[Samba] Excel 2003 open/save problem

2006-11-17 Thread Beschorner Daniel
Since we installed the Bitdefender antivirus software on some of our
WindowsXP clients we often see the message already open / may have
changed in Excel 2003.

The test results are interesting:

Active antivirus on-access file scan:

against Samba 3.0.23d - Log level 1 - reproducible errors
against Samba 3.0.23d - Log level 10 - no errors, so cannot provide any
log ;-)
against W2K3 server - no errors


Without file scan:

all are fine


The regkey from http://support.microsoft.com/kb/324491 (which makes
Excel to flush the file cache before comparing timestamps) seems to fix
it even with Samba/Log level 1/Bitdefender.

So maybe some kind of timing issue?!?

Daniel
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Problem with copying large amount of files fromw2k3/sp1 to Samba 3.0.23c

2006-11-02 Thread Beschorner Daniel
The Linux kernels 2.6.17 - 2.6.17.11 have a bug with kernel oplocks that
hits Samba and shows your symptoms.
kernel oplocks = no may solve it.


It's running with a Linux 2.6.17.8 SMP kernel


 On Thu, 2006-11-02 at 14:25 +0100, Beschorner Daniel wrote:
 What Linux kernel version you are running on the production server?
 
 Daniel
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Samba 3.0.23 trusts 2003 AD Domain

2006-07-11 Thread Beschorner Daniel
Can anyone confirm that SID - name lookup with a trusted domain is broken?

Thanks
Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Samba 3.0.23 trusts 2003 AD Domain

2006-07-11 Thread Beschorner Daniel
 Beschorner Daniel wrote:
 Can anyone confirm that SID - name lookup with 
 a trusted domain is broken?

 Works fine for a Samba DC trusted Windows 2003 AD:

Jerry, thank you for checking this! But we don't use winbindd, so I don't
even got the wbinfo command.
I simply add an ACL entry from the trusted domain to a harddisk file per
security tab.
When I open the dialog window again I just see the SID of the foreign user.
The level 10 log simply says not mapped, I can see no effords to lookup
the SID through the foreign DC.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] File attribute problem 3.0.23

2006-07-05 Thread Beschorner Daniel
We have a problem with an application that clears the archive bit before
writing and sets it after writing.
The latter one doesn't succeed if the writer != file owner.
Dos filemode is enabled and manually setting is fine.
Samba is 3.0.23RC3.
Client is XP/SP2.
Seems to loose the connection before setting the bit and a new smbd is
spawn.

Daniel

[2006/07/05 09:32:36, 10] locking/locking.c:is_locked(96)
  is_locked: optimisation - exclusive oplock on file Dev/Inst.ism
[2006/07/05 09:32:36, 10] locking/locking.c:is_locked(134)
  is_locked: flavour = WINDOWS_LOCK brl start=0 len=5429 unlocked for fnum
10866 file Dev/Inst.ism
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode(326)
  dos_mode: Dev/Inst.ism
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode_from_sbuf(193)
  dos_mode_from_sbuf returning
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode(364)
  dos_mode returning
[2006/07/05 09:32:36, 10] smbd/dosmode.c:file_set_dosmode(393)
  file_set_dosmode: setting dos mode 0x20 on file Dev/Inst.ism
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode(326)
  dos_mode: Dev/Inst.ism
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode_from_sbuf(193)
  dos_mode_from_sbuf returning
[2006/07/05 09:32:36, 8] smbd/dosmode.c:dos_mode(364)
  dos_mode returning
[2006/07/05 09:32:36, 3] smbd/dosmode.c:unix_mode(147)
  unix_mode(Dev/Inst.ism) returning 0760
[2006/07/05 09:32:36, 5] smbd/files.c:file_new(126)
  allocated file structure 6771, fnum = 10867 (2 used)
[2006/07/05 09:32:36, 0] lib/util_sock.c:get_peer_addr(1229)
  getpeername failed. Error was Transport endpoint is not connected
[2006/07/05 09:32:36, 0] lib/util_sock.c:write_data(562)
  write_data: write failure in writing to client 192.168.1.4. Error
Connection reset by peer
[2006/07/05 09:32:36, 0] lib/util_sock.c:send_smb(769)
  Error writing 4 bytes to client. -1. (Connection reset by peer)
[2006/07/05 09:32:36, 1] smbd/service.c:make_connection_snum(941)
  dev4 (192.168.1.4) connect to service Dev initially as user xxx (uid=100,
gid=100) (pid 20030)
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re:URGENT!!!!! Problem: outlook.pst with samba 3.0.21c!!!!!!!!

2006-03-15 Thread Beschorner Daniel
We also got it sporadically.

https://bugzilla.samba.org/show_bug.cgi?id=3587
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] [Samba Version 3.0.20b-3.4-SUSE]: WinXP-Error writing to share

2006-03-10 Thread Beschorner Daniel
 My money is on the switch :-). This is a classic my tcp connection
 went away and I don't know why error message.
 
 Jeremy.

Your money was invested well ;-)

In our situation the problems disappeared for now (cross the fingers!) with
a new hub, what makes sense because of a fine working Win2003 Server x64 +
Samba in an other network.

Still got these (but doesnt' seem to harm):

[2006/03/10 13:20:35, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
[2006/03/10 13:20:35, 0] lib/access.c:check_access(328)
[2006/03/10 13:20:35, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
[2006/03/10 13:20:35, 1] smbd/process.c:process_smb(1187)
[2006/03/10 13:20:35, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
[2006/03/10 13:20:35, 0] lib/util_sock.c:write_data(557)
  write_data: write failure in writing to client 0.0.0.0. Error Connection
reset by peer
[2006/03/10 13:20:35, 0] lib/util_sock.c:send_smb(765)
  Error writing 5 bytes to client. -1. (Connection reset by peer)

Thank you Jeremy  Robert!


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] [Samba Version 3.0.20b-3.4-SUSE]: WinXP-Error writing to share

2006-03-07 Thread Beschorner Daniel
We have a similar or same problem with one of our servers after upgrade from
3.0.14 to 3.0.21x (incidentally??).

The log shows things like:

write_data: write failure in writing to client 192.168.17.249. Error Broken
pipe

[2006/03/06 20:46:47, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
[2006/03/06 20:46:47, 0] lib/access.c:check_access(328)
[2006/03/06 20:46:47, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
  Denied connection from  (0.0.0.0)
[2006/03/06 20:46:47, 1] smbd/process.c:process_smb(1187)
[2006/03/06 20:46:47, 0] lib/util_sock.c:get_peer_addr(1225)
  getpeername failed. Error was Transport endpoint is not connected
  Connection denied from 0.0.0.0
[2006/03/06 20:46:47, 0] lib/util_sock.c:write_data(557)
  write_data: write failure in writing to client 192.168.17.250. Error
Connection reset by peer
[2006/03/06 20:46:47, 0] lib/util_sock.c:send_smb(765)
  Error writing 5 bytes to client. -1. (Connection reset by peer)

Clients are XP x64.

