Re: [Samba] NT_STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT

2011-03-07 Thread Andrew Bartlett
(ie 3.5) this much will work. If you need Samba to be an AD domain controller, then you will need to use Samba4. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. --

Re: [Samba] Advice for W2K migration to samba

2011-03-07 Thread Andrew Bartlett
On Fri, 2011-03-04 at 10:47 +0100, Marcello Romani wrote: > Il 04/03/2011 05:43, Andrew Bartlett ha scritto: > > On Thu, 2011-03-03 at 09:17 +0100, Marcello Romani wrote: > >> Hallo, > >> I'm running a W2K AD network with about 20 clients (mostly Windows >

Re: [Samba] How to use another attribute than the uid ?

2011-03-03 Thread Andrew Bartlett
" parameter is > the only way, I think. Even this (and it would be insecure, and very unsupported) isn't likely to work well, we do expect the schema to match our schema. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Dev

Re: [Samba] Advice for W2K migration to samba

2011-03-03 Thread Andrew Bartlett
cess/failure stories in > similar setups would be great. > Thanks in advance. This (Windows 2000 -> Samba4) certainly has been made to work, multiple times. Those successful migrations that I know of were via Windows 2003 due to an odd Kerberos interop issue between Samba4

Re: [Samba] SAMBA 4 test error after provision: NT_STATUS_INTERNAL_ERROR

2011-03-02 Thread Andrew Bartlett
is in the server logs at the time? perhaps turn up the debug level? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscribe from this list go to t

Re: [Samba] S4 and phpldapadmin

2011-03-02 Thread Andrew Bartlett
did you make to the generated config file for it to work for you? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscribe from this list go to the

Re: [Samba] Samba4 start error

2011-02-27 Thread Andrew Bartlett
missed or mis-understood one of the steps. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscribe from this list go to the following URL and read

Re: [Samba] Samba4 start error

2011-02-27 Thread Andrew Bartlett
nds are not part of Samba4. As is almost correctly mentioned above, to run 'samba' (the Samba4 server binary) from /usr/local/samba, you need to run: /usr/local/sbin/samba Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Develope

Re: [Samba] bind9 dlopen/dlz problems [update]

2011-02-08 Thread Andrew Bartlett
will publish some more docs on this. But in the meantime, you seem to have cracked the setup for the less secure, unsafe (no transactions) but works-for-a-demo mode of operation :-). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Develop

Re: [Samba] Seperate BIND server for Samba 4

2011-02-07 Thread Andrew Bartlett
s of that discussion and other research, Kai and Metze started writing Samba4's own DNS server. Then tridge and the BIND folks got together, and given the excellent progress made, not reinventing this particular wheel seems to be the best way forward at the moment. Andrew Bartlett -- Andre

Re: [Samba] Old question - NT4 BDC in Samba domain?

2011-02-06 Thread Andrew Bartlett
gt; NT4 BDC will work in a Samba PDC enviroment? Look into the tools (myldap-pub.py or something) mentioned on the lists to migrate Samba3 to Samba4, which will get you a replication source you could then use to migrate to AD if you can't use Samba4. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Samba PDC & Exchange 2000 Server

2011-02-06 Thread Andrew Bartlett
nds to support Exchange. Any issues with the exchange install failing are bugs we want to fix. Certainly we have reports of exchange-supporting AD environments being imported into Samba4, but I don't know if folks have used Exchange itself directly against Samba4. Andrew Bartlett

Re: [Samba] Access to s3 shares when userPrincipalName differs from the sAMAccountName

2011-02-03 Thread Andrew Bartlett
ing NTLM or Kerberos? Either way, this is unlikely to be a Samba3 bug, given that it's not been raised before, so perhaps re-raise the issue on samba-technical, with network traces etc to show what's going on, and I'll happily look into it for you. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Seperate BIND server for Samba 4

2011-02-03 Thread Andrew Bartlett
I prefer dnsmasq as nameserver; do you support this > program too? No. BIND is the only server that will support the range of functions Samba requires. I know BIND has a bad name in some minds, but we did look and there is no suitable alternative. I also don't think BIND deserves the re

Re: [Samba] Seperate BIND server for Samba 4

2011-02-02 Thread Andrew Bartlett
at this stage, but if security is your worry then of course the AD DC is the heart of that. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscribe

Re: [Samba] Some direction of Samba4 Sid to Uid/Gid ?

