search for: autorit

Displaying 15 results from an estimated 15 matches for "autorit".

Did you mean: autorid
2006 Dec 18
2
Slightly OT: DNS -force client always use authoritative
Is there a specific way to set a name server so that clients are always *forced* to use an autoritative name server? UltraDNS and some others have mentioned little features they have, but it only hints at the possibility that somewhere in the DNS spec. -karlski
2019 Oct 20
4
GPO for Computer/Machine not working
...e does not get access to the sysvol. This can also be seen within the details, as the gpt.ini can't be accessed (Policy Version 65535): Verkn?pfungsort ad.die-tessuns.de Konfigurierte Erweiterungen {827D319E-6EAC-11D2-A4EA-00C04F79F83A} Erzwungen Nein Deaktiviert Keine Sicherheitsfilter NT-AUTORIT?T\Authentifizierte Benutzer Revision AD (2), SYSVOL (65535) WMI-Filter Grund: abgelehnt Zugriff verweigert (Sicherheitsfilterung) Whereas the User has the correct security Groups: Der Benutzer ist Mitglied der folgenden Sicherheitsgruppen ------------------------------------------------...
2019 Oct 21
2
GPO for Computer/Machine not working
...within the details, as the >> gpt.ini can't be accessed (Policy Version 65535): >> >> Verkn?pfungsort ad.die-tessuns.de >> Konfigurierte Erweiterungen {827D319E-6EAC-11D2-A4EA-00C04F79F83A} >> Erzwungen Nein >> Deaktiviert Keine >> Sicherheitsfilter NT-AUTORIT?T\Authentifizierte Benutzer >> Revision AD (2), SYSVOL (65535) >> WMI-Filter >> Grund: abgelehnt Zugriff verweigert (Sicherheitsfilterung) >> >> >> Whereas the User has the correct security Groups: >> >> ?? Der Benutzer ist Mitglied der folgenden Sich...
2019 Nov 28
0
security = ads parameter not working in samba 4.9.5
...dentials have been revoked .. Means the Active Directory account to which the keytab is related has been disabled, locked, expired, or deleted. Thats the first thing that needs to be verified. Also the bind config. If its an DC, in global options add: auth-nxdomain yes; Your DC = the Autoritive server of your domain.. ( a quick look ) Greetz, Louis > -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Rowland penny via samba > Verzonden: donderdag 28 november 2019 11:27 > Aan: sambalist > Onderwerp: Re: [Samba] se...
2019 Oct 20
0
GPO for Computer/Machine not working
...svol. This can also be seen within the details, as the gpt.ini > can't be accessed (Policy Version 65535): > > Verkn?pfungsort ad.die-tessuns.de > Konfigurierte Erweiterungen {827D319E-6EAC-11D2-A4EA-00C04F79F83A} > Erzwungen Nein > Deaktiviert Keine > Sicherheitsfilter NT-AUTORIT?T\Authentifizierte Benutzer > Revision AD (2), SYSVOL (65535) > WMI-Filter > Grund: abgelehnt Zugriff verweigert (Sicherheitsfilterung) > > > Whereas the User has the correct security Groups: > > ?? Der Benutzer ist Mitglied der folgenden Sicherheitsgruppen > ??? --------...
2019 Oct 31
0
GPO for Computer/Machine not working
...vol. This can also be seen within the details, as the gpt.ini > can't be accessed (Policy Version 65535): > > Verkn?pfungsort ad.die-tessuns.de > Konfigurierte Erweiterungen {827D319E-6EAC-11D2-A4EA-00C04F79F83A} > Erzwungen Nein > Deaktiviert Keine > Sicherheitsfilter NT-AUTORIT?T\Authentifizierte Benutzer > Revision AD (2), SYSVOL (65535) > WMI-Filter > Grund: abgelehnt Zugriff verweigert (Sicherheitsfilterung) > > > Whereas the User has the correct security Groups: > > ?? Der Benutzer ist Mitglied der folgenden Sicherheitsgruppen > ??? ---...
2009 Sep 19
1
Apache: confusion about virtual hosts and DNS on a local network
.... contact.kikinovak.net. ( 2009070201 ; serial 28800 ; refresh (8 hours) 14400 ; retry (4 hours) 2419200 ; expire (4 weeks) 86400 ; minimum (1 day) ) ; D?finit le serveur de noms faisant autorit? NS babasse.presbytere.local. ; Nos machines 1 PTR babasse.presbytere.local. 2 PTR buildbox.presbytere.local. 3 PTR lifebook.presbytere.local. 4 PTR raymonde.presbytere.local. 5 PTR jukebox.presbyter...
