michael Gasch
hi, for a more professional solution one would choose HSM, because samba offers HSM support, too. e.g. you could use commvault, xfs and samba to transparently migrate data off shares. greez Douglas Sterner wrote: Can anyone recommend any solutions for plucking files out of my samba shares

Re: [Samba] users via winbind and using @group in smb.conf

2007-01-05 Thread Michael Gasch
+0100, Michael Gasch wrote: could you please try the latest samba (or at least 3.0.23c) and use valid users = Unix Group\your_local_group This does not change very much: | [Server B] | # smbd -V | Version 3.0.23c-2 | # cat /etc/samba/smb.conf |grep valid users | valid users = Unix Group

[Samba] Documentation about level2-oplocks probably misleading?!?!

2006-12-01 Thread Michael Gasch
in the smb.conf file but testparm reports it as being set? or does testparm just display the default settings without logic checking (e.g. if kernel oplocks == yes, then level2 oplocks = no)? thx! hope my question is clear :) micha -- Michael Gasch Max Planck Institute for Evolutionary Anthropology

Re: [Samba] Trouble Renaming Computer

2006-11-14 Thread Michael Gasch
-512) - DomainAdmins /etc/group shows. DomainAdmins:x:507:elinori,root /etc/samba/smbusers # Unix_name = SMB_name1 SMB_name2 ... root = administrator admin Is there something i am missing? What do the log errors mean? Regards, Les -- Michael Gasch Max Planck Institute for Evolutionary

Re: [Samba] Weird Samba upload performance on Gigabit network

2006-11-12 Thread Michael Gasch
hey david, are you by any chance running OSX 10.4.8? we had the same problem and it was related to samba OSX (10.4.8). OSX to an W2k3-Server was fine. so we thought it might be samba. but after downgrading OSX to 10.4.7 everything was fine again. so the apple update must have changed/ broken

Re: [Samba] noobie winbind question

2006-11-08 Thread Michael Gasch
hi Does that mean that with a Samba PDC with winbindd running, samba users could log onto a Linux machine without having a Linux user account? yes, winbindd can retrieve the required information from an AD-/ NT-domain and dynamically map windows accounts to linux accounts. on a PDC winbindd

Re: [Samba] Logon script with Administrator rights

2006-10-25 Thread Michael Gasch
los modelos de serie y extras en MSN Motor. http://motor.msn.es/researchcentre/ -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax

Re: [Samba] rrd tool to make samba usage graphs?

2006-10-15 Thread Michael Gasch
hi, not really an answer, but you could trigger the rrd with a preexec script. greez Guido Lorenzutti wrote: Someone knows of a tool to make samba usage graphs? I know this isn't exactly samba related. But I have several samba fileservers and it would be great to have such tool to measure the

Re: [Samba] [Follow-UP] samba BDC + LDAP slave Referral errors

2006-10-11 Thread Michael Gasch
for causing so much trouble! thx! Andrew Bartlett wrote: On Tue, 2006-10-10 at 11:22 +0200, Michael Gasch wrote: hi, sorry to confuse you. i did set up updateref but no additional referrals. as i read here http://tech.stlsawall.com/index.php/?page_id=4 it´s impossible to have simple bind working

Re: [Samba] [Follow-UP] samba BDC + LDAP slave Referral errors

2006-10-10 Thread Michael Gasch
to modify a replicated local database. If specified multiple times, each url is provided. Best Regards, Bruno Guerreiro -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Michael Gasch Sent: terça-feira, 10 de Outubro de 2006 7:37 To: samba Subject: [Samba

Re: [Samba] samba BDC + LDAP slave Referral errors

2006-10-09 Thread Michael Gasch
/pdb_ldap.c:ldapsam_update_sam_account(1720) ldapsam_update_sam_account: failed to modify user with uid = pc00829$, error: (Success) Kind regards, Ivo Zwonarz. -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig

[Samba] [Follow-UP] samba BDC + LDAP slave Referral errors

2006-10-09 Thread Michael Gasch
/pdb_ldap.c:ldapsam_update_sam_account(1720) ldapsam_update_sam_account: failed to modify user with uid = pc00829$, error: (Success) Kind regards, Ivo Zwonarz. -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany

