Miguel Medalha | 1 Feb 2009 03:36
Picon
Favicon

Re: User Manager for Domains -- Groups not showing


> 3.0.34 is now installed. no change. 'net rpc list groups' returns
> nothing, while 'net rpc group members <group>' returns the correct
> data
>
>   

The correct syntax is 'net rpc group list' ...
--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

John Casterlin | 1 Feb 2009 17:54
Picon

IMAP Authentication

Does anyone have any experience using an IMAP server to authenticate Samba
users? The idea is to control viability and read/write access to file/print
services using an Internal only email server.

Thanks, John 

--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

simo | 1 Feb 2009 19:11
Picon
Favicon

Re: IMAP Authentication

On Sun, 2009-02-01 at 16:54 +0000, John Casterlin wrote:
> Does anyone have any experience using an IMAP server to authenticate Samba
> users? The idea is to control viability and read/write access to file/print
> services using an Internal only email server.

It's not possible to use external, password based, authentication
services, unless you use clear text authentication, which is
incompatible with domain memberships.

Simo.

-- 
Simo Sorce
Samba Team GPL Compliance Officer <simo <at> samba.org>
Principal Software Engineer at Red Hat, Inc. <simo <at> redhat.com>

--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Athunye | 1 Feb 2009 20:33
Picon

Groups and permissions.


I was reading this in mount.cifs man: "It is possible to set the 
mode for mount.cifs to setuid root to allow non-root users to 
mount shares to directories for which they have write 
permission." 
Suppose I have /mnt/docs, and the docs directory is in 
the group "files". I am not the owner of that directory, but instead I am in 
the group "files" , should I be able to mount that share as user ?

-- 
View this message in context: http://www.nabble.com/Groups-and-permissions.-tp21779318p21779318.html
Sent from the Samba - General mailing list archive at Nabble.com.

--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

kb9vqf | 2 Feb 2009 02:50
Favicon

Samba 4--are multiple domain administrators possible?

I have a quick question for someone knowledgeable in Samba 4:
I recently set up a Samba 4 test server, utilizing the built-in LDAP
server, and joined an Windows XP client to it.  After logging in with the
precreated "administrator" account I then attempted to add another user
and grant that user domain administrator privileges by adding him to the
"Domain Admins" group.

When I logged in under the new user, I was completely locked out of any
administrative tasks, even though that user was showing up under the
"Domain Admins" group.  Does Samba 4 not yet understand multiple domain
administrators, or did I do something wrong?

Thank you for any assistance you can offer.  Samba 4 is quite impressive
even in alpha!

Timothy Pearson

--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

kb9vqf | 2 Feb 2009 07:19
Favicon

Re: Samba 4--are multiple domain administrators possible?

I tried granting the user admin privileges via the Windows XP domain user
management console (after adding them to the "Domain Admins" group), but
this had no effect.

Do I have to do something permissions-wise on the Linux end?

Thank you,

Timothy Pearson

> you can add a person to a domain admin group, but if you don't grant them
> privileges to do admin task he/she will not be able to do the
> administration
> that you want so grant him/her the task to admin and you will see that the
> status will change
>
> --------------------------------------------------
> From: <kb9vqf <at> pearsoncomputing.net>
> Sent: 02/01/2009 8:50 PM
> To: <samba <at> lists.samba.org>
> Subject: [Samba] Samba 4--are multiple domain administrators possible?
>
>> I have a quick question for someone knowledgeable in Samba 4:
>> I recently set up a Samba 4 test server, utilizing the built-in LDAP
>> server, and joined an Windows XP client to it.  After logging in with
>> the
>> precreated "administrator" account I then attempted to add another user
>> and grant that user domain administrator privileges by adding him to the
>> "Domain Admins" group.
>>
(Continue reading)

Ray Klassen | 2 Feb 2009 07:45
Picon

Re: IMAP Authentication

No. But authenticating both against LDAP makes good sense....