2011-01-16 Thread Andrew Bartlett
get abcde from the system but not from the samba4. Furthermore, > files created via samba by the uid 300018 is not deletable by user uid 1000. Correct. Samba4 uses it's own uid and gid space, and manages all aspects of the user. You could edit the idmap.ldb I suppose. Eventually we will

Re: [Samba] web based backend

2010-12-26 Thread Andrew Bartlett
On Sun, 2010-12-26 at 22:46 +1100, Andrew Bartlett wrote: > On Sun, 2010-12-26 at 11:17 +0100, Vaclav Klecanda wrote: > > Yes, python provision scripts are easy to use. But it is necessary to > > say: "yes, these scripts are the API and wont change. Here is the > > docu

Re: [Samba] web based backend

2010-12-26 Thread Andrew Bartlett
are interested in developing this, please have a go, and make a proposal on the samba-technical list. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- T

Re: [Samba] Multinetwork environment without WINS server

2010-12-25 Thread Andrew Bartlett
e same OpenLDAP tree. Samba3 isn't bound by the 'one PDC' requirement, except within a NetBIOS scope. Otherwise, as has been suggested, you can run Samba4 as an AD domain controller. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Aut

Re: [Samba] web based backend

2010-12-25 Thread Andrew Bartlett
ings are not an issue for python based wrappers. libsmbclient is the Samba3 client library, which is quite distinct. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco

Re: [Samba] changing SID breaks some permissions

2010-12-25 Thread Andrew Bartlett
. I fear it will be difficult to find and fix all the instances, but others who are more involved in this code regularly may wish to comment. In short, you may be better to re-configure this workstation from scratch. Andrew Bartlett -- Andrew Bartletthttp://sa

Re: [Samba] web based backend

2010-12-25 Thread Andrew Bartlett
rd for web GUIs). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscribe from this list go to the following URL and read the instructions: https:

Re: [Samba] reducing smbd memory footprint

2010-12-25 Thread Andrew Bartlett
t; option and run "strip" on it, and look up those > options and tools. This won't help anything except the on-disk size, as those pages are only mapped in by the debugger in the case that they are needed. Otherwise, they just stay on disk. It may help to explain what you are

Re: [Samba] Multiple LDAP backends with different search base

2010-12-23 Thread Andrew Bartlett
perhaps another OpenLDAP instance can be configured as a combining proxy for the different bases, or you can replicate all the data using manual scripts into a single tree. Multiple distinct LDAP trees should serve multiple distinct LDAP domains. What exactly are you t

Re: [Samba] How to bind properly to Samba4 LDAP server?

2010-12-18 Thread Andrew Bartlett
t you have missed out 'cn=users' from the DN. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: This is a digitally signed me

Re: [Samba] Running a sleepy server (was: smbd on a battery-powered device)

2010-12-16 Thread Andrew Bartlett
On Thu, 2010-12-16 at 13:36 -0800, Liam wrote: > On Wed, Dec 15, 2010 at 1:31 AM, Andrew Bartlett wrote: > > > On Mon, 2010-12-13 at 12:37 -0800, Liam wrote: > > > I'm setting up samba service on a battery-powered WiFi device. The > > > plan is to have it

Re: [Samba] Centos-DS as backend

2010-12-16 Thread Andrew Bartlett
e, using the LDAP backend is > incompatible with DRS replication. You have been warned. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. -- To unsubscr

Re: [Samba] smbd on a battery-powered device

2010-12-15 Thread Andrew Bartlett
clients may keep a connection open for quite some time while not actually using it. (I don't have personal experience with this setup, but wanted to give you some hints about where to start). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Aut

Re: [Samba] samba4 AD controller, production

2010-12-10 Thread Andrew Bartlett
a-technical on irc.freenode.net. The code is still alpha, but that mostly means that we need you to work with us closely when something goes wrong, so we can fix it up or work around it as quickly as possible. Andrew Bartlett -- Andrew Bartletthttp://samba.or

Re: [Samba] error in module acl: insufficient access rights (50)

