Re: [Samba] ldap+kerberos+samba

2013-02-18 Thread Andrew Bartlett
the server-side integration of LDAP, Kerberos and the Domain protocols that allow Samba and windows member servers to join it, and for it to 'just work'. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

[SCM] Samba Shared Repository - branch master updated

2013-02-18 Thread Andrew Bartlett
ksee...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Mon Feb 18 13:57:40 CET 2013 on sn-devel-104 commit 240df6c7b05e3c5c7be80d7607824147f360d64e Author: Karolin Seeger ksee...@samba.org Date: Mon Feb 18 10:05:23 2013 +0100

[SCM] Samba Shared Repository - branch master updated

2013-02-18 Thread Andrew Bartlett
- commit 06780ae82281fb62a08d0c3604d2e679976756c2 Author: Andrew Bartlett abart...@samba.org Date: Sat Feb 16 08:51:51 2013 +1100 samba_upgradeprovision: Remove options to fix FS ACLs samba-tool ntacl sysvolreset handles this better, and makes

[SCM] Samba Shared Repository - branch master updated

2013-02-18 Thread Andrew Bartlett
- commit 2cf83f7c645e4b216cf6f23857fd72ec0e6ca7a6 Author: Andrew Bartlett abart...@samba.org Date: Sun Feb 17 18:15:52 2013 +1100 samba_upgradeprovision: Use tdb_util.tdb_copy not shutil.copy2 This is really important, because copying a file will both ignore locks held by another

[Samba] PROPOSAL: Remove SWAT in Samba 4.1

2013-02-17 Thread Andrew Bartlett
in 4.0.2 to SWAT in the first place. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] PROPOSAL: Remove SWAT in Samba 4.1

2013-02-17 Thread Andrew Bartlett
On Sun, 2013-02-17 at 20:52 -0500, Nico Kadel-Garcia wrote: On Sun, Feb 17, 2013 at 7:02 PM, Andrew Bartlett abart...@samba.org wrote: As most of you would have noticed, we have now had 3 CVE-nominated security issues for SWAT in the past couple of years. Has webmin kept up to date

[SCM] Samba Shared Repository - branch master updated

2013-02-17 Thread Andrew Bartlett
- commit dcc94f093317ffa2bbbc776fb82657088eb63305 Author: Andrew Bartlett abart...@samba.org Date: Wed Feb 6 20:58:18 2013 +1100 s4-nbt: Ensure source4/ nbt client and server honour 'disable netbios' Reviewed-by: Stefan Metzmacher me...@samba.org

Re: [Samba] Recommended Upgrade technique for 4.0.3 (was Re: Should I run dbcheck and sysvolreset when upgrading 4.0.0 to 4.0.3?)

2013-02-16 Thread Andrew Bartlett
On Sat, 2013-02-16 at 12:55 +1100, Andrew Bartlett wrote: On Fri, 2013-02-15 at 12:52 +1100, Andrew Bartlett wrote: On Thu, 2013-02-14 at 20:50 -0500, Thomas Simmons wrote: Thank you, Andrew. Just to be clear, you're saying I can upgrade to 4.0.3 (but do nothing after make install

[SCM] Samba Shared Repository - branch master updated

2013-02-16 Thread Andrew Bartlett
there was no case for this error code, no fallback to the internal resolver would occur. This led to replication failing on FreeBSD. Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Sun Feb 17 07:06:36

Re: [Samba] [Samba 4.0] Floating KVNO

2013-02-15 Thread Andrew Bartlett
On Fri, 2013-02-15 at 10:22 +0100, Kaito Kumashiro wrote: On Fri, Feb 15, 2013 at 2:26 AM, Andrew Bartlett abart...@samba.org wrote: I'm using Samba 4.0.1 also to authenticate users via Kerberos. Once in a while however I have to regenerate a keytab, because for reasons unknown to me

Re: [Samba] Recommended Upgrade technique for 4.0.3 (was Re: Should I run dbcheck and sysvolreset when upgrading 4.0.0 to 4.0.3?)

