Re: [Samba] Error in provisioning Samba4 Alpha 18 from git

2012-02-16 Thread steve
. Run make again. Make install deletes stuff in the build. Then the provision will work. HTH, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Build Active Directory with Samba

2012-02-16 Thread steve
/index.php/Samba4/HOWTO HTH, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] acl's, Samba4 and rw shares

2012-02-16 Thread steve
ntacls I believe I've done a few ldbsearch's in /usr/local/samba/private but I can't find anything to do with the dropbox share I have defined. Any ideas? Thanks On 02/16/2012 06:37 AM, steve wrote: Hi I'm trying to make a share called dropbox rw for members of a group. /usr/local/samba/etc

Re: [Samba] Samba4 internal dns server cannot find ldap

2012-02-16 Thread steve
On 02/14/2012 07:56 AM, Kai Blin wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 2012-02-12 10:23, steve wrote: Hi Steve, ../source4/dsdb/dns/dns_update.c:294: Failed DNS update - NT_STATUS_IO_TIMEOUT dns child failed to find name '_ldap._tcp.HH3.SITE' of type SRV finddcs: Failed

Re: [Samba] acl's, Samba4 and rw shares

2012-02-16 Thread steve
with. I posed this question in samba-technical IRC, was advised that samba-tool ntacl was more for scripting than actual management at this point in time.. I believe you'll get better results with tieing up a windows box.. On 02/16/2012 12:31 PM, steve wrote: On 02/16/2012 03:48 PM, Aaron E

Re: [Samba] Samba4 internal dns server cannot find ldap

2012-02-16 Thread steve
cp smb.conf.steve back to smb.conf add your interfaces=??? to it and hope for the best. Or are we talking about a clean install from nothing? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 ldbmodify Unwilling to perform error 53

2012-02-15 Thread steve
On 15/02/12 14:35, Andrew Bartlett wrote: On Tue, 2012-02-14 at 16:56 +0100, steve wrote: Hi everyone samba --version Version 4.0.0alpha18-GIT-bfc7481 openSUSE 12.1 If I do this: ldbmodify --url=/usr/local/samba/private/sam.ldb -b dc=hh3,dc=site dn: CN=steve6,CN=Users,DC=hh3,DC=site

Re: [Samba] samba4 provision error

2012-02-15 Thread steve
and then it should provision OK. HTH Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba4 gid-to-sid question

2012-02-15 Thread steve
question is, to which category of SID does S-1-5-21-980186919-4150830324-975011627-1121 belong? Can we assume that this is fixed for the life of the domain? Under what circustances could s4 change it, and if id did, would we be given warning? Thanks, Steve -- To unsubscribe from this list go

Re: [Samba] samba 4 PAM and xscreensaver

2012-02-15 Thread steve
On 01/09/2012 08:42 AM, steve wrote: Hi I have a Linux client running XFCE and authenticating against Samba 4. When trying to return to the session after xscreensaver has kicked in, authentication fails. Sorry to bump, but I've just seen this in the xscreensaver doco: XScreenSaver

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-14 Thread steve
No s3 installed on this box. Where is the info coming from now? Thanks, Steve Samba4 stores idmap information under an idmap.ldb named ldb file which is NOT exported to AD. So you could modify things by ldbediting it directly. Geza, I'm really struggling with ldbsearch. The doco is almost non

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-14 Thread steve
On 14/02/12 10:50, steve wrote: On 02/14/2012 06:47 AM, Gémes Géza wrote: Hi On 02/13/2012 07:53 PM, Gémes Géza wrote: Hi, See comments/questions below: Hi When I type this: getent passwd steve6 steve6:*:315:316:steve6:/home/CACTUS/steve6:/bin/bash I can see that the info is coming

[Samba] Samba4 ldbmodify Unwilling to perform error 53

2012-02-14 Thread steve
have to do: ldbmodify the add stuff sleep 5 ldbmodify the replace stuff What am I doing wrong? Maybe my slow hardware? Is it possible to add and replace in one go? Cheers, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman

