search for: domguests

Displaying 20 results from an estimated 22 matches for "domguests".

2005 Nov 21
1
does a pdc need to be in the domain itself?
...having the SID part of the first "net getlocalsid" map to no unix group but they are also not used: > net groupmap list > [...] > Domain Users (S-1-5-21-4166838278-3756557259-2095403906-513) -> -1 > domadmins (S-1-5-21-2018781741-1218799122-1862565094-512) -> admin > domguests (S-1-5-21-2018781741-1218799122-1862565094-514) -> nobody > Domain Guests (S-1-5-21-4166838278-3756557259-2095403906-514) -> -1 > Domain Admins (S-1-5-21-4166838278-3756557259-2095403906-512) -> -1 > domusers (S-1-5-21-2018781741-1218799122-1862565094-513) -> users > [...]...
2003 Dec 09
0
group mappings pitfalls in samba 3
...an already established domain running under Samba 2.2.8. I then upgraded to 3.0. I removed the 'domain admin users = root' line from my smb.conf because certain tools complained about it being there. After the upgrade, I followed the Samba 3 HOWTO docs on samba.org. I created my domadm, domguests, and domusers groups. I used the command 'net groupmap add ntgroup="Domain Admins" UNIXgroup=domadm' to map the groups together. This should have had the same effect as having the 'domain admin users = root' line in 2.2.8, but whenever I would logon to any computer in t...
2005 Apr 15
1
The conflicting domain portions are not supported for NETLOGON calls
...gt; usuarios NT Admins (S-1-5-21-2403845858-3771094018-3344062789-719) -> ntadmin Domain Admins (S-1-5-21-528226156-890416033-2029241632-512) -> domadmin Domain Users (S-1-5-21-528226156-890416033-2029241632-513) -> domusers Domain Guests (S-1-5-21-528226156-890416033-2029241632-514) -> domguests -- -----BEGIN GEEK CODE BLOCK----- Version: 3.1 GCS/IT d- s+:+() a31 C+++ UBL+++$ P+ L+++ E--- W++ N+ o++ K- w--- O+ M+ V- PS+ PE+ Y++ PGP+>+++ t+ 5 X+$ R- tv-- b+++ DI D++>+++ G++ e- h+(++) !r !z ------END GEEK CODE BLOCK------
2004 Oct 01
1
can't join a domain
when trying to put a samba3 server into a domain (samba3 pdc) I always get the following error messages: [root@file samba]# net join -d 2 -U smbadmin RHEL -S server1.example.com [2004/09/30 23:36:35, 2] lib/interface.c:add_interface(79) added interface ip=192.168.0.150 bcast=192.168.0.255 nmask=255.255.255.0 smbadmin's password: [2004/09/30 23:36:37, 1] libads/ldap.c:ads_connect(251)
2011 Aug 04
1
No admin privileges after upgrade from 3.5.8 to 3.6.0rc3
Hi, since I was bitten badly by this today, I take the additional time to report this issue here. After upgrading from samba 3.5.8 to 3.6.0rc3, Administrator on the xp clients (yes, still xp sp3, no vista, no win7 clients here) lost its admin privileges. My Samba PDC setup evolved over about a decade now, but since it still needs to support a small environment only (20 xp, 30 users), I
2004 Jul 06
1
Q about net groupmap examples on samba.org
Considering the following page... http://us3.samba.org/samba/docs/man/guide/small.html First of, my compliments to John for some great examples to study. In my mind I see three levels of security: 1) Linux - such as SSH'ing into the Linux server, Linux accounts and groups come into play here 2) Samba PDC - "Domain Admins" "Domain Users" come into play here. Examples
2005 Apr 15
1
The conflicting domain portions are not supported
...users usuarios de samba (S-1-5-21-528226156-890416033-2029241632-717) -> usuarios Domain Admins (S-1-5-21-528226156-890416033-2029241632-512) -> domadmin Domain Users (S-1-5-21-528226156-890416033-2029241632-513) -> domusers Domain Guests (S-1-5-21-528226156-890416033-2029241632-514) -> domguests > What's the output of the net getlocalsid? # net getlocalsid SID for domain ORA9I is: S-1-5-21-528226156-890416033-2029241632 > It should match the SambaSID value in the SambaDomainName ldap entry. [2005/04/15 13:40:36, 10] auth/auth_util.c:debug_nt_user_token(490) NT user token of...
2004 Apr 14
1
samba-latest and tdbsam - unable to logon to domain?
...to logon to the domain. I have created the tdbsam using the "smbpasswd -a root" command. I also added User Administrator as unix and samba account. I also mapped groups "Domain Admins", "Domain users" and "Domain Guests" to unix groups domadmins, domusers and domguests using the "net groupmap modify" command. But is doesn't work. I cannot join a XP professional ws to the domain, I keep getting the message that the domain controller cannot be found. I am able to open the netlogon share from the ws when I am logged on the ws as a local Administrator,...
2004 Mar 18
3
migration nt4 with ldap problem
...seradd.pl -w -d /dev/null -g domcomputers -s /bin/false "%u" -----------------snap--------------------------------- here are the steps of my migration 1. smbldap-groupadd.pl -g 512 -r 512 domadmins smbldap-groupadd.pl -g 513 -r 513 domusers smbldap-groupadd.pl -g 514 -r 514 domguests smbldap-groupadd.pl -g 515 -r 515 domcomputers 1. smbd and nmbd don''t run 2. net rpc join -S WALDFEE -w HOLLADIE -U administrator%blabla 3. net rpc testjoin Join to 'HOLLADIE' is OK 4. net rpc vampire -S waldfee -U Administrator%blabla works fine and sort al...