2010-12-06 Thread Andrew Bartlett
ked? > Anil, I don't think so, because even if I run the script with root privileges > I'm getting the same error. changing the mode to 777 of anything is almost never the correct solution, and indeed yes, this isn't relevent for LDAP anyway. Andrew Bartl

Re: [Samba] error in module acl: insufficient access rights (50)

2010-12-03 Thread Andrew Bartlett
t I'm getting: error in module acl: insufficient access > rights (50). > > Where's the problem? Well, to start with: was the bind actually successful? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, S

Re: [Samba] kerberos @ samba4 DC

2010-12-03 Thread Andrew Bartlett
DOWS 2000 DOMAIN) = { > kdc = (HOSTNAME).(WINDOWS 2000 DOMAIN):88 > } Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: This

Re: [Samba] Windows 2000 vs SAMBA 4

2010-12-01 Thread Andrew Bartlett
r issues remain. Our automated testing infrastructure is being extended to support this, and so we should be able to reliably handle this in the near future. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba T

Re: [Samba] Support for WMI?

2010-11-09 Thread Andrew Bartlett
//lists.samba.org/archive/samba-technical/2010-January/068656.html Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: This is a dig

Re: [Samba] How to enable smb signing on samba

2010-11-05 Thread Andrew Bartlett
available = yes > > encrypt passwords = yes > server signing = mandatory You cannot use security=share and smb signing at the same time. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http:/

Re: [Samba] ACtive directoryin Ubuntu

2010-10-28 Thread Andrew Bartlett
//wiki.samba.org/index.php/Samba4/HOWTO/Join_a_domain_as_a_DC -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: This is a digitally signed message

Re: [Samba] Samba 4 Bad password lockout

2010-10-20 Thread Andrew Bartlett
; >> Net pwsettings has settings for Complexity, Password history Length, > >> Minimum password length, Minimum password age, and Maximum password age. > >> > >> But I can not see how to set a bad password login attempts. Samba4 does not track bad password login

Re: [Samba] samba4 servers with one "master" sam.ldb

2010-10-17 Thread Andrew Bartlett
The workgroup for all Samba servers in a domian must be the same, just as the realm must be the same. If they are not, then they are not in the same domain, and no replication should be expected. Magnus, You are of course free to try and set up whatever manual processes you wish to operati

Re: [Samba] rpcclient and NTLMV2 authentication

2010-09-30 Thread Andrew Bartlett
nd NTLM) can I still connect with rpcclient ? rpcclient will honour the same setting in the smb.conf as smbclient - 'client ntlmv2 auth = yes' should do it. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba

Re: [Samba] Samba4 intersite DC replication

2010-09-29 Thread Andrew Bartlett
lowly starting to understand sites (it will allow computers to be put in sites, and return the correct site names), but it is at a very early stage. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Re: [Samba] Upgrade to Alfa13

2010-09-26 Thread Andrew Bartlett
On Sun, 2010-09-26 at 12:58 -0700, Jelmer Vernooij wrote: > On Sun, 2010-09-26 at 20:47 +0200, Michael Wood wrote: > > On 26 September 2010 04:21, Andrew Bartlett wrote: > > > On Sat, 2010-09-25 at 11:29 -0700, Jelmer Vernooij wrote: > > >> On Sat, 2010-09-25 at 1

Re: [Samba] Upgrade to Alfa13

2010-09-25 Thread Andrew Bartlett
1 > didn't). We no longer have big generated configure and Makefile's, I > suspect that explains at least part of the reduction in size. We also don't have the generated PIDL output in the Samba4 tarball (this will still be provided for Samba3 tarballs). That is probably resp

Re: [Samba] net rpc SeDiskOperatorPrivilege failing for domain user

2010-09-23 Thread Andrew Bartlett
s to the local box - just use 'net sam rights'. I hope this helps, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: Th

Re: [Samba] Samba 4 compile instructions

2010-09-23 Thread Andrew Bartlett
4? Yes, by selecting a different prefix as you have, you certainly can keep both on the system at the same time. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc.