[Fwd: Re: [Samba] How to tell Samba not to use the passwd file]

2006-10-01 Thread Michael Gasch
. Hmmm...ok. Must have gotten broken then. Thanks for letting me know. i did not verified the current state but did you make any progress in this? just asking :) ... greez -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz

[Samba] inverse veto files

2006-10-01 Thread Michael Gasch
odt-files to be stored on a share regex would be nice to have but i'm aware of the complexity and possible performance issues. thx! micha -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone

Re: [Samba] prevent users from logging in as nobody

2006-09-28 Thread Michael Gasch
this? Thanks, -Jeff Hi Jeff Please check whether the user nobody is mapped to guest or false password. Regards Rune -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137

Re: [Samba] prevent users from logging in as nobody

2006-09-27 Thread Michael Gasch
guest ok = no in [global] if nobody is your guest account greez Jeff Davis wrote: OK, probably a rookie question, but I've got some users that have been logging in to the domain as nobody... What do I need to change to disable this? Thanks, -Jeff -- To unsubscribe from this list go to

Re: [Samba] file locking question

2006-09-24 Thread Michael Gasch
? TIA, Greg -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399 -- To unsubscribe from this list go

Re: [Samba] Finding Accounts inside Trusted Domains

2006-09-23 Thread Michael Gasch
hi, if the trust has correctly been set up this should work. your workstation will contact your DC supplying the creds you gave it (MATH\user incl. pw). the DC will then forward this to its trusted DC (MATH DC). this should reply with OK and your DC should allow login. are you running

Re: [Samba] NT Group to single unix ID

2006-09-13 Thread Michael Gasch
hi, i recommend using username map like user1 = @nt_group1 micha Randall, Ray wrote: Hello Samba Gurus, I have been searching for a week for a solution to this problem with no resolution thus far. I have a need to map an NT Group (a large group of NT users) to a single unix user ID. I

Re: [Samba] String to SID

2006-09-13 Thread Michael Gasch
try using fully qualified domain names micha Matthew Preskett wrote: After upgrading from samba 3.0.22 to 3.0.23a (FC 5) i started having problems with groups and access to shares. (using winbind for group mapping) Looking in my smbd.log i found errors relating to string_to_sid:

Re: [Samba] Re: samba + ldap query filter

2006-09-05 Thread Michael Gasch
it seems that is not used in new versions of samba :( the official advise is to configure it via nss-ldap configuration file micha -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

[Samba] [Follow-Up] Domain login - XP 64 - Samba

2006-08-31 Thread Michael Gasch
hi list, just read this http://www.gatago.com/linux/samba/14522736.html and this seems to be my solution 'cause i'm also hitting the same problem. unfortunately i can't use original debian packages anymore, because they seem to not integrate the patch, yet (still sub-releases of 3.0.14). or

Re: [Samba] Mount CiFS as root on Linux

2006-08-20 Thread Michael Gasch
hi, but what about pipes KDE for example is creating during session startup? had this problem with home directories mounted with cifs, where KDE did not start successfully. didn't verify this with recent versions. micha Andrew Bartlett wrote: On Fri, 2006-08-18 at 14:04 +0200, Jerome

Re: [Samba] samba 3.0.23b - cannot create builtin accounts

2006-08-20 Thread Michael Gasch
i guess it's net sam createbuiltin (requires winbindd running) greez -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

Re: [Samba] where winbindd has to be running?

2006-08-20 Thread Michael Gasch
Gianluca Cecchi wrote: If I have a samba 3 pdc and a samba 3 domain member. The latter has also ssh/telnet access through network. I want to authenticate smb connections for both and telenet for domain member against the pdc. Where has to be running winbindd? On pdc, domain member or both? Which

Re: [Samba] Problem with Domain SID

2006-08-18 Thread Michael Gasch
the 'profiles' tool to change all the SIDs in the user profile file (NTUSER.DAT) Simo. -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49

Re: [Samba] pam_winbind says I need new password

2006-08-16 Thread Michael Gasch
-- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399 -- To unsubscribe from this list go to the following URL

Re: [Samba] smbldap-tools and disabling a user

2006-08-16 Thread Michael Gasch
-userdel supports deleting both, but smbldap-usermod only supports disabling the Samba half of things... - Logan -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49

Re: [Samba] 3.0.20 - 3.0.23 SID/group error?? Won't connect.