2013-02-15 Thread Andrew Bartlett
On Fri, 2013-02-15 at 12:52 +1100, Andrew Bartlett wrote: On Thu, 2013-02-14 at 20:50 -0500, Thomas Simmons wrote: Thank you, Andrew. Just to be clear, you're saying I can upgrade to 4.0.3 (but do nothing after make install)? If it will make things worse in any way, I can stay at 4.0.0

Re: [Samba] Thank-you to Samba developers

2013-02-15 Thread Andrew Bartlett
(it depends how you count us) active developers in Australia these days. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL

Re: [Samba] map to guest = bad user ignored in Samba 4?

2013-02-15 Thread Andrew Bartlett
. Sorry, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options

Re: [Samba] samba4 binary

2013-02-15 Thread Andrew Bartlett
repositories. That would be up to the packagers, so you should ask your distribution for their plans. We hope as the next major release of distributions passes around that this situation will improve, or that others (like SerNet's enterprisesamba.org) will prepare appropriate packages. Andrew Bartlett

Re: [Samba] map to guest = bad user ignored in Samba 4?

2013-02-14 Thread Andrew Bartlett
the same? The 'right' way is meant to be that you enable the guest account, but I'm pretty sure this is all just unimplemented in the AD DC mode right now. Please file a bug, or better still write up a patch :-) Andrew Bartlett -- Andrew Bartletthttp://samba.org

Re: [Samba] [Samba 4.0] Floating KVNO

2013-02-14 Thread Andrew Bartlett
, specifically the version number for the unicodePwd attribute. It should only change if that attribute is changed. What is the client in this case? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

[Samba] Recommended Upgrade technique for 4.0.3 (was Re: Should I run dbcheck and sysvolreset when upgrading 4.0.0 to 4.0.3?)

2013-02-14 Thread Andrew Bartlett
to reinstate any specific changes they actually want. In summary, I don't have a recommended technique yet, but we hope to get one soon. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Re: [Samba] Recommended Upgrade technique for 4.0.3 (was Re: Should I run dbcheck and sysvolreset when upgrading 4.0.0 to 4.0.3?)

2013-02-14 Thread Andrew Bartlett
the security issue we fixed in 4.0.1, and makes a significant number of other fixes. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] NTLMv2 with win2003 AD question

2013-02-14 Thread Andrew Bartlett
(servicePrincipalName values), we should be able to enforce this properly. I would love a patch to do this in a way that matches windows behaviour, both for the client and server. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba

Re: [Samba] Upgrading from 4.0.0 to 4.0.3

2013-02-12 Thread Andrew Bartlett
. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Starting S4 in production

2013-02-11 Thread Andrew Bartlett
to have progressed fine! Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

Re: [Samba] file server

2013-02-11 Thread Andrew Bartlett
on both independently. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org

Re: [Samba] S3 as domain member with S4

2013-02-11 Thread Andrew Bartlett
://www.samba.org/samba/docs/man/Samba-Guide/unixclients.html#adssdm -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] Strange winbindd messages

2013-02-11 Thread Andrew Bartlett
On Fri, 2013-02-08 at 11:50 -0500, John Center wrote: Hi Andrew, Thanks for getting back to me. On 02/07/2013 04:52 PM, Andrew Bartlett wrote: On Fri, 2013-02-08 at 08:43 +1100, Andrew Bartlett wrote: On Wed, 2013-01-23 at 11:59 -0500, John Center wrote: Hi, We are running samba

Re: [Samba] NTLM autentication problems

2013-02-11 Thread Andrew Bartlett
in bugzilla. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman

Re: [Samba] Samba 4 : File server

2013-02-11 Thread Andrew Bartlett
as fixing this should not be difficult. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

[Samba] [PATCH] Fix classicupgrade error message (was Re: Classicupgrade not work)

2013-02-11 Thread Andrew Bartlett
, and then if someone could review and/or push this to master I would appreciate it. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org From bc6e7aaa73f52c449006b061c370e6c759c7620a Mon Sep 17

Re: [Samba] [PATCH] Fix classicupgrade error message (was Re: Classicupgrade not work)

2013-02-11 Thread Andrew Bartlett
the previous patch, and then apply this one. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org From 22a1661a8312cbad99eb9fe016db4deefc11a9d1 Mon Sep 17 00:00:00 2001 From: Andrew Bartlett