Re: [Samba] samba-tool set default group

2012-02-13 Thread steve
On 10/02/12 18:28, Gémes Géza wrote: 2012-02-10 12:11 keltezéssel, steve írta: On 02/10/2012 12:08 PM, steve wrote: On 02/09/2012 07:17 PM, Gémes Géza wrote: 2012-02-09 14:21 keltezéssel, steve írta: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool

[Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-13 Thread steve
is the info coming from now? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-13 Thread steve
coming from now? Thanks, Steve Regards Geza Everything is OK. Login and uid:gid mapping are fine on both Linux and win7 clients. I'm just trying to script all this from the Linux side without having to tie up a win7 box to do it. The other thread explains why I know there must be a difference

Re: [Samba] Samba 4, where is wbinfo 'info' stored?

2012-02-13 Thread steve
On 02/13/2012 08:03 PM, steve wrote: On 02/13/2012 07:53 PM, Gémes Géza wrote: Hi, See comments/questions below: Hi When I type this: getent passwd steve6 steve6:*:315:316:steve6:/home/CACTUS/steve6:/bin/bash I can see that the info is coming from LDAP by looking at the ldif for cn

[Samba] Samba4 internal dns server cannot find ldap

2012-02-12 Thread steve
in the internal server? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] samba 4 provision fails [solved]

2012-02-12 Thread steve
On 02/11/2012 12:16 PM, steve wrote: On 02/11/2012 09:07 AM, steve wrote: Version 4.0.0alpha18-GIT-389bb4f Ubuntu 11.10 Provision fails with: Setting up sam.ldb users and groups Traceback (most recent call last): File ./source4/setup/provision, line 262, in module useeadb=eadb, next_rid

[Samba] Samba 4 no longer accepts SASL GSSAPI?

2012-02-12 Thread steve
passwd uid samAccountName mappasswd homeDirectoryunixHomeDirectory sasl_mech GSSAPI sasl_realm HH3.SITE krb5_ccname /tmp/krb5cc_0 There is a ticket cache in /tmp/krb5cc_0 A conventional bind works fine. Thanks, Steve -- To unsubscribe from this list go to the following URL

Re: [Samba] samba 4 provision fails [solved]

2012-02-12 Thread steve
On 02/12/2012 07:01 PM, Matthieu Patou wrote: Steve Ubuntu no longer ships with libreadline5-dev The apt-get line in the wiki should read: apt-get install build-essential libattr1-dev libblkid-dev libgnutls-dev libreadline-gplv2-dev python-dev autoconf python-dnspython gdb pkg-config

[Samba] samba 4 provision fails

2012-02-11 Thread steve
? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] samba 4 provision fails

2012-02-11 Thread steve
On 02/11/2012 09:07 AM, steve wrote: Version 4.0.0alpha18-GIT-389bb4f Ubuntu 11.10 Provision fails with: Setting up sam.ldb users and groups Traceback (most recent call last): File ./source4/setup/provision, line 262, in module useeadb=eadb, next_rid=opts.next_rid, lp=lp) File bin

Re: [Samba] samba-tool set default group

2012-02-11 Thread steve
On 02/11/2012 11:07 PM, Matthieu Patou wrote: On 02/09/2012 05:21 AM, steve wrote: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve But steve's default group is still Users. I'm looking for soething like this: 'samba

Re: [Samba] samba-tool set default group

2012-02-10 Thread steve
On 02/09/2012 07:17 PM, Gémes Géza wrote: 2012-02-09 14:21 keltezéssel, steve írta: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve But steve's default group is still Users. I'm looking for soething like this: 'samba

Re: [Samba] samba-tool set default group

2012-02-10 Thread steve
On 02/10/2012 12:08 PM, steve wrote: On 02/09/2012 07:17 PM, Gémes Géza wrote: 2012-02-09 14:21 keltezéssel, steve írta: Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve But steve's default group is still Users. I'm

[Samba] latest Samba 4 does not look in keytab

2012-02-10 Thread steve
/hh3.hh3.s...@hh3.site (des-cbc-md5) 1 nfs/hh3.hh3.s...@hh3.site (arcfour-hmac) How do I tell this new version to look in the keytab? or, How do I add the nfs internally? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

