RE: [Samba] File Creation Error on an SMB Volume

2004-11-29 Thread Toby Schaefer


-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of Matthias Heckmann
Sent: Wednesday, November 24, 2004 10:44 AM
To: '[EMAIL PROTECTED]'
Subject: [Samba] File Creation Error on an SMB Volume

Hi folks,
My SMB server is a Helios Ethershare 3.1 on a Tru64 Alpha machine.
We are now integrating more and more gentoo-Linux Servers. These are the
SMB Clients. 

On Obelix (one of our gentoo-Servers) I can mount the SMB Volume from the
Ethershare Server.
obelix nc4smb # whoami
root
obelix # mount -t smbfs -o username=m.heckmann //192.9.100.32/MIB_Pat_01
/mnt/nc4smb

i can also:
obelix # cd /mnt/nc4smb
obelix nc4smb # ls -al
total 44
drwxr-xr-x  1 root root  4096 Nov 23 10:20 .
drwxr-xr-x  5 root root   144 Nov 23 10:19 ..
-rwxr--r--  1 root root 20183 Oct  6 14:32 excuses
-rwxr--r--  1 root root  5011 Apr 15  2002 java.jpg
drwxr-xr-x  1 root root  4096 Nov 23 10:32 layouts
-rwxr--r--  1 root root99 Nov 23  2004 todo.txt
-rwxr--r--  1 root root 10560 Nov 16  2001 tomcatlogo.jpg
obelix nc4smb # cat todo.txt
TODO

- hover the garden
- make sandwich
- brush my teeth
- kidnap my neighbours dog

obelix nc4smb # echo - grease my bikes chain  todo.txt 
obelix nc4smb # cat todo.txt 
TODO

- hover the garden
- make sandwich
- brush my teeth
- kidnap my neighbours dog
- grease my bikes chainobelix nc4smb # 

but:
obelix nc4smb # echo i want to create a file  new.txt
-bash: new.txt: Input/output error

also: 
obelix nc4smb # cp /tmp/cptofile.txt /mnt/nc4smb/
cp: cannot create regular file `/mnt/nc4smb/cptofile.txt': Input/output
error


So you see the problem. 
Can mount, can read can write to an existing file.
But _Cant_ create a file.
By the way: On the Helios Ethershare Server i did:
chmod -R 777 /data/MIB_Pat_01 (which is the smb share)
but the ls -al on obelix shows -rwxr--r--

further Infos:
obelix nc4smb # uname -a 
Linux obelix 2.6.9-gentoo-r1 #1 SMP Wed Nov 3 15:27:32 CET 2004 i686
Intel(R) Xeon(TM) CPU 3.06GHz GenuineIntel GNU/Linux

obelix nc4smb # smbstatus 
Samba version 3.0.7

obelix nc4smb # cat /etc/samba/smb.conf
[global]
workgroup = ncag 
server string = 
show add printer wizard = no
local master = no
domain master = no
preferred master = no
os level = 0

[just_a_few_shares]
.
.
.
.
 

My Windoze has no problem with this share, everything works fine.
Tell me what additional infos you need to get along the problem.
I have everything. Debug outputs, ethereal caps (window$ connect,create.
successing. / linux mount,create. failing. ).
 
Thanks for your help, in advance.
I would really welcome a solution for this.
It is a crucial criterion for the future of LiNUX in our company. ;-)
 
Matthias Heckmann

 
-
Matthias Heckmann
Systemadministrator
n c ag 
In der Luberzen 25 
8902 Urdorf 
-
t:+41 1 735 38 38 
t dir:+41 1 735 38 10  
-
Web:  www.ncag.ch 
E-mail:[EMAIL PROTECTED] 
-
 

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba



Unfortunetely, I can not say that I have found the solution to this problem
yet, but I can say that I am experiencing it over multiple samba versions
(including RPMs) on Tao Linux 1.0u3 (RHEL3 clone). I'd add more information,
but Mr. Heckmann did a very through job of explaining the problem in detail.
I am currently having the problem with samba-3.0.7-1.3E.1; however, it has
happened for 3 or 4 RPM updates (and reinstalls) as well as custom compiled
versions as well... All the exact same problems.  Any help would be
appreciated!

