[Samba] fw: hi

2013-05-13 Thread ray klassen


 http://www.thamesbd.com/ljidvelmy.php 















  















 



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] SAMBA implementation for DOS ?

2013-05-08 Thread ray klassen
Memory usage is the reason (imho) that Novell was king in the dos era. The 
lanman client was just too huge even running on NETBEUI. Add to that a TCP/IP 
stack and in DOS terms you have a 200 to 300 K behemoth. 

I just googled linux clipper compiler. Have you tried 'Clip?' Looks like it 
might fill the bill and then you wouldn't be stuck with the limitations of DOS




- Original Message -
From: czezz cz...@o2.pl
To: samba@lists.samba.org; Neal Murphy neal.p.mur...@alum.wpi.edu; 
sa...@jubileegroup.co.uk; Marc Muehlfeld sa...@marc-muehlfeld.de
Cc: 
Sent: Wednesday, 8 May 2013, 0:50
Subject: Re: [Samba] SAMBA implementation for DOS ?

Hi,
thank you all for answers.
 
@Ged and Neal,
yes - I considered using DOSBox and/or DOSEMU. This is solution that I will 
keep away from.
The true is that with DOSBox I dont even need to care about network 
configuration and there is enough memory to run required application.
The thing is that my Clipper/dBase application is located on Linux server and 
shared with SAMBA.
8 nodes (PCs/workstations) are connected to that share. If I use DOSbox, then 
DOSbox node will always overwrite its changes over dBase/database. Which will 
erase changes done by other nodes. 
 
VirtualBox: as I have written - I have 8 nodes (PCs/workstations). Each of them 
needs to communicate to Linux/Samba server where application is shared. DOS 
must have samba client. VB wont help that way.
However I do my tests with FreeDOS inside of VirtualBox.
 
@Marc - yes, Im playing around that.
So far, on the FreeDOS I have managed to get 485KB of free conventional memory. 
Application I need to run requires little bit above 500KB.
MS Client take most of it... nightmare :(
 
One last chance might be NFS client for DOS...
But I was just hoping that there is some old/discontinued Samba project for DOS.
 
BR,
czezz
Dnia 8 maja 2013 0:18 Neal Murphy lt;neal.p.mur...@alum.wpi.edugt; napisał(a):
On Tuesday, May 07, 2013 05:57:13 PM G.W. Haywood wrote:
gt; Hi there,
gt; 
gt; On Tue, 7 May 2013 czezz wrote:
gt; gt; I use FreeDOS with MS Client to map a network drive. However MS
gt; gt; Client is a memory hog and prevents me to run all applications I
gt; gt; need. Therefore I would like to ask here is there SAMBA
gt; gt; implementation for DOS ?
gt; 
gt; Have you considered using DOSBox on a Linux machine? Then you can do
gt; whatever you want with drives, mapping, NAS, or whatever. I use it a
gt; lot for an old application that I wrote over twenty years ago, it does
gt; everything that I need.
gt; 
gt; Alternatively you could try VirtualBox, which will let you do similar
gt; things with drives but I don't know how flexible it is.
To extend this concept a little, mayhap czezz could run each DOS app in a 
separate VM or separate DOSBox. Then he wouldn't need to worry about RAM.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba 
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Re: [Samba] LDAP recommendations please

2013-02-22 Thread ray klassen
Touche. Although my goal is replication, not proxying.



- Original Message -
From: Adam Tauno Williams awill...@whitemice.org
To: samba@lists.samba.org
Cc: 
Sent: Thursday, 21 February 2013, 11:59
Subject: Re: [Samba] LDAP recommendations please

On Thu, 2013-02-21 at 16:36 +, ray klassen wrote:
 Actually I was hoping to use the new internal LDAP as the master.
 I notice that 
 http://www.windowsitpro.com/content1/topic/integrate-active-directory-and-openldap-98449/catpath/ldap
 has an article on using slapd as a proxy to Active Directory.
 This one loks even better. Never used 389Server but there's a first time for 
 everything
 http://www.linuxmail.info/ad-fds-sync-howto/
 (I did google this before I asked the question, but I was searching for 
 samba4 ldap, not active directory ldap. 
 I hope samba4 AD is that similar that I can pull similar stunts to the ones 
 described)
 Upgrading to AD requires that you use our internal LDAP backend.
 https://wiki.samba.org/index.php/Samba4/FAQ

stop with the googling, and just look at the docs.
  https://wiki.samba.org/index.php/Samba4/beyond
  The wiki has an openLDAP proxy to AD section.


-- 
Adam Tauno Williams  GPG D95ED383
Systems Administrator, Python Developer, LPI / NCLA

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] LDAP recommendations please

2013-02-21 Thread ray klassen
Actually I was hoping to use the new internal LDAP as the master.


I notice that 
http://www.windowsitpro.com/content1/topic/integrate-active-directory-and-openldap-98449/catpath/ldap
has an article on using slapd as a proxy to Active Directory.

This one looks even better. Never used 389Server but there's a first time for 
everything
http://www.linuxmail.info/ad-fds-sync-howto/

(I did google this before I asked the question, but I was searching for samba4 
ldap, not active directory ldap. 
I hope samba4 AD is that similar that I can pull similar stunts to the ones 
described)



- Original Message -
From: Andrew Bartlett abart...@samba.org
To: ray klassen julius_ahenobar...@yahoo.co.uk
Cc: samba@lists.samba.org samba@lists.samba.org
Sent: Thursday, 21 February 2013, 0:51
Subject: Re: [Samba] LDAP recommendations please

On Wed, 2013-02-20 at 20:50 +, ray klassen wrote:
 Currently I have a samba 3 domain setup with an LDAP backend. It's been very 
 convenient and fault tolerant for me to put read-only replicas of the ldap 
 database on all servers that use LDAP authentication. I'd like to keep doing 
 that after switching to samba 4. Can that be done?

Yes, it can.  However, it will remain a 'classic' domain controller, and
not be an AD domain controller.

Upgrading to AD requires that you use our internal LDAP backend.

https://wiki.samba.org/index.php/Samba4/FAQ

Sorry,

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team          http://samba.org
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] LDAP recommendations please

2013-02-20 Thread ray klassen
Currently I have a samba 3 domain setup with an LDAP backend. It's been very 
convenient and fault tolerant for me to put read-only replicas of the ldap 
database on all servers that use LDAP authentication. I'd like to keep doing 
that after switching to samba 4. Can that be done?
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] work-around on ipv6 samba 4 internal dns

2013-02-08 Thread ray klassen
you can disable ipv6 at a machine level

echo net.ipv6.conf.all.disable_ipv6=1  /etc/sysctl.d/disableipv6.conf

which I did.

quote
So. Installed my first Samba 4.03 PDC 
Kept it simple, used samba's internal DNS forwarding to the main DNS server. 
Edited resolv.conf to query localhost. 
All was well until I tried to pull down ntp from my debian (6.0) apt source. 
Suddenly, no can do. all the DNS supplied was in IPV6 which my router doesn't 
pass. 
Can I disable ipv6 in the Samba internal DNS server?
/quote 
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] having issues with shares

2013-02-08 Thread ray klassen
I would start by disabling oplocks.



- Original Message -
From: Donny Brooks dbro...@mdah.state.ms.us
To: samba@lists.samba.org
Cc: 
Sent: Friday, 8 February 2013, 12:56
Subject: [Samba] having issues with shares

We recently migrated our install from an ancient fedora 11 install of samba and 
openldap to a centos 6.3 setup with its openldap and samba. The domain has been 
totally recreated from scratch as the person that did the previous setup has 
not been employed here in many years. After fighting with shares for a while we 
mostly got them fixed and working. However the biggest issue now is when our 
GIS people try to connect to their samba share. Previously two pople could be 
editing different feature classes, different files, but now it will not let the 
second person do anything but view. Here is a brief explanation from our head 
GIS guy:

We currently have 5 data sets in one feature class in the GIS. 

site_point
site_poly
survey_point
survey_line
survey_poly

Before the conversion to the new Domain:

User A could open up the GIS on computer 1 and begin to edit one of the data 
set. (site_point for example) and User B could open up the GIS on computer 2 
and begin to edit any other data set  except what User A was editing (in this 
example site_point).  As long a two people didn't try and edit the same data 
set it worked.

After the Domain conversion:

User A opens up the GIS on computer 1 and begins to edit any of our data sets. 
User B opens up the GIS on computer 2 and attempts to edit any of our data sets 
a window opens up with several errors about  file locks.  ( I can send up 
screen shots in the morning)  As we saw in the samba logs it appears that once 
User A begins editing the one data set all the other data sets in the feature 
class get .lock files along with the one that User A is actually editing.  The 
only way User B can edit data is if User A exits the GIS completely.


So with that we have been trying everything we can think of to get it working 
correctly again. When I setup the share I copied the existing share from the 
old domain and put it in the new one making only the domain name change to the 
section. 