[Samba] Samba 4 samba-tool user add fails

2012-02-10 Thread steve
samba-tool user add nfs-u New Password: ERROR(ldb): Failed to add user 'nfs-u': - operations error at ../source4/dsdb/samdb/ldb_modules/password_hash.c:2163 Anyone? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

Re: [Samba] latest Samba 4 does not look in keytab

2012-02-10 Thread steve
On 02/10/2012 07:24 PM, Gémes Géza wrote: 2012-02-10 17:58 keltezéssel, steve írta: Hi After upgrading to Version 4.0.0alpha18-GIT-24ed8c5 on Ubuntu 11.10, Samba 4 no longer looks in the keytab for my nfs server entry: mount -t nfs4 foo bar --o sec=krb5 Kerberos: AS-REQ nfs/hh3.hh3.s...@hh3

Re: [Samba] RFC2307 Samba4 [Was: Linux users and Samba 4]

2012-02-09 Thread steve
On 13/01/12 16:59, Adam Tauno Williams wrote: On Fri, 2012-01-13 at 10:32 -0500, Adam Tauno Williams wrote: On Fri, 2012-01-13 at 02:51 +0100, steve wrote: On 12/01/12 23:02, Adam Tauno Williams wrote: Quoting stevest...@steve-ss.com: Samba4's winbind does not support RFC2307, so doing

[Samba] samba-tool set default group

2012-02-09 Thread steve
Hi How do I set the default group for a user? e.g. samba-tool group add opensuse samba-tool group addusers opensuse steve But steve's default group is still Users. I'm looking for soething like this: 'samba-tool group setdefaultgroup steve opensuse' But here isn't that command. I have to do

Re: [Samba] Samba4 user mapping into filesystem

2012-02-09 Thread steve
] RFC2307 Samba4 [Was: Linux users and Samba 4] thread. Just posted an update to it so it's prob. in your inbox now. HTH, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4 and new Kerberos version

2012-02-08 Thread steve
On 07/02/12 20:52, Gémes Géza wrote: 2012-02-07 16:07 keltezéssel, steve írta: On 07/02/12 12:01, Andrew Bartlett wrote: On Tue, 2012-02-07 at 10:24 +0100, steve wrote: I just got this from the mit list: quote DES transition == The krb5-1.8 release disables single-DES

[Samba] Any news on Samba 4 winbind?

2012-02-08 Thread steve
. Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Any news on Samba 4 winbind?

2012-02-08 Thread steve
On 02/08/2012 09:43 AM, steve wrote: Hi I have nfs4 with idmapd working perfectly via the S4 LDAP. For Linux clients that is. I can specify uid:gid and name mapping works fine between server and client. If I want to map the Linux users to a windows 7 box, I'm stuck with the values

Re: [Samba] Samba 4 latest git failed to provision: DNS

2012-02-08 Thread steve
On 02/08/2012 01:33 AM, steve wrote: On 07/02/12 23:45, steve wrote: This: https://lists.samba.org/archive/samba-technical/2012-February/081535.html fixes this: More dns problems: samba --version Version 4.0.0alpha18-GIT-e32ad9b bin/tdbbackup: /home/steve/samba-master/bin/shared/private

Re: [Samba] Samba 4 posixGroup mapping

2012-02-07 Thread steve
On 07/02/12 06:57, Gémes Géza wrote: 2012-02-06 23:58 keltezéssel, steve írta: On 02/06/2012 08:10 PM, Gémes Géza wrote: 2012-02-06 09:29 keltezéssel, steve írta: On 02/06/2012 07:19 AM, Gémes Géza wrote: 2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called

[Samba] Samba 4 and new Kerberos version

2012-02-07 Thread steve
not support stronger ciphers. /quote Does/will this apply to us? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba 4 git pull error

2012-02-07 Thread steve
steve@hh3:~/samba-master git pull Updating bfc7481..e32ad9b error: Your local changes to the following files would be overwritten by merge: auth/common_auth.h auth/credentials/credentials_ntlm.c auth/credentials/credentials_samba3.c snip source3/lib/util_cmdline.c source3

