Re: [Samba] Winbind problem revisited

2004-12-22 Thread Luke Mewburn
On Tue, Dec 21, 2004 at 01:49:46PM -0600, Brian Kesting wrote: | ---/etc/nsswitch.conf- | | passwd: compat winbind | group: files dns compat winbind | shadow: files winbind [digression about nsswitch] On various nsswitch implementations (including the

Re: [Samba] Winbind + NIS + winbind trusted domains

2004-12-15 Thread Luke Mewburn
On Wed, Dec 15, 2004 at 11:36:38AM +0100, Christoph Scheeder wrote: | Hi, | that behavior is logical correct, i would say. | What happens is: | the user is found from nis, and gets an userid not from the winbind-range. | As a result samba is not able to verify this uid against the AD, as

Re: [Samba] Winbind + NIS + winbind trusted domains

2004-12-15 Thread Luke Mewburn
On Wed, Dec 15, 2004 at 10:14:12AM -, Plant, Dean wrote: | I need to setup a samba file server with user access from a Windows AD | domain and a separate Solaris NIS domain. All of our users have an account | on the AD domain but only some of our users have a Unix account. I would |

Re: [Samba] Re: winbind: authenticating UNIX user before Win Domain user

2004-11-19 Thread Luke Mewburn
On Thu, Nov 18, 2004 at 10:49:39AM -0800, Matt Seitz wrote: | Luke Mewburn wrote: | I have the same requirement; except samba can't currently do this. See: | http://lists.samba.org/archive/samba/2004-October/094981.html | | I implemented a trim default domain option and provided

Re: [Samba] winbind: authenticating UNIX user before Win Domain user

2004-11-17 Thread Luke Mewburn
On Wed, Nov 17, 2004 at 03:48:06PM -0500, Greg Chavez wrote: | We have a samba 3.0.7 server on RHEL-3 (rain) joined as a domain | member (security = domain) to a win2k pdc (clouds) for the domain DOM. | We have several unix users and two Win-only users. The unix users | have matching AD

Re: [Samba] Unable to join AD (FreeBSD)

2004-11-09 Thread Luke Mewburn
On Tue, Nov 09, 2004 at 04:46:40PM -0500, Josh Kropf wrote: | I am trying to get samba 3.0.7 working with our win2k DC. I installed samba | from the ports collection, so the kerberos library looks to be the heimdel | version. Which version of FreeBSD ? Which version of heimdal ? Are you

Re: [Samba] winbind name service required for active directory (ADS) authentication and group-based authorization?

2004-10-29 Thread Luke Mewburn
On Fri, Oct 29, 2004 at 09:16:02AM -0700, DeStefano, Paul wrote: | Solution: ADS, perhaps? | | I've read lots of documents and they seem to indicated | that, when using ADS authentication (by which I mean | security=ADS and the proper relm, etc.) winbind is NOT | involved in the

Re: [Samba] winbind: using idmap only if user doesn't exist in UNIX getpw*(3) ?

2004-10-27 Thread Luke Mewburn
On Wed, Oct 27, 2004 at 01:23:43PM -0500, Gerald (Jerry) Carter wrote: | On Wed, 27 Oct 2004, Luke Mewburn wrote: | | I have a requirement to use winbind to allocate UID/GIDs for | users but only if they aren't in the non-winbind nsswitch sources. | | I have had no succes so far

[Samba] winbind: using idmap only if user doesn't exist in UNIX getpw*(3) ?

2004-10-26 Thread Luke Mewburn
Greetings all. I have a requirement to use winbind to allocate UID/GIDs for users but only if they aren't in the non-winbind nsswitch sources. I.e, given smb.conf; samba 3.0.7 realm = DOMAIN workgroup = DOMAIN log level = 3 idmap:10 winbind:10 idmap gid =

Re: [Samba] Problem Enumerating AD users

2004-10-24 Thread Luke Mewburn
On Sat, Oct 23, 2004 at 04:45:41PM +0100, George Trigg wrote: | However when doing a getent passwd I am only returned the local unix users | and I get the following error in the syslog. | | Oct 23 16:23:40 ecto winbindd[2089]: [2004/10/23 16:23:40, 0] |

Re: map_username() inconsistencies [was Re: [Samba] Re: ADS valid users can't map share]

2004-10-21 Thread Luke Mewburn
On Wed, Oct 20, 2004 at 09:21:09PM -0500, Gerald (Jerry) Carter wrote: | I've done some more digging and the username map stuff is a little | worse than I initially thought. | | (a) when 'security = user', the username map is applied before | the password is checked is checked. |

Re: [Samba] Winbindd on FreeBSD 4.10 Help

2004-09-28 Thread Luke Mewburn
On Thu, Sep 23, 2004 at 08:53:22AM -0400, Elijah Savage wrote: | When I installed this box I specifically installed it for this task and | installed linux compatibilty during intstall, the /etc/nsswitch.conf was | created and everything. I can join my AD domain as NT4 style but not | with

Re: [Samba] Winbindd on FreeBSD 4.10 Help

2004-09-23 Thread Luke Mewburn
On Thu, Sep 23, 2004 at 07:45:57AM -0400, Elijah Savage wrote: | Even with linux compatibilty installed it has no nsswitch support? I | thought if you installed linux compatibilty then nsswitch support works. Oh, right; binaries within the Linux compat heirarchy should probably work if the

Re: [Samba] Winbindd on FreeBSD 4.10 Help

2004-09-22 Thread Luke Mewburn
On Wed, Sep 22, 2004 at 03:30:35PM -0400, Elijah Savage wrote: | Yes I did edit the nsswitch.conf just as you have it which looks just | like the way it does in the book. FreeBSD 4.10 doesn't appear to have nsswitch support, at least on the version I have installed under VMware. FreeBSD 5.x