Here is the old setup:

[pictures]
    comment = Shared Folder for Pictures
    path = /samba/pictures
    read only = No
    create mask = 0667
    directory mask = 0770
        csc policy = disable
        nt acl support = no
        force security mode = 777
        valid users = @hpres
        force group = @ADMIN\hpres
        #inherit permissions = yes
        write list = @ADMIN\hpres

Here is the new:

[hp-pictures]
        comment = Shared Folder for Historic Preservation Pictures
        path = /samba/arrowhead/hp-pictures
        read only = No
        create mask = 0667
        directory mask = 0770
    csc policy = disable
    nt acl support = no
    force security mode = 777
        valid users = @hpres
        force group = @MDAH\hpres
        write list = @MDAH\hpres

Anyone have an idea why this could be happening?

-- 

Donny B.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Samba's built in DNS -- Can I turn off IPV6

2013-02-06 Thread ray klassen
So. Installed my first Samba 4.03 PDC Kept it simple, used samba's internal DNS 
forwarding to the main DNS server. Edited resolv.conf to query localhost. All 
was well until I tried to pull down ntp from my debian (6.0) apt source. 
Suddenly, no can do. all the DNS supplied was in IPV6 which my router doesn't 
pass. Can I disable ipv6 in the Samba internal DNS server?


Please?
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Posted this question once already -- no response. Password expiry problem

2013-01-15 Thread ray klassen
Solved this problem 


gentle rant
This is precisely the sort of question that should be answerable on this list. 

Has no one run into this before? 

I've brought it up twice here and several times on the irc channel with no 
response, but the solution was simple enough
/gentle rant

anyway here it is. So that it goes in the mailing list and others can find it.

/etc/smbldap-tools/smbldap.conf includes a line that says 

defaultMaxPasswordAge=45 

This affects the sambaPwdMustChange date stamp attribute in the ldap user 
record at the time smbldap-passwd is run.

sambaPwdMustChange appears to trump the user X flag and the maximum password 
age system policy


Maybe that's the nature of the samba 3.x beast. 

Maybe it has to be that way if you are using LDAP. 
Now that Samba 4 is out probably no one will want to comment on that.




- Original Message -
From: ray klassen julius_ahenobar...@yahoo.co.uk
To: samba@lists.samba.org samba@lists.samba.org
Cc: 
Sent: Monday, 14 January 2013, 10:06
Subject: [Samba] Posted this question once already -- no response. Password 
expiry problem

A user with the X (password doesn't expire) flag on his account was forced to 
change his password because it expired on a system with 


pdbedit -P'maximum password age'

account policy maximum password age description: Maximum password age, in 
seconds (default: -1 = never expire passwords)

What's going on? why is samba ignoring this and expiring passwords anyways?

samba Version: 2:3.6.3-2ubuntu2.3 on ubuntu Precise

But I'm having the same issue with whatever version of samba is current on 
debian squeeze.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Posted this question once already -- no response. Password expiry problem

2013-01-14 Thread ray klassen
A user with the X (password doesn't expire) flag on his account was forced to 
change his password because it expired on a system with 


pdbedit -P'maximum password age'

account policy maximum password age description: Maximum password age, in 
seconds (default: -1 = never expire passwords)

What's going on? why is samba ignoring this and expiring passwords anyways?

samba Version: 2:3.6.3-2ubuntu2.3 on ubuntu Precise

But I'm having the same issue with whatever version of samba is current on 
debian squeeze.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Password expiry

2013-01-07 Thread ray klassen
Can't disable password expiry for 2 different samba 3.X installations. One is 
based on Debian squeeze, the other Ubuntu precise. I have altered the password 
policy with pdbedit pdbedit -P maximum password age -C -1 and set the X 
flag on accounts pdbedit -c [X ] username   and the accounts passwords 
still exipre. Please help.

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] AD file server

2012-09-13 Thread ray klassen
OK i'm intrigued. I've been watching the various beta pages on the wiki for 
Samba 4 since it went beta and I still don't quite get something 

Samba 4.0 beta ships with two distinct file servers.  We now use the 
file server from the Samba 3.x series 'smbd' for all file serving by
default. 
Samba 4.0 also ships with the 'NTVFS' file server.  This file 
server is what was used in all previous alpha releases of Samba 4.0, and is
tuned to match the requirements of an AD domain controller. 


Does this mean that if you want to use a samba 4.0 host as a domain controller 
you must use the NTVFS file server? And therefore if you have a Samba 3.x 
domain controller that is also functioning as a file server, it's advisable to 
migrate the domain controller functionality to another machine as part of the 
upgrade?

(Thanks for all the hard work)

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] VPN/WAN Domain members

2010-11-24 Thread ray klassen
I have about 60 PC's running windows XP behind vpn routers in different 
locations. I find that they lose connection or sync (or whatever the right word 
is) to the domain periodically, probably when the vpn shuts down due to low 
demand. The result is that any domain user not already in the local password 
hash cache cannot log in and any local share with domain permissions on it will 
not allow the a domain account access if the pc is not rebooted. Is there any 
way to force windows to resync without a reboot or to make XP more fault 
tolerant to slower connections to the samba domain?

Thanks in advance. etc...



  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Registry Settings for Windows 7

2010-04-20 Thread ray klassen
The sambawiki has some helpful info on a windows 7 box joining a samba 3 
domain. It also worked fine with windows 2008 server.

My problem is this (quoting from the wiki)

   Changing the Primary Domain DNS name of this computer to  failed.
The name will remain MYDOM.  The error was:

The specified domain either does not exist or could not be contacted 

This warning can be ignored or silenced with setting other registry keys. 

Does anyone know what registry keys are referred to here? I'd really like to 
stop the machine from changing its name to name.domain. I'm trying to deploy a 
remote desktop application that complains that the name of the machine is not 
the same as the name of the certificate.


  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Point'n'print support of various printer drivers

2010-04-19 Thread ray klassen
There are some I've never gotten to work. There's a crash (unhandled exception 
or something like that) right in the middle of configuring the driver that 
looked very much to me that it was a call back to the server. Certain 
Konica-Minolta drivers do this. Any other wisdom out there on this subject 
would be appreciated. I don't know of a list. 

I may try again, now that my server's up to the latest greatest 3.x...




From: Roel van Meer ro...@bokxing.nl
To: ray klassen julius_ahenobar...@yahoo.co.uk
Cc: samba@lists.samba.org
Sent: Mon, 19 April, 2010 0:17:48
Subject: Re: [Samba] Point'n'print support of various printer drivers

ray klassen writes:

 The problem is always when a printer driver makes a call to a windows dll on 
 the server which the linux server can't respond to. Wish the driver 
 developers would brain up...

So you're saying those drivers just cannot work, right?

Is there a list somewhere of drivers that are known (not) to work with samba 
point'n'print?

Regards,

roel


 
 From: Ryan Suarez ryan.sua...@sheridanc.on.ca
 To: Roel van Meer ro...@bokxing.nl; samba@lists.samba.org
 Sent: Fri, 16 April, 2010 12:03:34
 Subject: Re: [Samba] Point'n'print support of various printer drivers
 
 Roel van Meer wrote:
 We're using Point'n'print with different versions of samba (3.3.x, 3.4.x,
 3.5.x) and in most cases it works really well. However, there are some
 printer drivers with which we just cannot get printing to work properly:
 in these cases not all driver features (like color, duplex or multiple
 copies) are available.
 
 I was wondering if this is a known inherent problem with some printer 
 drivers, or if this is caused by samba not supporting specific methods or 
 other requirements that these drivers would have.
 
 The reason I'm asking is that I would like to know whether or not it's
 useful filing bugs for these issues. I already have test setups and I'm
 willing and able to spend time helping debug these issues, but if this is
 one of those things that'll just never work it's not really useful
 bothering anyone with it.
 
 Examples of drivers that we can't get to work properly are the Brother 
 HL4040-CN and various drivers from HP (the bundled Windows drivers for HP 
 printers usually work fine.)
 Great question +1.  All our lexmark drivers work like a charm.
 
 Xerox drivers are a PITA.  I'm referring to vendor specific drivers, since 
 Windows does not have a bundle for the newest Xerox models we have.  I was 
 also considering filing bug reports for these.
 -- To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba
 
 
 
   -- To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba



  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Point'n'print support of various printer drivers

2010-04-17 Thread ray klassen
The problem is always when a printer driver makes a call to a windows dll on 
the server which the linux server can't respond to. Wish the driver developers 
would brain up...





From: Ryan Suarez ryan.sua...@sheridanc.on.ca
To: Roel van Meer ro...@bokxing.nl; samba@lists.samba.org
Sent: Fri, 16 April, 2010 12:03:34
Subject: Re: [Samba] Point'n'print support of various printer drivers

Roel van Meer wrote:
 We're using Point'n'print with different versions of samba (3.3.x, 3.4.x, 
 3.5.x) and in most cases it works really well. However, there are some 
 printer drivers with which we just cannot get printing to work properly: in 
 these cases not all driver features (like color, duplex or multiple copies) 
 are available.
 
 I was wondering if this is a known inherent problem with some printer 
 drivers, or if this is caused by samba not supporting specific methods or 
 other requirements that these drivers would have.
 
 The reason I'm asking is that I would like to know whether or not it's useful 
 filing bugs for these issues. I already have test setups and I'm willing and 
 able to spend time helping debug these issues, but if this is one of those 
 things that'll just never work it's not really useful bothering anyone with 
 it.
 
