search for: _on_a_samba_ad_dc

Displaying 20 results from an estimated 36 matches for "_on_a_samba_ad_dc".

2017 Apr 18
2
Centos 7 Samba4 SSL/TLS Support?
Hi. Following this document: https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC I have a Centos 7.x with samba4.4.4 with openldap 2.4.40. If I run the command: smbd -b | grep "ENABLE_GNUTLS" I don't get any answer, this mean that samba doesn't have ssl support? Thanks for your time. -- LIving the dream...
2017 Mar 10
2
Replication with a self-signed certificate
Hello, I just configured a three-site DCs setup with Samba 4.6.0, and replication worked great. But then I added a custom cert to one of the DCs to authenticate various apps against it. I used this wiki https://wiki.samba.org/index. php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC Now I can authenticate my apps over LDAPS against my DC, but broke replication. How do I need to configure replication to work with a self-signed cert? Thanks, -Mike
2017 Mar 11
2
Replication with a self-signed certificate
...-site DCs setup with Samba 4.6.0, and > > replication worked great. > > But then I added a custom cert to one of the DCs to authenticate > > various apps against it. I used this wiki https://wiki.samba.org/in > > de > > x. > > php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC > > > > Now I can authenticate my apps over LDAPS against my DC, but broke > > replication. > > > > How do I need to configure replication to work with a self-signed > > cert? > > The two are not related - replication is not over LDAP or LDAPS, but >...
2018 Aug 08
2
LDAPS is not working
Hi, after a successfully migrating my NT4 with OpenLDAP to a Samba4 AD...I got a problem. Like in the sambawiki tutorial (https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC) I tried to configure LDAPS. I used the auto-configured certs. They are located in "/var/lib/samba/private/tls". My smb.conf: # Global parameters [global] netbios name = PDC realm = COMPANY.COM workgroup = COMPANY server role = active directory domain cont...
2016 Sep 03
1
Samba4 and sssd authentication not working due "Transport encryption required."
https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC <https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC> > On Sep 3, 2016, at 7:59 AM, Fosiul Alam via samba <samba at lists.samba.org> wrote: > > Hi Both > Thanks > > from Samba4 side i need this help, I can see that sshd has this opti...
2018 Sep 05
2
Authenticating against Samba 4 AD LDAP service
Also: -H ldap://10.100.0.4 should probably be ldaps://URI You can potentially this in smb.conf, but that is definitely not recommended. https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC Kris Lou klou at themusiclink.net On Wed, Sep 5, 2018 at 2:10 AM, Rowland Penny via samba < samba at lists.samba.org> wrote: > On Wed, 05 Sep 2018 15:46:04 +0700 > Konstantin Boyandin via samba <samba at lists.samba.org> wrote: > > > Hello, > > > > One of...
2020 Nov 09
2
How to configure samba domain member to use LDAPS instead of LDAP
Hello, is there any documented procedure to configure a samba domain member (AD windows domain) to use LDAPS instead of LDAP Thanks Andrea
2020 Nov 11
2
Samba 4.11 with SSL authority CA role
I have OpenSSL forgenrate the CA root file in my server and work fine. My question is, ?howto i say to Samba (configuration) for work with CA certificates? . I dont find information about this. Thanks. Saludos. --- Miguel El mar., 10 nov. 2020 a las 15:22, S?rgio Basto (<sergio at serjux.com>) escribi?: > On Tue, 2020-11-10 at 14:48 -0300, Miguel Angel Coa M. via samba wrote: >
2020 Nov 09
3
How to configure samba domain member to use LDAPS instead of LDAP
...ucciarre' via samba wrote: >> >> is there any documented procedure to configure a samba domain member >> (AD windows domain) to use LDAPS instead of LDAP > The only documentation I know of is here: > > https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC > > > But it is meant for a DC. > > Are you talking about using ldaps with ldap searches ? If so, then > don't, use kerberos instead, it is even more secure. > > Rowland > > >
2019 Apr 09
2
Possible incorrect file permissions in documentation for setting up Samba with LDAP(S)?
...files needed for LDAP via TLS all need "special permissions" - and mentions to delete old files without the required permissions to force file renewal. Yet in the official Samba documentation for setting up LDAPS here (https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC) it says only to set these special permissions on ONE of the generated certificate *.pem files - the private key file. Is this definitely correct? Should we not set root owner on the additional cert.pem and ca.pem too? I ask because I wanted to flag this. It seems like a contradiction and I a...
