Rowland penny
2019-Nov-29 09:29 UTC
[Samba] security=domain fails after upgr. to 4.9, winbind doesn't help
On 29/11/2019 09:13, Ralph Boehme via samba wrote:> On 11/29/19 10:04 AM, Frank Steiner via samba wrote: >> Hi Rowland, >> >> thanks for all your input! >> >> Rowland penny via samba wrote: >> >>> Could it be Selinux or Apparmor (not sure which SLES uses) stopping smbd >>> contacting winbindd ? >> No, none of these is running on our systems. >> >>> Could the SLES Samba packages be wrong ? >> Yes, that's a possibility. I opened a SR with SUSE support, but they >> usually take some time to analyse and propose a solution. I asked here >> because I thought there might be an obvious mis-configuration that >> I did and that expers on this list would immediately see :-) But >> if that's not then I guess an error in the SuSE packages is likely. >> >>> Have you tried starting smbd and then winbind ? >> Yes, in all combinations and restarts etc. Nothing helped :-( > which doesn't surprise me. Wasn't "security=domain" removed in that > timeframe?No, it is still there, 'security = domain' == Nt4-style PDC, 'security = ADS' == AD DC> > You may want to switch to security=ads.wWell yes, but this would entail a classicupgrade Rowland
Ralph Boehme
2019-Nov-29 09:57 UTC
[Samba] security=domain fails after upgr. to 4.9, winbind doesn't help
On 11/29/19 10:29 AM, Rowland penny via samba wrote:> On 29/11/2019 09:13, Ralph Boehme via samba wrote: >> On 11/29/19 10:04 AM, Frank Steiner via samba wrote: >>> Hi Rowland, >>> >>> thanks for all your input! >>> >>> Rowland penny via samba wrote: >>> >>>> Could it be Selinux or Apparmor (not sure which SLES uses) stopping >>>> smbd >>>> contacting winbindd ? >>> No, none of these is running on our systems. >>> ? >>>> Could the SLES Samba packages be wrong ? >>> Yes, that's a possibility. I opened a SR with SUSE support, but they >>> usually take some time to analyse and propose a solution. I asked here >>> because I thought there might be an obvious mis-configuration that >>> I did and that expers on this list would immediately see :-) But >>> if that's not then I guess an error in the SuSE packages is likely. >>> ? >>>> Have you tried starting smbd and then winbind ? >>> Yes, in all combinations and restarts etc. Nothing helped :-( >> which doesn't surprise me. Wasn't "security=domain" removed in that >> timeframe? > No, it is still there, 'security = domain' == Nt4-style PDC, 'security > ADS' == AD DCoops, sorry, got confused, I remembered *something* with domain was removed, albeit that was just the auth_domain backend and not the security=domain mode. Sorry for the confusion! :) -slow -- Ralph Boehme, Samba Team https://samba.org/ Samba Developer, SerNet GmbH https://sernet.de/en/samba/ GPG-Fingerprint FAE2C6088A24252051C559E4AA1E9B7126399E46
Rowland penny
2019-Nov-29 10:00 UTC
[Samba] security=domain fails after upgr. to 4.9, winbind doesn't help
On 29/11/2019 09:57, Ralph Boehme wrote:> On 11/29/19 10:29 AM, Rowland penny via samba wrote: >> On 29/11/2019 09:13, Ralph Boehme via samba wrote: >>> On 11/29/19 10:04 AM, Frank Steiner via samba wrote: >>>> Hi Rowland, >>>> >>>> thanks for all your input! >>>> >>>> Rowland penny via samba wrote: >>>> >>>>> Could it be Selinux or Apparmor (not sure which SLES uses) stopping >>>>> smbd >>>>> contacting winbindd ? >>>> No, none of these is running on our systems. >>>> >>>>> Could the SLES Samba packages be wrong ? >>>> Yes, that's a possibility. I opened a SR with SUSE support, but they >>>> usually take some time to analyse and propose a solution. I asked here >>>> because I thought there might be an obvious mis-configuration that >>>> I did and that expers on this list would immediately see :-) But >>>> if that's not then I guess an error in the SuSE packages is likely. >>>> >>>>> Have you tried starting smbd and then winbind ? >>>> Yes, in all combinations and restarts etc. Nothing helped :-( >>> which doesn't surprise me. Wasn't "security=domain" removed in that >>> timeframe? >> No, it is still there, 'security = domain' == Nt4-style PDC, 'security >> ADS' == AD DC > oops, sorry, got confused, I remembered *something* with domain was > removed, albeit that was just the auth_domain backend and not the > security=domain mode. Sorry for the confusion! :) > > -slow >Oh good, it isn't just me that gets confused then :-) Rowland
Possibly Parallel Threads
- security=domain fails after upgr. to 4.9, winbind doesn't help
- security=domain fails after upgr. to 4.9, winbind doesn't help
- security=domain fails after upgr. to 4.9, winbind doesn't help
- security=domain fails after upgr. to 4.9, winbind doesn't help
- security=domain fails after upgr. to 4.9, winbind doesn't help