When saving fails the Windows log reports mrxsmb - delayed write failed.

I still suspect the network hardware (switch? NICs?) to do something wrong,
but can't Samba take out yet.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] nmbd shutdown

2006-02-27 Thread Beschorner Daniel
For many samba releases (maybe for longer than 3.0) I see that the nmbd (PDC
 WINS) doesn't shutdown on the first kill signal but on the second.
Any idea?

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Joining domain with W2K SP1 fails

2006-01-28 Thread Beschorner Daniel
After a fresh re-install of a W2K workstation I noticed that it is
impossible to join a Samba domain (3.0.21a).
Wrong credentials is displayed and the log gives:

libsmb/smbencrypt.c:decode_pw_buffer(514)
  decode_pw_buffer: incorrect password length (959351032).

With SP4 all is going fine.

It should be not a problem nowadays, I just want to report it.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Trying to delay for oplocks twice

2006-01-04 Thread Beschorner Daniel
We have a lot of 

[2006/01/04 18:44:40, 0] smbd/open.c:open_file_ntcreate(1355)
  Trying to delay for oplocks twice

in the logs. Do they harm in general?

And only in one single case I got this, don't know if I ever will get it
reproduced, so maybe not related and happened by accident:

Samba version 3.0.21a
PID Username  Group Machine
--
 8231   testuser  users ws24(192.168.1.24)
 8673   testuser  users ws24(192.168.1.24)
 3822   testuserusers ws24(192.168.1.24)

Service  pid machine Connected at

IPC$ 3822 ws24  Wed Jan  4 17:33:14 2006
IPC$ 8231 ws24  Wed Jan  4 17:35:02 2006
testuser 3822 ws24  Wed Jan  4 07:50:41 2006
Projects 8673 ws24  Wed Jan  4 18:44:40 2006

3822  DENY_WRITE 0x2019f RDWR NONE outlook/rsc.pst   Wed Jan  4 17:20:40
2006
8673  DENY_NONE  0x20089 RDONLY NONE outlook/rsc.pst   Wed Jan  4 18:49:38
2006

Windows complained about Cannot access rcs.pst, in use by another process.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Trying to delay for oplocks twice

2006-01-04 Thread Beschorner Daniel
 
Sorry, the second problem just seems to be related to an offline printer:

#0  0x2b3e76d4 in waitpid () from /lib64/tls/libc.so.6
#1  0x005963c0 in smbrun ()
#2  0x0058a8e1 in print_run_command ()
#3  0x0058accf in generic_job_submit ()
#4  0x005bbb20 in print_job_end ()
#5  0x004f5f9a in _spoolss_enddocprinter_internal ()
#6  0x004f073a in api_spoolss_enddocprinter ()
#7  0x0051eaf1 in api_rpcTNP ()
#8  0x0051ee75 in api_pipe_request ()
#9  0x0051b975 in write_to_internal_pipe ()
#10 0x004510f1 in api_fd_reply ()
#11 0x00451b70 in reply_trans ()
#12 0x00497128 in switch_message ()
#13 0x004973e9 in process_smb ()
#14 0x0049810f in smbd_process ()
#15 0x0060f1ff in main ()

After the job was printed some hours later all went fine.



We have a lot of 

[2006/01/04 18:44:40, 0] smbd/open.c:open_file_ntcreate(1355)
  Trying to delay for oplocks twice

in the logs. Do they harm in general?

And only in one single case I got this, don't know if I ever will get it
reproduced, so maybe not related and happened by accident:

Samba version 3.0.21a
PID Username  Group Machine
--
 8231   testuser  users ws24(192.168.1.24)
 8673   testuser  users ws24(192.168.1.24)
 3822   testuserusers ws24(192.168.1.24)

Service  pid machine Connected at

IPC$ 3822 ws24  Wed Jan  4 17:33:14 2006
IPC$ 8231 ws24  Wed Jan  4 17:35:02 2006
testuser 3822 ws24  Wed Jan  4 07:50:41 2006
Projects 8673 ws24  Wed Jan  4 18:44:40 2006

3822  DENY_WRITE 0x2019f RDWR NONE outlook/rsc.pst   Wed Jan  4 17:20:40
2006
8673  DENY_NONE  0x20089 RDONLY NONE outlook/rsc.pst   Wed Jan  4 18:49:38
2006

Windows complained about Cannot access rcs.pst, in use by another process.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Trying to delay for oplocks twice

2006-01-04 Thread Beschorner Daniel

# grep version  Posting
Samba version 3.0.21a
:-)

 What Samba version?  If it's 3.0.21, please test 3.0.21a
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Trying to delay for oplocks twice

2006-01-04 Thread Beschorner Daniel
The question is whether blocking is well defined in this case (because lpd
hangs) or if it is an error that the file serving/locking services of the
smbd process hang altogether.

My print section looks like this:

printing = lprng
print command = lpr -r -P'%p' %s
lpq command = lpq -P'%p'
lprm command = lprm -P'%p' %j
lppause command = lpc hold '%p' %j
lpresume command = lpc release '%p' %j
queuepause command = lpc stop '%p'
queueresume command = lpc start '%p'
use client driver = No
default devmode = No
force printername = No 

It's a Linux x64 system with lprng printing.

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Beschorner Daniel wrote:
  
 Sorry, the second problem just seems to be related to an offline
printer:
 
 #0  0x2b3e76d4 in waitpid () from /lib64/tls/libc.so.6
 #1  0x005963c0 in smbrun ()
 #2  0x0058a8e1 in print_run_command ()
 #3  0x0058accf in generic_job_submit ()
 #4  0x005bbb20 in print_job_end ()
 #5  0x004f5f9a in _spoolss_enddocprinter_internal ()
 #6  0x004f073a in api_spoolss_enddocprinter ()
 #7  0x0051eaf1 in api_rpcTNP ()
 #8  0x0051ee75 in api_pipe_request ()
 #9  0x0051b975 in write_to_internal_pipe ()
 #10 0x004510f1 in api_fd_reply ()
 #11 0x00451b70 in reply_trans ()
 #12 0x00497128 in switch_message ()
 #13 0x004973e9 in process_smb ()
 #14 0x0049810f in smbd_process ()
 #15 0x0060f1ff in main ()
 
 After the job was printed some hours later all went fine.

Please give me some more details on the server OS
and the outout from 'testparm -v'
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] 3.0.21 and Rejecting auth request from client

2006-01-04 Thread Beschorner Daniel
It seems to be uncritical because the client falls back to another call:

https://bugzilla.samba.org/show_bug.cgi?id=3366

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] displayName vs. cn

2005-10-11 Thread Beschorner Daniel
In 3.0.20a/ldapsam the Usrmgr shows in the all users view the displayName
attribute as full name, but in the user properties view the cn attribute.
Seems a little bit inconsistent to me, shouldn't be the algorithm to
retrieve the full name always the same?