Re: [Samba] Samba 4 posixGroup mapping

2012-02-07 Thread steve
idea. Would you include a default group for the user perhaps? e.g. samba-tool group addmembers $6 $1 ($6 would already exist) Looking good. Thanks for your time. Will report back. Cheers, Steve Hi Geza, hi everyone. I had a go at the script. I called it s4user and got it down to 4 parameters

Re: [Samba] Samba 4 posixGroup mapping

2012-02-07 Thread steve
Password: User 'steve6' created successfully SASL/GSSAPI authentication started SASL username: administra...@hh3.site SASL SSF: 56 SASL data security layer installed. modifying entry cn=steve6,cn=Users,dc=hh3,dc=site Added members to group suseusers steve6 rfc2307-ified hh3:/home/steve # exit exit steve

Re: [Samba] Samba 4 and new Kerberos version

2012-02-07 Thread steve
On 07/02/12 12:01, Andrew Bartlett wrote: On Tue, 2012-02-07 at 10:24 +0100, steve wrote: I just got this from the mit list: quote DES transition == The krb5-1.8 release disables single-DES cryptosystems by default. As a result, you may need to add the libdefaults setting

[Samba] Samba 4 latest git failed to provision: DNS

2012-02-07 Thread steve
More dns problems: samba --version Version 4.0.0alpha18-GIT-e32ad9b bin/tdbbackup: /home/steve/samba-master/bin/shared/private/libtdb.so: version `SAMBA_4.0.0ALPHA18_DEVELOPERBUILD' not found (required by bin/tdbbackup) Failed to setup database for BIND, AD based DNS cannot be used Traceback

Re: [Samba] Samba 4 latest git failed to provision: DNS

2012-02-07 Thread steve
On 07/02/12 23:45, steve wrote: More dns problems: samba --version Version 4.0.0alpha18-GIT-e32ad9b bin/tdbbackup: /home/steve/samba-master/bin/shared/private/libtdb.so: version `SAMBA_4.0.0ALPHA18_DEVELOPERBUILD' not found (required by bin/tdbbackup) Failed to setup database for BIND, AD

Re: [Samba] Samba 4 posixGroup mapping

2012-02-06 Thread steve
On 02/06/2012 07:19 AM, Gémes Géza wrote: 2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called suseusers and mixed in posixGroup and gidNumber using samba-tool group add as a basis. It works, e.g. when I added an existing user to the group: getent group suseusers

Re: [Samba] Samba 4 posixGroup mapping

2012-02-06 Thread steve
On 02/06/2012 08:10 PM, Gémes Géza wrote: 2012-02-06 09:29 keltezéssel, steve írta: On 02/06/2012 07:19 AM, Gémes Géza wrote: 2012-02-06 01:27 keltezéssel, steve írta: Hi I've created a Samba 4 group called suseusers and mixed in posixGroup and gidNumber using samba-tool group add as a basis

Re: [Samba] Samba4: Incorrect version of dlz_bind9.so

2012-02-05 Thread steve
/dlz_minimal.h edit out #define DLZ_DLOPEN_VERSION 1 and add #define DLZ_DLOPEN_VERSION 2 Then rebuild: ./configure.developer. . . HTH Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba 4 wbinfo -i question

2012-02-05 Thread steve
Hi In this example, wbinfo -i steve CACTUS\steve:*:319:100:steve4:/home/CACTUS/steve4:/bin/bash where is the '100' stored? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] Samba 4 posixGroup mapping

2012-02-05 Thread steve
at it. Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] samba machine$ accounts

2012-02-02 Thread steve
join prepares a keytab with host/fqdn@REALM host/hostname@REALM hostname$@REALM entries. 1. Can I have the net command without installing the whole of Samba? 2. Is this part of what happens during net ads join -Uxxx? net ads keytab add hostname$ openSUSE 12.1 Thanks, Steve -- To unsubscribe

Re: [Samba] nfs4 with Samba 4 [solved]

2012-02-01 Thread steve
On 01/31/2012 05:13 PM, steve wrote: On 01/29/2012 10:20 AM, steve wrote: On 29/01/12 08:17, steve wrote: On 29/01/12 07:32, Gémes Géza wrote: 2012-01-28 21:44 keltezéssel, steve írta: On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve

Re: [Samba] samba 4 PAM and xscreensaver

2012-02-01 Thread steve
On 01/09/2012 08:42 AM, steve wrote: Hi I have a Linux client running XFCE and authenticating against Samba 4. When trying to return to the session after xscreensaver has kicked in, authentication fails. Sorry to bump, but I've just seen this in the xscreensaver doco: XScreenSaver

Re: [Samba] nfs4 with Samba 4

2012-01-31 Thread steve
On 01/29/2012 10:20 AM, steve wrote: On 29/01/12 08:17, steve wrote: On 29/01/12 07:32, Gémes Géza wrote: 2012-01-28 21:44 keltezéssel, steve írta: On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza

Re: [Samba] nfs4 with Samba 4

2012-01-29 Thread steve
On 29/01/12 08:17, steve wrote: On 29/01/12 07:32, Gémes Géza wrote: 2012-01-28 21:44 keltezéssel, steve írta: On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: As the nfs4 is writeable

[Samba] nfs4 with Samba 4

2012-01-28 Thread steve
to cd to /mnt. Only root can enter. The permissions using ls -la are: d? ? ???? mnt You can see that /home has indeed been mounted but with strange permissions. Has anyone tried nfs with Samba 4 Kerberos? Why the permissions? What am I missing? Cheers, Steve

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread steve
On 28/01/12 11:03, Gémes Géza wrote: 2012-01-28 10:40 keltezéssel, steve írta: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 openSUSE 12.1 Conventional nfs4 export works fine, but I'm having trouble kerberizing it for Samba 4 for my Samba 4 users. I've setup the nfs4 pseudo stuff like

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread steve
On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: Summary: 1. kerberized /etc/exports /exportgss/krb5(rw,fsid=0,insecure,no_subtree_check,async) /export/homegss/krb5(rw,nohide,insecure,no_subtree_check,async) then: mount -t nfs4 hh3:/home /mnt -o sec=krb5

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread steve
On 28/01/12 17:12, Gémes Géza wrote: 2012-01-28 12:21 keltezéssel, steve írta: On 28/01/12 11:03, Gémes Géza wrote: 2012-01-28 10:40 keltezéssel, steve írta: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 openSUSE 12.1 Conventional nfs4 export works fine, but I'm having trouble kerberizing

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread steve
On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: Summary: 1. kerberized /etc/exports /exportgss/krb5(rw,fsid=0,insecure,no_subtree_check,async) /export/homegss/krb5(rw,nohide

Re: [Samba] nfs4 with Samba 4

2012-01-28 Thread steve
On 29/01/12 07:32, Gémes Géza wrote: 2012-01-28 21:44 keltezéssel, steve írta: On 28/01/12 20:29, Gémes Géza wrote: 2012-01-28 18:41 keltezéssel, steve írta: On 28/01/12 12:21, steve wrote: On 28/01/12 11:03, Gémes Géza wrote: As the nfs4 is writeable without the krb5, that's why I thought

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-26 Thread steve
On 01/27/2012 05:37 AM, Andrew Bartlett wrote: On Sun, 2012-01-22 at 15:32 +0100, steve wrote: even though I've made a ldap/hh3.site principal: hh3:/tmp # samba-tool spn add ldap/hh3.site Administrator hh3:/tmp # samba-tool domain exportkeytab /etc/ldap.keytab --principal=ldap/hh3.site Why do

[Samba] samba 3 a 4 with kerberized nfs4

2012-01-25 Thread steve
. I now mv the keytab and recreate it _without_ nfs. It still mounts! Why does the server(s4) need the nfs principal but the client(s3) not? How can I tell if Kerberos is working? Cheers, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https

[Samba] Samba 4 GSSAPI problem

2012-01-23 Thread steve
Hi Same checkout, same provision, same machine. openSUSE samba --version Version 4.0.0alpha18-GIT-c3a7573 hh3:/home/steve # ldapsearch -H ldap://192.168.1.3 cn=steve2 -b dc=hh3,dc=site -Y GSSAPI SASL/GSSAPI authentication started snip and all is OK. Ubuntu samba --version Version