[SCM] Samba Shared Repository - branch master updated

2013-02-11 Thread Andrew Bartlett
- commit efd60aeff7aac308d85b767cdf394dd866cce078 Author: Guenter Kukkukk ku...@samba.org Date: Tue Feb 12 05:37:09 2013 +0100 Fix some cut-and-paste and spelling in debug messages Signed-off-by: Guenter Kukkukk ku...@samba.org Reviewed-by: Andrew Bartlett abart

[Samba] Samba 4 talk from FOSDEM and linux.conf.au

2013-02-10 Thread Andrew Bartlett
a great overview of where we are at with Samba 4.0. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions

Re: [Samba] fileserver.conf

2013-02-10 Thread Andrew Bartlett
? Im running samba 4.0.3 We eliminated this file in recent Samba 4.0 versions (I think during the rc series), and instead apply the configuration changes internally. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba

[SCM] Samba Shared Repository - branch master updated

2013-02-09 Thread Andrew Bartlett
of warnings. Timur provided the wscript method, I added the configure.in correction. Signed-off-by: Timur Bakeyev ti...@freebsd.org Signed-off-by: Richard Sharpe realrichardsha...@gmail.com Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett

Re: [Samba] samba4 AD DC manually creating DNS records?

2013-02-07 Thread Andrew Bartlett
, where you can handle it with either the internal DNS server, or bind9 using the dlz module. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] Strange winbindd messages

2013-02-07 Thread Andrew Bartlett
password. Can you try Samba 3.6.12 and see if the changes in the meantime have fixed this? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] Strange winbindd messages

2013-02-07 Thread Andrew Bartlett
On Fri, 2013-02-08 at 08:43 +1100, Andrew Bartlett wrote: On Wed, 2013-01-23 at 11:59 -0500, John Center wrote: Hi, We are running samba v3.6.3 on Ubuntu 12.04 server. This is being used with FreeRADIUS for wireless authentication with AD. We just logged a set of messages from

[SCM] Samba Shared Repository - branch master updated

2013-02-07 Thread Andrew Bartlett
- commit 554ba5ebbf1d2e520883cfad6f8a2ed6eb9b2b0f Author: Matthieu Patou m...@matws.net Date: Tue Jan 8 00:09:32 2013 -0800 ldb: Add more data test data for one level test cases Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master

Re: [Samba] Solaris 11 can't join Active Directory Domain

2013-02-06 Thread Andrew Bartlett
what is going wrong here? Does this work against a freshly provisioned Samba 4.0.3 domain? We fixed a lot of ACL related things with that release. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Re: [Samba] Searches under non-schema base DN returns schema objects?

2013-02-06 Thread Andrew Bartlett
before you upgraded? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman

Re: [Samba] Resetting a User Password From S3 or S4 Member Server

2013-02-06 Thread Andrew Bartlett
like 'samba-tool' can take -H on commands like 'samba-tool user setpassword -H ldap://foo'. There are also many other tools that can do this over many different protocols, including kpasswd, LDAP and SAMR. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] Cannot logon Samba 4 via plaintext password

2013-02-06 Thread Andrew Bartlett
and security perspective for quite some time now. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

[Samba] AD DC LDAP support for the 'password change' extended operation

2013-02-06 Thread Andrew Bartlett
- it remains a wishlist item that one of our developers was working on at some point, but has not progressed beyond that. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from

Re: [Samba] Able to join Samba client as MEMBER server to Windows 2008 R2 RWDC but not to RODC

2013-02-06 Thread Andrew Bartlett
and krb5.conf files. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman

Re: [Samba] Samba support for RODC

2013-02-06 Thread Andrew Bartlett
capture and work with us to uncover the underlying issue. https://wiki.samba.org/index.php/Capture_Packets Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from

[SCM] Samba Shared Repository - branch master updated

2013-02-04 Thread Andrew Bartlett
- commit 4c1527b1ce26759dbb7470b23f9f83a391d99b30 Author: Christian Ambach a...@samba.org Date: Tue Jan 8 17:10:27 2013 +0100 s3:modules remove gpfs_getacl_alloc last caller has gone Signed-off-by: Christian Ambach a...@samba.org Reviewed-by: Andrew Bartlett abart