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] displayName vs. cn

2005-10-11 Thread Beschorner Daniel
| In 3.0.20a/ldapsam the Usrmgr shows in the all users
| view the displayName attribute as full name, but in the
| user properties view the cn attribute. Seems a little
| bit inconsistent to me, shouldn't be the algorithm to
| retrieve the full name always the same?

 Is this different from 3.0.20?  Or just 3.0.20 versions?
 And to clarify, you have both the displayName and cn attribute
 in a user account entry right?

With 3.0.14 it was different, all our users got full names. I didn't try
3.0.20, but can do if necessary.

Because of this change I realized how poorly our displayNames are maintained
(only 5 of 150 users), in fact since 3.0.20a most users doesn't have a full
name any longer in the user list.
In user details (and for instance in Windows login information after
Ctrl+Alt+Del) they still have.
Both entries in Usrmgr claim to have the full name, but they differ.




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] problems with samba 3 and termnal server

2005-10-11 Thread Beschorner Daniel
One smbd per user on W2K TS with this registry key:

http://support.microsoft.com/kb/818528/ 

You need the hotfix 818528 (included in Update Rollup 1 for SP4) for the key
to become effective.

Daniel

-Ursprüngliche Nachricht-
Von: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Im
Auftrag von Jeremy Allison
Gesendet: Dienstag, 11. Oktober 2005 18:12
An: Lorenzo Pilotti
Cc: samba@lists.samba.org
Betreff: Re: [Samba] problems with samba 3 and termnal server

On Tue, Oct 11, 2005 at 10:20:41AM +0200, Lorenzo Pilotti wrote:
 
 a customer currently uses a Suse 9.2 pro with the last version of Samba to
 share a folder containing data for an Enterprise Management program
(Windows
 based).
 
 everything works fine with local clients (many 98s and 1 XP machine).
 
 we have some (15) clients connecting to the ERP program via a Terminal
Server
 (Windows2K server). these clients often stuck in some requests for 5 to 15
 minutes (randomly) and then unlock and continue working.

Clients usually time out after 30 seconds. What is happening on the wire
between terminal server and Samba during that time ?

 note that:
 - the same folder on a Win2000 machine works fine (ie. no stucks)
 - this means it is a samba problem
 - local clients work find
 - this means it is a terminal-server-related problem
 
 i thought it was something related to oplocks and i have disabled them
(level
 1 AND level 2) but the problem is still here.
 
 now I ***suppose*** this is something like:
 - samba receives many connections from the same IP (the terminal server)
 and has problems de-mux-ing the requests...
 
 any ideas???

It's possible to set a registry setting that causes TS to open a new
SMB connection for every logged on user, this should help if the problem
is requests getting stuck in smbd's single threaded queue. The TS client
has some multi-threaded synchronisation problems that Microsoft could only
solve by going back to the (sensible) multi-connection model. They only
changed to single-connection to screw Samba over in a big account anyway
(the honest and sad truth :-).

You can look up the registry setting on MSDN, or someone on the list may
have it to hand.

Jeremy.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


solved [Samba] net utility (3.0.12) acting strange

2005-03-23 Thread Beschorner Daniel
See also for this: https://bugzilla.samba.org/show_bug.cgi?id=1631
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] compiling on an old system...

2005-02-08 Thread Beschorner Daniel
Remove the flags -Wl,-Bsymbolic and maybe -Wl,--allow-shlib-undefined
from your Makefile.
Very old linkers don't like them.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] compiling on an old system...

2005-02-08 Thread Beschorner Daniel
BTW, are these really errors or just warnings?


|Remove the flags -Wl,-Bsymbolic and maybe -Wl,--allow-shlib-undefined
from your Makefile.
|Very old linkers don't like them.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] DOS Attributes On Folders

2005-01-26 Thread Beschorner Daniel
Yes, per default DOS directory attributes are not working at all.
With store dos attributes = yes it is working.

Daniel

-Ursprüngliche Nachricht-
Von: Max Bolingbroke [mailto:[EMAIL PROTECTED] 
Gesendet: Dienstag, 25. Januar 2005 00:31
An: Beschorner Daniel
Betreff: Re: Access denied changing file attributes

Seems like I was a little hasty :) I have found out that DOS attributes 
on directories are still not functioning (though without an access 
denied error - it just fails silently). I've started a new thread about 
it, but I suspect this is a Samba limitation.. have you got any ideas 
what might cause this problem?

Max Bolingbroke

Beschorner Daniel wrote:

It would had been my first idea if you had specified your version of Samba.
I was assuming 3.0.10.

Glad it works now!
Daniel

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Visual Studio/Samba Compile from Shares issue

2005-01-25 Thread Beschorner Daniel
Did you try dos filetimes = yes and dos filemode = yes?

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re:Access denied changing file attributes

2005-01-24 Thread Beschorner Daniel
Hi Max,

my first idea with this log file is that you're using the release 3.0.8 of
Samba, are you?
It has an evil bug related to file attributes, fixed in 3.0.9.

Daniel


-Ursprüngliche Nachricht-
Von: Max Bolingbroke [mailto:[EMAIL PROTECTED] 
Gesendet: Montag, 24. Januar 2005 08:03
An: Beschorner Daniel
Betreff: Re: Access denied changing file attributes

Hi,

The log is attached, created using log level = 10 in smb.conf. I zipped 
it since its 360k unzipped. Thanks for the help!

Max Bolingbroke

Beschorner Daniel wrote:

Strange, the admin users line should give to you full root access to the
share, so access denied is quite impossible.
Did you restart smbd after inserting the line?
Maybe something basically broken...?!?
Next idea is a look to the log.smbd at log level 10.
Can you send it to me per mail?

Daniel



-Ursprüngliche Nachricht-
Von: Max Bolingbroke [mailto:[EMAIL PROTECTED]
Gesendet: Sonntag, 23. Januar 2005 16:33
An: Beschorner Daniel
Cc: 'samba@lists.samba.org'
Betreff: Re: Access denied changing file attributes


No change whatsoever :) Are there any other possible problems?

Thanks in advance,

Max Bolingbroke

Beschorner Daniel wrote:

  

Try adding admin users = mbolingbroke to the share und try again.

 



For a sample file that I am trying to change the
attributes of. Since Samba should be authenticating
me as mbolingbroke, I don't think this is the problem.
   

  

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Access denied changing file attributes

2005-01-24 Thread Beschorner Daniel
It would had been my first idea if you had specified your version of Samba.
I was assuming 3.0.10.

