[Samba] OpenSUSE 11.1 with OpenLDAP => some surprises (ldap.conf, nss-ldap.conf, nsswitch.conf)

2009-02-12 Thread malte . mueller
Hi, this has nothing directly to do with samba, but there might be some people who try to use samba with (Open)LDAP on OpenSUSE 11.1 like me. Between 10.2 and 11.1 the nss_ldap configuration has changed a bit. The file which configures the access to ldap is now /etc/nss-ldap.conf and seems t

Re: [Samba] 4th Submission to Samba List -- No Response Yet

2009-02-12 Thread Karolin Seeger
Hi Eric, On Wed, Feb 11, 2009 at 02:24:20PM -0800, Robinson, Eric wrote: > Thanks, guys. 3.0.28 is the latest that yum pulls down. I guess I can > build from source. maybe you are interested in using the 3.0.34 SerNet packages available at ftp://ftp.sernet.de/pub/samba/tested/ (as a yum repo). K

Re: [Samba] desactivating NTLM fallback when accessing a share and kerberos auth fails

2009-02-12 Thread Guillaume Rousse
Volker Lendecke a écrit : On Wed, Feb 11, 2009 at 05:10:02PM +0100, Guillaume Rousse wrote: Guillaume Rousse a écrit : For members of the domain, tough, the client first attempt a kerberos auth, which fails, as he is not using print server FQDN, and doesn't performs host name canonicalization.

Re: [Samba] Samba and NetAPP filers, the PDC problem...

2009-02-12 Thread Frank Bonnet
Volker Lendecke wrote: On Tue, Feb 10, 2009 at 01:45:38PM +0100, Frank Bonnet wrote: I run samba in full debug mode (10) then I get that kind of error Ah, that one. There was some discussion on the list recently iirc. What you definitely have to do is precreate the machine account with smbpass

Re: [Samba] The way things used to work...

2009-02-12 Thread J. Pilfold-Bagwell
Try changing "force group = foobar" to "force group = DOMAIN\foobar" . The way Samba handles groups was changed (it was in the release notes around 3.0.28) and if you use read list and write list in smb.conf, users are now specified using DOMAIN\username and groups using +DOMAIN \groupname instead

Re: [Samba] Samba and NetAPP filers, the PDC problem...

2009-02-12 Thread Volker Lendecke
On Thu, Feb 12, 2009 at 10:22:23AM +0100, Frank Bonnet wrote: > Well not much success even after creating the account by hand You might want to take a look at bug 5920 for the trick. Because I don't have a NetApp box to test, I can't really fix this. Volker pgpdjwVuwf282.pgp Description: PGP si

Re: [Samba] desactivating NTLM fallback when accessing a share and kerberos auth fails

2009-02-12 Thread Volker Lendecke
On Thu, Feb 12, 2009 at 09:49:01AM +0100, Guillaume Rousse wrote: > Is there any way to either: > - perform some kind of name canonicalization, either on client or server > side ? Set the correct service principal names in your DC. > - desactivate any kind of authentication but kerberos, either

Re: [Samba] Connect without password

2009-02-12 Thread Bertram Scharpf
Hi, Am Mittwoch, 11. Feb 2009, 16:40:52 -0500 schrieb John Drescher: > On Wed, Feb 11, 2009 at 4:31 PM, Bertram Scharpf > wrote: > > > > smbclient -N -U Guest //somepc/floppy -c 'get somefile.txt' > > > > Now, I tried for about 1 1/2 hours to configure the XP in some way > > that this is accepte

[Samba] SAMBA+LDAP: Domain-Policies WHERE?

2009-02-12 Thread Axel Werner
Hi! i realy got stuck on testing samba and ldap scenarios. i want to use PASSWORD POLICIES. But it looked like SAMBA ignores my Policy Settings within my LDAP DOMAIN Object. I have set - sambaMaxPwdAge 300 - sambaMinPwdAge 60 - sambaMinPwdLength 8 - sambaPwdHistoryLength 10 and so on. Someo

[Samba] Samba Newbie

2009-02-12 Thread Eddie Humphries
Hello, I have been looking for a Windows alternative for File & Print servers. Currently, we are using Win 2003. Patching overhead and virus outbreaks are becoming problematic with reducing head count. I have looked at the site, but there is no reference to 'better or the same as Win2003' only

Re: [Samba] desactivating NTLM fallback when accessing a share and kerberos auth fails

2009-02-12 Thread Guillaume Rousse
Volker Lendecke a écrit : On Thu, Feb 12, 2009 at 09:49:01AM +0100, Guillaume Rousse wrote: Is there any way to either: - perform some kind of name canonicalization, either on client or server side ? Set the correct service principal names in your DC. Many thanks, it worked. And I also made

[Samba] Samba 3.0.24 + LDAP - User Lockout not working

2009-02-12 Thread Axel Werner
Hi, im trying to setup a password policy with samba and openldap. while lockout works perfect on openldap it looks like it does not work with my samba. Ive set "sambaLockoutThreshold" to 3 and "sambaLockoutDuration" to -1 (lockout forever) within the Domain-Object in LDAP. So i expect whene

[Samba] Resilience inquiry: What happens to samba clients if a domain controller fails?