Re: [Samba] Samba Server Under Microsoft Windows Network

2013-02-03 Thread Andrew Bartlett
This is because as an AD DC we do not support net iOS browsing. This is normal, access the server by name and it will work fine. Fabian von Romberg fromberg...@hotmail.com wrote: Hi All, Im running a samba4 server. When I logged onto the server from a XP Machine and then I go to My Network

Re: [Samba] Samba4 Authentication

2013-02-03 Thread Andrew Bartlett
configurations permit it (such as correct DNS). This is validated by the KDC against the same database (samdb) that NTLM logins work against, to ensure consistent behaviour for the user. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer

Re: [Samba] Questions for minimal AD DC, DNS setup and Posix use

2013-02-01 Thread Andrew Bartlett
On Fri, 2013-02-01 at 10:50 +0200, Michael Wood wrote: Hi On 1 February 2013 04:18, Andrew Bartlett abart...@samba.org wrote: On Fri, 2013-02-01 at 07:45 +1100, Dewayne Geraghty wrote: [...] Andrew, I would like to avoid killing processes by not asking for them to start. :) Regards

Re: [Samba] Samba OpenLDAP Domain issue

2013-01-31 Thread Andrew Bartlett
. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Questions for minimal AD DC, DNS setup and Posix use

2013-01-31 Thread Andrew Bartlett
, but is not the default. We essentially need to transform these details into manpage notes. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL

Re: [Samba] unique index violation on objectGUID, CN=Deleted Objects, DC=samdom, DC=domain

2013-01-31 Thread Andrew Bartlett
explicitly states this is a bad idea... ) Samba treats having two objects with the same objectGUID as an impossibility, and has been coded with that as a fundamental assumption. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication

Re: [Samba] Questions for minimal AD DC, DNS setup and Posix use

2013-01-31 Thread Andrew Bartlett
On Fri, 2013-02-01 at 07:45 +1100, Dewayne Geraghty wrote: -Original Message- From: Michael Wood [mailto:esiot...@gmail.com] Sent: Friday, 1 February 2013 12:22 AM To: Andrew Bartlett Cc: Dewayne; samba@lists.samba.org Subject: Re: [Samba] Questions for minimal AD DC, DNS

Re: [Samba] How to query posix attributes from Samba 4?

2013-01-30 Thread Andrew Bartlett
. With anonymous quires enabled, I'm not able to see anything below my basedn, and with acl:read=false set in smb.conf the attributes don't appear either. Try v4-0-test from GIT, or set 'acl:search=false' (I misspoke earlier) until you can install 4.0.3 due next week. Andrew Bartlett

Re: [Samba] Ubuntu 12.04 Authentication by Samba4

2013-01-30 Thread Andrew Bartlett
in the list will share their knowledge, so that i can implement it in my organization. With thanks in advance. Just join it like you would any other AD Domain. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] Samba4 Winbind - is it really not possible to be sensible?

2013-01-28 Thread Andrew Bartlett
. This is one of the many reasons we recommend against combining these roles on sites with complex requirements. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from

Re: [Samba] Samba Authentication With Kerberos

2013-01-28 Thread Andrew Bartlett
never know which localhost that is. If you have somehow registered a 'localhost' as a servicePrincipalName, then this is likely the cause of the issue. (This error indicates that the key you got from the KDC is not the key that the server has in it's secrets database/keytab.) Andrew Bartlett

Re: [Samba] fail-over, redundancy, bdc, multi-dc-domain

2013-01-28 Thread Andrew Bartlett
) wiki/how-to's on how to accomplish something in the neighborhood on this subjet? The main HOWTO contains information on joining to an existing domain. That is what you need to do on your second DC. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

[SCM] Samba Shared Repository - branch master updated

2013-01-27 Thread Andrew Bartlett
just like process_prefork http://gitweb.samba.org/?p=samba.git;a=shortlog;h=master - Log - commit 0f8ef5a2c83e0496ef79c3d6f8b1188fdd1943a0 Author: Andrew Bartlett abart...@samba.org Date: Tue Jan 22 23:39:15 2013 +1100 selftest

Re: [Samba] migrating from Samba3 with tdbsam to samba4 AD server?