Glad it works now!
Daniel

-Ursprüngliche Nachricht-
Von: Max Bolingbroke [mailto:[EMAIL PROTECTED]
Gesendet: Montag, 24. Januar 2005 20:22
An: Beschorner Daniel
Cc: 'samba@lists.samba.org'
Betreff: Re: Access denied changing file attributes


Hi,

Thanks very much for pointing that out! Upgraded to 3.0.10 and 
everything works, even when I put it in an extended attribute as nature 
intended. Thanks again!

Max Bolingbroke
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Access denied changing file attributes

2005-01-23 Thread Beschorner Daniel
Try adding admin users = mbolingbroke to the share und try again.

 For a sample file that I am trying to change the
 attributes of. Since Samba should be authenticating
 me as mbolingbroke, I don't think this is the problem.

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Re: Access denied changing file attributes

2005-01-23 Thread Beschorner Daniel
Strange, the admin users line should give to you full root access to the
share, so access denied is quite impossible.
Did you restart smbd after inserting the line?
Maybe something basically broken...?!?
Next idea is a look to the log.smbd at log level 10.
Can you send it to me per mail?

Daniel



-Ursprüngliche Nachricht-
Von: Max Bolingbroke [mailto:[EMAIL PROTECTED]
Gesendet: Sonntag, 23. Januar 2005 16:33
An: Beschorner Daniel
Cc: 'samba@lists.samba.org'
Betreff: Re: Access denied changing file attributes


No change whatsoever :) Are there any other possible problems?

Thanks in advance,

Max Bolingbroke

Beschorner Daniel wrote:

Try adding admin users = mbolingbroke to the share und try again.

  

For a sample file that I am trying to change the
attributes of. Since Samba should be authenticating
me as mbolingbroke, I don't think this is the problem.


--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Access denied changing file attributes

2005-01-21 Thread Beschorner Daniel
Hi Max,

are you owner of the files you want to handle?
Only file owner is allowed to change file permissions (where attributes are
mapped), write access isn't enough.

Daniel

 I've been tearing my hair out trying to get DOS file attributes
 to work with Samba. An  error occured applying  attributes
 to the file file name Access is denied. 

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] new printing patch for 3.0.10

2005-01-11 Thread Beschorner Daniel
This one line seems indeed to correct the listed jobs problem after some
quick tests.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] new printing patch for 3.0.10

2005-01-07 Thread Beschorner Daniel
In our environment the v2 patch unfortunately doesn't seem to fix the
problem, old jobs are still listed.
W2K-SP4/XP-SP2, lprng, SuSE 9.0

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Cannot share MSAccess DB after upgrade 3.0.5 to 3.0.8

2004-12-17 Thread Beschorner Daniel
3.0.8 has an evil file attribute bug if your samba server has ACL support.
Try 3.0.10.

Daniel.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] strange error in 3.0.8

2004-11-19 Thread Beschorner Daniel
Hi Mathias,

A known bug in 3.0.8, 3.0.9 will fix it.

Here is a patch for 3.0.8:

https://bugzilla.samba.org/show_bug.cgi?id=2019

Daniel

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] VSS on samba

2004-11-12 Thread Beschorner Daniel
Hi Nathan,

we have it running.
Important seem to be:

dos filetimes = yes
dos filetime resolution = yes   (maybe no longer needed)
fake directory create times = yes
admin users = VSS users (users must be able to change attributes of files
they don't own!)

admin users means root rights for everybody on this share, but it's the
only way we got it working (so are at least my experiences).

We have oplocks enabled without problems.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Permission / file_set_dosmode problem in 3.0.8

2004-11-10 Thread Beschorner Daniel
--- branches/SAMBA_3_0_RELEASE/source/smbd/dosmode.c2004/10/25 19:25:54
3220
+++ branches/SAMBA_3_0_RELEASE/source/smbd/dosmode.c2004/11/07 20:42:45
3605
@@ -344,7 +344,9 @@
return(-1);
}
 
-   get_acl_group_bits(conn, fname, st-st_mode);
+   if (!get_acl_group_bits(conn, fname, st-st_mode)) {
+   return(-1);
+   }
 
if (S_ISDIR(st-st_mode))
dosmode |= aDIR;

This change seems to break it.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Permissions problem with 3.0.8

2004-11-09 Thread Beschorner Daniel
Since 3.0.8 we have a file permission problem (group related???).
I didn't take a closer look at it, our production environment went back to
3.0.7.

symptoms: certain files can't be recreated/deleted, but group rights should
allow it.

3.0.7 works fine.

Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


AW: [Samba] Permissions problem with 3.0.8

2004-11-09 Thread Beschorner Daniel
We use LDAP backend and Linux 2.6.
It happens only --with-acl-support.
This 2 errors I found in the level 10 log when I try to copy a fresh copied
file a second time on itself (permissions of test file are -r-xrw, user
and group match)
Maybe the attribute mapping goes another path with acl support?
3.0.7 works fine.

Daniel




[2004/11/09 17:02:02, 10] smbd/open.c:open_file_shared1(1038)
  open_file_shared: fname = bootfont.bin, dos_attrs = 27, share_mode = 41,
ofun = 12, mode = 560, oplock request = 3
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(283)
  dos_mode: bootfont.bin
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode_from_sbuf(151)
  dos_mode_from_sbuf returning ra
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(315)
  dos_mode returning ra
[2004/11/09 17:02:02, 10] smbd/open.c:open_match_attributes(922)
  open_match_attributes: file bootfont.bin old_dos_mode = 0x21,
existing_mode = 0100560, new_dos_mode = 0x27 returned_mode =
[2004/11/09 17:02:02, 5] smbd/open.c:open_file_shared1(1141)
  open_file_shared: read/write access requested for file bootfont.bin on
read only file
[2004/11/09 17:02:02, 5] smbd/files.c:file_free(385)
  freed files structure 5799 (2 used)
[2004/11/09 17:02:02, 10] smbd/trans2.c:set_bad_path_error(2234)
  set_bad_path_error: err = 13 bad_path = 0
[2004/11/09 17:02:02, 3] smbd/error.c:error_packet(105)
  error string = Permission denied
[2004/11/09 17:02:02, 3] smbd/error.c:error_packet(129)
  error packet at smbd/trans2.c(2243) cmd=162 (SMBntcreateX)
NT_STATUS_ACCESS_DENIED

...

