Displaying 20 results from an estimated 24 matches for "adgroups".
Did you mean:
adgroup
2015 Apr 16
2
Group Mapping: All Users from a Domain group should be able to write to a local group
Hello Mailinglist,
I have created a local user "localuser" who is in the local group
"localgroup"
$ id
uid=1001(localuser) gid=1001(localgroup) groups=1001(localgroup)
My machine authenticates against Active Directory - works
The AD-User "aduser" belongs to a domain group "adgroup"
$ id
uid=6161(aduser) gid=5513(dom?nen-benutzer)
2010 Apr 29
1
Samba and Active directory groups
Hi list,
I have successfully authenticated active directory users with samba. Now I need to create some Active directory security groups and authenticate and redirect those users to a specific directory.
Ex:
IT_GROUP - user x , user y
FIN_group - user a, user b
If the user x , access the samba server, that user will be redirected to the specific directory (that's in the samba stanza).
This
2019 Feb 08
2
Permission issue
Hi,
We did a classicupgrade of our Ubuntu Server (4.3.11, TDB), the server DC5 also host shares. Post the migration we are seeing some permission issues.
When trying to give permission to a domain group/user to folder/file we get the following
chown "LIN\\myadmin:LIN\\adgroup" adtest/
chown: invalid user: 'LIN\\myadmin:LIN\\adgroup'
wbinfo --ping-dc : checking the NETLOGON
2006 May 26
0
Local groups with ADS users
Hi everybody,
I've configured SAMBA for joining the ADs of the place where i work, and
everything is working fine. This means that with "getent passwd" i see
all the local and the ADS users, i am also able to log into my machine
via ssh by using the pam_winbind module and so on.
I've configured some directories that are shared by samba and are
property of their owners and
2017 Aug 10
0
getent group adgroup not showing members
Hello,
I'm bringing up a AD domain member server on RHEL 7.4 which provides
packages with samba 4.6.2. I've joined the domain and cannot seem to get
this command to provide a list of group members:
getent group adgroupname
what comes back is just
adgroupname:x:gid:
On another machine running RHEL 6.8, the same getent returns a full listing:
adgroupname:*:gid:user1,user2,user3,etc
id
2017 Nov 06
1
ntfs user mappings?
...rmap ]; then
rm -f /tmp/ntfs-3g.usermap
fi
WBINFO=$(which wbinfo)
if [ -z "${WBINFO}" ]; then
echo
echo "Cannot find 'wbinfo', is it installed?"
echo "Cannot continue...Exiting"
exit 1
fi
## Get users
ADUSERS=$(${WBINFO} -u)
## Get groups
ADGROUPS=$(${WBINFO} -g)
while IFS= read -r line
do
SID=$(${WBINFO} -n "$line" | awk '{print $1}')
echo "$line::$SID" >> /tmp/ntfs-3g.usermap
done <<< "$ADUSERS"
while IFS= read -r line
do
SID=$(${WBINFO} -n "$line" | awk '{print $1}...
2019 Feb 08
0
Permission issue
On Fri, 8 Feb 2019 06:22:05 +0000
Praveen Ghimire via samba <samba at lists.samba.org> wrote:
> Hi,
>
> We did a classicupgrade of our Ubuntu Server (4.3.11, TDB), the
> server DC5 also host shares. Post the migration we are seeing some
> permission issues.
>
> When trying to give permission to a domain group/user to folder/file
> we get the following
>
>
2019 Feb 08
4
Permission issue
Hi Rowland,
The user's ID range would have been below 3600, the current max rid is 3506
The links have been setup following this link, then restarted the samba-ad-dc service
https://wiki.samba.org/index.php/Libnss_winbind_Links
I followed the following to configure the winbindd stuff,
https://wiki.samba.org/index.php/Configuring_Winbindd_on_a_Samba_AD_DC
template shell = /bin/bash
2015 Apr 05
0
Samba as AD member can not validate domain user
On 05/04/15 19:42, jd at ionica.lv wrote:
> I am sorry for many P.S.
>
>>> When domain user tries to access file server (samba4, member of AD
>>> domain)
>>> server logs such error:
>>>
>>> 2015/04/05 21:13:01.095178, 1]
>>> ../source3/auth/user_krb5.c:164(get_user_from_kerberos_info)
>>> Username DOMAINwusername is invalid on
2007 Mar 28
0
Active Directory Groups within /etc/group
I apologize if I'm going down the wrong avenue here...
I have Samba/Winbind working to authenticate AD accounts to my Linux
server. I can perform getent passwd ADUser and view the user
credentials as well as using getent group ADGroup to view AD groups.