2004 Sep 28
0
domain admin group does not have root privileges on windows 2000 or xp machines
I recently upgraded to samba 3 (running on FreeBSD 4.10). I quickly discovered the lack of the domain admins setting from samba 2, and found documentation directing me to use net groupmap. So I've got the domain admins group set to include @wheel: olympus# net groupmap list System Operators (S-1-5-32-549) -> -1 Replicators (S-1-5-32-552) -> -1 Guests (S-1-5-32-546) -> -1 Domain
2005 Mar 15
0
trouble with groupmap
Samba Version 3.0.9-1.3E.2 installed on Vanilla installation of CentOS Users who log in are unable to install printers via a script like they do in all of our other domains. The drivers have been installed properly an rpcclient enumdrivers confirms this. When the user logs in, they are assigned guest privileges, and I believe that this is what's preventing the print install. A quick tail
2012 Oct 10
2
samba4, classicupgrade: set_nt_acl_no_snum: fset_nt_acl returned NT_STATUS_INVALID_OWNER
...dn: ou=groups,dc=example,dc=com dn: ou=computers,dc=example,dc=com dn: sambaDomainName=EXAMPLE,dc=example,dc=com dn: cn=domusers,ou=groups,dc=example,dc=com dn: cn=domadmins,ou=groups,dc=example,dc=com dn: uid=Administrator,ou=users,dc=example,dc=com dn: uid=nobody,ou=users,dc=example,dc=com dn: cn=domguests,ou=groups,dc=example,dc=com dn: sambaSID=S-1-5-32-544,ou=groups,dc=example,dc=com dn: sambaSID=S-1-5-32-545,ou=groups,dc=example,dc=com dn: sambaSID=S-1-5-32-546,ou=groups,dc=example,dc=com dn: uid=nbensa,ou=users,dc=example,dc=com dn: uid=samba3$,ou=computers,dc=example,dc=com dn: uid=marisa,ou=us...
2007 Apr 25
2
Can not grant SeMachineAccountPrivilege on Debian Etch
I am testing out Debian Etch, and ran into an issue granting SeMachineAccountPrivilege to an account... which granting that permission had been troublesome in the past. The command I am issuing is: net rpc rights grant LDS-DEMO\\ldsinst SeMachineAccountPrivilege And I try running the command with an account that is a member of the "Domain Admins" group. The command returns: Failed to
2007 Jun 01
2
Not seeing the expected group memberships with ifmember.exe /list
We have bumped into a most odd problem. Server: Debian Etch and their Samba 3.0.24-2 Client: WinXP SP2, MSI v3, all hot fixes The following settings are in place on the server: #!/bin/bash # # initGrps.sh # Map Windows Domain Groups to UNIX groups net groupmap add ntgroup="Domain Admins" unixgroup=domadmin rid=512 type=d net groupmap add ntgroup="Domain Users"
2003 Dec 16
2
Samba 3.0.1 Available for Download
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In an attempt to avoid the holiday rush common to software releases, the Samba Team is proud to announce the availability of the first patch release of the Samba 3.0 code base. This is the latest stable release of Samba and is the version that all production Samba servers should be running for all current bug-fixes. Some of the more common bugs in
2003 Dec 16
2
Samba 3.0.1 Available for Download
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In an attempt to avoid the holiday rush common to software releases, the Samba Team is proud to announce the availability of the first patch release of the Samba 3.0 code base. This is the latest stable release of Samba and is the version that all production Samba servers should be running for all current bug-fixes. Some of the more common bugs in
2011 Feb 03
1
POSIX ACLs vs. EA security.NTACLs
...t it exposed that I do not understand the relationship between these three. Here is a typical share that is used by three classes of users (see below) (with NFS, the directory): [Shared] comment = Public Share on %h path = /home/shared valid users = +domadmins, +domusers, +domguests write list = +domadmins, +domusers force group = domusers inherit permissions = yes inherit acls = yes map acl inherit = yes acl group control = yes ea support = yes vfs object = acl_xattr recycle store dos attributes = yes...
2009 Mar 11
1
Samba PDC - Kerberised CIFS access
Hi All, I have machine M1 hosting Samba PDC. It stores only user information. I have machine M2 acting as KDC server. I have machine M3 hosting CIFS shares and it joins into the domain hosted by PDC M1. I have machine M4 used as CIFS client. On M2, I have added users and cifs/host service principals for M3. Also added service principal in keytab file. I have added all the user and service
2007 Apr 26
0
Pdbedit -L: strange error looking up RID 513 by key RID_00000201
...ange because I did "net mapgroup add..." without there were problems. I stick underneath a copy here of net mapgroup: Linux:~# net groupmap list Domain Admins (S-1-5-21-275117359-2948478385-1723927003-512) -> domadmin Domain Guests (S-1-5-21-275117359-2948478385-1723927003-514) -> domguests Domain Users (S-1-5-21-275117359-2948478385-1723927003-513) -> domusers ----------------END PASTE------------------------------------------------- Samba works fine and testparm is: Linux:~# testparm Load smb config files from /etc/samba/smb.conf Processing section "[homes]" Processing...
2007 Apr 29
1
Urgent pls!!! Error in "pdbedit -L" with rid 513
...s to me strange because I did "net mapgroup add..." without there were problems. I paste a copy here of net mapgroup: Linux:~# net groupmap list Domain Admins (S-1-5-21-275117359-2948478385-1723927003-512) -> domadmin Domain Guests (S-1-5-21-275117359-2948478385-1723927003-514) -> domguests Domain Users (S-1-5-21-275117359-2948478385-1723927003-513) -> domusers ----------------END PASTE------------------------------------------------- Samba works fine and testparm is: Linux:~# testparm Load smb config files from /etc/samba/smb.conf Processing section "[homes]" Processing...