Re: [Samba] Samba 4 GSSAPI problem

2012-01-23 Thread steve
On 23/01/12 15:37, Raffael Sahli wrote: On 01/23/2012 02:24 PM, steve wrote: Hi Same checkout, same provision, same machine. openSUSE samba --version Version 4.0.0alpha18-GIT-c3a7573 hh3:/home/steve # ldapsearch -H ldap://192.168.1.3 cn=steve2 -b dc=hh3,dc=site -Y GSSAPI SASL/GSSAPI

Re: [Samba] Samba 4 Cannot contact any KDC for requested realm

2012-01-22 Thread steve
On 22/01/12 10:19, Gémes Géza wrote: 2012-01-21 09:42 keltezéssel, steve írta: Version 4.0.0alpha18-GIT-957ec28 with dns hh3.site realm SITE After starting samba -i -d3, wbinfo -i someuser gives this: ldb_wrap open of secrets.ldb using SPNEGO Selected protocol [8][NT LANMAN 1.0] Cannot reach

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-22 Thread steve
On 20/01/12 18:19, steve wrote: On 01/20/2012 04:09 PM, Michael Wood wrote: On 20 January 2012 15:23, stevest...@steve-ss.com wrote: On 20/01/12 12:41, Michael Wood wrote: [...] I did this: samba-tool user add nslcd-service New Password: User 'nslcd-service' created successfully kinit

[Samba] Samba 4 Cannot contact any KDC for requested realm

2012-01-21 Thread steve
too. Any ideas? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

[Samba] samba-tool and net ads

2012-01-21 Thread steve
Hi 1. How do I do this: samba-tool domain exportkeytab anyold.keytab --principal=samba4user on a box without samba-tool? 2. Is anyold.keytab, valid only for the machine upon which it was created? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-20 Thread steve
On 20/01/12 07:55, steve wrote: Hi, Even if you are scared of death of samba-technical I'm posting it there as well, maybe someone can answer the questions which arise when I tried to check out your use case. So I've tried first: # ldapsearch -H ldap://samba4.kzsdabas.hu cn=Administrator

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-20 Thread steve
you could probably compile it yourself. If I get time, I'll go through this on Ubuntu (where Geza pointed me to k5start). Thanks again. Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-20 Thread steve
I can't find k5start for openSUSE. I'll ask the guys over at the suse list for that one. Otherwise you could probably compile it yourself. If I get time, I'll go through this on Ubuntu (where Geza pointed me to k5start). Thanks again. Steve Got an old k5start from the openSUSE vaults

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-20 Thread steve
On 01/20/2012 04:09 PM, Michael Wood wrote: On 20 January 2012 15:23, stevest...@steve-ss.com wrote: On 20/01/12 12:41, Michael Wood wrote: [...] I did this: samba-tool user add nslcd-service New Password: User 'nslcd-service' created successfully kinit nslcd-service Password for nslcd

Re: [Samba] Samba 4 will not start after new checkout [URGENT]

2012-01-19 Thread steve
Hi everyone I've marked the thread as URGENT. Another post has reported similar during provisioning. Could someone on samba-technical send a copy there too? Thanks, Steve On 01/18/2012 08:40 PM, Charles Tryon wrote: Ummm... no, unless it's with using ANY external bind rather than

Re: [Samba] Samba 4 will not start after new checkout [URGENT]

2012-01-19 Thread steve
On 01/19/2012 09:23 AM, Michael Wood wrote: On 19 January 2012 10:05, stevest...@steve-ss.com wrote: Hi everyone I've marked the thread as URGENT. Another post has reported similar during provisioning. Could someone on samba-technical send a copy there too? It's been mentioned on samba

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-19 Thread steve
On 01/18/2012 09:56 PM, Gémes Géza wrote: 2012-01-18 12:12 keltezéssel, steve írta: On 01/17/2012 09:40 PM, Gémes Géza wrote: Hi, See comments inline: Hi everyone I'm trying to use kerberos to authenticate to Samba 4 ldap. At the moment, I authenticate by specifying the binddn and password

Re: [Samba] Samba 4 will not start after new checkout [OK now]

2012-01-19 Thread steve
All OK for me: samba --version Version 4.0.0alpha18-GIT-95c514a Cheers, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] is winbind needed if i provide unix attributes?