On Sun, Feb 1, 2009 at 8:54 AM, John Casterlin <jcaster2000 <at> comcast.net> wrote:
> Does anyone have any experience using an IMAP server to authenticate Samba
> users? The idea is to control viability and read/write access to file/print
> services using an Internal only email server.
>
> Thanks, John
>
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>
--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Robert Schetterer | 2 Feb 2009 08:31

Re: IMAP Authentication

Ray Klassen schrieb:
> No. But authenticating both against LDAP makes good sense....
> 
> On Sun, Feb 1, 2009 at 8:54 AM, John Casterlin <jcaster2000 <at> comcast.net> wrote:
>> Does anyone have any experience using an IMAP server to authenticate Samba
>> users? The idea is to control viability and read/write access to file/print
>> services using an Internal only email server.
>>
>> Thanks, John
>>
>> --
>> To unsubscribe from this list go to the following URL and read the
>> instructions:  https://lists.samba.org/mailman/options/samba
>>
Hi, with dovecot you can use winbind
and ldap should work too

http://wiki.dovecot.org/Authentication/Mechanisms/Winbind?highlight=(winbind)
-- 
Best Regards

MfG Robert Schetterer

Germany/Munich/Bavaria
--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Jacky Wu | 2 Feb 2009 12:24
Picon

How to setup the policy "Domain controller: Refuse machine account password changes" in SAMBA`

Dear All,

When a workstation is joined a domain, its machine account password change
every 30 days for Windws 2K and XP pro. There is a policy in Windows domain
controller "Domain controller: Refuse machine account password changes". If
enabled, the policy can avoid workstation account password periodic change.

Can we set up similar policy in samba configuration file to 'refuse machine
account password changes'?

Thank you!

-- 
Best regards,
Jacky Wu
--

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Alejandro Escanero Blanco | 2 Feb 2009 14:14
Picon

Large file problem with version 3.0.34

I have a problem with large files (>2 Gb) in a Debian sarge based system.
I install samba 3.0.34 with this configuration:
./configure --with-smbwrapper --with-ldap --with-automount 
--with-smbmount --with-pam --with-pam_smbpass --with-ldapsam 
--with-syslog --without-profiling-data --with-quotas --with-sys-quotas 
--with-libsmbclient --with-acl-support --with-utmp --with-vfs 
--with-winbind --localstatedir='/var/lib/samba/locks' 
--prefix='/usr/local/samba' --mandir='${prefix}/man' 
--exec_prefix='${prefix}' --sbindir='${exec_prefix}/sbin' 
--bindir='${exec_prefix}/bin' --sysconfdir='/etc/samba' 
--with-configdir='/etc/samba' --with-lockdir='/var/lib/samba/locks' 
--with-logfilebase='/var/log/samba' --libdir='${exec_prefix}/lib' 
--with-piddir='/var/lib/samba/locks' 
--with-privatedir='/etc/samba/private' --with-swatdir='${prefix}/swat' 
--enable-cups

Kernel is a 2.6.8
I uploaded two files of 2,2Gb and 2,9 Gb and i can't get it from a 
Windows XP or a smbclient.
The log (level 10) says:

[2009/02/02 09:40:15, 3] smbd/process.c:switch_message(927)
  switch message SMBntcreateX (pid 31174) conn 0x8544638
[2009/02/02 09:40:15, 4] smbd/uid.c:change_to_user(226)
  change_to_user: Skipping user change - already user
[2009/02/02 09:40:15, 5] smbd/filename.c:unix_convert(147)
  unix_convert called on file "PATH/FILE.zip"
[2009/02/02 09:40:15, 2] smbd/dosmode.c:unix_mode(90)
  unix_mode(PATH/FILE.zip) inheriting from PATH
[2009/02/02 09:40:15, 2] smbd/dosmode.c:unix_mode(99)
(Continue reading)


Gmane