Toby Schaefer


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Windows access to samba share

2004-03-03 Thread Toby Schaefer


-|-Original Message-
-|From: [EMAIL PROTECTED]
-|[mailto:[EMAIL PROTECTED] On
-|Behalf Of Mike Westkamper
-|Sent: Wednesday, March 03, 2004 4:41 PM
-|To: SAMBA
-|Subject: [Samba] Windows access to samba share
-|
-|
-|I am new to the list so my problem is likely redundant.
-|
-|I am using Samba on a remote Linux system to offer Windows clients access
-|to
-|data being collected by a real-time system. The real-time data collection
-|systems are built on the RH 8 Linux distribution. I also have one that was
-|built using the RH Fedora Core 1 distribution. The data collection
-|software
-|runs as root (yes I do know its not the best way but for a number of
-|reasons
-|it is most convenient and the system ONLY runs the one application).
-|
-|This system is an isolated subnet with only 6 boxes, 5 are Linux data
-|collection systems and the 6th is a Windows 2000 GUI box.
-|
-|The problem arises when Windows client try's to access the data. It gets
-|an
-|Access Denied message.
-|
-|From the default smb.conf - the following are my changes from the
-|default...
-|
-|workgroup = WORKGROUP
-|
-|hosts allow = 192.168.1. 127.
-|
-|security = share
-|
-|[filestore]
-|comment = Digital Data Files
-|path = /filestore
-|public = yes
-|writable = yes
-|create mask = 0777
-|directory mode = 0777
-|
-|I am not a Linux guru, however is do have some experience with both Samba
-|and Linux.
-|
-|Any help will be greatly appreciated.
-|
-|Mike
-|
-|This message is private and contains confidential information intended
-|only
-|for the use of the recipient(s). If you have received this e-mail in error
-|and are not the intended recipient you must not disclose, copy or
-|distribute
-|it to anyone else. Please advise the sender immediately,
-|[EMAIL PROTECTED], and delete this email and all attachments.
-|
-|--
-|To unsubscribe from this list go to the following URL and read the
-|instructions:  http://lists.samba.org/mailman/listinfo/samba


Two things immediately come to mind:

1.  Make sure that you have created a user for the person logging in (both
in Linux and Samba)

2.  Make sure that the user that you created has linux access to the files.
(If the files are -rw-rw and that users doesn't belong to the same group
as the group on the file, samba will give an access denied.)

The big 'kicker' when learning the basics of samba/linux interaction is that
you always need to check the permissions on the base shared directory as
well -  I've found that linux permissions account for about 50% of the
'basic' samba problems that I've seen, and it's easy to overlook.

Cheers,

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Re: school PDC questions

2004-02-09 Thread Toby Schaefer


-|-Original Message-
-|From: [EMAIL PROTECTED]
-|[mailto:[EMAIL PROTECTED] On
-|Behalf Of Ivo Dancet
-|Sent: Monday, February 09, 2004 12:06 PM
-|To: [EMAIL PROTECTED]
-|Subject: [Samba] Re: school PDC questions
-|
-|sorry, I was convinced I had added I would have to support 100 pc's
-|(maybe 150 in the future).
-|
-|Are there any apps that make the task of adding users in bulk simple?
-|
-|--
-|To unsubscribe from this list go to the following URL and read the
-|instructions:  http://lists.samba.org/mailman/listinfo/samba

We are using Samba 3 / OpenLDAP at our district and are using LAM (LDAP
Account Manager) for 'counselor access';  It's easy to learn and teach,
although a linux workstation with GQ or another LDAP editor sometimes will
work a bit better. LAM supports mass adds through importing files, though we
have not used this functionality yet.

Lan is available at http://lam.sf.net

Cheers,

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] roaming profiles...

2004-01-08 Thread Toby Schaefer


-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of kent E.
Sent: Thursday, January 08, 2004 4:20 AM
To: samba
Subject: [Samba] roaming profiles...

hey guys i want to hear your experience regarding this situation

got this one user who store lots of big chunk files in his My
Documents folder now as she logs out ... it took us several minutes for
us to be able to shut down...

how to take care of this? can i select which to include in the roaming
files ...