 Examples of drivers that we can't get to work properly are the Brother 
 HL4040-CN and various drivers from HP (the bundled Windows drivers for HP 
 printers usually work fine.)
Great question +1.  All our lexmark drivers work like a charm.

Xerox drivers are a PITA.  I'm referring to vendor specific drivers, since 
Windows does not have a bundle for the newest Xerox models we have.  I was also 
considering filing bug reports for these.
-- To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba



  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

2010-04-16 Thread ray klassen
Okay, so I've just put the sernet repo file in my yum.repos.d directory and a 
yum update will elevate my samba server to the latest version. Is there any 
pitfall that is out there that I can avoid before yum updating.

Centos 5.3
samba3-3.0.34-37  related packages
openldap-2.3.43-3.el5  related packages

I still have my samba3-3.0.34 packages squirreled away so I can force downgrade 
if I need to, but I don't want to if I don't have to.

Any advice before the plunge?
Ray


  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

2010-04-16 Thread ray klassen


Well that's a bit of a relief. I've no active directory in our system. I was 
trying to wait for samba 4 to go production. Only thing is I've a win 2008 
server that I want to bring into our domain and as it's similar to windows 7, 
it would seem that an update to 3.atleast4 is indicated.



From: Hoover, Tony hoo...@sal.ksu.edu
To: ray klassen julius_ahenobar...@yahoo.co.uk; samba@lists.samba.org
Sent: Fri, 16 April, 2010 11:30:07
Subject: RE: [Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

If you're not connecting to an Active Directory (either as a trusted domain,
or as a domain member), configuring Kerberos may not be required.  
If you do require Kerberos,  the [realms] and [domain_realm] sections would
need to be customized for your network.  Additionally, the default_realm
entry in the [libdefaults] section would need to be edited.



Tony Hoover, Network Administrator
KSU - Salina, College of Technology and Aviation
(785) 826-2660

Don't Blend in...


-Original Message-
From: ray klassen [mailto:julius_ahenobar...@yahoo.co.uk] 
Sent: Friday, April 16, 2010 1:04 PM
To: Hoover, Tony
Subject: Re: [Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

Wow. Thanks.

Is there any quick way do create a krb5.conf file. (i.e. standard defaults
and so on?)



From: Hoover, Tony hoo...@sal.ksu.edu
To: ray klassen julius_ahenobar...@yahoo.co.uk; samba@lists.samba.org
Sent: Fri, 16 April, 2010 10:00:28
Subject: RE: [Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

Some entries in your smb.conf have changed default values.  Get a listing
from testparm -v before and after to be able to work around those details.


Also, IIRC, With the newer samba 3 packages (starting around 3.3), you need
to have a correctly configured krb5.conf file.



Tony Hoover, Network Administrator
KSU - Salina, College of Technology and Aviation
(785) 826-2660

Don't Blend in...


-Original Message-
From: samba-boun...@lists.samba.org [mailto:samba-boun...@lists.samba.org]
On Behalf Of ray klassen
Sent: Friday, April 16, 2010 10:46 AM
To: samba@lists.samba.org
Subject: [Samba] Any pitfalls updating straight from 3.0.34 to 3.5.2?

Okay, so I've just put the sernet repo file in my yum.repos.d directory and
a yum update will elevate my samba server to the latest version. Is there
any pitfall that is out there that I can avoid before yum updating.

Centos 5.3
samba3-3.0.34-37  related packages
openldap-2.3.43-3.el5  related packages

I still have my samba3-3.0.34 packages squirreled away so I can force
downgrade if I need to, but I don't want to if I don't have to.

Any advice before the plunge?
Ray


  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


  
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] parameter default devmode missing in man pages and other docs

2009-05-16 Thread ray klassen
would it make sense to for the developers to pull in some code from the wine or 
winelib projects to take care of device mode issues. I've replaced a few 
printers recently with ones for which I can't set up point and print with samba 
anymore...





From: Karolin Seeger ksee...@samba.org
To: Axel Werner m...@awerner.homeip.net
Cc: samba@lists.samba.org
Sent: Thursday, 14 May, 2009 4:30:23
Subject: Re: [Samba] parameter default devmode missing in man pages and other 
docs

Hi Axel,

On Thu, May 14, 2009 at 10:15:59AM +0200, Axel Werner wrote:
 Why is the smb.conf  Parameter default devmode missing in pretty much any 
 samba documentation like man page etc ??

 does someone have a good official  explaination about this parameter ?

man smm.conf (3.3.4):
-8--snip--8--
default devmode (S)

   This parameter is only applicable to printable services. When
smbd is serving Printer Drivers to
   Windows NT/2k/XP clients, each printer on the Samba server has
a Device Mode which defines
   things such as paper size and orientation and duplex settings.
The device mode can only
   correctly be generated by the printer driver itself (which can
only be executed on a Win32
   platform). Because smbd is unable to execute the driver code to
generate the device mode, the
   default behavior is to set this field to NULL.

   Most problems with serving printer drivers to Windows NT/2k/XP
clients can be traced to a
   problem with the generated device mode. Certain drivers will do
things such as crashing the
   clientŽs Explorer.exe with a NULL devmode. However, other
printer drivers can cause the clientŽs
   spooler service (spoolsv.exe) to die if the devmode was not
created by the driver itself (i.e.
   smbd generates a default devmode).

   This parameter should be used with care and tested with the
printer driver in question. It is
   better to leave the device mode to NULL and let the Windows
client set the correct values.
   Because drivers do not do this all the time, setting default
devmode = yes will instruct smbd to
   generate a default one.

   For more information on Windows NT/2k printing and Device
Modes, see the MSDN documentation.

   Default: default devmode = yes
-8--snap--8--

Cheers,
Karolin

-- 
Sambahttp://www.samba.org
SerNethttp://www.sernet.de
sambaXPhttp://www.sambaxp.org



--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Upgrading to 3.3.4 from 3.0.34

2009-05-11 Thread ray klassen
Are there any pitfalls from just dropping a 3.3.x version on to a 3.0.34 
installation?



--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Users can't login on Samba+Ldap

2009-05-11 Thread ray klassen
/etc/ldap.conf has to include a lookup for passwd in the ou=Computers section 
or machines have to be duplicated in /etc/passwd

just find the one for Users and add a similar one for Computers.






From: dogb...@infinito.it dogb...@infinito.it
To: Adam Williams awill...@mdah.state.ms.us
Cc: samba@lists.samba.org
Sent: Monday, 11 May, 2009 7:35:01
Subject: Re: [Samba] Users can't login on Samba+Ldap

Yes, this is the [GLOBAL] section of my smb.conf

[global]
dos charset = 850
unix charset = ISO8859-1
workgroup = DOMAIN.IT
server string = SERVERNAME
map to guest = Bad User
passdb backend = ldapsam:ldap://localhost/
syslog = 0
log file = /var/log/samba/%m
max log size = 10
smb ports = 3D 139
time server = Yes
deadtime = 10
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
printcap name = cups
add user script = /usr/sbin/smbldap-useradd -m %u
delete user script = /usr/sbin/smbldap-userdel %u
add group script = /usr/sbin/smbldap-groupadd -p %g
add user to group script = /usr/sbin/smbldap-groupmod -m %u %g
delete user from group script = /usr/sbin/smbldap-groupmod -x %u
%g
set primary group script = /usr/sbin/smbldap-usermod -g '%g' '%u'
add machine script = /usr/sbin/smbldap-useradd -t 0 -w %u
logon script = logon.bat
logon path =
logon drive = C:
logon home =
domain logons = Yes
os level = 15
preferred master = Yes
domain master = Yes
wins support = Yes
ldap admin dn = cn=admin,dc=DOMAIN,dc=IT
ldap group suffix = ou=Groups
ldap machine suffix = ou=Computers
ldap passwd sync = Yes
ldap suffix = dc=DOMAIN,dc=IT
ldap user suffix = ou=Users
create mask = 0640
directory mask = 0750
nt acl support = No
case sensitive = No
dont descend = /proc,/dev,/etc,/lib,/lost+found,/initrd



 
 
 do you have   ldap machine suffix = ou=Computers
 in smb.conf?
 
 dogb...@infinito.it wrote:
 gt;
 gt; If I join a workstation (directly by the workstation) it is added to
ldap db
 gt; but it doesn't see the domain until I manually add an entry for it in
 gt; /etc/passwd
 gt;
 gt;  
 
 


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba




--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Users can't login on Samba+Ldap

2009-05-11 Thread ray klassen
add 
nss_base_passwdou=Computers,dc=padl,dc=com?one

where Computers is the organizational unit where you've got machine names 
stored. You'll end up with 2 nss_base_passwd entries, one for users, one for 
computers...




From: dogb...@infinito.it dogb...@infinito.it
To: ray klassen julius_ahenobar...@yahoo.co.uk; Adam Williams 
awill...@mdah.state.ms.us
Cc: samba@lists.samba.org
Sent: Monday, 11 May, 2009 8:08:49
Subject: Re: [Samba] Users can't login on Samba+Ldap

Is this the section that has to be configured in ldap.conf?