Re: [Samba] Reverse DNS, Kerberos, and Samba4 as a DC

2010-09-19 Thread Andrew Bartlett
#x27;ve Cc'ed samba-technical for a better chance at an authoritative answer. The use of reverse DNS for Kerberos can introduce security holes and Windows does not use it in that way. However, I think MIT Kerberos might, if you are intending to use unix hosts. (It may also have options to turn

Re: [Samba] required ldap signed connection on domain controllers

2010-09-11 Thread Andrew Bartlett
The Samba Team appreciates the efforts that SerNet puts into their packages, and simply refers users to them. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc.

Re: [Samba] required ldap signed connection on domain controllers

2010-09-11 Thread Andrew Bartlett
d I correct it ? I tried to compile the last Samba on Redhat os > but I have new errors (impossible to start smbd nor nmbd)... Indeed, as you have suspected, you need a newer version than 3.0.33. Try the RPMs from http://ftp.sernet.de/pub/samba/3.5/rhel/5/x86_64/ if y

Re: [Samba] Machine account reject

2010-09-11 Thread Andrew Bartlett
hing at all to do with 'netlogon_creds_server_check failed', I suspect the issue has happened because your Windows 7 clients have changed their machine account password, but try and use the new password 'too soon'. Once the password has replicated back to the local DC, then ever

Re: [Samba] winbind and pptpd authentication failure

2010-09-09 Thread Andrew Bartlett
On Thu, 2010-09-09 at 14:33 +0200, John Anderson wrote: > On 09/09/10 13:57, Andrew Bartlett wrote: > > On Tue, 2010-09-07 at 17:35 +0200, John Anderson wrote: > >> I have a linux firewall using winbind to authenticate users coming in > >> with PPTP. It all seemed t

Re: [Samba] winbind and pptpd authentication failure

2010-09-09 Thread Andrew Bartlett
pp to say "mutual authentication > failed". I hacked the ppp sources (chap_ms.c) gently to output the two > hashes. > I'be been using samba-3.5.4 (and 3.4.6 and 3.4.8) and ppp-2.4.[2345] > (tried all of them) on a x86_64 gentoo box. Try with the lastest GIT tre

Re: [Samba] Samba4 and Windows 7 password change

2010-09-09 Thread Andrew Bartlett
first condition and which > I've tried for the first time ever. > > Can anyone confirm this behavior? That's an odd one. Perhaps it's a minimum password age? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication

Re: [Samba] SAMBA4 kinit fails

2010-09-08 Thread Andrew Bartlett
om = MYDOMAIN.COM > > > > Change the contents of /etc/krb5.conf to > [libdefaults] > dns_lookup_realm = true > dns_lookup_kdc = true > > Even though the system is using DNS kerberos doesn't use DNS due to > the settings that you've configured

Re: [Samba] Samba 4 compile instructions

2010-09-08 Thread Andrew Bartlett
re long overdue with making another Samba4 release, and the last alpha is quite old now. Please try again with the current version in our GIT tree. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team h

Re: [Samba] Kerberos as a password backend

2010-09-08 Thread Andrew Bartlett
T or Heimdal KDC. See 'kerberos method' in your smb.conf for the documentation. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Descrip

[Samba] provision unable to guess 'domian users' group (was Re: Strange provisioning error)

2010-09-03 Thread Andrew Bartlett
x27;staff' in /etc/passwd. What OS is this? You can override this with --users= option (see the provision --help for other options for the other groups we try and lookup) I'll add an exception handler here that explains the situation in better detail. > > Also when I

Re: [Samba] Implementing Samba4

2010-09-02 Thread Andrew Bartlett
the instance we configure in the way that we expect. > And one last question, is it possible to create interdomain trust with the > current version of Samba4? Not yet. (We of course intend to support this, but we don't at this time). Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Is possible to use samba4 and openldap without ldapi?

2010-07-27 Thread Andrew Bartlett
s to push those patches I'm fine with that, but we still have a long way to go to resolve the other issues) Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc.