TIA
Kent

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba
-


You can select what *directories* not to back up via NT4 policies.  Get
poledit.exe from an NT server and make a policy that states not to back up
whichever directories you want.. I suggest at the bare minimum Temp and
Temporary Internet Files.  In your case you may want to say My Documents\Big
Files or something similar.

Cheers,
Toby

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] User Management / Samba 3.0.1 LDAP / USERMGR.EXE problems

2004-01-06 Thread Toby Schaefer
Hello,
 
  I'm using Samba 3.0.1 with LDAP backend running as a PDC here.  When I
start up usrmgr.exe from Windows NT, it will read all the users (or
computers, for srvmgr.exe) in the domain and report them back correctly.
However, whomever I am logged in as ( including gid 512 users) it will not
let me see details or change anything.  In the logs after trying to view a
users details I will get (hand typed from across the room, so forgive the
lack of log lines):
 
rpc_server/src_samr_nt.c:access_check_samr_object(93) _samr_open_user:
ACCESS DENIED (requested: 0x00601bf)
 
Before that it does access  checks se_access_check  of different SID
variations, ending in also S-1-5-21-...-512.
Does anyone have any idea why it is not enabling me to use the usrmgr.exe to
manage users?  The scripts work great as far as I am concerned, but with the
school I work for enrolling new students soon, I need a counselor level
tool that they can do simple tasks with. :)  If not, does anyone have any
recommendations for other gui / cheesy user management that will run on
windows?
 
Thanks in advance!
 
Toby Schaefer
 
 
 
 
 
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Samba 3 PDC with LDAP - Error when changing userpasswordfrom windows

2003-12-18 Thread Toby Schaefer
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of [EMAIL PROTECTED]
Sent: Thursday, December 18, 2003 11:38 AM
To: Craig White
Cc: [EMAIL PROTECTED]
Subject: Re: [Samba] Samba 3 PDC with LDAP - Error when changing
userpasswordfrom windows

here my passwd chat log (sorry, it's long): 
 
-BEGIN- 
[2003/12/18 18:33:31, 3] smbd/chgpasswd.c:chat_with_program(419) 
  Dochild for user jchomarat3 (uid=0,gid=0) (as_root = Yes) 
[2003/12/18 18:33:31, 10] smbd/chgpasswd.c:dochild(217) 
  Invoking '/usr/local/sbin/smbldap-passwd.pl -o jchomarat3' as password
change 
program. 
[2003/12/18 18:33:32, 10] lib/util_sock.c:read_socket_with_timeout(263) 
  read_socket_with_timeout: timeout read. select timed out. 
[2003/12/18 18:33:32, 100] smbd/chgpasswd.c:expect(271) 
  expect: expected [*New*password*] received [Changing password for
jchomarat3 
  New password : ] match yes 
[2003/12/18 18:33:32, 10] smbd/chgpasswd.c:expect(282) 
  expect: returning True 


 [2003/12/18 18:33:32, 11] passdb/pdb_get_set.c:pdb_get_init_flags(189) 
  element 19: SET 
[2003/12/18 18:33:32, 11] lib/smbldap.c:smbldap_open(820) 
  smbldap_open: already connected to the LDAP server 
[2003/12/18 18:33:32, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1173) 
  ldapsam_modify_entry: Failed to modify user dn=
uid=jchomarat3,ou=People,dc=ph 
onambule-tv,dc=com with: Type or value exists 
modify/add: sambaLMPassword: value #0 already exists 
[2003/12/18 18:33:32, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1366) 
  ldapsam_update_sam_account: failed to modify user with uid = jchomarat3,
error 
: modify/add: sambaLMPassword: value #0 already exists (Success) 
[2003/12/18 18:33:32, 3] smbd/sec_ctx.c:pop_sec_ctx(386) 
  pop_sec_ctx (1003, 512) - sec_ctx_stack_ndx = 1 
[2003/12/18 18:33:32, 5]
rpc_parse/parse_samr.c:init_samr_r_chgpasswd_user(7177) 
  init_r_chgpasswd_user 
[2003/12/18 18:33:32, 5] rpc_server/srv_samr_nt.c:_samr_chgpasswd_user(1553)

  _samr_chgpasswd_user: 1553 
[2003/12/18 18:33:32, 5] rpc_parse/parse_prs.c:prs_debug(81) 
  00 samr_io_r_chgpasswd_user 
[2003/12/18 18:33:32, 5] rpc_parse/parse_prs.c:prs_ntstatus(664) 
   status: NT_STATUS_ACCESS_DENIED 
--END- 



From what it looks like, you are most likely setup correctly... A few
questions:

1. In your smb.conf, is pw change as such:

passwd chat debug = Yes
passwd program =/usr/local/bin/smbldap-passwd.pl -o %u
passwd chat = *new*password* %n\n *new*password:* %n\ *successfully*

(I'm guessing it is due to your logs showing it correctly.)