2006-08-13 Thread Michael Gasch
I've got a long mail that explains we made this change and we had a hard time with 3.0.23. I'll try to send it out next week. that's very good news! i was about to ask the list about these changes because they horribly confused me :) thx! micha -- To unsubscribe from this list go to the

Re: [Samba] FW: HELP -- Problem with access list on samba 3.0.23b but not on 3.0.20c PDC

2006-08-10 Thread Michael Gasch
did you try putting the domain component in front of groups/users? if you comment out valid users it works, right? micha M. D. Parker wrote: -Original Message- From: M. D. Parker [mailto:[EMAIL PROTECTED] Sent: Thursday, August 10, 2006 9:02 AM To: 'samba@lists.samba.org' Subject:

Re: [Samba] Identically named users and groups

2006-08-09 Thread Michael Gasch
the world better? --Balian -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.4 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFE2IfWIR7qMdg1EfYRAqtlAJ9PpSQ5MWinpY9ypzz6GZFCO44YywCgludf TmP3IRehGnRBAxYjC/NCHy8= =8d3j -END PGP SIGNATURE- -- Michael

Re: [Samba] Samba 3.0.23b Available for Download

2006-08-09 Thread Michael Gasch
to local accounts and their tokens will be modified appropriately to reflect the local SID and group membership. and if winbind is running with use default domain are users also mapped to local ones? many thx in advance! micha -- Michael Gasch Max Planck Institute for Evolutionary Anthropology

Re: [Samba] Samba 3.0.23b Available for Download

2006-08-09 Thread Michael Gasch
to local accounts and their tokens will be modified appropriately to reflect the local SID and group membership. and if winbind is running with use default domain are users also mapped to local ones? many thx in advance! micha -- Michael Gasch Max Planck Institute for Evolutionary Anthropology

Re: [Samba] Identically named users and groups

2006-08-09 Thread Michael Gasch
and a group at the same time. How did you get Windows to do that? well, this was kind of mind game: i have a samba PDC with a group test and a user test. this works fine for the DC (tested). how would samba on a member solve this issue, if smbclient connects (no windows involved)? micha -- Michael

Re: [Samba] Identically named users and groups

2006-08-09 Thread Michael Gasch
ok, understand :) i just wanted to find out the way samba would solve this issue if there´s a user and a group with the same name. if i´d ever face this problem, i would rename either of them. thx! micha Volker Lendecke wrote: On Wed, Aug 09, 2006 at 11:02:24AM +0200, Michael Gasch wrote

Re: [Samba] Identically named users and groups

2006-08-08 Thread Michael Gasch
(MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFE11PrIR7qMdg1EfYRAjBmAKDkFM5/L1fdGKy97rbzky0y4cvb6gCgtkgM P2F5fJqC/zMD1Ye/lJ355mU= =Y8l/ -END PGP SIGNATURE- -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution

Re: [Samba] reverse veto files?

2006-08-06 Thread Michael Gasch
Guido Lorenzutti wrote: Im currently having a very long list of veto files, just to be sure that the people ONLY can write documents and styleshets. Is there any plan to have a reverse veto files to ONLY allow this type of file? Because when I have a lot of veto files the samba gets too slow,

Re: [Samba] Problem with PRODUCTION machine, please respond quickly!!

2006-08-04 Thread Michael Gasch
check the ACL's of this file with getfacl? RAlf -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399

Re: [Samba] Problem with PRODUCTION machine, please respond quickly!!