Re: [Samba] Samba4 and account policy

2010-06-13 Thread Andrew Bartlett
and the files it serves. See the 'net pwsettings' command to control server-side password policies in Samba4. Andrew Bartlett -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] dns.keytab

2010-06-12 Thread Andrew Bartlett
amba/private/dns.keytab: unexpected > token > > Any ideas what am I doing wrong? Don't set the nsupdate command unless you have configured static keys. (which means a key file you have generated, not the samba-managed Kerberos keytab) Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Samba4 join existing domain

2010-06-12 Thread Andrew Bartlett
xcatly the tutorial: > http://wiki.samba.org/index.php/Samba4/HOWTO/Join_a_domain_as_a_DC > > kinit administrator is working and not time issues between the servers. > > Please advise, > Thanks G'day, I'll need more than the last lines of the log before I can give

Re: [Samba] Samba 4--Somethings decidedly broken

2010-06-12 Thread Andrew Bartlett
en these hosts? The auth code for Kerberos will trigger NT_STATUS_INVALID_PARAMETER (yeah, it is probably not the best choice of error code) if Kerberos won't work. Perhaps turn up the debug level and see if there are more clues? Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Regression of 5616?

2010-06-05 Thread Andrew Bartlett
cvd [IPCP ConfReq id=0x8 >> 0.0.0.0>] > >> Jun 3 11:10:40 debian pppd[17826]: sent [IPCP ConfNak id=0x8 >> 192.168.54.181>] > >> Jun 3 11:10:40 debian pppd[17826]: rcvd [IPCP ConfReq id=0x9 >> 192.168.54.181>] > >> Jun 3 11:10:40 debian pppd[1

Re: [Samba] Samba4 - List of options for smb.conf

2010-05-25 Thread Andrew Bartlett
On Mon, 2010-05-24 at 20:33 +0100, Lukasz Zalewski wrote: > On 22/04/2010 12:14, Andrew Bartlett wrote: > > On Tue, 2010-04-20 at 12:44 -0400, Stuart Wehrly wrote: > >> Is there a list of options for smb.conf? > > > > Sadly Samba4 does lack documentation. But test

Re: [Samba] Samba4 upgradeprovision and sysvol permissions error

2010-05-21 Thread Andrew Bartlett
update to upgradeprovision is pending - keep an eye on the GIT tree or ask Matthieu Patou (CC'ed). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc.

Re: [Samba] unable to join to a Samba4 domain

2010-05-20 Thread Andrew Bartlett
ords for that zone and see which ones > you are missing Indeed, if you used a zone file other than the one we generated, then you are asking for trouble. Please us the one we generate. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authenti

Re: [Samba] Samba4-alpha11

2010-05-17 Thread Andrew Bartlett
On Sat, 2010-05-15 at 17:21 -0700, t...@tms3.com wrote: > > > > > > --- Original message --- > > Subject: Re: [Samba] Samba4-alpha11 > > From: Andrew Bartlett > > To: > > Cc: > > Date: Saturday, 15/05/2010 5:14 AM > > >

Re: [Samba] samba4 - where is libnss_winbind.so?

2010-05-15 Thread Andrew Bartlett
inbind built from the source3 build. You need to set (in smb.conf) winbindd socket directory = /tmp/.winbindd Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Develope

Re: [Samba] Samba4-alpha11

2010-05-15 Thread Andrew Bartlett
've noticed so far (still in early lab stage) is a GC > issue. > > Now if I can upgrade a Samba3-LDAP domain This should not be to hard, as a one-way, change the schema upgrade. If you want to help with that, I can point you some of the tools and existing attempts that you could

Re: [Samba] Samba4 and group policy password policy

2010-05-15 Thread Andrew Bartlett
self (it just hosts it for Windows clients to apply locally. See the 'net pwsettings' command for the way to change these settings in the Samba4 domain until this functionality is extended. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/

Re: [Samba] samba3 and samba4 in the same domain?

2010-05-11 Thread Andrew Bartlett
On Tue, 2010-05-11 at 10:30 +0200, Tomasz Chmielewski wrote: > Am 11.05.2010 06:59, Tomasz Chmielewski wrote: > > Am 11.05.2010 03:08, Andrew Bartlett wrote: > >> On Mon, 2010-05-10 at 14:40 +0200, Tomasz Chmielewski wrote: > >>> I have a Samba3 + OpenLDAP installati

Re: [Samba] FreeIPA + samba 4, any news?

2010-05-10 Thread Andrew Bartlett
ora DS/'389' can work as a Samba4 backend, but beyond that I don't know their status (and it's not very clear on their wiki). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://sam

Re: [Samba] samba3 and samba4 in the same domain?