[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(283)
  dos_mode: bootfont.bin
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode_from_sbuf(151)
  dos_mode_from_sbuf returning ra
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(315)
  dos_mode returning ra
[2004/11/09 17:02:02, 6] smbd/trans2.c:call_trans2setfilepathinfo(3621)
  actime: Wed Apr  2 13:00:00 2003
   modtime: Thu Jan  1 01:00:00 1970
   size: 4952 dosmode: a0
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(283)
  dos_mode: bootfont.bin
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode_from_sbuf(151)
  dos_mode_from_sbuf returning ra
[2004/11/09 17:02:02, 8] smbd/dosmode.c:dos_mode(315)
  dos_mode returning ra
[2004/11/09 17:02:02, 10] smbd/trans2.c:call_trans2setfilepathinfo(3678)
  call_trans2setfilepathinfo: file bootfont.bin : setting dos mode a0
[2004/11/09 17:02:02, 10] smbd/dosmode.c:file_set_dosmode(340)
  file_set_dosmode: setting dos mode 0xa0 on file bootfont.bin
[2004/11/09 17:02:02, 2] smbd/trans2.c:call_trans2setfilepathinfo(3681)
  file_set_dosmode of bootfont.bin failed (No data available)
[2004/11/09 17:02:02, 3] smbd/error.c:error_packet(105)
  error string = No data available
[2004/11/09 17:02:02, 3] smbd/error.c:error_packet(129)
  error packet at smbd/trans2.c(3682) cmd=50 (SMBtrans2)
NT_STATUS_ACCESS_DENIED


-Ursprüngliche Nachricht-
Von: Gerald (Jerry) Carter [mailto:[EMAIL PROTECTED]
Gesendet: Dienstag, 9. November 2004 15:16
An: Beschorner Daniel
Cc: '[EMAIL PROTECTED]'
Betreff: Re: [Samba] Permissions problem with 3.0.8

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Beschorner Daniel wrote:
| Since 3.0.8 we have a file permission problem (group related???).
| I didn't take a closer look at it, our production environment went 
| back to 3.0.7.
|
| symptoms: certain files can't be recreated/deleted, but group rights
should
| allow it.
|
| 3.0.7 works fine.

We'll need a lot more information.





cheers, jerry
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFBkNEaIR7qMdg1EfYRAm3ZAJ9OusYDoQOvA8a/hglSsrn+ctw6DQCg6ugq
Ty8XyPgZBQb24C+qVMpFmpk=
=p3FL
-END PGP SIGNATURE-
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] EA Bug?

2004-08-03 Thread Beschorner Daniel
Since we use Samba 3.0.5 on Linux 2.6 with xattr and acl on ext3 I'm not
longer able to set file attributes.
In detail, I'm able fine because they are saved as the EA user.DOSATTRIB at
the file.
But the other part of Samba didn't know that and uses the normal mapping for
reading the attributes resulting in no change of them.
So I'm unable to mark a file e.g. read only.

ea support = No
store dos attributes = No
are both on their defaults.

Any hint?

Thanks
Daniel

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Usrmgr.exe / W2K Server

2004-07-06 Thread Beschorner Daniel
Hi!

I can use this legacy tool fine to display/modify user information on W2K
workstations.
Double click a user on W2K Server gives procedure out of range
Any idea?

Environment is Samba 3.0.4 / LDAP.

DB
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Can't joint domain per LDAP slave servers

2004-06-03 Thread Beschorner Daniel
Hi!

We have a replicated LDAP Samba network.
I tried all versions since 3.0.2a (master and slaves), but only in the
network with the master LDAP server I can join the domain successfully.

The slave's smbd ends up with:

[2004/06/03 19:29:58, 0] rpc_server/srv_samr.c:api_samr_set_userinfo(786)
  api_samr_set_userinfo: Unable to unmarshall SAMR_Q_SET_USERINFO.
[2004/06/03 19:29:58, 0] libsmb/smbencrypt.c:decode_pw_buffer(521)
  decode_pw_buffer: incorrect password length (-1061250291).
[2004/06/03 19:29:58, 0] libsmb/smbencrypt.c:decode_pw_buffer(522)
  decode_pw_buffer: check that 'encrypt passwords = yes'

and incorrect user name is displayed by the client.

The machine accounts are manually created.

Any idea?

Regards
Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] SOLVED Can't joint domain per LDAP slave servers

2004-06-03 Thread Beschorner Daniel
Strange.

Both systems are Linux.
I compiled the LDAP slave Samba with CFLAGS=-O2 -march=i686 and SuSE's GCC
3.3.1.
The fine working master got the same CFLAGS but SuSE's GCC 2.95.3.

Without CFLAGS the GCC 3.3.1 works fine too.

Didn't know that optimization (and GCC3) is that dangerous

Thanks anyway
Daniel

--

Hi!

We have a replicated LDAP Samba network.
I tried all versions since 3.0.2a (master and slaves), but only in the
network with the master LDAP server I can join the domain successfully.

The slave's smbd ends up with:

[2004/06/03 19:29:58, 0] rpc_server/srv_samr.c:api_samr_set_userinfo(786)
  api_samr_set_userinfo: Unable to unmarshall SAMR_Q_SET_USERINFO.
[2004/06/03 19:29:58, 0] libsmb/smbencrypt.c:decode_pw_buffer(521)
  decode_pw_buffer: incorrect password length (-1061250291).
[2004/06/03 19:29:58, 0] libsmb/smbencrypt.c:decode_pw_buffer(522)
  decode_pw_buffer: check that 'encrypt passwords = yes'

and incorrect user name is displayed by the client.

The machine accounts are manually created.

Any idea?

Regards
Daniel
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] W2K3 Server + RAS + Samba 3.0 Domain

2004-03-30 Thread Beschorner Daniel
Hi!

 On Tue, 2004-03-30 at 00:32, Daniel Holtkamp wrote:
  Hi !
  
  I´m trying to figure out if it´s possible to add a W2K3 Server into a
  Samba 3.0 Domain and then have the RAS-Service on the W2K3 server
  authenthicate against the Samba Domain.
  
  Bringing the 2K3 into the Domain was not much of a problem, working fine
  so far, i can log on using Domain users etc.
  
  But i´ve been trying for a week now and i can´t get the RAS Service
  working properly. It always complains that it can´t authenticate the
  user on the Domain, but from the logs it´s not even trying to.
  
  Of course i asked google and searched this list but the closest thing i
  found was about Win2000 RAS ... and it was a post about that not working
  either.
 
 We didn't have the 'dialin' privilege stored.  Samba HEAD is slowly
 gaining privileges now.
 
  Question: Anyone ever gotten this to work ? With a 2K or 2K3 Server ?

Yes, it works for me at least with W2K.

Two things are necessary:

1. the SambaMungedDial attribute in the ldapsam backend (I believe since
3.0.1 in the scheme), don't know if there are any other backends supporting
it. This allows you the set the RAS allowed switch in user manager for
domains.