2012-01-19 Thread steve
no mappings. is this right? can i ignore winbind in my setup? regards, abosch Hi. We're running s3/LDAP with uid:gid, shell and home directory all in LDAP. No winbind anywhere. HTH Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

[Samba] Samba 4 LDAP security

2012-01-19 Thread steve
not the Admin password that is needed. Until I can get the kerberized bind working (probably never!), any comments about the security of this? Are there other processes where passwords have to be stored in a file? Thanks, Steve -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-19 Thread steve
I can bind is by removing the sasl_mech GSSAPI and giving the binddn and bindpw in /etc/nslcd.conf 'So I'm stuck with 'Unknown authentication method'. Are we sure that nslcd can bind using Kerbreros? Thanks for your patience, Steve Hi, Even if you are scared of death of samba-technical I'm

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-19 Thread steve
http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html#badpass I'm working as client and host on the same box here. Could this be the cause of the Decrypt integrity check failed ?? Cheers Steve -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-19 Thread steve
On 19/01/12 19:11, steve wrote: http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html#badpass I'm working as client and host on the same box here. Could this be the cause of the Decrypt integrity check failed ?? Cheers Steve Just to confirm: samba-tool spn delete host samba-tool

Re: [Samba] is winbind needed if i provide unix attributes?

2012-01-19 Thread steve
and Administrator on win 7. Samba for the win 7 clients only, nfs for Linux file sharing. You do not need to join the Linux clients to the domain if you use LDAP. Ubuntu and openSUSE have a great little utility to join the Linux clients to LDAP via nss-ldap. HTH Steve -- To unsubscribe from

[Samba] Samba 4 GSS server Update(krb5)(1) Update failed: Miscellaneous failure (see text): Decrypt integrity check failed

2012-01-19 Thread steve
something to do with what the KDC has and what the keytab has. The KDC and the keytab are on the same openSUSE machine. Deleting the principal brings me back to the first error and recreating it to the second. Can any Kerberos gurus help me with this one? Thanks Steve -- To unsubscribe from this list

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-19 Thread steve
: 2012-01-20T07:53:37 endtime: 2012-01-20T17:48:01 renew till: 2012-01-21T07:47:56 GSS server Update(krb5)(1) Update failed: Miscellaneous failure (see text): Decrypt integrity check failed And again the integrity check failed error. Help! Cheers, Steve -- To unsubscribe from this list go

Re: [Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-18 Thread steve
principal but samba-tool spn doesn't let me add an ldap principal. Any ideas anyone? Thanks, Steve Regards Geza Hi Geza OK. Now on Ubuntu. I have k5init installed and have made a host principal: klist -k /etc/host.keytab Keytab name: WRFILE:/etc/host.keytab KVNO Principal

[Samba] Samba 4 will not start after new checkout

2012-01-18 Thread steve
process model 'standard' my $PREFIX should be /usr/local/samba I think. The path is there and I can export PREFIX=/usr/local/samba but nada. Also, what about Unknown process model 'standard'. Can anyone help? Thanks Steve -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Samba 4 will not start after new checkout

2012-01-18 Thread steve
Hi I couldn't get any bind to work for Ubuntu on previous checkouts except 9.9.0b1 Have modified source4/dns_server/dlz_minimal.h Is bind the prob? If so how do I use the internal bind? Thanks Steve On 01/18/2012 07:31 PM, Charles Tryon wrote: Are you using bind9.8, 9.7 or the internal bind

[Samba] Samba 4 and GSSAPI kerberos ldap connect

2012-01-17 Thread steve
. Any ideas anyone? Thanks, Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4 ldb_wrap open of idmap.ldb

2012-01-17 Thread steve
On 18/01/12 04:54, Andrew Bartlett wrote: On Sun, 2012-01-15 at 14:49 +0100, steve wrote: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 I'm using nslcd to map Samba 4 users to uid:gid and home directory. At startup I get this: Why are you not using nss_winbind? I know the Samba4 winbindd