2013-01-25 Thread Andrew Bartlett
just run 'samba-tool domain classicupgrade' and it does all the right things. See https://wiki.samba.org/index.php/Samba4/samba3upgrade/HOWTO Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Re: [Samba] [Samba 4] Issues with uidNumber and gidNumber in AD for Linux clients

2013-01-25 Thread Andrew Bartlett
essentially becoming groups), and we have no choice but to match. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

[SCM] Samba Shared Repository - branch master updated

2013-01-25 Thread Andrew Bartlett
- commit c5db4eb9104f1a95220273ee2b0290d157053922 Author: Andrew Bartlett abart...@samba.org Date: Fri Jan 25 13:15:51 2013 +1100 bug9598: s4-process_single: Use pid,fd as cluster_id in process_single just like process_prefork

Re: [Samba] generate keytab

2013-01-24 Thread Andrew Bartlett
as, or kinit as HTTP/www.nisled@nisled.org. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] MS AD Tools

2013-01-23 Thread Andrew Bartlett
unimplemented - we don't do web services for example. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions

Re: [Samba] [Samba 4] Issues with uidNumber and gidNumber in AD for Linux clients

2013-01-23 Thread Andrew Bartlett
special about Samba 4.0 as an AD DC with Linux clients that hasn't already been done for a Windows AD domain. The Samba Team recommends winbind as the AD client to use on Linux, because it handles these and many other details much better than just nss_ldap. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] [PATCH] Re: Using samba4 with kerberos outside of an AD realm

2013-01-22 Thread Andrew Bartlett
On Mon, 2013-01-21 at 23:25 -0700, Kyle Brantley wrote: On 1/21/2013 9:14 PM, Kyle Brantley wrote: On 1/21/2013 8:46 PM, Andrew Bartlett wrote: On Mon, 2013-01-21 at 15:44 -0700, Kyle Brantley wrote: On 1/21/2013 3:15 PM, Andrew Bartlett wrote: On Mon, 2013-01-21 at 11:34 -0700, Kyle

[SCM] Samba Shared Repository - branch master updated

2013-01-22 Thread Andrew Bartlett
there is no need to re-force bash as the echo will execute in a bash shell Signed-off-by: Matthieu Patou m...@matws.net Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Jan 22 13

Re: [Samba] Samba 3.5.6 : netlogon_creds_server_check errors in logs

2013-01-21 Thread Andrew Bartlett
both the current and previous domain join pw, and will sometimes try the old domain join password. That is, as you noticed, no harm seems to come from these messages, despite them normally indicating a breakdown in the trust relationship. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Using samba4 with kerberos outside of an AD realm

2013-01-21 Thread Andrew Bartlett
actually be fatal). Then, once we rule out it being something else, it probably just needs a new test environment to be created in our 'make test' that tells our AD server to not send the PAC. This will allow this code path to be covered, and prevent regressions. Andrew Bartlett -- Andrew

[Samba] [PATCH] Re: Using samba4 with kerberos outside of an AD realm

2013-01-21 Thread Andrew Bartlett
On Mon, 2013-01-21 at 15:44 -0700, Kyle Brantley wrote: On 1/21/2013 3:15 PM, Andrew Bartlett wrote: On Mon, 2013-01-21 at 11:34 -0700, Kyle Brantley wrote: Hello -- I'm trying to run a samba4 server (note: Fedora packaged version, samba-4.0.0-174.fc18.x86_64) under a kerberos realm

[SCM] Samba Shared Repository - branch master updated

2013-01-21 Thread Andrew Bartlett
flags Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Tue Jan 22 00:12:17 CET 2013 on sn-devel-104 commit fa591a6d3cf9182b6d49621c83a6c3fbfeab1ee7 Author: Matthieu Patou m...@matws.net Date: Mon

Re: [Samba] Samba4 Integration With Google

2013-01-20 Thread Andrew Bartlett
. We would need to modify Samba to store (somewhere, perhaps we can use the userPassword attribute) this hashed password . Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Re: [Samba] Problem joining Samba 4 to an older Samba 4 alpha 17

2013-01-20 Thread Andrew Bartlett
On Fri, 2013-01-18 at 13:48 +0100, Daniel Hedblom wrote: 2013/1/18 Andrew Bartlett abart...@samba.org On Fri, 2013-01-18 at 10:11 +0100, Daniel Hedblom wrote: Hi there, Im trying to join a samba 4.0.1 server to an older samba 4 alpha 17 server. Whatever i do the join