2. this evil patch to bypass the samba function access check

--- srv_samr_nt.c.orig  Tue Feb 10 10:44:51 2004
+++ srv_samr_nt.c   Tue Mar 30 18:13:48 2004
@@ -102,6 +102,7 @@

 NTSTATUS access_check_samr_function(uint32 acc_granted, uint32
acc_required, const char *debug)
 {
+   return NT_STATUS_OK;
DEBUG(5,(%s: access check ((granted: %#010x;  required: %#010x)\n,
debug, acc_granted, acc_required));
if ((acc_granted  acc_required) != acc_required) {


Without this patch you'll see the known message cannot authenticate... in
Windows and this

[2004/03/30 18:10:10, 2]
rpc_server/srv_samr_nt.c:access_check_samr_function(115)
  _samr_lookup_domain: ACCESS DENIED (granted: 0x0020;  required:
0x0010)

in the logs.


It's dirty and for my own use, but maybe no problem for developers to work
out a clean solution?!?

Daniel




 
 No, but I've got it working with 'Samba RAS' ;-)
 
 http://hawkerc.net/staff/abartlet/comp3700
 
 This applies just as well to modem dial-ins as to VPNs.  I hope to clean
 it up a bit more, and get it into the PPPd distribution.
 
 See also the updated patch in that directory.
 
 Andrew Bartlett
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] lease broken message

2004-01-06 Thread Beschorner Daniel
I often get this message in the logs (Samba 3.0.1, SuSE 8.2, Linux 2.4.23,
glibc 2.3.2):

lease broken - owner pid = pid of a smbd process

What does it mean? (kernel oplocks related???)
Is it a linux or samba problem?

Thanks
DB
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Samba 2.2.3a and Windows Sychronization

2003-11-07 Thread Beschorner Daniel
This problem with offline sync in 2.2.3a is fixed since samba 2.2.4.

DB
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] Clear text authentication impossible???

2003-10-22 Thread Beschorner Daniel
We have an Exchange 5.5 server in our Samba 3 domain und want to have POP3
access with clear text authentication from clients.
But no kind of credentials is accepted.

It did a level 10 log on the Samba server and found my clear text password
in the log (in nt_chal_resp and lm_chal_resp fields) during authentication.

Is it possible that Samba can't handle the clear-text pass-through from
POP3-Client per Exchange server and takes it for NTLMv2 challenge

Thanks
Daniel


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Clear text authentication impossible???

2003-10-22 Thread Beschorner Daniel
Ok, here it comes. Samba PDC is called server, Exchange got the fantastic
name exchange, domain is i-bn.
I changed the password to p.a.s.s.w.o.r.d and PASSWORD at both
occurrences, originally it was lower case, too.

Daniel


-Ursprüngliche Nachricht-
Von: Jeremy Allison [mailto:[EMAIL PROTECTED]
Gesendet: Mittwoch, 22. Oktober 2003 21:16
An: Beschorner Daniel
Cc: '[EMAIL PROTECTED]'
Betreff: Re: [Samba] Clear text authentication impossible???


On Wed, Oct 22, 2003 at 03:27:31PM +0200, Beschorner Daniel wrote:
 We have an Exchange 5.5 server in our Samba 3 domain und want to have POP3
 access with clear text authentication from clients.
 But no kind of credentials is accepted.
 
 It did a level 10 log on the Samba server and found my clear text password
 in the log (in nt_chal_resp and lm_chal_resp fields) during
authentication.
 
 Is it possible that Samba can't handle the clear-text pass-through from
 POP3-Client per Exchange server and takes it for NTLMv2 challenge

Can you post the debug level 10 log please (obfuscate all passwords of
course :-).

Jeremy.

[2003/10/22 14:55:29, 5] lib/debug.c:debug_dump_status(359)
  INFO: Current debug levels:
all: True/10
tdb: False/0
printdrivers: False/0
lanman: False/0
smb: False/0
rpc_parse: False/0
rpc_srv: False/0
rpc_cli: False/0
passdb: False/0
sam: False/0
auth: False/0
winbind: False/0
vfs: False/0
idmap: False/0
[2003/10/22 14:55:41, 10] lib/util_sock.c:read_smb_length_return_keepalive(463)
  got smb length of 400
[2003/10/22 14:55:41, 6] smbd/process.c:process_smb(889)
  got message type 0x0 of len 0x190
[2003/10/22 14:55:41, 3] smbd/process.c:process_smb(890)
  Transaction 78 of length 404
[2003/10/22 14:55:41, 5] lib/util.c:show_msg(456)
[2003/10/22 14:55:41, 5] lib/util.c:show_msg(466)
  size=400
  smb_com=0x2f
  smb_rcls=0
  smb_reh=0
  smb_err=0
  smb_flg=24
  smb_flg2=51207
  smb_tid=1
  smb_pid=65279
  smb_uid=100
  smb_mid=4992
  smt_wct=14
  smb_vwv[ 0]=  255 (0xFF)
  smb_vwv[ 1]=57054 (0xDEDE)
  smb_vwv[ 2]=29711 (0x740F)
  smb_vwv[ 3]=0 (0x0)
  smb_vwv[ 4]=0 (0x0)
  smb_vwv[ 5]=65535 (0x)
  smb_vwv[ 6]=65535 (0x)
  smb_vwv[ 7]=8 (0x8)
  smb_vwv[ 8]=  336 (0x150)
  smb_vwv[ 9]=0 (0x0)
  smb_vwv[10]=  336 (0x150)
  smb_vwv[11]=   64 (0x40)
  smb_vwv[12]=0 (0x0)
  smb_vwv[13]=0 (0x0)
  smb_bcc=337
[2003/10/22 14:55:41, 10] lib/util.c:dump_data(1825)
  [000] EE 05 00 00 03 10 00 00  00 50 01 20 00 05 00 00  Œ... .P. 
  [010] 00 0E 01 00 00 00 00 02  00 92 0D 4E EE C7 0D 98   ...NŒ€..
  [020] 8A 34 38 32 F5 C7 17 DC  82 B5 58 F0 72 A1 C2 4D  .482õ€.š .æXðr­ÂM
  [030] 09 51 64 72 38 80 38 43  44 2A 1C 63 19 5F 2F 96  .Qdr8.8C D*.c._/.
  [040] C3 62 11 84 4A C2 94 E7  42 E1 DF B7 F1 B1 1F 7F  Ãb..JÂ.‡ B áú¤ñ..
  [050] 08 ED DE C2 A3 8B AF 25  9C E6 C4 45 9D 30 88 8D  .¡Þœ.»% .‘ŽE.0..
  [060] 6D 7D 0C 57 09 90 1B 12  45 73 6A F1 09 DF 74 4D  m}.W Esj¤.átM
  [070] 54 8E 61 A1 77 48 A9 25  23 DA 47 C5 9A E9 41 CC  T.a­wH©% #ÚG.‚AÌ
  [080] AE 86 D6 A4 2B 8C 5A 88  AD 38 1F D0 EA C7 36 3E  ½.™±+.Z. í8.Ј€6
  [090] AB 23 09 0F 54 96 68 5A  FC 58 52 FC AB 55 0D 9D  ®#..T.hZ XR®U..
  [0A0] 02 EC B8 FC 1A B3 0D AB  97 14 48 00 8C 59 49 E6  .¸.³.® ..H..YI‘
  [0B0] 1C E3 99 43 89 1D 2E DB  A0 46 FA 11 6B 82 C4 3F  .ã.C...Û ÿF£.k.Ž?
  [0C0] E0 03 DA E7 04 35 DE 31  A0 FB 1A DA 14 BE 48 D3  ….ڇ.5Þ1 ÿ–.Ú.¾HÓ
  [0D0] 74 E3 AF 92 BB F9 24 0A  D3 47 D4 B6 7F BB D6 BE  tã».¯—$. ÓGÔ.¯™¾
  [0E0] 20 D8 A0 BA 7F 86 E2 2C  1A 8B 0A 19 86 A7 E0 98   Øÿ§..ƒ, .….
  [0F0] B4 C8 25 06 AE 61 B3 3C  C2 26 BB 17 FD EA D8 73  ´È%.½a³ ¯.²ˆØs
  [100] CD B6 F7 9A B1 64 7C CF  CA 00 07 25 05 72 69 C2  Íö.ñd|Ï Ê..%.riÂ
  [110] 06 CF 8D C4 78 88 E8 8C  4C C6 0D 5B 0A 54 49 3A  .Ï.Žx.Š. L’.[.TI:
  [120] F9 A6 4E 96 81 5C 27 60  2F 44 06 02 00 20 74 09  —¼N..\'` /D... t.
  [130] 00 77 00 7A 00 FF FF 00  00 7F 2D FB 2C A7 0F 4B  .w.z.˜˜. ..-–,.K
  [140] BE 1C A8 2B 05 F1 20 D7  B5 9F 17 31 1E 97 0D 3C  ¾.¿+.¤ × æ..1...
  [150] EC 
[2003/10/22 14:55:41, 3] smbd/process.c:switch_message(685)
  switch message SMBwriteX (pid 16801)
[2003/10/22 14:55:41, 4] smbd/uid.c:change_to_user(122)
  change_to_user: Skipping user change - already user
[2003/10/22 14:55:41, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1151)
  search for pipe pnum=740f
[2003/10/22 14:55:41, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1155)
  pipe name NETLOGON pnum=740f (pipes_open=2)
[2003/10/22 14:55:41, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1155)
  pipe name NETLOGON pnum=740d (pipes_open=2)
[2003/10/22 14:55:41, 6] rpc_server/srv_pipe_hnd.c:write_to_pipe(852)
  write_to_pipe: 740f name: NETLOGON open: Yes len: 336
[2003/10/22 14:55:41, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
  write_to_pipe: data_left = 336
[2003/10/22 14:55:41, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(778)
  process_incoming_data: Start