2. It seems that it's dying trying to open a second connection to your LDAP
server that it isn't closing.  Have you the latest smbldap-tools (the ones
that came with Samba3?), and have you modified them at all.

3. You may want to do a test - It seems to not be updating all your tokens
correctly.  To test this, make a note of what the sambaLMPassword is, then
try to change the password.  See if this value changes.  If it doesn't, then
it's going to get rather confusing having multiple hashes!

4.  Finally, has the password chat ever worked over there?  It's working in
our domain beautifully; however, YMMV. :)  If it has never worked correctly,
I'd at this point look to make sure your schema is correct and that somehow
the sambaLMPassword portion didn't get hosed during setup.

Cheers,

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Samba 3 PDC with LDAP - Error when changing userpasswordfrom windows

2003-12-18 Thread Toby Schaefer
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of [EMAIL PROTECTED]
Sent: Thursday, December 18, 2003 11:38 AM
To: Craig White
Cc: [EMAIL PROTECTED]
Subject: Re: [Samba] Samba 3 PDC with LDAP - Error when changing
userpasswordfrom windows

here my passwd chat log (sorry, it's long): 
 
-BEGIN- 
[2003/12/18 18:33:31, 3] smbd/chgpasswd.c:chat_with_program(419) 
  Dochild for user jchomarat3 (uid=0,gid=0) (as_root = Yes) 
[2003/12/18 18:33:31, 10] smbd/chgpasswd.c:dochild(217) 
  Invoking '/usr/local/sbin/smbldap-passwd.pl -o jchomarat3' as password
change 
program. 
[2003/12/18 18:33:32, 10] lib/util_sock.c:read_socket_with_timeout(263) 
  read_socket_with_timeout: timeout read. select timed out. 
[2003/12/18 18:33:32, 100] smbd/chgpasswd.c:expect(271) 
  expect: expected [*New*password*] received [Changing password for
jchomarat3 
  New password : ] match yes 
[2003/12/18 18:33:32, 10] smbd/chgpasswd.c:expect(282) 
  expect: returning True 


 [2003/12/18 18:33:32, 11] passdb/pdb_get_set.c:pdb_get_init_flags(189) 
  element 19: SET 
[2003/12/18 18:33:32, 11] lib/smbldap.c:smbldap_open(820) 
  smbldap_open: already connected to the LDAP server 
[2003/12/18 18:33:32, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1173) 
  ldapsam_modify_entry: Failed to modify user dn=
uid=jchomarat3,ou=People,dc=ph 
onambule-tv,dc=com with: Type or value exists 
modify/add: sambaLMPassword: value #0 already exists 
[2003/12/18 18:33:32, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1366) 
  ldapsam_update_sam_account: failed to modify user with uid = jchomarat3,
error 
: modify/add: sambaLMPassword: value #0 already exists (Success) 
[2003/12/18 18:33:32, 3] smbd/sec_ctx.c:pop_sec_ctx(386) 
  pop_sec_ctx (1003, 512) - sec_ctx_stack_ndx = 1 
[2003/12/18 18:33:32, 5]
rpc_parse/parse_samr.c:init_samr_r_chgpasswd_user(7177) 
  init_r_chgpasswd_user 
[2003/12/18 18:33:32, 5] rpc_server/srv_samr_nt.c:_samr_chgpasswd_user(1553)

  _samr_chgpasswd_user: 1553 
[2003/12/18 18:33:32, 5] rpc_parse/parse_prs.c:prs_debug(81) 
  00 samr_io_r_chgpasswd_user 
[2003/12/18 18:33:32, 5] rpc_parse/parse_prs.c:prs_ntstatus(664) 
   status: NT_STATUS_ACCESS_DENIED 
--END- 



From what it looks like, you are most likely setup correctly... A few
questions:

1. In your smb.conf, is pw change as such:

passwd chat debug = Yes
passwd program =/usr/local/bin/smbldap-passwd.pl -o %u
passwd chat = *new*password* %n\n *new*password:* %n\ *successfully*

(I'm guessing it is due to your logs showing it correctly.)