2009-02-12 Thread Avron Gray
Hello folks, I have been asked about the resilience of samba clients when faced with a domain controller failure. My client's environment has multiple Windows Domain Controllers (we'll call them dc1 - dc9). Assuming that domain replication operates as expected (and does, from Windows workstation

Re: [Samba] Samba and NetAPP filers, the PDC problem...

2009-02-12 Thread Frank Bonnet
Volker Lendecke wrote: On Thu, Feb 12, 2009 at 10:22:23AM +0100, Frank Bonnet wrote: Well not much success even after creating the account by hand You might want to take a look at bug 5920 for the trick. Because I don't have a NetApp box to test, I can't really fix this. Volker this does no

Re: [Samba] Samba and NetAPP filers, the PDC problem...

2009-02-12 Thread Volker Lendecke
On Thu, Feb 12, 2009 at 05:08:14PM +0100, Frank Bonnet wrote: > Volker Lendecke wrote: > >On Thu, Feb 12, 2009 at 10:22:23AM +0100, Frank Bonnet wrote: > >>Well not much success even after creating the account by hand > > > >You might want to take a look at bug 5920 for the trick. > >Because I don'

Re: [Samba] OpenSUSE 11.1 with OpenLDAP => some surprises (ldap.conf, nss-ldap.conf, nsswitch.conf)

2009-02-12 Thread Björn Jacke
On 2009-02-12 at 08:58 +0100 malte.muel...@ewetel.net sent off: > this has nothing directly to do with samba, but there might be some people > who try to use samba with (Open)LDAP on OpenSUSE 11.1 like me. > Between 10.2 and 11.1 the nss_ldap configuration has changed a bit. The I think nss_ldap

[Samba] logon hours

2009-02-12 Thread Helmut Hullen
Hallo, how and where can I set the "Logon hours" (shown with "pdbedit") to another value as "..."? I can work as (Linux) root. I need this option for some users. Viele Gruesse! Helmut -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.

[Samba] Samba and Windows Server 2008 64bit

2009-02-12 Thread Darrell A. Sullivan, II
I am having to add a server running Windows Server 2008 64bit edition to my system network in order to use a solid state drive solution. The computers in my network consist of Linux machines as well as workstations running Windows 2000 and Windows XP professional and a Windows NT server that is run

Re: [Samba] Samba and Windows Server 2008 64bit

2009-02-12 Thread Volker Lendecke
On Thu, Feb 12, 2009 at 01:13:47PM -0500, Darrell A. Sullivan, II wrote: > Failure Information: > Failure Reason: An Error occured during Logon. > Status: 0xc002002e > Sub Status: 0x0 > > I looked up the 0xc002002e error and that is evidently > RPC_NT_PROCNUM_OUT_OF_RANGE. This sounds a lo

[Samba] Questions about PDC with SAMBA

2009-02-12 Thread Marcelo Opazo Vivallos
Hi! I have 8 subnets: 192.168.100.x/24 192.168.150.y/24 192.168.200.z/16 etc ... Install a Primary Domain Controller (PDC), so that users to perform authentication on the domain with its mounting remote disks, among others. The network is correctly configured, that is, the teams are perfectly by

Re: [Samba] Questions about PDC with SAMBA

2009-02-12 Thread Vlastimil Šetka
Marcelo Opazo Vivallos: Hi! I have 8 subnets: 192.168.100.x/24 192.168.150.y/24 192.168.200.z/16 etc ... Install a Primary Domain Controller (PDC), so that users to perform authentication on the domain with its mounting remote disks, among others. The network is correctly configured, that is, t

Re: [Samba] Questions about PDC with SAMBA

2009-02-12 Thread Ari Constancio
On Thu, Feb 12, 2009 at 10:04 PM, Marcelo Opazo Vivallos wrote: > Hi! > > I have 8 subnets: > 192.168.100.x/24 > 192.168.150.y/24 > 192.168.200.z/16 > etc ... > > Install a Primary Domain Controller (PDC), so that > users to perform authentication on the domain with its mounting > remote disks, am

[Samba] passwd program error causes misleading windows error message

2009-02-12 Thread James Holmes
I have samba setup to use an external password change command using: [global] ... unix password sync = Yes ldap password sync = No passwd program = /path/to/smbldap-passwd -u %u passwd chat = *New*password* %n\n *Retype*new*password* %n\n I use the Idealx smbldap-passwd command to update my LDAP

Re: [Samba] vfs objects

2009-02-12 Thread Andy Kelk
2009/2/7 Clinton Mills : > When I rename skel_transparent.c to mytest.c and add > > vfs objects = mytest > Make sure that, in your init_samba_module function, you are setting the right vfs name in your call to smb_register_vfs. (i.e., make sure it's not still registering itself as skel_transparent

[Samba] Long printer name in CUPS not appear in Samba

2009-02-12 Thread HB
Hi I have a Samba 3.2.7 acting as a PDC for files and printers sharing. All the print configuration is ok and network printers shared by Samba and managed by CUPS are working. Except that if I put a printer name longer than 15 characters in CUPS , it is not seen at all in samba . With less th

Re: [Samba] Questions about PDC with SAMBA

2009-02-12 Thread Helmut Hullen
Hallo, Marcelo, Du meintest am 12.02.09: > I have 8 subnets: > 192.168.100.x/24 > 192.168.150.y/24 > 192.168.200.z/16 > etc ... The third net includes the first two. Viele Gruesse! Helmut -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.