RE: [Samba] Clear text authentication impossible???

2003-10-22 Thread Beschorner Daniel
So I'm only the 2nd winner with this bug :-)

Thank you, it works! (got to move the definition of pwhash[16] one line
higher in the patch to compile)

Daniel

-Ursprüngliche Nachricht-
Von: Andrew Bartlett [mailto:[EMAIL PROTECTED]
Gesendet: Donnerstag, 23. Oktober 2003 00:51
An: Jeremy Allison
Cc: Beschorner Daniel; '[EMAIL PROTECTED]'
Betreff: Re: [Samba] Clear text authentication impossible???


On Thu, 2003-10-23 at 05:16, Jeremy Allison wrote:
 On Wed, Oct 22, 2003 at 03:27:31PM +0200, Beschorner Daniel wrote:
  We have an Exchange 5.5 server in our Samba 3 domain und want to have
POP3
  access with clear text authentication from clients.
  But no kind of credentials is accepted.
  
  It did a level 10 log on the Samba server and found my clear text
password
  in the log (in nt_chal_resp and lm_chal_resp fields) during
authentication.
  
  Is it possible that Samba can't handle the clear-text pass-through from
  POP3-Client per Exchange server and takes it for NTLMv2 challenge
 
 Can you post the debug level 10 log please (obfuscate all passwords of
course :-).

I picked this one up at the end of last week.   I never got it into CVS,
because I didn't have the setup to test it.  (And I wanted to clean it
up a bit, we should also handle the 'interactive' login in a similar
way, and possibly 'ascii' passwords against the LM hash).

Thanks to Fabien Chevalier for providing the information that made
fixing this so easy.

Andrew Bartlett

-- 
Andrew Bartlett [EMAIL PROTECTED]
Manager, Authentication Subsystems, Samba Team  [EMAIL PROTECTED]
Student Network Administrator, Hawker College   [EMAIL PROTECTED]
http://samba.org http://build.samba.org http://hawkerc.net
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


AW: [Samba] W2K RAS Server in Samba 3.0.0 Domain

2003-10-12 Thread Beschorner Daniel
I patched samba to always return ACCESS_GRANTED for testing.
So I came to this:

IASSAM.LOG
[556] 23:23:53:671: Inserting attribute msNPAllowDialin.
[556] 23:23:53:671: Successfully retrieved per-user attributes.

Dialin now only fails with Dialin not allowed for user, but I'm not able
to set it in UserMgr.
Is it difficult to map this attribute?

Daniel

-Ursprüngliche Nachricht-
Von: Andrew Bartlett [mailto:[EMAIL PROTECTED]
Gesendet: Samstag, 11. Oktober 2003 02:17
An: Beschorner Daniel
Cc: '[EMAIL PROTECTED]'
Betreff: Re: [Samba] W2K RAS Server in Samba 3.0.0 Domain


On Sat, 2003-10-11 at 02:37, Beschorner Daniel wrote:
 We set up a DialIn W2K SP4 member server in our Samba 3.0.0 domain.
 
 When a client dials in the RAS server complains:
 
 Error 930: The authentication server did not respond to authentication
 requests in a timely fashion. 
 
 
 I tracked down the RAS logfile IASSAM.LOG:
 
 [576] 18:30:34:921: NT-SAM Names handler received request with user
identity
 root.
 [576] 18:30:34:921: Prepending default domain.
 [576] 18:30:34:921: SAM-Account-Name is DOMAIN\root.
 [576] 18:30:34:921: NT-SAM Authentication handler received request for
 DOMAIN\root.
 [576] 18:30:34:921: Processing MS-CHAP v2 authentication.
 [576] 18:30:34:968: LogonUser succeeded.
 [576] 18:30:34:968: NT-SAM User Authorization handler received request for
 DOMAIN\root.
 [576] 18:30:34:968: Using downlevel dial-in parameters.
 [576] 18:30:34:968: DS not installed for domain DOMAIN.
 [576] 18:30:34:968: Connecting to SAM server on \\SERVER.
 [576] 18:30:35:093: Connecting to SAM server on \\SERVER.
 [576] 18:30:35:093: Per-user attribute retrieval failed: Access denied
 
 
 Here a corresponding suspect part of the level 10 smbd.log that breaks
 it?!?
 
