Displaying 4 results from an estimated 4 matches for "cylic".
Did you mean:
cyclic
2017 Aug 16
2
SAMBA4 - Trusted relationship lost every Weeks
...through bidirectional trust).
The fact is this is not the prettiest config, as we didn't have
prerequisites for idmap_ad, we tried idmap_ldap backend and it works.
Using several fileservers, they resolve the same uid/gid for a specific
user.
IMO I don't think this setup can cause such a cylic problem (exactly
every week..), but I'm probably wrong.
> (as an
> aside, I do hope that workgroup DOMAIN_A != realm DOMAIN_A).
>> For sure, in production they are different (this is the result of
anonymising config)
> You should
> also probably be using the winbind 'r...
2017 Aug 17
1
SAMBA4 - Trusted relationship lost every Weeks
...end and it works.
> You don't have to use the 'ad' backend, in fact in your case I would
> use the 'rid' backend
>
>> Using several fileservers, they resolve the same uid/gid for a
>> specific user.
>> IMO I don't think this setup can cause such a cylic problem (exactly
>> every week..), but I'm probably wrong.
> I don't think it is either, what I think is going wrong is the kerberos
> ticket is expiring and I don't think you can fix it with your smb.conf.
> I would have expected an idmap block something like this:
>...
2017 Aug 16
0
SAMBA4 - Trusted relationship lost every Weeks
...we tried idmap_ldap backend and it works.
You don't have to use the 'ad' backend, in fact in your case I would
use the 'rid' backend
> Using several fileservers, they resolve the same uid/gid for a
> specific user.
> IMO I don't think this setup can cause such a cylic problem (exactly
> every week..), but I'm probably wrong.
I don't think it is either, what I think is going wrong is the kerberos
ticket is expiring and I don't think you can fix it with your smb.conf.
I would have expected an idmap block something like this:
idmap config * :...
2017 Aug 16
2
SAMBA4 - Trusted relationship lost every Weeks
Hi,
Here is our smb.conf.
Please note that this server uses nss resolution for DOMAIN_B users and
idmap_ldap backend to resolve DOMAIN_A users.
Trusted relationship between works well for other services between those
two domains. Only samba4 fileserver needs to rejoin DOMAIN_A domain (AD
2008 server) every week.
#======================= Global Settings