2. It seems that it's dying trying to open a second connection to your LDAP
server that it isn't closing.  Have you the latest smbldap-tools (the ones
that came with Samba3?), and have you modified them at all.

3. You may want to do a test - It seems to not be updating all your tokens
correctly.  To test this, make a note of what the sambaLMPassword is, then
try to change the password.  See if this value changes.  If it doesn't, then
it's going to get rather confusing having multiple hashes!

4.  Finally, has the password chat ever worked over there?  It's working in
our domain beautifully; however, YMMV. :)  If it has never worked correctly,
I'd at this point look to make sure your schema is correct and that somehow
the sambaLMPassword portion didn't get hosed during setup.

Cheers,

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Samba 3 PDC with LDAP - Error when changinguserpasswordfrom windows

2003-12-18 Thread Toby Schaefer
 to help support his work, and simply because it's an
excellent samba reference.

Also, if you are looking for a good step-by-step for setting up Samba3 with
LDAP, Carl Weiss has made an excellent how-to for Samba3 setup with OpenLDAP
backend on RedHat 9.  It is available at
http://ninja.carlweiss.com:81/Samba3-redhat9-openldap.html .

Both are excellent references, Mr. Weiss's is a darn near
keystroke-by-keystroke method.

|e) In log, I saw that when a user under WinXP open a session on the domain,
|Samba search for a guest, nobody group or user in LDAP and after, it
|connects with Manager (my LDAP admin) and do the authentication process,
|why
|is it searching guest or nobody?

|Thank you very much for your help and advice!
|Sebastion Jousse.

I would have to see what you are trying to do exactly in the log files.  As
far as why samba uses permissions internally -- I'm sure that Jerry Carter
or some of the really knowledgeable people out there can explain it, I could
hazard a guess, but it would be safe to say in general:  That's how they
made it work with M$'s products.



- Original Message - 
From: Toby Schaefer [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Thursday, December 18, 2003 6:57 PM
Subject: RE: [Samba] Samba 3 PDC with LDAP - Error when
changinguserpasswordfrom windows


 From what it looks like, you are most likely setup correctly... A few
 questions:

 1. In your smb.conf, is pw change as such:

 passwd chat debug = Yes
 passwd program =/usr/local/bin/smbldap-passwd.pl -o %u
 passwd chat = *new*password* %n\n *new*password:* %n\ *successfully*

 (I'm guessing it is due to your logs showing it correctly.)

 2. It seems that it's dying trying to open a second connection to your
LDAP
 server that it isn't closing.  Have you the latest smbldap-tools (the ones
 that came with Samba3?), and have you modified them at all.

 3. You may want to do a test - It seems to not be updating all your tokens
 correctly.  To test this, make a note of what the sambaLMPassword is, then
 try to change the password.  See if this value changes.  If it doesn't,
then
 it's going to get rather confusing having multiple hashes!

 4.  Finally, has the password chat ever worked over there?  It's working
in
 our domain beautifully; however, YMMV. :)  If it has never worked
correctly,
 I'd at this point look to make sure your schema is correct and that
somehow
 the sambaLMPassword portion didn't get hosed during setup.

 Cheers,

 Toby Schaefer

-- Sorry to annoy, but for clarity comments are posting in-line. 

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


FW: [Samba] Samba 3 PDC with LDAP - Error when changinguserpasswordfrom windows

2003-12-18 Thread Toby Schaefer
 to help support his work, and simply because it's an
excellent samba reference.

Also, if you are looking for a good step-by-step for setting up Samba3 with
LDAP, Carl Weiss has made an excellent how-to for Samba3 setup with OpenLDAP
backend on RedHat 9.  It is available at
http://ninja.carlweiss.com:81/Samba3-redhat9-openldap.html .