 
 [2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:dbg_rw_punival(806)
   0028 buffer : D.O.M.A.I.N.
 [2003/10/10 18:30:37, 4]
 rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
   Found policy hnd[0] [000] 00 00 00 00 02 00 00 00  00 00 00 00 AD DE 86
3F
  ­Þ.?
   [010] 56 50 00 00   VP..
 [2003/10/10 18:30:37, 5]
 rpc_server/srv_samr_nt.c:access_check_samr_function(106)
   _samr_lookup_domain: access check ((granted: 0x0020;  required:
 0x0010)
 [2003/10/10 18:30:37, 2]
 rpc_server/srv_samr_nt.c:access_check_samr_function(115)
   _samr_lookup_domain: ACCESS DENIED (granted: 0x0020;  required:
 0x0010)
 [2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_debug(81)
   00 samr_io_r_lookup_domain
 [2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_uint32(634)
    ptr: 
 [2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_ntstatus(664)
   0004 status: NT_STATUS_ACCESS_DENIED

This looks like a bug to me - can you file it in bugzilla.samba.org - I
was involved in adding the access controls here, and I know there are
issues - we didn't get all the access masks perfect.

However, even when access is permitted, I'm not sure we serve up all the
right attributes anyway...

Andrew Bartlett

-- 
Andrew Bartlett [EMAIL PROTECTED]
Manager, Authentication Subsystems, Samba Team  [EMAIL PROTECTED]
Student Network Administrator, Hawker College   [EMAIL PROTECTED]
http://samba.org http://build.samba.org http://hawkerc.net
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] W2K RAS Server in Samba 3.0.0 Domain

2003-10-10 Thread Beschorner Daniel
We set up a DialIn W2K SP4 member server in our Samba 3.0.0 domain.

When a client dials in the RAS server complains:

Error 930: The authentication server did not respond to authentication
requests in a timely fashion. 


I tracked down the RAS logfile IASSAM.LOG:

[576] 18:30:34:921: NT-SAM Names handler received request with user identity
root.
[576] 18:30:34:921: Prepending default domain.
[576] 18:30:34:921: SAM-Account-Name is DOMAIN\root.
[576] 18:30:34:921: NT-SAM Authentication handler received request for
DOMAIN\root.
[576] 18:30:34:921: Processing MS-CHAP v2 authentication.
[576] 18:30:34:968: LogonUser succeeded.
[576] 18:30:34:968: NT-SAM User Authorization handler received request for
DOMAIN\root.
[576] 18:30:34:968: Using downlevel dial-in parameters.
[576] 18:30:34:968: DS not installed for domain DOMAIN.
[576] 18:30:34:968: Connecting to SAM server on \\SERVER.
[576] 18:30:35:093: Connecting to SAM server on \\SERVER.
[576] 18:30:35:093: Per-user attribute retrieval failed: Access denied


Here a corresponding suspect part of the level 10 smbd.log that breaks
it?!?


[2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:dbg_rw_punival(806)
  0028 buffer : D.O.M.A.I.N.
[2003/10/10 18:30:37, 4]
rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
  Found policy hnd[0] [000] 00 00 00 00 02 00 00 00  00 00 00 00 AD DE 86 3F
 ­Þ.?
  [010] 56 50 00 00   VP..
[2003/10/10 18:30:37, 5]
rpc_server/srv_samr_nt.c:access_check_samr_function(106)
  _samr_lookup_domain: access check ((granted: 0x0020;  required:
0x0010)
[2003/10/10 18:30:37, 2]
rpc_server/srv_samr_nt.c:access_check_samr_function(115)
  _samr_lookup_domain: ACCESS DENIED (granted: 0x0020;  required:
0x0010)
[2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_debug(81)
  00 samr_io_r_lookup_domain
[2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_uint32(634)
   ptr: 
[2003/10/10 18:30:37, 5] rpc_parse/parse_prs.c:prs_ntstatus(664)
  0004 status: NT_STATUS_ACCESS_DENIED

Or is it a configuration problem?
Anyone got this configuration to work???

Thanks
Daniel
--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


Oplock breaks in 2.2.6pre gone

2002-09-11 Thread Beschorner Daniel

It is nice to see that the many daily oplock breaks with W2K in 2.2.6pre
have finally gone away... (at least for me)

Thanks
Daniel



Problem with current 2.2.4-pre

2002-04-23 Thread Beschorner Daniel

Hi,

if 2.2.4 is really at horizon, this bug in current CVS should be fixed.

[2002/04/23 17:01:13, 0] smbd/open.c:open_file(179)
  Error doing fstat on open file kuhnert/NTUSER.DAT.tmp (No such file or
directory)
[2002/04/23 17:01:13, 0] smbd/open.c:open_file(179)
  Error doing fstat on open file kuhnert/ntuser.dat.LOG.tmp (No such file or
directory)

cheers,
Daniel

-Ursprüngliche Nachricht-
Von: Gerald (Jerry) Carter [mailto:[EMAIL PROTECTED]]
Gesendet: Montag, 15. April 2002 19:37
An: Beschorner Daniel
Cc: '[EMAIL PROTECTED]'
Betreff: Re: Problem with current 2.2.4-pre


On Thu, 11 Apr 2002, Beschorner Daniel wrote:

 Hi!
 
 Every time a user logs out from the Samba-PDC and the user profile is
 written to the profile share on the Samba-PDC this error occures on some
 (5-10) files of the profile in the log.
 
 [2002/04/11 09:39:06, 0] smbd/open.c:open_file(179)
   Error doing fstat on open file schnieders/Recent/Glsynt40.lnk (No such
 file or directory)
 
 Seems as the path would be only relative to the profile share, instead
of
 complete.
 





cheers, jerry
 -
 Hewlett-Packard http://www.hp.com
 SAMBA Team   http://www.samba.org
 --http://www.plainjoe.org
 Sam's Teach Yourself Samba in 24 Hours 2ed.  ISBN 0-672-32269-2
 --I never saved anything for the swim back. Ethan Hawk in Gattaca--




Problem with current 2.2.4-pre

2002-04-11 Thread Beschorner Daniel

Hi!

Every time a user logs out from the Samba-PDC and the user profile is
written to the profile share on the Samba-PDC this error occures on some
(5-10) files of the profile in the log.

[2002/04/11 09:39:06, 0] smbd/open.c:open_file(179)
  Error doing fstat on open file schnieders/Recent/Glsynt40.lnk (No such
file or directory)

Seems as the path would be only relative to the profile share, instead of
complete.

BTW, I got sometimes

[2002/04/11 11:07:08, 0] smbd/service.c:set_current_service(59)
  chdir (/home/schnieders) failed

but the directory should be so far OK, what could it be?

Regards
Daniel Beschorner