Displaying 20 results from an estimated 20000 matches similar to: "Upgrading from Samba 4.8.2 to 4.15.5"
2023 Jan 31
2
Upgrading from Samba 4.8.2 to 4.15.5
31.01.2023 08:55, Matt Savin via samba ?????:
> In group policies use DNS aliases, then you'll need to change only DNS
> entries for these aliases to point to a new host(s).
I'd say don't use simple dns aliases (cnames) in a DC, but use SPNs instead
(see samba-tool spn). This will manage CNAMEs too, and also manages the KRB
tickets and proper autentication of the server to the
2023 Jan 31
1
Upgrading from Samba 4.8.2 to 4.15.5
31.01.2023 18:33, Mark Foley via samba wrote:
> 1.01.2023 10:13, Michael Tokarev wrote:
>> I'd say don't use simple dns aliases (cnames) in a DC, but use SPNs instead
>
> In an AD Domain I mean, not in a DC.
> This bit is confusing. The DNS runs on the DC, so what do you mean "not in a DC"?
I wanted to write "don't use simple DNS aliases in an
2023 Jan 31
1
Upgrading from Samba 4.8.2 to 4.15.5
Mark,
In group policies use DNS aliases, then you'll need to change only DNS
entries for these aliases to point to a new host(s).
BR,
Matt
On Tue, Jan 31, 2023 at 12:52 AM Mark Foley via samba <samba at lists.samba.org>
wrote:
> On 1/30/2023 8:29 AM, Michael Tokarev via samba wrote:
> > 30.01.2023 06:14, Mark Foley via samba ?????:
> > [,,]
> >> 2. Let's
2023 Jan 31
1
The link (or more particularity the lack of a link) between AD SPNs and DNS
On Tue, 2023-01-31 at 10:13 +0300, Michael Tokarev via samba wrote:
> 31.01.2023 08:55, Matt Savin via samba ?????:
> > In group policies use DNS aliases, then you'll need to change only
> > DNS
> > entries for these aliases to point to a new host(s).
>
> I'd say don't use simple dns aliases (cnames) in a DC, but use SPNs
> instead
> (see samba-tool
2023 Jan 29
1
Upgrading from Samba 4.8.2 to 4.15.5
On 29/01/2023 13:31, Michael Tokarev via samba wrote:
> 29.01.2023 12:30, Rowland Penny via samba wrote:
> ..
>> Use another distro, such as Debian Bullseye, where you can get the
>> latest Samba from backports.
>
> It looks like Debian is the last major distro which builds Samba with
> Heimdal Kerberos
> instead of MIT Kerberos (and Ubuntu, which follows Debian in
2023 Jan 29
1
Upgrading from Samba 4.8.2 to 4.15.5
29.01.2023 16:51, Rowland Penny via samba wrote:
> From the distros you mentioned, the first two didn't supply Samba packages that could be provisioned as a DC, As far as I am aware, Slackware is the
> same. Arch did supply Samba packages that could be used as an AD DC, these used Samba's builtin Heimdal, are you saying that this has changed and they
> now use MIT ?
I
2023 Jan 29
1
Upgrading from Samba 4.8.2 to 4.15.5
On 29/01/2023 07:53, Mark Foley via samba wrote:
> On Sat, 28 Jan 2023 12:42:17 -0500 Mark Foley wrote:
>
> Thanks for that extensive response!
>
> --Mark
>
> On Sat Jan 28 05:12:23 2023 Rowland Penny via samba <samba at lists.samba.org> wrote
>>
>> [deleted]
>
>> You should be able to find out if your Samba packages were built with
>> MIT
2023 Jan 29
3
Upgrading from Samba 4.8.2 to 4.15.5
On 29/01/2023 14:00, Michael Tokarev via samba wrote:
> 29.01.2023 16:51, Rowland Penny via samba wrote:
>
>> ?From the distros you mentioned, the first two didn't supply Samba
>> packages that could be provisioned as a DC, As far as I am aware,
>> Slackware is the same. Arch did supply Samba packages that could be
>> used as an AD DC, these used Samba's
2023 Jan 29
1
Upgrading from Samba 4.8.2 to 4.15.5
On Sat, 28 Jan 2023 12:42:17 -0500 Mark Foley wrote:
Thanks for that extensive response!
--Mark
On Sat Jan 28 05:12:23 2023 Rowland Penny via samba <samba at lists.samba.org> wrote
>
> [deleted]
> You should be able to find out if your Samba packages were built with
> MIT by running:
>
> smbd -b | grep HAVE_LIBKADM5SRV_MIT
>
> You should get nothing returned if
2023 Jan 08
1
Issues demoting a samba DC.
On 08/01/2023 11:04, Michael Tokarev via samba wrote:
> Hello!
>
> I'm trying to remove a DC from our samba domain (samba 4.17.4).
> It was the primary controller (with FSMO roles), - I successfully
> transferred the roles to another DC.? Now it's time to demote:
>
> ai# samba-tool domain demote -U mjt-adm
> Using svdcp.tls.msk.ru as partner server for the
2023 Jan 08
2
Issues demoting a samba DC.
08.01.2023 14:21, Rowland Penny via samba wrote:
..
>> ai# samba-tool domain demote -U mjt-adm
..
>> ERROR(ldb): Error while renaming CN=AI,OU=Domain Controllers,DC=tls,DC=msk,DC=ru to CN=AI,CN=Computers,DC=tls,DC=msk,DC=ru - LDAP error 50
>> LDAP_INSUFFICIENT_ACCESS_RIGHTS -? <acl:access_denied renaming CN=AI,OU=Domain Controllers,DC=tls,DC=msk,DC=ru> <>
..
> If
2024 Apr 05
1
samba as a domain member: a way to ignore groups?
On Fri, 5 Apr 2024 17:24:33 +0300
Michael Tokarev <mjt at tls.msk.ru> wrote:
> 05.04.2024 17:16, Rowland Penny via samba wrote:
> > On Fri, 5 Apr 2024 16:43:42 +0300
> > Michael Tokarev via samba <samba at lists.samba.org> wrote:
> >
> >> Hi!
> >>
> >> We had stand-alone anonymous samba server serving a read-only share
> >> as
2024 Apr 05
1
samba as a domain member: a way to ignore groups?
05.04.2024 17:50, Rowland Penny via samba:
> On Fri, 5 Apr 2024 17:24:33 +0300
> Michael Tokarev <mjt at tls.msk.ru> wrote:
>
>> 05.04.2024 17:16, Rowland Penny via samba wrote:
>>> On Fri, 5 Apr 2024 16:43:42 +0300
>>> Michael Tokarev via samba <samba at lists.samba.org> wrote:
>>>
>>>> Hi!
>>>>
>>>> We had
2023 Jan 29
1
Upgrading from Samba 4.8.2 to 4.15.5
On 1/29/23 09:12, Rowland Penny via samba wrote:
>
>
> On 29/01/2023 14:00, Michael Tokarev via samba wrote:
>> 29.01.2023 16:51, Rowland Penny via samba wrote:
>>
>>> ?From the distros you mentioned, the first two didn't supply Samba
>>> packages that could be provisioned as a DC, As far as I am aware,
>>> Slackware is the same. Arch did
2015 Jul 29
2
CentOS 7.1 + qemu-kvm-ev + SLIC acpitable windows bug workaround
On 29.07.2015 21:34, Nux! wrote:
> Yes, you can.
> In fact you can use the binaries from the ovirt repo itself, no need to rebuild.
Thank you!
In fact - I can't use raw binaries from the ovirt repo itself,
because these qemu-kvm binaries contains one bug,
which is already fixed in Debian:
If you want to migrate Windows from hardware node
to VM using CentOS 7.1 on hardware node and
2023 Jan 08
1
Issues demoting a samba DC.
08.01.2023 18:54, Michael Tokarev wrote:
...
> And nope, after removing this stale A gc._msdcs record from samba DNS, it
> still does not work and still logs the same error message, apparenlty when
> trying to log in to the other DC for replication:
>
> [2023/01/08 18:50:43.390974,? 0] ../../source4/librpc/rpc/dcerpc_util.c:681(dcerpc_pipe_auth_recv)
> ? Failed to bind to uuid
2024 Apr 05
1
samba as a domain member: a way to ignore groups?
05.04.2024 17:16, Rowland Penny via samba wrote:
> On Fri, 5 Apr 2024 16:43:42 +0300
> Michael Tokarev via samba <samba at lists.samba.org> wrote:
>
>> Hi!
>>
>> We had stand-alone anonymous samba server serving a read-only share
>> as guest account. It worked well but had a few strange issues (like
>> lots of noise in logs about bad smb2 signature).
2023 Jan 31
1
Log errors on domain member
Sorry, did not send it to the list (damned Thunderbird)...
On 31.01.2023 18:14, Michael Tokarev via samba wrote:
> 31.01.2023 09:59, Peter Milesson via samba ?????:
>
>> The journal on a AD domain member server is cluttered with permission
>> denied entries of this message pair:
>>
>> ??? Jan 31 07:02:26 konsrvfast smbd[436004]: [2023/01/31
>> ???
2023 Jan 08
1
Issues demoting a samba DC.
On 08/01/2023 14:19, Michael Tokarev via samba wrote:
> 08.01.2023 14:21, Rowland Penny via samba wrote:
> ..
>>> ai# samba-tool domain demote -U mjt-adm
> ..
>>> ERROR(ldb): Error while renaming CN=AI,OU=Domain
>>> Controllers,DC=tls,DC=msk,DC=ru to
>>> CN=AI,CN=Computers,DC=tls,DC=msk,DC=ru - LDAP error 50
>>>
2010 Aug 17
0
[trivial patch] add newline after help output
Without this final newline the help output
looks quite ugly...
Signed-Off-By: Michael Tokarev <mjt at tls.msk.ru>
if that's really needed for such trivial things...
Thanks!
/mjt
--- syslinux-4.02/libinstaller/syslxopt.c.orig 2010-07-21 23:33:13.000000000 +0400
+++ syslinux-4.02/libinstaller/syslxopt.c 2010-08-17 22:37:24.955852630 +0400
@@ -125,5 +125,5 @@ void __attribute__