Both are excellent references, Mr. Weiss's is a darn near
keystroke-by-keystroke method.

|e) In log, I saw that when a user under WinXP open a session on the domain,
|Samba search for a guest, nobody group or user in LDAP and after, it
|connects with Manager (my LDAP admin) and do the authentication process,
|why
|is it searching guest or nobody?

|Thank you very much for your help and advice!
|Sebastion Jousse.

I would have to see what you are trying to do exactly in the log files.  As
far as why samba uses permissions internally -- I'm sure that Jerry Carter
or some of the really knowledgeable people out there can explain it, I could
hazard a guess, but it would be safe to say in general:  That's how they
made it work with M$'s products.



- Original Message - 
From: Toby Schaefer [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Thursday, December 18, 2003 6:57 PM
Subject: RE: [Samba] Samba 3 PDC with LDAP - Error when
changinguserpasswordfrom windows


 From what it looks like, you are most likely setup correctly... A few
 questions:

 1. In your smb.conf, is pw change as such:

 passwd chat debug = Yes
 passwd program =/usr/local/bin/smbldap-passwd.pl -o %u
 passwd chat = *new*password* %n\n *new*password:* %n\ *successfully*

 (I'm guessing it is due to your logs showing it correctly.)

 2. It seems that it's dying trying to open a second connection to your
LDAP
 server that it isn't closing.  Have you the latest smbldap-tools (the ones
 that came with Samba3?), and have you modified them at all.

 3. You may want to do a test - It seems to not be updating all your tokens
 correctly.  To test this, make a note of what the sambaLMPassword is, then
 try to change the password.  See if this value changes.  If it doesn't,
then
 it's going to get rather confusing having multiple hashes!

 4.  Finally, has the password chat ever worked over there?  It's working
in
 our domain beautifully; however, YMMV. :)  If it has never worked
correctly,
 I'd at this point look to make sure your schema is correct and that
somehow
 the sambaLMPassword portion didn't get hosed during setup.

 Cheers,

 Toby Schaefer

-- Sorry to annoy, but for clarity comments are posting in-line. 

Toby Schaefer

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] usrmgr.exe problems / samba3.0.1 LDAP

2003-12-18 Thread Toby Schaefer
Hello,

  I'm using Samba 3.0.1 with LDAP backend running as a PDC here.  When I
start up usrmgr.exe from Windows NT, it will read all the users (or
computers, for srvmgr.exe) in the domain and report them back correctly.
However, whomever I am logged in as ( including gid 512 users) it will not
let me see details or change anything.  In the logs after trying to view a
users details I will get (hand typed from across the room, so forgive the
lack of log lines):

rpc_server/src_samr_nt.c:access_check_samr_object(93) _samr_open_user:
ACCESS DENIED (requested: 0x00601bf)

Before that it does access  checks se_access_check  of different SID
variations, ending in also S-1-5-21-...-512.
Does anyone have any idea why it is not enabling me to use the usrmgr.exe to
manage users?  The scripts work great as far as I am concerned, but with the
school I work for enrolling new students soon, I need a counselor level
tool that they can do simple tasks with. :)  If not, does anyone have any
recommendations for other gui / cheesy user management that will run on
windows?

Thanks in advance!

Toby Schaefer









-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


[Samba] cross vlan browsing / domain authentication

2003-12-12 Thread Toby Schaefer
Greetings!

  I've been on the list for some time, and have recently deployed a samba
3.0.0 server / LDAP backend in order to provide domain authentication and
roaming profiles.  One question that I have is, when vlans are used, what is
the best way to propagate the server across them?  If I turn on WINS and use
my dhcp server to give the wins information, all the NetBIOS information
will flow freely - however, at a school system, the vlans are in place to
keep the students from seeing the teacher machines (The see no evil effect).
The other way that I know to do this is the lmhosts import on the client
machines, and this works nicely but is another step to repeat 1500 times. MS
Spams our DDNS with a lot of AD stuff, _ldap_tcp, _kerebos, etc, but samba
does not. 

So, what's the 'preferred' method for announcing the server and hiding the
clients cross-subnet?  Can we statically add the Samba server with the
_ldap, _kerebos, and other SRV listings into our DNS [and it work], or
should the lmhosts be the best solution.  I'm open to suggestions and ready
to really test this beast out!

Cheers,

Toby Schaefer
Nixa R-II School District




-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba