search for: centrify

Displaying 20 results from an estimated 42 matches for "centrify".

2019 Jan 28
4
Troubleshooting help?
Thank you Rowland! I guess that's part of my confusion, I'm not sure how to best debug where Centrify ends and Samba begins. But if these log.smbd errors indicate Centrify vice Samba, I'm good with that. My global smb.conf is (didn't bother with the commented out stuff): [global] security = ADS realm = <our domain name> workgroup = <our workgroup name> netbios name = <the s...
2019 Jan 28
2
Troubleshooting help?
I probably should have lead with this, but I did not create or deploy this particular setup, I was charged with keeping it going after the main person left. I have zero experience with Samba or Centrify, or I should say *had* no experience until this. So, I frankly have very little idea of what most of these options are for or why they're set the way they are. I can certainly edit per your suggestions and see if it helps at all. I have noticed that as people are getting window pop-ups askin...
2011 Mar 18
5
Replace NIS by Active Directory
...gid. How to move 1000 actual NIS users to AD ? How to keep the same id and gid for this 1000 users ? What's happen with nfs linux server and acess with gid and/id ? Use the same user/password for linux and Windows clients authentification? We test a solution who work very well. It's Centrify comercial software http://www.centrify.com/directcontrol/overview.asp . But we are looking a freeware solution. (kerberos ? openldap ? pam ? ...) Does someone has already successfully replace NIS by Ad authentification with freeware solution ? Regards. __________________________ Notre adresse d...
2019 Jan 25
2
Troubleshooting help?
I'm terribly sorry if this isn't the proper place/method by which to get help with troubleshooting Samba errors/issues, but it's the best one I could find. I have an instance of Samba 4.8.3 running on a Centos 7.6 VM server (kernel 3.10.0-957.1.3), along with Centrify 5.5.2-578, that will allow folks to map a shared drive from their Windows 10 machines generally fine, but quite regularly throws a bunch of errors to the log.smbd file with stuff like the following: *** stack smashing detected ***; /usr/sbin/smbd terminated ../lib/util/fault.c:79(fault report) INT...
2012 Oct 20
0
Passwords with special characters
Details: Ubuntu 12.10 Samba version - Version 3.5.11-cdc-4.5.3-573 CentrifyDC version - CentrifyDC 5.0.2-396 Hi all, I am using Centrify Express to connect to my work domain, and I am using their version of Samba, hence the version listed above. I already posted this query to them, and they directed me to here, stating that this may be a Samba issue: Centrify forum query...
2019 Jan 29
0
Troubleshooting help?
...on't really > have an insight into that piece. For my VM, my understanding is that > so long as it can verify the user requesting access to the share has > a valid login and are in the correct Active Roles group, they should > be able to access the share. > > What is in /etc/centrifydc/smb2.conf ? Looks like: > [global] > winbindd socket directory = /run/samba/winbindd2 > include = /etc/smb.conf > > I am indeed engaging with some Centrify support folks. The only rub > is, we're running Centos 7.6 on our server and they don't officially >...
2014 Apr 20
2
Allow access to a share for only one machine account
...(and with sssd on both machines to retrieve uid/gid from AD). I wish to set a share on ubuntu2 in the way so it could be accessible only from ubuntu1 (and by any user from ubuntu1, for instance by local root). I have found this solution though I'm not sure it solves my issue: http://community.centrify.com/t5/Centrify-enabled-Samba/How-to-allow-Windows-machine-accounts-to-connect-to-a-share-as/td-p/11834 Anyway, it does not work -- klist doesn't return any ticket for the machine account on either ubuntu1 or ubuntu2 (yet both machines are listed in AD in the group "Domain Computers"...
2019 Jan 26
0
Troubleshooting help?
...rote: > I'm terribly sorry if this isn't the proper place/method by which to > get help with troubleshooting Samba errors/issues, but it's the best > one I could find. I have an instance of Samba 4.8.3 running on a > Centos 7.6 VM server (kernel 3.10.0-957.1.3), along with Centrify > 5.5.2-578, that will allow folks to map a shared drive from their > Windows 10 machines generally fine, but quite regularly throws a > bunch of errors to the log.smbd file with stuff like the following: > > *** stack smashing detected ***; /usr/sbin/smbd terminated > ../lib/uti...
2019 Jan 28
0
Troubleshooting help?
On Mon, 28 Jan 2019 17:19:03 +0000 Scott Z. <sudz28 at hotmail.com> wrote: > Thank you Rowland! I guess that's part of my confusion, I'm not sure > how to best debug where Centrify ends and Samba begins. But if these > log.smbd errors indicate Centrify vice Samba, I'm good with that. My > global smb.conf is (didn't bother with the commented out stuff): I have added some comments to your smb.conf: [global] security = ADS realm = <our domain name> workgr...
2010 Nov 21
0
Old thread:how many people still use NIS?
Good morning! I've been offlist for years, and hopping back on for various reasons, I see a thread that I'd like to add to. There's an old thread on NIS use in Centrify that I'd like to add some comments to. I'm still forced to work with NIS for various reasons, including interaction with heavy duty NAS's that require it for NFSv4. I have been busy falling in serious love with Centrify (www.centrify.com) for this. For an environment that already has a...