2019 Apr 05
6
Enabling LDAPS in Samba in a dual-DC setup
...AD DC ad1 and a backup AD DC ad2, running on Samba 4.5.16-Debian on Raspbian. I would now like to enable LDAPS so my users can authenticate in other non Samba services using Active Directory. From reading the documentation here: https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC I understand that for the most basic LDAPS setup using the pre-existing self-signed certificate I need only add the following lines to my smb.conf to enable this: tls enabled  = yes tls keyfile  = tls/key.pem tls certfile = tls/cert.pem tls cafile   = tls/ca.pem My questions related to this are...
2020 Aug 06
4
Problem with intermediate certificate (tls cafile)
If I were guessing, based on some experience with certificate usage in other apps, concatenate your certificate and intermediate certificates into a single file which is then your "tls certfile" then point "tls cafile" to your issuers proper CA or just to your distro's CA bundle, e.g /etc/pki/tls/certs/ca-bundle.crt. Nick On 06/08/2020 16:36, MAS Jean-Louis via samba
2019 Sep 01
6
TLS questions
I am currently NOT using SSL on my Samba domain. While reading "Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC" and thinking about implementing. I'm having trouble "getting my head" around what certificates go where. Simply put, I am not clear as to generating certificates on the clients and then copy which files to to the server or vice versa? What happens when certificates expire? Pe...
2017 Mar 12
0
Replication with a self-signed certificate
...; > replication worked great. > > > But then I added a custom cert to one of the DCs to authenticate > > > various apps against it. I used this wiki https://wiki.samba.org/ > > > in > > > de > > > x. > > > php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC > > > > > > Now I can authenticate my apps over LDAPS against my DC, but > > > broke > > > replication. > > > > > > How do I need to configure replication to work with a self-signed > > > cert? > > > > The two are not rel...
2017 Apr 18
2
Centos 7 Samba4 SSL/TLS Support?
...samba.org> wrote: > On Tue, 18 Apr 2017 10:21:33 -0700 > Alberto Moreno via samba <samba at lists.samba.org> wrote: > > > Hi. > > > > Following this document: > > > > > > https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_ > (LDAPS)_on_a_Samba_AD_DC > > > > I have a Centos 7.x with samba4.4.4 with openldap 2.4.40. > > You don't have an AD DC! > > > > > If I run the command: > > > > smbd -b | grep "ENABLE_GNUTLS" > > > > I don't get any answer, this mean that samba d...
2017 May 15
0
Second DC won't start LDAP daemon
...nabled=no" in the config file. With "tls enabled=yes" (or nothing, since it's the default) I get: "Child 24011 (ldap) terminated with signal 4" I tried generating a self-signed certificate as per: > https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC Unfortunately, the only effect is that "Attempting to autogenerate TLS self-signed keys for https for hostname 'XXX.xxxxx.xxxxxxxx.xx'" changes to "TLS autogeneration skipped - some TLS files already exist". Then I get the same error as above. Any suggestion? TIA....
2018 Apr 17
1
tls verify peer with custom self-signed certificate
On 4/17/2018 3:56 AM, Marco Gaiarin via samba wrote: > Mandi! lingpanda101 via samba > In chel di` si favelave... > >>     When using a custom self-signed certificate, what is the appropriate >> value for 'tls verify peer ='? > ...AFAIk the same for every certificates; the CA's certificates have to > be in ''central store'', or have to be
2019 May 29
2
TLS 1.2 Support Samba-AD
Hi, Does Samba-AD support TLS 1.2 for LDAPS? If yes, can some one give more details on its configuration? Regards, Ananth
2020 Aug 10
0
[Solved] Problem with intermediate certificate (tls cafile)
...0 (ok) Note : You're quite right Christopher about not using localhost. I retested with the FQDN but without the modifications Nick suggested above, It doesn't work either. By the way, should the Samba's documentation (https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC#Using_a_trusted_certificate) be modified to explain that particular point ? Thanks -- Jean Louis Mas
2023 Jan 28
0
LDAPS , TLS
The wiki has a page https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC that discusses LDAPS but I am going to assume this only applies if using Samba as a domain controller? I also see there is a setting for "tls enabled" in the smb.conf file as well along with some other settings for configuring TLS. Can/should any of these be used when using "securi...