#nss_base_passwdou=People,dc=padl,dc=com?one
#nss_base_shadowou=People,dc=padl,dc=com?one
#nss_base_group ou=Group,dc=padl,dc=com?one
#nss_base_hosts ou=Hosts,dc=padl,dc=com?one
#nss_base_services  ou=Services,dc=padl,dc=com?one
#nss_base_networks  ou=Networks,dc=padl,dc=com?one
#nss_base_protocols ou=Protocols,dc=padl,dc=com?one
#nss_base_rpc   ou=Rpc,dc=padl,dc=com?one
#nss_base_ethersou=Ethers,dc=padl,dc=com?one
#nss_base_netmasks  ou=Networks,dc=padl,dc=com?ne
#nss_base_bootparamsou=Ethers,dc=padl,dc=com?one
#nss_base_aliases   ou=Aliases,dc=padl,dc=com?one
#nss_base_netgroup  ou=Netgroup,dc=padl,dc=com?one

because all the directives are commented excepted the following:
base dc=DOMAIN,dc=IT
binddn cn=anonymous,dc=DOMAIN,dc=IT
bindpw xxx
ldap_version 3
nss_initgroups_ignoreusers
pam_password md5
rootbinddn cn=admin,dc=dc=DOMAIN,dc=IT
uri ldap://127.0.0.1/



 /etc/ldap.conf has to include a lookup for passwd in the ou=Computers
section or machines have to be duplicated in /etc/passwdjust find the one
for Users and add a similar one for Computers.From: dogb...@infinito.it
lt;dogb...@infinito.itgt;To: Adam Williams
lt;awill...@mdah.state.ms.usgt;Cc: sa...@lists.samba.orgsent: Monday, 11
May, 2009 7:35:01Subject: Re: [Samba] Users can't login on Samba+LdapYes,
this is the [GLOBAL] section of my smb.conf[global]nbsp; nbsp; nbsp;
nbsp; dos charset = 850nbsp; nbsp; nbsp; nbsp; unix charset =
ISO8859-1nbsp; nbsp; nbsp; nbsp; workgroup = DOMAIN.ITnbsp; nbsp;
nbsp; nbsp; server string = SERVERNAMEnbsp; nbsp; nbsp; nbsp; map to
guest = Bad Usernbsp; nbsp; nbsp; nbsp; passdb backend =
ldapsam:ldap://localhost/nbsp; nbsp; nbsp; nbsp; syslog = 0nbsp; nbsp;
nbsp; nbsp; log file = /var/log/samba/%mnbsp; nbsp; nbsp; nbsp; max
log size = 10nbsp; nbsp; nbsp; nbsp; smb ports = 3D 139nbsp; nbsp;
nbsp; nbsp; time server = Yesnbsp; nbsp; nbsp; nbsp; deadtime =
10nbsp; nbsp; nbsp; nbsp; socket options = TCP_NODELAY SO_RCVBUF=8192
SO_SNDBUF=8192nbsp; nbsp; nbsp; nbsp; printcap name = cupsnbsp;
  nbsp; nbsp; nbsp; add user script = /usr/sbin/smbldap-useradd -m
%unbsp; nbsp; nbsp; nbsp; delete user script =
/usr/sbin/smbldap-userdel %unbsp; nbsp; nbsp; nbsp; add group script =
/usr/sbin/smbldap-groupadd -p %gnbsp; nbsp; nbsp; nbsp; add user to
group script = /usr/sbin/smbldap-groupmod -m %u %gnbsp; nbsp; nbsp;
nbsp; delete user from group script = /usr/sbin/smbldap-groupmod -x
%u%gnbsp; nbsp; nbsp; nbsp; set primary group script =
/usr/sbin/smbldap-usermod -g '%g' '%u'nbsp; nbsp; nbsp; nbsp; add
machine script = /usr/sbin/smbldap-useradd -t 0 -w %unbsp; nbsp; nbsp;
nbsp; logon script = logon.batnbsp; nbsp; nbsp; nbsp; logon path
=nbsp; nbsp; nbsp; nbsp; logon drive = C:nbsp; nbsp; nbsp; nbsp;
logon home =nbsp; nbsp; nbsp; nbsp; domain logons = Yesnbsp; nbsp;
nbsp; nbsp; os level = 15nbsp; nbsp; nbsp; nbsp; preferred
  master = Yesnbsp; nbsp; nbsp; nbsp; domain master = Yesnbsp; nbsp;
nbsp; nbsp; wins support = Yesnbsp; nbsp; nbsp; nbsp; ldap admin dn =
cn=admin,dc=DOMAIN,dc=ITnbsp; nbsp; nbsp; nbsp; ldap group suffix =
ou=Groupsnbsp; nbsp; nbsp; nbsp; ldap machine suffix =
ou=Computersnbsp; nbsp; nbsp; nbsp; ldap passwd sync = Yesnbsp; nbsp;
nbsp; nbsp; ldap suffix = dc=DOMAIN,dc=ITnbsp; nbsp; nbsp; nbsp; ldap
user suffix = ou=Usersnbsp; nbsp; nbsp; nbsp; create mask = 0640nbsp;
nbsp; nbsp; nbsp; directory mask = 0750nbsp; nbsp; nbsp; nbsp; nt acl
support = Nonbsp; nbsp; nbsp; nbsp; case sensitive = Nonbsp; nbsp;
nbsp; nbsp; dont descend = /proc,/dev,/etc,/lib,/lost+found,/initrdgt;
gt; gt; do you havenbsp;  ldap machine suffix = ou=Computersgt; in
smb.conf?gt; gt; dogb...@infinito.it wrote:gt; amp;gt;gt; amp;gt; If I
join a workstation (directly by the workstation) it is added toldap dbgt;
amp;gt; but it doesn't see the domain until I manually add an entry for it
ingt; amp;gt; /etc/passwdgt; amp;gt;gt; amp;gt;nbsp;  gt; gt; -- To
unsubscribe from this list go to the following URL and read
theinstructions:nbsp; https://lists.samba.org/mailman/options/samba
 
 
 
  



--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] nuther 3.0.x to 3.3.x question

2009-05-11 Thread ray klassen
I'm running into a bit of weirdness (actually several bits) with newer printer 
drivers (notably HP and Konica) not functioning properly as point and print 
drivers under samba 3.0. Is that likely to improve under 3.3.x? 

to elaborate further... Some Konica models printer drivers give me unhandled 
exception alerts. And one version of the HP CLJ4700 driver won't load on point 
and print and the later version when I upload it to the [printers} share makes 
windows XP complain that it wants a windows xp version of the driver. (I'm 
using XP.. SP3 if that makes a difference)




--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] samba machine accounts problem

2009-04-17 Thread Ray Klassen

 only ou=users, need i a second one for hosts? can i do this belated?



yes to (1) and I think yes to (2)...
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] samba machine accounts problem

2009-04-15 Thread Ray Klassen
/etc/ldap.conf

are you including a line like
nss_base_passwd ou=hosts,dc=server,dc=intern?one

/etc/nsswitch.conf

does it include the following?

passwd: files ldap
shadow: files ldap
group:  files ldap

This is how machine accounts in ldap become 'unix accounts' or that's
the way I do it...


On Tue, Apr 14, 2009 at 11:31 PM, Sven Buchstaller a...@quickline.de wrote:
 Hi list

 samba3-3.0.31-36
 openldap2-2.3.43-1.1

 my problem is i have stop my working openldap and restart it again, in
 the Log i see now = pdb_get_group_sid: Failed to find Unix account
 for ... a lot of machine accounts.
 Whats wrong? i must now all accounts rejoin to domain?

 example from a host

 # bart$, hosts, server.intern
 dn: uid=bart$,ou=hosts,dc=server,dc=intern
 objectClass: sambaSamAccount
 objectClass: posixAccount                ---unix account ?
 objectClass: account
 sambaDomainName: srv01
 displayName: bart
 sambaPrimaryGroupSID: S-1-5-21-3991578539-3149662252-1894531253-515
 sambaSID: S-1-5-21-3991578539-3149662252-1894531253-101524
 gidNumber: 515
 loginShell: /bin/false
 homeDirectory: /dev/null
 uid: bart$
 cn: bart
 uidNumber: 50262
 sambaPwdCanChange: 1196710001
 sambaPwdMustChange: 1204486001
 sambaAcctFlags: [WX         ]
 sambaPwdLastSet: 1238649797

 # search result
 search: 2
 result: 0 Success




 mfg sven

 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Users cannot rename, delete files on AD-member Samba server

2009-04-10 Thread Ray Klassen
What about unix extensions? enabled or disabled? Unix extensions seem
to bypass force group statements...

On Fri, Apr 10, 2009 at 10:26 AM, Jeremy Allison j...@samba.org wrote:
 On Fri, Apr 10, 2009 at 11:46:53AM -0400, Goldschrafe, Jeffrey wrote:
 Hi there!

 I'm having some strange permissions issues with one of my systems that's
 on an Active Directory domain.

 Here's the basic background:

  - System is joined to AD domain. Users authenticate fine via Kerberos,
 and are authorized via an AD user group. They can browse the share,
 create files, etc. without incident. valid users lets them in.
  - User information for the system (nsswitch) comes out of LDAP. The
 LDAP is non-AD (a legacy OpenLDAP setup), but the usernames all line up
 and Samba can resolve each user's UID/GID and secondary groups without a
 problem.
  - The share is semantically owned by a single Unix group.
  - That security group is mapped in net groupmap to a Unix group. I'm
 not entirely sure if this is actually necessary.
  - Share has force create mode = 0664 and force directory mode =
 0775 to ensure that files are writable by the group by default.