2006 Oct 25
0
files are getting saved as tmp files on the first save on Samba shares
...g Uni Grpahics software on the files on Samba shares. The user will save the file and it creates a .tmp file. The original file is gone. If the user saves again, the file is then saved with the correct extension and the .tmp file is gone. Any thoughts? Best Regards Sumana Annam Technical Support Centrify Corporation (650) 961-1100 x 257 www.centrify.com Identify. Simplify. Centrify. Securely integrate your Unix, Linux, Mac, Java and web platforms with Microsoft Active Directory's management services.
2007 Sep 17
3
[Bug 1364] New: default for ChallengeResponseAuthentication doesn' t match sshd_config
...config Product: Portable OpenSSH Version: 4.7p1 Platform: Other OS/Version: Other Status: NEW Severity: normal Priority: P2 Component: sshd AssignedTo: bitbucket at mindrot.org ReportedBy: nate.yocom at centrify.com between 4.5p1 and 4.6p1 the ChallengeResponseAuthentication parameter stopped defaulting to 'yes' and must be explicitly set to work. I suspect this is the result of the Match keyword support that was added - but it should either default correctly or the default sshd_config should be...
2012 Apr 23
1
Disable AD checking per share in smb.conf [sec=unclassified]
Hi, Is it possible to have non-authenticating shares on an server with security=ADS ? I have a RHEL server, with Centrify Express, and joined to a domain, but I would like to have a samba share that doesn't request a username/password for machines not on the domain. When I have a plain windows XP machine (not on the domain) attempt to connect, I get asked for a username/password. Is this possible? (to have a...
2018 Jan 14
2
Best way to generate Unix UIDs and GIDs?
...o avoid conflicts with those objects as well. This makes me think that a good way would be to generate UIDs/GUIDs from SID. I know SSSD does it (apparently not ensuring consistency[1]), but I could not find a script that does only this. However, I found this python script[2] which seems to be what Centrify does. What do you think about all of this? Regards, Yvan 1. https://funinit.wordpress.com/2017/09/14/integrating-red-hat-with-active-directory/ 2. https://gist.github.com/msmorul/11217186 -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: app...
2018 Sep 21
2
Heterogeneous mix OS smb share home redirection
...OS) situation. (On Ubuntu, leaning toward using winbind authentication. Yes, sssd works but sssd is more a redhat based option, not that it does not work with Ubuntu.) I have been doing "folder redirection" of Windows workstations for years with roaming profiles using GPO policies. Yes, Centrify and PBIS are viable options but, (again, in my case) I would prefer to use generally available linux OS solutions. Comes my question, is it a good or bad idea to share home directory in this heterogeneous workstation mix? And question two, how are others doing this? Thoughts? Thank you. Bob Wo...
2016 Aug 01
0
Samba AD member join failure - internal error
...a Samba AD Domain Controller on a fresh Ubuntu 16.04 installation, and at face value it looks to be working. The member join from two clients are not working, one another fresh Ubuntu 16.04 install, the other a Mac. The Mac used to join my old server install (which I had done a long time back with Centrify) just fine, but following same steps it does not join the new server. I have a feeling my issue is on the server side, where I missing something fundamental, but I need help figuring it out. Server side setup: http://pastebin.com/hnfZdn7i Client side setup: http://pastebin.com/sbPZUAEQ On the s...
2012 Mar 22
0
Disable AD checking per share in smb.conf [sec=unclassified]
Hi, Is it possible to have non-authenticating shares on an server with security=ADS ? I have a RHEL server, with Centrify Express, and joined to a domain, but I would like to have a samba share that doesn't request a username/password for machines not on the domain. When I have a plain windows XP machine (not on the domain) attempt to connect, I get asked for a username/password. Is this possible? (to have a...
2015 Jun 14
2
How Can I create a group policies with Samba?
Thank you but it just solve a problem. How about other? For example, You want to disable all Clients Firewall when they logging to their systems or set a specific proxy without Squid-cache. On Saturday, June 13, 2015 7:18 PM, Marc Muehlfeld <mmuehlfeld at samba.org> wrote: Hello Jason, Am 13.06.2015 um 16:36 schrieb Jason Long: > I mean is that If we have 2000 Linux clients
2012 Jan 11
4
Full replay logs of OpenSSH sessions
Hi all, I am not 100% sure if this is a -dev or a -user topic, but I am leaning towards the former. Feel free to cuss at me and tell me to ask -user, instead. I used to run a patchset that allowed full logs of everything taking place via OpenSSH. This also allowed me to replay any session, live or after the fact. I am fully aware of the security implications of logging everything, especially
2016 Dec 20
4
Problem with keytab: "Client not found in Kerberos database"
I finally found it, thanks to a clue from https://wiki.archlinux.org/index.php/Active_Directory_Integration This works: kinit -k -t /etc/krb5.keytab 'WRN-RADTEST$' These don't work: kinit -k -t /etc/krb5.keytab kinit -k -t /etc/krb5.keytab host/wrn-radtest.ad.example.net kinit -k -t /etc/krb5.keytab host/wrn-radtest That is: the keytab contains three different principals: root