When I modify /etc/group I can add ADUser to the file and the ADUser
will have the security desired. However when I add an ADGroup to
2013 May 06
0
net rpc group add & by/pass the group scope value
Hi folks,
Does anyone have a clue of how to by/pass the group scope value when creating a group in AD by using the net tools?
I can delete an AD group, add/remove members from a group but I can't create a group. I reckon it's because of the group scope value (even Power Shell/New-ADGroup prompts for it)
$ net -U $ADMIN_USER -S $DC_ADDRESS rpc group add $GROUP_NAME -c $OU
Error
2015 Jan 29
3
rfc2307 deprecated in Windows 2012 R2?
It is actually rather easy to set the attributes via powershell, and
that is probably the best way to add them in a Server 2012 R2
environment.
I wrote a powershell script to do this automatically for users and
groups in an entire domain that should be pretty generic to be reused.
It also mirrors the logic used in automatic winbind UID/GID generation
to be able to coexist in an environment where
2015 Jan 29
2
rfc2307 deprecated in Windows 2012 R2?
Ok, it's here: http://pastebin.com/JEnr5wUq
The id_offset is that value because i initially didn't use rfc2307
attributes, but instead
On 29 January 2015 at 23:27, Tim <lists at kiuni.de> wrote:
> @Hans-Kristian:
> I'd like to see it. How did you automate this?
>
> @Andrew:
> In another thread I suggested to set the rfc2307 info automatically when a
> domain
2015 Apr 05
2
Samba as AD member can not validate domain user
I am sorry for many P.S.
>> When domain user tries to access file server (samba4, member of AD domain)
>> server logs such error:
>>
>> 2015/04/05 21:13:01.095178, 1]
>> ../source3/auth/user_krb5.c:164(get_user_from_kerberos_info)
>> Username DOMAINwusername is invalid on this system
>>
>> [2015/04/05 21:13:01.095200, 1]
>>
2015 Jan 30
3
rfc2307 deprecated in Windows 2012 R2?
On 29/01/15 22:56, Hans-Kristian Bakke wrote:
> Something went wrong and the message got sent before it was finished.
> Here is the complete one:
>
> Ok, it's here: http://pastebin.com/JEnr5wUq
>
> The id_offset is that value because i initially didn't use rfc2307
> attributes, but instead had
>
> idmap config EXAMPLE : range = 300000-499999
>
> in
2004 Oct 22
0
share permissions for AD groups
Hello,
We have following environment
Win2k AD with "endless" number of groups (should be more then 1000) , on the
other site solaris9 samba3.0.7 compiled with all relevant optins , winbind ,
ads and so on , installations is ok , we joined AD domain w.o problems ,
getent * shows all like expected
same for wbinfo
The big problem remaining is , we want to restrict access to shares to
2004 Oct 22
0
AW: share permissions for AD groups
> Hello,
>
> We have following environment
>
> Win2k AD with "endless" number of groups (should be more then 1000) , on
> the other site solaris9 samba3.0.7 compiled with all relevant optins ,
> winbind , ads and so on , installations is ok , we joined AD domain w.o
> problems , getent * shows all like expected
> same for wbinfo
>
> The big problem
2017 Nov 05
3
ntfs user mappings?
On Sat, 4 Nov 2017 18:42:36 -0600
Jeff Sadowski <jeff.sadowski at gmail.com> wrote:
> I decided to continue trying the ldap route as well
>
> littlehex2int()
> {
> hex=$1
> hex_chunk=$(echo ${hex}|cut -c$2-$3)
> little=$(echo ${hex_chunk}|awk '{print
> substr($0,7,2)substr($0,5,2)substr($0,3,2)substr($0,1,2)}')
> echo "ibase=16; ${little}" |
2015 Jan 29
0
rfc2307 deprecated in Windows 2012 R2?
@Hans-Kristian:
I'd like to see it. How did you automate this?
@Andrew:
In another thread I suggested to set the rfc2307 info automatically when a domain is provisioned with --use-rfc2307. Possibly by an additional parameter.
This would make things easier in my eyes.
Thanks
Tim
Am 29. Januar 2015 22:02:14 MEZ, schrieb Hans-Kristian Bakke <hkbakke at gmail.com>:
>It is actually
2007 Apr 26
1
Joining Samba 3.24 to 2003 ADS
I'm hoping someone can give me a clue what I am doing wrong here,
Running Debian Etch AMD64, I followed the samba wiki at:
http://wiki.samba.org/index.php/Samba_
<http://wiki.samba.org/index.php/Samba_&_Active_Directory#Prerequisites>
&_Active_Directory#Prerequisites.
I get mostly good results, except when I try to run 'getent passwd' or
'getent group' only