Re: [Samba] Samba 4 ldb_wrap open of idmap.ldb

2012-01-16 Thread steve
a password. But then that will only last for 10 hours before Administrator has to a kinit again. Is there a way around this? I know it's something to do with principals but have so far not been able to wor out which to apply. Cheers Steve -- To unsubscribe from this list go to the following URL

Re: [Samba] Samba 4 kerberos and kinit

2012-01-16 Thread steve
(apology. forgot to send only to list) On 01/16/2012 07:18 PM, steve wrote: Well, either it will need to have the password hard coded in the config file like you have it at the moment, I believe, or it will need a ticket to access the directory. Anyway, I've a 10 hour experiment in progress

[Samba] Samba 4 ldb_wrap open of idmap.ldb

2012-01-15 Thread steve
) #mapgroup cn groupName #mapgroup uniqueMember member #mapgroup gidNumbergid #sasl_mech GSSAPI sasl_realm HH3.SITE #krb5_ccname /tmp/krb5cc_0 Thanks Steve -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] Samba 4 ldb_wrap open of idmap.ldb

2012-01-15 Thread steve
On 01/15/2012 04:17 PM, Michael Wood wrote: Hi On 15 January 2012 15:49, stevest...@steve-ss.com wrote: Hi everyone Version 4.0.0alpha18-GIT-bfc7481 I'm using nslcd to map Samba 4 users to uid:gid and home directory. At startup I get this: ldb_wrap open of secrets.ldb WARNING: no socket

Re: [Samba] Samba 4 kerberos and kinit

2012-01-15 Thread steve
On 01/15/2012 04:04 PM, Michael Wood wrote: On 14 January 2012 12:52, stevest...@steve-ss.com wrote: On 14/01/12 03:19, Michael Wood wrote: On 14 January 2012 01:24, stevest...@steve-ss.comwrote: [...] drwxr-xr-x 118 root root 12288 Jan 13 23:55 etc -rw--- 1 root root 1225 Jan 13

Re: [Samba] Samba 4 ldb_wrap open of idmap.ldb

2012-01-15 Thread steve
, it survives a restart however). Just here for the record in case others had a problem. Steve -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4 kerberos and kinit

2012-01-15 Thread steve
On 01/15/2012 10:23 PM, Michael Wood wrote: On 15 January 2012 18:32, stevest...@steve-ss.com wrote: On 01/15/2012 04:04 PM, Michael Wood wrote: On 14 January 2012 12:52, stevest...@steve-ss.com wrote: On 14/01/12 03:19, Michael Wood wrote: On 14 January 2012 01:24, stevest...@steve

[Samba] Linux hidden files on windows 7

2012-01-14 Thread steve
Hi everyone win7 machine joined to Samba4 domain Windows is set to hide hidden files, but viewing my Linux home folder in explorer shows all the files, dot or no dot. It's OK but it looks a mess. Is there anyway I can stop the hidden Linux files from showing? Cheers Steve -- To unsubscribe

[Samba] Samba 4 Screenshots

2012-01-14 Thread steve
Hi everyone I asked a while ago about screenshots, and in an effort to move Samba 4 away from the realms (geddit?) of 'rocket scientists only need apply', I've made some screenshots. Hope you like them. http://linuxcostablanca.blogspot.com/2012/01/samba-4-screenshots.html Cheers, Steve

Re: [Samba] Samba 4 kerberos and kinit

2012-01-13 Thread steve
On 13/01/12 04:37, steve wrote: On 13/01/12 03:06, steve wrote: On 12/01/12 19:53, Gémes Géza wrote: 2012-01-12 11:16 keltezéssel, steve írta: On 12/01/12 08:49, Andrew Bartlett wrote: On Thu, 2012-01-12 at 06:15 +0100, Gémes Géza wrote: 2012-01-11 23:48 keltezéssel, steve írta: Hi After

Re: [Samba] Samba 4 kerberos and kinit

2012-01-13 Thread steve
file to put in /var/run/nslcd ? Its been a long night! Cheers Steve It's to do with the host principal no? I need to do the equivalent of this: kadmin add -r host/machine.sample.com How do I specify the 'r' option with samba-tool?? So that translates to: spn host user stuff samba-tool

<    3   4   5   6   7   8   9   10   11   12   >