2010-05-10 Thread Andrew Bartlett
reate a setup with a unix-like schema, but you will have to ask them about their progress). We also don't yet have good upgrade scripts from Samba3. It can be done, but a lot of the task will be manual. Sorry, Andrew Bartlett -- Andrew Bartletthttp://samba

Re: [Samba] RE : RE : Domain not found in Samba 4 AD

2010-05-10 Thread Andrew Bartlett
to get it out as quickly as I should have. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description: This is a digitally signed messag

Re: [Samba] Samba4. Unable to join to client machines.

2010-05-10 Thread Andrew Bartlett
misconfiguration on any host-based firewall you may have. If you don't see any noise in the logs, I suspect that while Samba4 may be running, clients can't contact it. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Develop

Re: [Samba] samba4 make error - drsblobs.so

2010-05-04 Thread Andrew Bartlett
heckout from today, it should work. We finally changed to a new build system, which should fix this and many other issues. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba De

Re: [Samba] Windows7 able to join Samba4-alpha12 domain, but unable to manage

2010-05-02 Thread Andrew Bartlett
is sounds very much like an issue solved in the past few weeks. Perhaps try a current GIT snapshot? I am trying to get another alpha release made, but I've not managed to do it quite yet. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authen

Re: [Samba] samba 4 for new authentication domain?

2010-05-01 Thread Andrew Bartlett
very real production use I've personally assisted administrators with, I can attest that it does really work. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer,

Re: [Samba] samba 4 for new authentication domain?

2010-05-01 Thread Andrew Bartlett
it is also very much working for our users. http://wiki.samba.org/index.php/Samba4/videos Give it a try - particularly if you can put your traditional file-server and printer roles on a Samba3 member server. You will quickly find out what works for you, and what does not. Andrew B

Re: [Samba] Samba4 segfault

2010-04-22 Thread Andrew Bartlett
didn't make it to the list. Can you make it with git format-patch (if possible) and attach it to a bug, or mail it to me. I would be delighted to include it in the tree, or otherwise fix this bug. (Sorry for the slow response, I normally expect Samba4 questions on samba-technical during this

Re: [Samba] Samba4 - List of options for smb.conf

2010-04-22 Thread Andrew Bartlett
On Tue, 2010-04-20 at 12:44 -0400, Stuart Wehrly wrote: > Is there a list of options for smb.conf? Sadly Samba4 does lack documentation. But testparm -v from Samba4 should get you what you want. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abart

Re: [Samba] Samba4 clustering

2010-03-23 Thread Andrew Bartlett
See also the main HOWTO at http://wiki.samba.org/index.php/Samba4/HOWTO Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc Description:

Re: [Samba] Attribute ms-DS-User-Account-Disabled in samba4

2010-03-22 Thread Andrew Bartlett
On Mon, 2010-03-22 at 09:06 -0400, Konstantin Pobudzey wrote: > Hello Andrew Bartlett > Thank You for response. userParameters value is not set actually. > I found difference,it is value in userAccountControl. > ( if account enabled 512 ( 66048 if enabled and password never expi

Re: [Samba] Samba4 clustering

2010-03-22 Thread Andrew Bartlett
balance the domain? Correct. Load balancing is up to the client, but yes it should just work. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc

Re: [Samba] Samba4 clustering

2010-03-21 Thread Andrew Bartlett
Samba4 does not support any clustered operation. In it's primary role as an AD domain controller, this simply isn't needed - multiple DCs are expected. The fileserver could with work be clustered - indeed ctdb was first developed in Samba4 - but there is no work in this area at this time

Re: [Samba] Samba4 as a "plain LDAP" server?

2010-03-21 Thread Andrew Bartlett
y we can maintain the best of both worlds is wanted. We have to be an AD server first, but I'm open to ideas for how we can be better as well. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Re: [Samba] Samba4 as a "plain LDAP" server?

2010-03-21 Thread Andrew Bartlett
baNTPassword attribute, and the other Samba flags. ) With Samba4, the restrictions we have in the AD design (much closer integration with the KDC and LDAP server) have meant that these parts must now be under Samba4's control. I hope this clarifies things, Andrew Bartlett -- Andrew Bart

Re: [Samba] Attribute ms-DS-User-Account-Disabled in samba4

2010-03-21 Thread Andrew Bartlett
> for this ? Samba4 does not currently handle (or know about) this attribute. A disabled account has a flag in the userParameters set, and this is what we use. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba T

Re: [Samba] Samba4 as a "plain LDAP" server?