2019 Oct 31
0
GPO for Computer/Machine not working
...>>> gpt.ini can't be accessed (Policy Version 65535): >>> >>> Verkn?pfungsort ad.die-tessuns.de >>> Konfigurierte Erweiterungen {827D319E-6EAC-11D2-A4EA-00C04F79F83A} >>> Erzwungen Nein >>> Deaktiviert Keine >>> Sicherheitsfilter NT-AUTORIT?T\Authentifizierte Benutzer >>> Revision AD (2), SYSVOL (65535) >>> WMI-Filter >>> Grund: abgelehnt Zugriff verweigert (Sicherheitsfilterung) >>> >>> >>> Whereas the User has the correct security Groups: >>> >>> ?? Der Benutzer...
2019 Jul 29
2
Upgrading your Samba AD-DC from Stretch to Buster, used samba 4.10.6.
...o stop this in the logs: "resolver: info: resolver priming query complete log messages." // Which worked in the end :-) for the config. //forwarders { 62.212.131.101; 62.212.128.130; 8.8.8.8; //}; auth-nxdomain yes; // Default is no, but this server IS the autoritive server if you zones. listen-on-v6 { "none"; }; // i dont use ipv6 on my AD-DC. listen-on port 53 { "thisserverip"; 127.0.0.1; }; notify no; // After upgrade from stretch to buster, i've added. minimal-responses yes; // In at...
2019 Jul 16
3
messy replication
...vice ticket lifetime = 24 kdc:user ticket lifetime = 24 kdc:renewal lifetime = 168 Are beter if set in krb5.conf And AD-DC domain server, with guest ok = yes ? By default no guest is allowed. Shares with to long names might give problems. Bind9 auth-nxdomain yes; # because this server is autoritive for this dnsdomain name. tkey-gssapi-keytab "/var/lib/samba/private/dns.keytab"; Verify if bind still has access to that file. # packages. Still Lenny and Squeeze left overs. All and all.. Hmm, well, thats a lot of time to fix this. Next DC2. Debian 9.5 , out dated, should be...
2019 Jul 16
4
messy replication
Hi all, I have an old dc (4.0.9). Let's call it dc1. I also have a new one (4.5.16) which I'm planning to switch to. Let's call it dc2. After initial set up of dc2 I initialised replication and things looked ok for a couple of weeks. Recently I've managed to mess it up. Possibly by editing users and DNS records. Or copying Kerberos cache and trying to use it elsewhere for
2019 Jun 24
0
Reverse DNS
...e > https://www.isc.org/bind-keys > > //============================================================ > ============ > dnssec-validation auto; > tkey-gssapi-keytab "/var/lib/samba/private/dns.keytab"; > auth-nxdomain no; # conform to RFC1035 your AD DC is the AUTORITIVE server of the primary zone so.. auth-nxdomain yes; > listen-on-v6 { any; }; Add : empty-zones-enable no; That avoids possible conficts with configured zones. > }; > > ----------- > > Checking file: /etc/bind/named.conf.local > > // > // Do any local c...
2019 Jun 25
2
Reverse DNS
...ys > > > > //============================================================ > > ============ > > dnssec-validation auto; > > tkey-gssapi-keytab "/var/lib/samba/private/dns.keytab"; > > auth-nxdomain no; # conform to RFC1035 > your AD DC is the AUTORITIVE server of the primary zone so.. > auth-nxdomain yes; > > listen-on-v6 { any; }; > > Add : empty-zones-enable no; > That avoids possible conficts with configured zones. > > > }; > > > > ----------- > > > > Checking file: /etc/bin...
2019 Jun 19
4
Reverse DNS
Hi, We have some issue with the reverse DNS in Samba AD. We're running Bind9_DLZ on Ubuntu 18.04. The DHCP server(Ubuntu 16.04) is different to the AD server and not in the same AD domain. The DHCP scope points to the Samba AD server as the DNS server When a machine with DHCP assigned address tries to update the DNS record, it is able to update the forward zone but not the reverse zone. The
2019 Jun 26
0
Reverse DNS
...ys > > > > //============================================================ > > ============ > > dnssec-validation auto; > > tkey-gssapi-keytab "/var/lib/samba/private/dns.keytab"; > > auth-nxdomain no; # conform to RFC1035 > your AD DC is the AUTORITIVE server of the primary zone so.. > auth-nxdomain yes; > > listen-on-v6 { any; }; > > Add : empty-zones-enable no; > That avoids possible conficts with configured zones. > > > }; > > > > ----------- > > > > Checking file: /etc/bin...