 When a user connects to the share using a Windows client (XP or Vista),
 they are unable to rename folders, and unable to rename or delete files.
 They are able to delete folders, as long as the folders do not contain
 any files. This means that when using Explorer to create a file or
 folder, it can be created with the default name (e.g. New Folder or
 New Text Document.txt) but any attempt to assign a
 semantically-meaningful name will fail with an access denied error.
 This applies to renaming existing files as well, of course.

 When the same user connects from a Mac or Linux client, through Finder,
 Dolphin or smbclient, the same exact operations work. The user can
 rename and delete just fine as long as it isn't from Windows.

 We need to see level 10 logs of what is going on here before we
 can determine the problem. What version of Samba are you using ?

 Jeremy.
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Samba 3 versions

2009-04-08 Thread Ray Klassen
What are the roles of the different 3 versions?

3.0 Legacy?
3.2 Legacy +GPL3?
3.3 The continuing adventures?

Thanks
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Samba + LDAP = SLOW Help plesase

2009-04-02 Thread Ray Klassen
mysterious slowness sometimes has a timing out name service at its
back. Is WINS enabled on your server? Do the clients look to your
server as their WINS server? If a WINS lookup fails and then the
clients revert back to broadcast based name resolution, the symptoms
could be similar to what you're seeing.

On Thu, Apr 2, 2009 at 12:20 AM, Grey Karapetyan
grey.karapet...@gmail.com wrote:
 Thanks for answers!
 but i use a Fedora Directory Server.

 i try answer on your questions:
  what indexes do you have in slapd.conf?  what hardware is the server
 running on?
 Core2Quad/8gb ddr2

 would you copy your slapd.conf  to us? the index section only would be
 just OK. also. would you mind runing slapindex on the server (turn off
 OpenLDAP first)?, then try if it affected your pdc performance

 Sorry but i use FDS here is no config. All parametrs places in db. Any
 concrete parametrs i should show you?

 More important than anything else is your Berkley environment.  Do you
 have a reasonable DB-CONFIG file or are you asserting reasonable DB values
 via cn=config? But these are all OpenLDAP questions and not specific to
 Samba. Test your DSA to see if it is fast enough, then move back to testing
 Samba.

 This OpenLpad-specific parametrs?
 If i use getent passwd | grep -i username - works realy fast (1-2 seconds).
 (From my Samba server)


 =
 News:
 Now shares shows and opens fast.

 But printers from windows clients (when getting status printer) as before
 SLOW.
 Then i create local user on Samba server and disable ldap backend - printers
 works fast too.

 =
 in man smb.conf find 2 params
  ldapsam:trusted=yes
  ldapsam:editposix=yes

 somebodey use this?
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] Slow Links

2009-02-16 Thread Ray Klassen
we have about thirty vpn links in our network and all workstations
connect back to head office and authenticate to a samba domain with
ldap as the back end. In conjunction with a new software rollout (it's
web-based is completely unrelated to samba) I've been installing new
machines and approximately doubling my user base. What I'm finding is
that domain operations at the other end of an otherwise functional
VPN, can be hit and miss. Joining and disjoining a machine to a domain
is consistently possible. Renaming a machine works rarely -- bad
password. Sometimes I've had to power cycle a computer to force it to
log back into the domain because my brand new users can't log into the
machines. (Domain MYDOMAIN is not available)  I found I had fewer
problems (i.e. I could work around the issues) after I increased the
password chat timeout. Are there any other settings I should
implement?

Factors that might be turning this problem up after years of not
noticing it are --

Recent upgrade of samba from 3.0.28 to 3.0.34
Recent upgrade of samba.schema to support substring searches of sambaSID
The new boxes are running XP while the ones they are replacing ran 2000

thanks for your help in the recent past.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Strange issue with Samba + LDAP + Domain Member

2009-02-16 Thread Ray Klassen
I get around this by including

nss_base_passwd ou=Computers,dc=mydomain,dc=com?one

in /etc/ldap.conf

if nss_ldap isn't looking in your computers tree for passwd entries,
it will never see them as unix accounts.


On Sun, Feb 15, 2009 at 1:27 PM, John Drescher dresche...@gmail.com wrote:
 On Sun, Feb 15, 2009 at 12:27 PM, Bryan Celentano
 bryan.celent...@ultracontrols.aero wrote:
 Hey,



 I keep posting but no replies yet, this is a new issue, the rest I seem to
 have fixed.



 I have an odd issue:



 *   When I do net rpc join the PDC creates the account, and puts it into
 LDAP, which looks fine.
 *   I then can access the domain and winbind works fine from the Domain
 Member server.
 *   On the PDC I see the following error: pdb_get_group_sid: Failed to
 find Unix account for member$
 *   So I had a look into the nss_ldap and found it wasn't searching the
 ou=computers, so I added this in, and the error goes.
 *   Then I have a new issue, the domain member and winbind fails with
 NT_ACCESS_DENIED.
 *   So I remove the nss_ldap entry for the ou=computers and it all works
 again.



 Has anyone come across this issue?  Any help would be great.


 Yes. I have this issue (and have had it for at least 5 years) using
 the smbldap-tools. To workaround I now just precreate an account using
 LAM (http://lam.sourceforge.net/) and then all is well with the PDC
 join. The previous workaround was to create a user for the machine
 account on the pdc first in the /etc/passwd.

 John

 John
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Acces denied with usrmgr.exe

2009-02-16 Thread Ray Klassen
net rpc rights list Domain\ Admins
net rpc rights list Administrators

should give the info you need


On Mon, Feb 16, 2009 at 5:53 AM, HB ciradhb.forw...@laposte.net wrote:
 Hi

 I am trying to use usrmgr.exe in order to manage users and groups on my samba 
 server PDC (passdb backend = tdbsam ) .
 I have the following strange behavior of usrmgr.exe :

 *   when I launch usrmgr.exe from a user account that is part of the 
 Domain Admins group or that explicitly has the
 SeAddUsersPrivilege privilege, I can see the list of users and groups , and 
 create a new user, BUT when I double click on a user or
 group, I get the error popup : Access Denied , the user properties cannot be 
 edited or viewed at this time . The log level 2 trace
 is :
 [2009/02/16 17:18:40,  2] 
 rpc_server/srv_samr_nt.c:access_check_samr_function(246)
  _samr__LookupRids: ACCESS DENIED (granted: 0x000d067a;  required: 0x0100)
 *   The only account that can fully use usrmgr.exe is the samba root 
 account , everything works well under that account.

 I strongly suspect it is a bug on privilege checking , can someone confirm 
 that ? Is there a workarround to make it work as expected
 ?

 Thanks in advance

 henri


 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Groups and sambaSIDList

2009-02-05 Thread Ray Klassen
The group list problem you describe is identical to mine of a week ago.
Seems to be related to schema and the ability of ldap to do substring
searches against the sambaSID attribute.

I made the problem go away by using a the latest samba,
samba(3).schema, and changing sambaSID indexing in slapd.conf from eq,
to eq,pres,sub, and slapindexing my ldap data.

Now I've got some different problems where machine domain membership
seems to be flakey, and I have to track that down, so I'm not
recommending my fix yet.





On Thu, Feb 5, 2009 at 3:17 AM, Christian Huldt christ...@solvare.se wrote:
 I have a problem with one samba 3.0.24 pdc using ldap with nss etc,
 sharing works fine, but ownership and the security tab seems crippled,
 and usrmgr.exe complains about the specified local group does not
 exist (of course without saying which group) so I dived in to check

 I found filters like this one below in the ldap log - is that to support
 nested groups? There are no groups with any sambaSIDList attribute - or,
 there was no groups with any sambaSIDList attribute until I found that I
 could not get ownership until I added the SID of the admin account I was
 using as a sambaSIDList attribute to the admin group, memberuid did not
 suffice.

 I tend to believe that something is seriously skew with this
 installation as all tools seems to add group members as memberuid, not
 as sambaSIDlists, but I am grateful for any word to or against this is.

 I was told the was some strangeness happening while vampiring the
 domain, but they managed to work around that...

 ((|(objectClass=sambaGroupMapping)(sambaGroupType=4))(|(sambaSIDList=s-1-5-21-1623357179-225914852-925700815-501)(sambaSIDList=s-1-1-0)(sambaSIDList=s-1-5-2)(sambaSIDList=s-1-5-32-546)))

 --
 mvh
 Christian Huldt
 0704612207

 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-02-03 Thread Ray Klassen
Well here's the deal and I haven't tested it live yet, but it should work

-samba queries the groups with a wildcard search against sambaSID.
-sambaSID was set to be indexed by 'eq' not 'sub'
-sambaSID cannot be indexed by 'sub' without an updated schema. I used
the one from the samba3 package I just installed
-after changing the index type in slapd.conf, slapindex has to be run.
-after that wildcard searches against ou=groups, etc for the sambaSID
attribute work
-ergo, when I run this live, samba searches for group, should work as well

Thanks Volker for setting me on the right path.

My slapd.conf is a mishmash from several howto's from a time when I
understood less.