2006-08-04 Thread Michael Gasch
the script the sets some rights before another script tries te delete the files... Let me check on this for a moment... Be wright back at ya... On vr, 2006-08-04 at 12:30 +0200, Michael Gasch wrote: # file: frontpg.lck # owner: mpsfrontpageacct # group: Domain\040Admins user::r-- user:wws01$:rwx

Re: [Samba] Samba 3.0.14 and w2k3 terminal server / strange logon problem / is this in general possible

2006-08-02 Thread Michael Gasch
1. Is it possible to use samba as a DC and connect to the DC over a TS/CAE Server on w2k3 server. that`s exactly the same setup we´re happily running sounds like the w2k3 machine has not been joined properly? can you logon (directly) to the w2k3 machine as a domain member? greez -- Michael

Re: [Samba] [HELP] Samba 3.0.23a pam_winbind says password expired

2006-08-02 Thread Michael Gasch
; } } With best regards, P. Trifonov -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399

[Samba] [questions] aio settings in smb.conf and compile options

2006-08-01 Thread Michael Gasch
for example?!?! -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399 -- To unsubscribe from this list go

[Samba] [HELP] Samba 3.0.23a pam_winbind says password expired

2006-08-01 Thread Michael Gasch
hi, i just do some tests with a fresh compiled samba 3.0.23a. trying to authenticate against PAM with pam_winbind gives: Aug 1 09:59:21 humevo36 pam_winbind[27853]: pam_winbind: pam_sm_authenticate (flags: 0x) Aug 1 09:59:23 humevo36 pam_winbind[27853]: Verify user `gasch' Aug 1

Re: [Samba] [HELP] Samba 3.0.23a pam_winbind says password expired

2006-08-01 Thread Michael Gasch
humevo36 su: FAILED SU (to gasch) gasch on /dev/pts/3 It seems to me that I have similar problem. However, su succeeds and just writes to the console Your password has expired With best regards, P. Trifonov -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department

Re: [Samba] [HELP] Samba 3.0.23a pam_winbind says password expired

2006-08-01 Thread Michael Gasch
hi peter, thx for your response. so what's the difference in our setups? could you please post your samba DC version, pam settings and smb.conf of the member? i want to figure out my problem. i'm not new to samba so we should be able to fix this rather soon :) thx! Peter Trifonov wrote:

Re: [Samba] [questions] aio settings in smb.conf and compile options

2006-08-01 Thread Michael Gasch
thx to jeremy and volker for your quick and detailed response (as usual)... if someone has any explanation for --with-automount i would appreciate this as well :) i'm just trying to explore samba features i recognized but often can't interpret there meaning. @jeremy looks like you took

Re: [Samba] trust domain list

2006-07-28 Thread Michael Gasch
hi in short words: what is the difference in output between: Trusted domains list: DOMA S-1-5-21-790525478-1844823847-725345543 DOMB S-1-5-21-776971034-1374619893-1389755056 means you trust those remote DCs. your DC relies on the correct authentication of

Re: [Samba] ldapsam ignores ldap user suffix when doing username lookup

2006-07-27 Thread Michael Gasch
hi, what about using ACLs to restrict uid-searches in the base for samba admin? greez Haas Florian wrote: Greetings. Since this is my first post to this list, hello everyone. Here's an issue concerning the ldapsam backend. I'm having a problem with the ldap user suffix param not being

Re: [Samba] samba still remembers the old domain name i used for testing

2006-07-27 Thread Michael Gasch
éric le hénaff wrote: hello i tried to do a fresh start with erasing all tdb files but when i restart samba it still remembers the old domain name i used for testing net getlocalsid gives domain B and should give domain A. how to fix it ? thank you did you delete secrets.tdb? greez -- To

Re: [Samba] BDC - how do I check logons?

2006-07-26 Thread Michael Gasch
netstat, network traces or smbstatus on BDC greez Martin Hochreiter wrote: Hi! How do I check If a XP client uses the BDC for logons and not the PDC? lg Martin -- To unsubscribe from this list go to the following URL and read the instructions:

Re: [Samba] BDC - how do I check logons?

2006-07-26 Thread Michael Gasch
you have to check for connections to IPC$ share during client logon process greez Martin Hochreiter wrote: Michael Gasch schrieb: netstat, network traces or smbstatus on BDC greez Martin Hochreiter wrote: Hi! How do I check If a XP client uses the BDC for logons and not the PDC? lg

Re: [Samba] How can I influence domain logons? was: BDC - how do I check logons?

2006-07-26 Thread Michael Gasch
i think you can't really influence this. the client (in the netbios world) broadcasts for the DMB #1b and for DCs #1c. the first DC answering will be contacted IMHO. for testing purposes you could try to stop *mbds on PDC and try to logon on a client. it should contact the BDC. greez

[Fwd: Re: [Samba] USRMGR and 3.0.23a]

2006-07-25 Thread Michael Gasch
does this explain the behaviour in your case? greez -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

Re: [Samba] User rights: Disable user right to delete

2006-07-25 Thread Michael Gasch
fname lname wrote: is it possible to give a user the right modify a file but not to del a file? a file that he owns or someone else? greez -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba

Re: [Samba] Excluding directories from a read-only = yes

2006-07-20 Thread Michael Gasch
i think it's hard in smb.conf without using ACLs provided by the filesystem. can you use veto files, or must your users be able to see those thousands of folders, too? greez Ed Curtis wrote: I have a share with thousands of folders. In each of those folders there is another directory named

Re: [Samba] Cifs Mount w/ACL

2006-07-20 Thread Michael Gasch
this tool could be a possible workaround http://de.samba.org/samba/docs/man/manpages-3/smbcacls.1.html greez Max Kipness wrote: Hello - I've tried doing some research of previous posts and can't seem to figure out how this may be done. Basically I would like to mount a Windows XP share

Re: [Samba] Precedence of access parameters

2006-07-06 Thread Michael Gasch
= user1 user2 read list = user1 write list = user2 thanks in advance for any info... -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49

Re: [Samba] Default behavior of setting SUID bit in directories.

2006-07-04 Thread Michael Gasch
. I'm using Debian Sarge for example, and it doesn't do that, I dont know even how to enable that behavior. Am I missing something? Any Linux/Unix flavor does that (inherit the owner when a directory has the SUID bit set) by default? Regards. Edmundo Valle Neto -- Michael Gasch Max

Re: [Samba] System account home directory exposure

2006-07-04 Thread Michael Gasch
= administrator admin #nobody = guest -- Michael Gasch Max Planck Institute for Evolutionary Anthropology Department of Human Evolution (IT Staff) Deutscher Platz 6 D-04103 Leipzig Germany Phone: 49 (0)341 - 3550 137 49 (0)341 - 3550 374 Fax: 49 (0)341 - 3550 399 -- To unsubscribe from this list

Re: [Samba] Samba and trusted domains

2006-07-03 Thread Michael Gasch
idmap_init: could not load remote backend 'ITGIL=1-1' Could not init idmap -- netlogon proxy only The idmap directory exists; do I need to run something manually? P.S ITGIL = my domain EU15 = my trusted domain Thanks, Nir -Original Message- From: Michael Gasch [mailto:[EMAIL

Re: [Samba] Samba and trusted domains

2006-07-03 Thread Michael Gasch
should add to my smb.conf file when ITGIL = my domain and EU15 = my trusted domain? Thanks, Nir -Original Message- From: Michael Gasch [mailto:[EMAIL PROTECTED] Sent: Monday, July 03, 2006 11:22 AM To: Nir Barkan Cc: samba@lists.samba.org Subject: Re: [Samba] Samba and trusted domains

Re: [Samba] Samba and trusted domains

2006-07-03 Thread Michael Gasch
on the winbind debug Nir -Original Message- From: Michael Gasch [mailto:[EMAIL PROTECTED] Sent: Monday, July 03, 2006 2:31 PM To: Nir Barkan Cc: samba@lists.samba.org Subject: Re: [Samba] Samba and trusted domains looks good, but the log isn´t very informative. what does now id EU15

Re: [Samba] Samba and trusted domains

2006-07-03 Thread Michael Gasch
getservbyname() avoid nis services: files nis sendmailvars: files printers: user files nis auth_attr: files nis prof_attr: files nis project:files nis project:files nis -Original Message- From: Michael Gasch [mailto:[EMAIL PROTECTED] Sent: Monday, July 03, 2006 4:06 PM To: Nir

  1   2   3   4   >