2010-03-21 Thread Andrew Bartlett
domain controller, and we can't enable behaviours that are in conflict with being an AD DC. For example, we will soon enable ACL support that will block anonymous access to our directory - while most POSIX clients prefer anonymous searches. I hope this clarifies things, Andrew Bartlett -

Re: [Samba] samba4: getent group stalls

2010-03-21 Thread Andrew Bartlett
illa when you pin things down a bit more. Perhaps also try a 'git bisect' to find the failing revision. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Develope

Re: [Samba] Samba4 join existing domain

2010-03-21 Thread Andrew Bartlett
dns_lookup_realm = true dns_lookup_kdc = true is set, and then try a 'kinit administrator' to check that this works first. Also perhaps turn up the debug level (add -d3 for example). Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authent

Re: [Samba] Samba4 Auth Against OpenDirectory (OpenLDAP)

2010-03-21 Thread Andrew Bartlett
they are stored in a separate password store, accessed by the Open Directory KDC and the password server. We can talk about the options and how we might be able to make something work for you on samba-technical if you like. I'm sorry this isn't so easy, Andrew Bartlett -- Andrew Bart

Re: [Samba] How Configure Samba4 to use Openldap-Backend?

2010-02-09 Thread Andrew Bartlett
-w" No, these have been autoconfigured by the provision script. > Could someone, who has this configuration running, be so kind to send me > an example smb.conf There is nothing special in the smb.conf. Instead, the provision script embeds the right information in the sam.ldb datab

Re: [Samba] Is NTLMv2 auth possible with security = SERVER ?

2010-02-08 Thread Andrew Bartlett
ues to get around > such an issue? You should never use 'security=server' if there is any other possible way to authenticate your users. It is a disgusting man in the middle attack, that therefore makes important security features go away, including NTLMv2. Andrew Bartlett -- An

Re: [Samba] Samba 4: permissive modify fails

2010-02-07 Thread Andrew Bartlett
he > attribute with the same value already exists or when an attribute to > be deleted does not exists. Correct, we don't currently support this control. Please file a bug, and we will try and get to it soon. Andrew Bartlett -- Andrew Bartlett

Re: [Samba] Samba 4: LookupAccountName fails

2010-02-07 Thread Andrew Bartlett
up running against Windows. That way, we can match the behaviour, and write a testsuite for it. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc. signature.asc D

Re: [Samba] BDC & passwd changes

2010-02-06 Thread Andrew Bartlett
On Sun, 2010-02-07 at 00:21 +1100, Mike Fabre wrote: > On Sat, Feb 06, 2010 at 08:18:06PM +1100, Andrew Bartlett wrote: > > On Fri, 2010-02-05 at 10:21 +1100, Mike Fabre wrote: > > > Hello > > > > > > I have a network setup with one Samba PDC and two Samba

Re: [Samba] BDC & passwd changes

2010-02-06 Thread Andrew Bartlett
e Samba DCs PDCs of their own networks. That way, they will all be contacted for password changes, because on each of their local networks, they hold the DOMAIN#1B name. (They need not be read-write OpenLDAP replicas, as Samba happily handles the referral to the master for writes). Andrew

Re: [Samba] provision-backend gone ?!

2010-01-29 Thread Andrew Bartlett
his will not work in the latest alpha, but we hope to integrate some patches Endi has been working on to fix this soon. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, C

Re: [Samba] how to use m4_pattern_allow

2010-01-18 Thread Andrew Bartlett
ttern_allow" This means that the version of 'acl' you are trying to install is not compatible with the OS yo are trying to install it on. Why are you not trying to install it via a package management system? Andrew Bartlett -- Andrew Bartletthtt

Re: [Samba] Windows7 Join PDC

2010-01-18 Thread Andrew Bartlett
mpt to upgrade Samba on it's own. Or if you must, then find RPM packages (sernet has some for a wide variety of OS versions) of the recent code pre-packaged. It is best to upgrade the server OS to a current revision for other reasons anyway. Andrew Bartlett -- Andrew Bartlett

<    4   5   6   7   8   9   10   11   12   13   >