Is there an ideal setup for indexing?
currently I've got this

index objectClass   eq
index cnpres,sub,eq
index snpres,sub,eq
index uid   pres,sub,eq
index displayName   pres,sub,eq
index uidNumber eq
index gidNumber eq
index memberUID eq
index sambaSID  eq
index sambaPrimaryGroupSID  eq
index sambaDomainName   eq
index sambaGroupTypeeq
index sambaSIDList  eq
index uniqueMember  eq
index default   sub


sambaSID will be changed, as of tonight some time. but are there any
other entries that are a pitfall for the future?

On Mon, Feb 2, 2009 at 3:37 PM, Ray Klassen rayklas...@gmail.com wrote:
 well that is the weirdest thing

 Just like the samba ldap request, it returns nothing

 although if I look at the record using

 ldapsearch -x -b ou=Groups,dc=thisdomain,dc=com '((cn=groupname*))

 ...the sambaSID attribute is there just like it should be, with the
 right number and everything.

 Would a slapindex be in order? or what'


 On Mon, Feb 2, 2009 at 10:17 AM, Volker Lendecke
 volker.lende...@sernet.de wrote:
 On Mon, Feb 02, 2009 at 09:16:06AM -0800, Ray Klassen wrote:
 One sanitized debug lo coming up. This is not using user manager for
 domains. This is with net rpc group list.


  What you need to do is provide a debug level 10 log of smbd
  trying to enumerate groups.
 
  Volker
 

   smbldap_search_paged: base = [ou=Groups,dc=thisdomain,dc=com],
 filter = 
 [((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))],scope
 = [2], pagesize = [1024]
 [2009/02/02 08:41:20, 5] lib/smbldap.c:smbldap_search_ext(1182)
   smbldap_search_ext: base = [ou=Groups,dc=thisdomain,dc=com], filter
 = 
 [((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))],
 scope = [2]
 [2009/02/02 08:41:20, 3] lib/smbldap.c:smbldap_search_paged(1333)
   smbldap_search_paged: search was successfull
 [2009/02/02 08:41:20, 10] 
 rpc_server/srv_samr_nt.c:_samr_query_dispinfo(1289)
   samr_reply_query_dispinfo: starting group enumeration at index 0
 [2009/02/02 08:41:20, 3] smbd/sec_ctx.c:pop_sec_ctx(356)
   pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
 [2009/02/02 08:41:20, 5] rpc_parse/parse_samr.c:init_sam_dispinfo_3(1810)
   init_sam_dispinfo_3: num_entries: 0

 To me this looks as if you don't have any groups in your
 LDAP tree under ou=Groups,dc=thisdomain,dc=com. You should
 be able to do the exact same search with ldapsearch:

 ldapsearx -x -b ou=Groups,dc=thisdomain,dc=com 
 '((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))'

 and see what comes back.

 Volker


-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-02-02 Thread Ray Klassen
Ok. I installed LAM. It happily sees all groups etc. because it's
accessing them directly through ldap. There doesn't seem to be a
utility there to 'fix errors'

It's when you access the information via samba (i.e. RPC) that you
can't get a group list. The list is the only information I've found
you can't get via RPC and the list is available elsewhere, (getent,
LAM, net groupmap, etc.) so it doesn't cripple me, but I'd like to
setup USER MANAGER for DOMAINS for my user admin person if I can.



On Sat, Jan 31, 2009 at 3:44 PM, John Drescher dresche...@gmail.com wrote:
 did smbldap-tools get upgraded along with samba? if not, you should update
 them separately.

 if so, you will have to delete and re-create the groups in order for them to
 be created correctly.

 Another workaround would be to delete the groups and use net rpc group to
 re-create them. This worked for me.


 I would just install LAM (http://lam.sourceforge.net)

 and fix the errors in the LDAP with that.

 John
 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-02-02 Thread Ray Klassen
well that is the weirdest thing

Just like the samba ldap request, it returns nothing

although if I look at the record using

ldapsearch -x -b ou=Groups,dc=thisdomain,dc=com '((cn=groupname*))

...the sambaSID attribute is there just like it should be, with the
right number and everything.

Would a slapindex be in order? or what'


On Mon, Feb 2, 2009 at 10:17 AM, Volker Lendecke
volker.lende...@sernet.de wrote:
 On Mon, Feb 02, 2009 at 09:16:06AM -0800, Ray Klassen wrote:
 One sanitized debug lo coming up. This is not using user manager for
 domains. This is with net rpc group list.


  What you need to do is provide a debug level 10 log of smbd
  trying to enumerate groups.
 
  Volker
 

   smbldap_search_paged: base = [ou=Groups,dc=thisdomain,dc=com],
 filter = 
 [((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))],scope
 = [2], pagesize = [1024]
 [2009/02/02 08:41:20, 5] lib/smbldap.c:smbldap_search_ext(1182)
   smbldap_search_ext: base = [ou=Groups,dc=thisdomain,dc=com], filter
 = 
 [((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))],
 scope = [2]
 [2009/02/02 08:41:20, 3] lib/smbldap.c:smbldap_search_paged(1333)
   smbldap_search_paged: search was successfull
 [2009/02/02 08:41:20, 10] rpc_server/srv_samr_nt.c:_samr_query_dispinfo(1289)
   samr_reply_query_dispinfo: starting group enumeration at index 0
 [2009/02/02 08:41:20, 3] smbd/sec_ctx.c:pop_sec_ctx(356)
   pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
 [2009/02/02 08:41:20, 5] rpc_parse/parse_samr.c:init_sam_dispinfo_3(1810)
   init_sam_dispinfo_3: num_entries: 0

 To me this looks as if you don't have any groups in your
 LDAP tree under ou=Groups,dc=thisdomain,dc=com. You should
 be able to do the exact same search with ldapsearch:

 ldapsearx -x -b ou=Groups,dc=thisdomain,dc=com 
 '((objectclass=sambaGroupMapping)(sambaGroupType=2)(sambaSID=S-1-5-21-XX-XX-XX*))'

 and see what comes back.

 Volker

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-02-01 Thread Ray Klassen
Yes. Thanks. That's what I've been using. I just typed it in from a
failing memory, obviously. :)

On Sat, Jan 31, 2009 at 6:36 PM, Miguel Medalha miguelmeda...@sapo.pt wrote:

 3.0.34 is now installed. no change. 'net rpc list groups' returns
 nothing, while 'net rpc group members group' returns the correct
 data



 The correct syntax is 'net rpc group list' ...

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] IMAP Authentication

2009-02-01 Thread Ray Klassen
No. But authenticating both against LDAP makes good sense

On Sun, Feb 1, 2009 at 8:54 AM, John Casterlin jcaster2...@comcast.net wrote:
 Does anyone have any experience using an IMAP server to authenticate Samba
 users? The idea is to control viability and read/write access to file/print
 services using an Internal only email server.

 Thanks, John

 --
 To unsubscribe from this list go to the following URL and read the
 instructions:  https://lists.samba.org/mailman/options/samba

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-01-31 Thread Ray Klassen
On Fri, Jan 30, 2009 at 10:27 AM, Jeremy Allison j...@samba.org wrote:
 On Fri, Jan 30, 2009 at 12:13:45AM -0800, Ray Klassen wrote:
 I have a network of about 100+ users with a Samba 3.0.25 server with
 an LDAP backend that I configured myself (with some help). Recently I
 have had to add about 300 more users to my system and now I need to
 get a slightly less technical person to help me manage the accounts.
 I've been happily using smbldap-tools all of this time, but when I
 showed what I do to my hapless trainee, her eyes started to glaze
 over. So as an alternative I'd like to start using the 'User Manager
 for Domains' in the SRVTOOLS.EXE archive. She might find the point and
 click of it all more friendly. Only thing is, when I start up User
 Manager, I can see all the users, but I can't see the groups. So I did
 a bit of checking and found that nowhere are those available as a
 list. Not even 'net rpc group list' will give me a list, even though
 if I add someone to my Domain Admins group everything works correctly.
 At the windows workstation end I can access the groups by name, to set
 the permissions of a share to certain group, etc. but I can't list
 them as I can the users.I've checked all the files...
 smb.conf,ldap.conf,slapd.conf,smbldap.conf and the Groups directive
 matches up with the right ldap 'ou' and so on. Has anyone any
 pointers?

 There was a bug in earlier versions of the smbldap-tools
 that creates groups with the wrong sid-type. I'd suggest
 upgrading to 3.0.34 (latest 3.0.x release) and then ensuring
 the group-type is changed in your LDAP db (I think it should be
 type 5, rather than type 4 but this could be the other way
 around :-).

 Jeremy.



3.0.34 is now installed. no change. 'net rpc list groups' returns
nothing, while 'net rpc group members group' returns the correct
data

tried changing the group type on a few groups. no change in behavior there.

cleaned up some error messages in my slapd.log where I assume samba
was requesting indexes from slapd.log. just told slap.conf to index
those attributes and the messages went away.