Re: [Samba] Problem joining Samba 4 to an older Samba 4 alpha 17

2013-01-18 Thread Andrew Bartlett
in place, and start the 4.0.1 release. The role transfer stuff isn't as reliable as we would like, whereas in-place is. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe

Re: [Samba] Samba4 Integration With Google

2013-01-18 Thread Andrew Bartlett
really want 150 DCs), and will be stretching our replication capabilities. I'll help you however I can, but you may wish to engage some professional support as well. I do wish you all the best. It is great to see folks taking Samba 4.0 as an AD DC to new and exciting places! Andrew Bartlett

Re: [Samba] Problems with smbclient send netbios message

2013-01-18 Thread Andrew Bartlett
tested as part of 'make test' in the 4.0 release, so you may have better luck there. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following

Re: [Samba] pam_smbpass.so on AIX

2013-01-18 Thread Andrew Bartlett
when linking), but perhaps that's working for our binaries (eg swat), but not our plugins when loaded by telnet? Anyway, that's how I would start debugging this. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] Samba4 Domain Account Lockout

2013-01-16 Thread Andrew Bartlett
login attempts to a domain account (e.g., the default domain administrator) and lock the account once a certain threshold has been reached and if so how is that configured? No, this is not yet implemented in the AD DC. Sorry, Andrew Bartlett -- Andrew Bartletthttp

Re: [Samba] samba 4 samba-tool user encrypted password

2013-01-16 Thread Andrew Bartlett
for examples of code that can set the magic flags to allow this. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Switching between acl_tdb and acl_xattr

2013-01-16 Thread Andrew Bartlett
On Tue, 2013-01-15 at 23:14 +, Steve Tice wrote: Andrew Bartlett abartlet at samba.org writes: Using Samba 4.0.0, the python bindings or even samba-tool ntacl get/set would be quite a good choice here. We can read directly the NT ACL from the tdb and then set it using the xattr

Re: [Samba] Samba4: no --use-ntvfs option on samba-tool ntacl sysvolcheck

2013-01-16 Thread Andrew Bartlett
limitation in Samba 4.0.0 ? It shouldn't matter. The options are needed for writing, as while the ntvfs server reads and writes version 1, the VFS layer from smbd reads version 1, 2 (never used) as well as the current version 3. Andrew Bartlett -- Andrew Bartletthttp

Re: [Samba] Suggest Forest/Function Level ?

2013-01-16 Thread Andrew Bartlett
, but using the default functional level (2008 R2) is a good idea. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Samba4 domain classicupgrade conversion not supported

2013-01-16 Thread Andrew Bartlett
not provide that db, and we will skip it. Otherwise, hack the script to skip this step. If you could supply your actual database, we may be able to make the script more robust in the future. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet

Re: [Samba] Server Key [Re-] Generation after Install?

2013-01-16 Thread Andrew Bartlett
might want to re-generate (if anything). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] Server Key [Re-] Generation after Install?

2013-01-16 Thread Andrew Bartlett
On Wed, 2013-01-16 at 07:57 -0500, Jeffrey Walton wrote: On Wed, Jan 16, 2013 at 6:41 AM, Andrew Bartlett abart...@samba.org wrote: On Tue, 2013-01-15 at 14:44 -0500, Jeffrey Walton wrote: Hi All, I recently stood up a Linux server with Samba and wanted to re-generate any keys the Samba

Re: [Samba] Samba 3 classicupgrade to Samba AD

2013-01-16 Thread Andrew Bartlett
detail to the error than what you pasted? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

Re: [Samba] samba-tool dbcheck produces wrong instancetype errors

2013-01-15 Thread Andrew Bartlett
On Tue, 2013-01-15 at 11:19 +, Chris Lewis wrote: On 11/01/13 12:22, Andrew Bartlett wrote: On Thu, 2013-01-10 at 16:50 +, Chris Lewis wrote: Hi All, I have joined a samba4 instance to en existing W2k8 AD domain as an additional domain controller. When I do samba-tool

Re: [Samba] Samba 3 classicupgrade to Samba AD

2013-01-14 Thread Andrew Bartlett
without errors? Any help is much appreciated. A workaround for this is in the 4.0.0 release. Are you running Samba 4.0.0? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Re: [Samba] samba-tool dbcheck produces wrong instancetype errors

2013-01-11 Thread Andrew Bartlett
suspect we are getting the domain join stuff wrong, so we then trigger this incorrectly in dbcheck. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] Switching between

2013-01-11 Thread Andrew Bartlett
. That said, we haven't deliberately changed anything about the on-disk format here, as far as I'm aware. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go

Re: [Samba] Samba 4 Services for UNIX? [SOLVED]

2013-01-09 Thread Andrew Bartlett
Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba4 as a RODC

2013-01-09 Thread Andrew Bartlett
On Wed, 2013-01-09 at 16:32 +0100, Jaymzwise Jaymzwise wrote: Hi ! Is it possible to join Samba4 as a RODC in an AD Domain (Windows 2K8 PDC) ? Yes. You will have to replicate the sysvol share manually however. Andrew Bartlett -- Andrew Bartletthttp

Re: [Samba] Samba4 internal DNS not responding to DNS requests

2013-01-09 Thread Andrew Bartlett
closing old ones, until reaching the limit of max files... I don't know wether it's been already fixed or not. But it doesn't happen with bind. This topic is been in the list before. Yes, we fixed that (with a timeout). Andrew Bartlett -- Andrew Bartletthttp

[SCM] Samba Shared Repository - branch master updated

2013-01-09 Thread Andrew Bartlett
+0100 s3-lib: Use new strict directory create function in create_pipe_sock(). Reviewed-by: Andrew Bartlett abart...@samba.org Autobuild-User(master): Andrew Bartlett abart...@samba.org Autobuild-Date(master): Wed Jan 9 10:55:23 CET 2013 on sn-devel-104 commit

[SCM] Samba Shared Repository - branch master updated

2013-01-08 Thread Andrew Bartlett
411440d2d9085fe9db0e3c26c025c6b94d02c00f Author: Jesper Larsen jesper.lar...@ixonos.com Date: Fri Jan 4 13:03:58 2013 +0100 replace: Fix compilation of rep_mkstemp Commit 1fbc185 removed the variable 'p'. Use the equivalent variable 'template' instead. Reviewed-by: Andrew Bartlett abart

Re: [Samba] Samba 4 Services for UNIX?

2013-01-07 Thread Andrew Bartlett
, but I'll leave to other users to describe the process in more detail. See also: https://wiki.samba.org/index.php/Samba4/Schema_extenstions Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Re: [Samba] [PATCH] Re: samba-tool domain classicupgrade with LDAP backend

2013-01-07 Thread Andrew Bartlett
, None) Can you set 'log level = 10' in your smb.conf and try again, I'm very must lost as to what the error is if this doesn't fix it. Can you contact this host using ldbsearch? eg: ldbsearch -H ldap://XX.X.es Andrew Bartlett -- Andrew Bartletthttp

Re: [Samba] [PATCH] Re: samba-tool domain classicupgrade with LDAP backend

2013-01-07 Thread Andrew Bartlett
On Tue, 2013-01-08 at 18:42 +1100, Andrew Bartlett wrote: On Fri, 2013-01-04 at 12:53 +0100, Juan Asensio Sánchez wrote: Hi Andrew Unfortunately, after applying the patch, recompile, uninstall and install again, I am getting the same error: # cd ~/samba-4.0.0 # patch -p1

Re: [Samba] samba-tool domain classicupgrade with LDAP backend

2013-01-04 Thread Andrew Bartlett
because it fell out of other work. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https

[Samba] [PATCH] Re: samba-tool domain classicupgrade with LDAP backend

2013-01-04 Thread Andrew Bartlett
On Fri, 2013-01-04 at 10:18 +0100, Juan Asensio Sánchez wrote: Hi 2013/1/4 Andrew Bartlett abart...@samba.org On Fri, 2013-01-04 at 08:57 +0100, Juan Asensio Sánchez wrote: Hi I forgot to explain my scenario... I have one Samba3

Re: [Samba] Samba 3 classicupgrade to Samba AD

2013-01-04 Thread Andrew Bartlett
. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] Samba 4.1.0pre1 and problem from creating home users dir from command line

2013-01-04 Thread Andrew Bartlett
and chown commands. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman

<    8   9   10   11   12   13   14   15   16   17   >