Upping the loglevel in slapd.conf...
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] User Manager for Domains -- Groups not showing

2009-01-31 Thread Ray Klassen
On Sat, Jan 31, 2009 at 6:44 AM, Ray Klassen rayklas...@gmail.com wrote:
 On Fri, Jan 30, 2009 at 10:27 AM, Jeremy Allison j...@samba.org wrote:
 On Fri, Jan 30, 2009 at 12:13:45AM -0800, Ray Klassen wrote:
 I have a network of about 100+ users with a Samba 3.0.25 server with
 an LDAP backend that I configured myself (with some help). Recently I
 have had to add about 300 more users to my system and now I need to
 get a slightly less technical person to help me manage the accounts.
 I've been happily using smbldap-tools all of this time, but when I
 showed what I do to my hapless trainee, her eyes started to glaze
 over. So as an alternative I'd like to start using the 'User Manager
 for Domains' in the SRVTOOLS.EXE archive. She might find the point and
 click of it all more friendly. Only thing is, when I start up User
 Manager, I can see all the users, but I can't see the groups. So I did
 a bit of checking and found that nowhere are those available as a
 list. Not even 'net rpc group list' will give me a list, even though
 if I add someone to my Domain Admins group everything works correctly.
 At the windows workstation end I can access the groups by name, to set
 the permissions of a share to certain group, etc. but I can't list
 them as I can the users.I've checked all the files...
 smb.conf,ldap.conf,slapd.conf,smbldap.conf and the Groups directive
 matches up with the right ldap 'ou' and so on. Has anyone any
 pointers?

 There was a bug in earlier versions of the smbldap-tools
 that creates groups with the wrong sid-type. I'd suggest
 upgrading to 3.0.34 (latest 3.0.x release) and then ensuring
 the group-type is changed in your LDAP db (I think it should be
 type 5, rather than type 4 but this could be the other way
 around :-).

 Jeremy.



 3.0.34 is now installed. no change. 'net rpc list groups' returns
 nothing, while 'net rpc group members group' returns the correct
 data

 tried changing the group type on a few groups. no change in behavior there.

 cleaned up some error messages in my slapd.log where I assume samba
 was requesting indexes from slapd.log. just told slap.conf to index
 those attributes and the messages went away.

 Upping the loglevel in slapd.conf...


looking at the slapd logging after  a  'net rpc list groups'  it
locates 57 groups and then queries the sambaSIDList attribute on each
one. (which I said earlier I wasn't set) After which it records
'bdb_search: no candidates' and thats that...
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


[Samba] User Manager for Domains -- Groups not showing

2009-01-30 Thread Ray Klassen
I have a network of about 100+ users with a Samba 3.0.25 server with
an LDAP backend that I configured myself (with some help). Recently I
have had to add about 300 more users to my system and now I need to
get a slightly less technical person to help me manage the accounts.
I've been happily using smbldap-tools all of this time, but when I
showed what I do to my hapless trainee, her eyes started to glaze
over. So as an alternative I'd like to start using the 'User Manager
for Domains' in the SRVTOOLS.EXE archive. She might find the point and
click of it all more friendly. Only thing is, when I start up User
Manager, I can see all the users, but I can't see the groups. So I did
a bit of checking and found that nowhere are those available as a
list. Not even 'net rpc group list' will give me a list, even though
if I add someone to my Domain Admins group everything works correctly.
At the windows workstation end I can access the groups by name, to set
the permissions of a share to certain group, etc. but I can't list
them as I can the users.I've checked all the files...
smb.conf,ldap.conf,slapd.conf,smbldap.conf and the Groups directive
matches up with the right ldap 'ou' and so on. Has anyone any
pointers?
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: RE: [Samba] User Manager for Domains -- Groups not showing

2009-01-30 Thread Ray Klassen
net rpc group list -- returns nothing
net rpc group members domain\ users -- works fine!

recheck your smbldap-tools/smbldap.conf
there must be a typo inhere, or
your smb.conf has a typo.

checked and rechecked!

On Fri, Jan 30, 2009 at 12:23 AM,  rayklas...@gmail.com wrote:
 Currently ...

 passwd: files ldap
 shadow: files ldap
 group: files ldap


 yeah the unix end of things is perfectly happy with ldap

 getent passwd | grep root gives me both the /etc/passwd and ldap entries

 getent group |grep Domain\ Users gives me the ldap samba group

 Group Mappings are just fine. except no list through samba...



 On Jan 30, 2009 12:17am, L. P. H. van Belle ob...@bazuin.nl wrote:
 hi,



 check

 nsswitch.conf

 should have something like..



 passwd: compat ldap

 group:  compat ldap

 shadow: compat ldap





 Louis

 -Oorspronkelijk bericht-

 Van: rayklas...@gmail.com

 [mailto:samba-bounces+belle=bazuin...@lists.samba.org] Namens

 Ray Klassen

 Verzonden: 2009-01-30 09:14

 Aan: samba@lists.samba.org

 Onderwerp: [Samba] User Manager for Domains -- Groups not showing

 

 I have a network of about 100+ users with a Samba 3.0.25 server with

 an LDAP backend that I configured myself (with some help). Recently I

 have had to add about 300 more users to my system and now I need to

 get a slightly less technical person to help me manage the accounts.

 I've been happily using smbldap-tools all of this time, but when I

 showed what I do to my hapless trainee, her eyes started to glaze

 over. So as an alternative I'd like to start using the 'User Manager

 for Domains' in the SRVTOOLS.EXE archive. She might find the point and

 click of it all more friendly. Only thing is, when I start up User

 Manager, I can see all the users, but I can't see the groups. So I did

 a bit of checking and found that nowhere are those available as a

 list. Not even 'net rpc group list' will give me a list, even though

 if I add someone to my Domain Admins group everything works correctly.

 At the windows workstation end I can access the groups by name, to set

 the permissions of a share to certain group, etc. but I can't list

 them as I can the users.I've checked all the files...

 smb.conf,ldap.conf,slapd.conf,smbldap.conf and the Groups directive

 matches up with the right ldap 'ou' and so on. Has anyone any

 pointers?

 --

 To unsubscribe from this list go to the following URL and read the

 instructions:  https://lists.samba.org/mailman/options/samba

 

 



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: RE: [Samba] User Manager for Domains -- Groups not showing

2009-01-30 Thread Ray Klassen
I got a debug log going on the actual ldap query and it looks like its
looking for an attribute sambaSIDList but that attribute is set on
none of my groups. Any guesses as how I should populate that?

On Fri, Jan 30, 2009 at 12:23 AM,  rayklas...@gmail.com wrote:
 Currently ...

 passwd: files ldap
 shadow: files ldap
 group: files ldap


 yeah the unix end of things is perfectly happy with ldap

 getent passwd | grep root gives me both the /etc/passwd and ldap entries

 getent group |grep Domain\ Users gives me the ldap samba group

 Group Mappings are just fine. except no list through samba...



 On Jan 30, 2009 12:17am, L. P. H. van Belle ob...@bazuin.nl wrote:
 hi,



 check

 nsswitch.conf

 should have something like..



 passwd: compat ldap

 group:  compat ldap

 shadow: compat ldap





 Louis

 -Oorspronkelijk bericht-

 Van: rayklas...@gmail.com

 [mailto:samba-bounces+belle=bazuin...@lists.samba.org] Namens

 Ray Klassen

 Verzonden: 2009-01-30 09:14

 Aan: samba@lists.samba.org

 Onderwerp: [Samba] User Manager for Domains -- Groups not showing

 

 I have a network of about 100+ users with a Samba 3.0.25 server with

 an LDAP backend that I configured myself (with some help). Recently I

 have had to add about 300 more users to my system and now I need to

 get a slightly less technical person to help me manage the accounts.

 I've been happily using smbldap-tools all of this time, but when I

 showed what I do to my hapless trainee, her eyes started to glaze

 over. So as an alternative I'd like to start using the 'User Manager

 for Domains' in the SRVTOOLS.EXE archive. She might find the point and

 click of it all more friendly. Only thing is, when I start up User

 Manager, I can see all the users, but I can't see the groups. So I did

 a bit of checking and found that nowhere are those available as a

 list. Not even 'net rpc group list' will give me a list, even though

 if I add someone to my Domain Admins group everything works correctly.

 At the windows workstation end I can access the groups by name, to set

 the permissions of a share to certain group, etc. but I can't list

 them as I can the users.I've checked all the files...

 smb.conf,ldap.conf,slapd.conf,smbldap.conf and the Groups directive

 matches up with the right ldap 'ou' and so on. Has anyone any

 pointers?

 --

 To unsubscribe from this list go to the following URL and read the

 instructions:  https://lists.samba.org/mailman/options/samba

 

 



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Re: [Samba] Samba and LDAP: Trouble adding Win XP machines to the domain

2007-06-27 Thread Ray Klassen

mikelOn wrote:


I have tried to add a new machine right now and this is the log of the
operation:

[2007/06/27 18:53:42, 3] passdb/pdb_interface.c:pdb_default_create_user(368)
  _samr_create_user: Running the command `/usr/sbin/smbldap-useradd -w
mikelvm$' gave 0
[2007/06/27 18:53:42, 3] passdb/pdb_interface.c:pdb_default_create_user(384)
  pdb_default_create_user: failed to create a new user structure:
NT_STATUS_NO_SUCH_USER

As you can see is not of much help (at least for me). I even debugged the
domain addition process in windows which failed in the NetUserAdd api with
the same error (NT_STATUS_NO_SUCH_USER).

The only think I can guess is that samba is not doing its job...

Thanks for your time,

Mikel


Edmundo Valle Neto wrote:

mikelOn escreveu:

Hi Alex,

I don´t think those modifiers would change anything but I have tried them
anyway and the objectclass is still not being added.

Thanks for the suggestion.


Alex Crow wrote:
  

On Wed, 2007-06-27 at 01:42 -0700, mikelOn wrote:


Hi all,

I finally found where the problem is. The samba attributes are not
being
added when the workstation entry is created. The sambaSamAccount
objectclass is missing. 


Why is it not being added if it is suppossed to be a windows
workstation?
Is
there a bug in the smbldap-useradd script when invoked with the -w
parameter?

  

You need both -a and -m passwd to smbldap-useradd for the samba
attributes to be added, IMHO.

Alex

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Again, those scripts are used only by tools that create accounts trough 
samba, like net or usrmgr, if you dont use it those lines will not be

used.

About the samba attributes, when you add a machine account the script 
add machine must NOT ADD SAMBA ATTRIBUTES, only posix, samba does that 
alone. Refer to the idealx documentation (if you really want that things 
work properly, reading the documentation is not an option), it was 
already discussed here and the documentation explains how to configure 
that and how it should work.


http://sourceforge.net/docman/display_doc.php?docid=33543group_id=166108

About knowing what is happening, put a log level 2 or 3 and try to join 
a machine. Look at the logs, it should say what exit the script gave and 
what samba tried to do.


Regards.

Edmundo Valle Neto


--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba






What does the your /etc/libnss-ldap.conf or /etc/ldap.conf look like?



--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] quickbooks 2003 multiuser

2007-06-26 Thread Ray Klassen

Gary Attaway wrote:

I apologize if this has already been asked. In my searching, I have not
found a clear answer.

How do you setup Samba for Quickbooks 2003 multi-user?

I appreciate any help.

Gary



for a access style database like quickbooks, I would turn off all oplocks...


--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] enable privileges = yes doesn't work

2007-05-24 Thread Ray Klassen
I can't do any domain level stuff as anybody but root. I've given the 
Domain Admins group SeMachineAccount Privilege for instance, but when I 
try to add a machine as a non root member of Domain Admins I get the 
error smbldap_open: cannot access LDAP when not root




enable privileges = yes  ---  is in my smb.conf

I'm running samba-3.0.24 (compiled from Source RPM) on Centos 5

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] can't browser a samba server from a specific pc in the network

2007-05-17 Thread Ray Klassen

)\(@sS wrote:

hello everyone,
i'm not even sure there is something wrong with samba here but im taking 
all

chances...
i have a linux samba server and 3 winXP prof pcs in my setup.

now from one of the winxp boxes i can not seem to access my shares on the
server. that is when i try to go through network neighborhood path.
the message that is returned is : \\stargaze is not accessible. You may not
have permission to use the shares... please contact sys admin etcetc. it
ends by stating 'the Server service is not started'.
well i did check the service setting in windows services and the Server
service is indeed running automatically. so no problem there,,

note that i have mapped a few of the shares on network drives to have quick
access to them from windows explorer.. i can STILL access these shares
!!!

i also tried logging on to my shares (ie with the same (username and pass)
from the other pc's and it works fine - thats why i am saying it might not
even be a samba misconfigure...

any ideas why i can access the shares though from network neighborhood?
thank you in advance for your help
nass


What's the state of your firewalling on that particular machine?



--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


Re: [Samba] Can't login to domain from Windows 2K clients

2007-05-17 Thread Ray Klassen

David Lynum wrote:

List,

I'm running Samba 3.01012 on Fedora Core 2.  A consultant setup the 
linux servers, including the one running samba.  The problem is that 
recently some w2k users, but not all, can no longer login to our 
domain.  They were able to login just fine before, but now can't.  Yes, 
they were already joined to the domain.  No changes were made to their 
user accounts.  The error message that comes from the Windows login 
screen is The system is unable to login you in because the domain 
joeblow is not available.  One of the reasons that this is a major 
problem is because our user use roaming profiles.  What I've done as a 
work around is to create a local windows account for the users.  I then 
run \\servername\share from run and they're able to mount the folders 
they need from the server running samba.  So yes, the shares are still 
working.  We also are running ldap servers.  It appears as though one of 
the ldap servers is the pdc?  An additional problem is that when I goto 
My Network Places - Entire Network - double click on Microsoft Windows 
Network, I can see the domain name for the workgroup.  But when I double 
click on it I receive the error message YouthUpRising is not 
accessible.  The network path was not found.  Also there are some w2k 
computers that are still a part of the workgroup workgroup.  I used to 
be able to see both the youthuprising domain and the workgroup 
workgroup when I went into my network places.  But now I can no longer 
see the workgroup workgroup.


I hope that my explanation is clear, at least clear than mud.  I need 
help on this asap.  The problem doesn't seem to be growing, but I need 
it resolved quickly.


Thanks


Here's a copy of a port of smb.conf.
# Global parameters
[global]
  workgroup = YOUTHUPRISING
   server string = Youth Uprising %h

   passdb backend = ldapsam:ldap://auth1.inside.youthuprising.org
   username map = /etc/samba/smbusers
   log level = 1
   syslog = 0
   log file = /var/log/samba/%m
   max log size = 50
   smb ports = 139 445
   name resolve order = wins bcast hosts
   printcap name = CUPS
   show add printer wizard = No
   logon script = scripts\logon.bat
   logon path = \\file\profiles\%U
   logon drive = X:
   domain logons = No
   domain master = No
#wins server = xx.xx.xx.xx
   ldap suffix = dc=inside,dc=youthuprising,dc=org
   ldap machine suffix = ou=People
   ldap user suffix = ou=People
   ldap group suffix = ou=Groups
   ldap idmap suffix = ou=Idmap
   ldap admin dn = cn=Manager,dc=inside,dc=youthuprising,dc=org
#   ldap port = 389
#   ldap server = auth0.youthuprising.org
   utmp = Yes
   idmap backend = ldap:ldap://auth1.inside.youthuprising.org
  idmap uid = 1-2
  idmap gid = 1-2
   printing = cups
   printer admin = Administrator, root
  security = user




Just a thought. you might try enabling wins support = yes and pointing 
your windows boxes at your server as the wins server.



--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Third time lucky. I need help with samba printers!

2007-05-11 Thread Ray Klassen
I'm not a complete noob. I've setup numerous samba boxes and have never 
seen this before. It happened after moving to a new server. my 
[printers} share is identical to the old server, as well as the [global] 
cups/printing  directives in smb.conf


when accessing printers via unc I get incorrect function
(I've gotten into the useful habit of connecting up my windows users to 
printers by simply doing [start] [run] \\server\printer [enter]. this 
does not work anymore) even though I can browse \\server for the printer 
and connect to it fine.


Server is a PDC with ldap back end. Printers are using cups.

Is there anyone who will respond?

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] Third time lucky. I need help with samba printers!

2007-05-11 Thread Ray Klassen

Further. I set log level to 3 and the entry :


 konica. is not a valid printer name

is very interesting. the dot after konica is nowhere in my config files.



I'm not a complete noob. I've setup numerous samba boxes and have never
seen this before. It happened after moving to a new server. my
[printers} share is identical to the old server, as well as the [global]
cups/printing  directives in smb.conf

when accessing printers via unc I get incorrect function
(I've gotten into the useful habit of connecting up my windows users to
printers by simply doing [start] [run] \\server\printer [enter]. this
does not work anymore) even though I can browse \\server for the printer
and connect to it fine.

Server is a PDC with ldap back end. Printers are using cups.

Is there anyone who will respond?

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] problems accessing printers by UNC path

2007-05-04 Thread Ray Klassen

Recently switched main samba servers and turned up a problem

CUPS printers are all published and can be connected to by browsing the 
server, but if, as I was used to doing, you connect by entering the UNC 
of the printer directly in the run dialog in windows. you get


\\server\printershare is not accessible. You might not have permission 
to use this network resource. Contact the administrator of this server 
to find out if you have access permissions


and the log on the samba box
says
printershare is not a valid printer name
couldn't find service printershare


I've set up lot's of samba boxes before and never seen this.


Non-printer UNC's work fine.

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba


[Samba] problems accessing printers by UNC path --Help!

2007-05-04 Thread Ray Klassen
Further. What's a concise way to describe this problem. It must have 
been encountered before. I usually google all of my issues and find 
answers that way. I don't even know what search terms would help me...




 Original Message 
Subject: [Samba] problems accessing printers by UNC path
Date: Fri, 04 May 2007 11:40:47 -0700
From: Ray Klassen [EMAIL PROTECTED]
To: samba@lists.samba.org

Recently switched main samba servers and turned up a problem

CUPS printers are all published and can be connected to by browsing the
server, but if, as I was used to doing, you connect by entering the UNC
of the printer directly in the run dialog in windows. you get

\\server\printershare is not accessible. You might not have permission
to use this network resource. Contact the administrator of this server
to find out if you have access permissions

and the log on the samba box
says
printershare is not a valid printer name
couldn't find service printershare


I've set up lot's of samba boxes before and never seen this.


Non-printer UNC's work fine.

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

--
Ray Klassen
Computer SysAdmin
MCC Supportive Care Services
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba