Displaying 20 results from an estimated 400 matches for "sambaprimarygroupsid".
2007 Dec 19
1
Problems adding a NTSp6a machine to a SAMBA PDC Domain + LDAP: sambaPrimaryGroupSID
...modify(1377)
smbldap_modify: dn => [uid=windowsntldap
$,ou=machines,ou=samba,dc=itdeusto,dc=local]
[2007/12/19 14:38:03, 10] lib/smbldap.c:smbldap_modify(1397)
Failed to modify dn: uid=windowsntldap
$,ou=machines,ou=samba,dc=xxxxx,dc=local, error: 20 (Type or value
exists) (modify/add: sambaPrimaryGroupSID: value #0 already exists)
[2007/12/19 14:38:03, 5] rpc_parse/parse_prs.c:prs_debug(84)
000000 samr_io_r_set_userinfo
The smbd proccess have a problem trying to modify the LDAP entry that
have been created
I have been using the Samba version that came with CentOS 5.1
(samba-3.0.25b) I also...
2007 Feb 05
1
smbldap machine account pb since 3.0.23c-1
Hello
When a windows xp workstation join a domain, by windows gui parameters, ldap
machine attributes are not filled correctly:
- No attribute sambaprimarygroupsid (before, there was one terminated by 515)
- rid (of sambasid) is not equal a 2*uid+1000
If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid
terminated by 513)
All the others samba attributes are ok
Same problem if i use "smbldap-useradd -w" before joining th...
2007 Mar 06
0
SambaNextRid, SambaPrimaryGroupSid.
Hello All
With Samba 3.0.24 with ldap backend, what can i do for using algorithm "rid =
2*uid + 1000", when samba create samba attributes (sambasid) of computer
account, instead of SambaNextRid from SambaDomainName entry ?
Is samba able to create SambaPrimaryGroupSid (with rid = 515) with other samba
attributes ?
Why 3.0.22 -> 3.0.23 upgrade has modified thoses two.
thanks, regards
P.S.I've already post this on the list
--
Emmanuel musso
technicien informatique
I.U.T. Paul Sabatier
D?pt G?nie ?lectrique 0562258241
Service informatique 0562258025...
2005 Dec 30
0
strange trusts in 3.0.21?
...ACDEV trusts DEVXP and DEVEX
DEVXP trusts ACDEV and DEVEX
DEVEX trusts ACDEV and DEVXP
A machine INTDEV4 (INTDEV4$) joins ACDEV.
INTDEV4 shows INTDEV4 (local machine), ACDEV, DEVEX and DEVXP as possible
choices for logging in. Perfect.
Three users are used for testing:
billtest (sambaSID & sambaPrimaryGroupSID is in ACDEV)
log on to ACDEV - YES
log on to DEVXP - YES
log on to DEVEX - YES
edwartho (sambaSID & sambaPrimaryGroupSID is in DEVEX)
log on to ACDEV - **NO**
log on to DEVXP - YES
log on to DEVEX - YES
test1 (sambaSID & sambaPrimaryGroupSID is in DEVXP)
log on to ACDEV - **NO**
l...
2004 Sep 06
0
What is the correct SambaPrimaryGroupSID
Hi,
I ask to you for a small question :
I have some user with this SambaPrimaryGroiupSID =
S-1-5-21-XXXXX-XXXXX-XXXX-1443
And other user with this SambaPrimaryGroiupSID =
S-1-5-21-XXXXX-XXXXX-XXXX-513
What is correct SambaPrimaryGroiupSID ?
The SambaSID of my primary group is S-1-5-21-XXXXX-XXXXX-XXXX-513
The S-1-5-21-XXXXX-XXXXX-XXXX-1443 is the result of GID 221*2 + 1001 RID
algorithm
I use
2009 Aug 12
1
sambaprimaryGroupSid
Hi all!
I'm configuring a samba PDC with an LDAP sam. Everything is working
great except that when I do pdbedit -Lv root (which is my "Domain
Administrator" account) I see that it's getting a Primary Group SID
value of S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-513 instead of the
S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-512 that is stored in my LDAP tree.
Does someone
2003 Aug 04
1
Group mapping... static ???
...) Created Group mapping : net groupmap add sid=<mySID>-513
unixgroup=domusers ntgroup="Domain Users" type=domain (then "net groupmap
list", OK)
5) Finally, created LDAP (samba) user : smbpasswd -a foo
Ok, no problem, foo gets the domain local sid + the domain users rid as
SambaPrimaryGroupSid, he IS a Win Domain User.
Here is what I don't understand : If I delete the groupmapping or modify
it, the SambaPrimaryGroupSid of foo isn't modified ! Foo remains a Domain
User...
Another example : if I create first the user, then the mapping : the user
doens't get the new SambaPrimar...
2006 Jan 26
1
Creating a machine account manually (EMC, Samba PDC)
...db/pdb_ldap.c:init_ldap_from_sam(1064)
init_ldap_from_sam: Setting entry for user: boxer$
[2006/01/26 15:32:09, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1648)
ldapsam_modify_entry: Failed to modify user dn=
uid=boxer$,ou=Computers,dc=zapeng,dc=com with: No such attribute
modify/delete: sambaPrimaryGroupSID: no such value
[2006/01/26 15:32:09, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1873)
ldapsam_update_sam_account: failed to modify user with uid = boxer$,
error: modify/delete: sambaPrimaryGroupSID: no such value (Success)
[2006/01/26 15:32:09, 2] passdb/pdb_ldap.c:init_sam_from_ldap(640)...
2005 May 10
1
Are the following cockups in ldap entries or normal behaviour now ?
...,<snip>
objectClass: posixGroup
objectClass: sambaGroupMapping
gidNumber: 513
cn: Domain Users
<snip>
description: All domain users
memberUid: administrator
memberUid: deloitte
memberUid: iusr_guests
memberUid: template
My machines all have a SID that ends in 513 the domain users RID:
sambaPrimaryGroupSID: S-1-5-21-<snip>-513
My users have no passwords set eg:
dn: uid=deloitte,ou=Users
<snip>
sambaLMPassword: XXX
sambaPrimaryGroupSID: S-1-5-21-<snip>-513
sambaNTPassword: XXX
Is this expected behaviour when vampiring from an NT server using the
smbldap-tools-0.8.8.tgz ?
Or does...
2006 Mar 18
1
problems adding machines after upgrade - sambaSID attribute incomplete!
...o 3.0.21c now we can't
do that anymore!.
In adding a machine, the "wellcome to domain XXX" message appears, but
after rebooting the machine it doesn't works!. Looking the openldap
entries, now we are having these kind of entries:
sambaSID: S-1-5-21-2502698289-3639879065-4582
sambaPrimaryGroupSID: S-1-5-21-2502698289-3639879065-7544774837-515
note that "one part" of the Samba SID is missing, the correct should be:
sambaSID: S-1-5-21-2502698289-3639879065-7544774837-4582
so, I tried to fix the sambaSID attribute by hand on the openldap server
using phpldapadmin but no luck. Al...
2013 Jun 10
2
Samba + LDAP: Issue adding machine.
Greetings.
I've run into a trouble when trying to add a new Win7 machine on a domain.
The domain is controlled by a server running Samba + LDAP (samba compiled
with ldap support), on a Debian 5 OS at the local network.
I've added the machine name to the LDAP three through phpldapadmin using
the option "Samba3 Machine" on the related submenu and via terminal on
samba. Then I
2005 Mar 11
2
smbldap-useradd -w problem
...omputer either does not exist or is inaccessible". In the
samba log I can see:
[2005/03/09 13:15:26, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1479)
ldapsam_modify_entry: Failed to modify user dn=
uid=nt4box$,ou=People,dc=econo
mists-inc,dc=com with: No such attribute
modify/delete: sambaPrimaryGroupSID: no such value
[2005/03/09 13:15:26, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1694)
ldapsam_update_sam_account: failed to modify user with uid = nt4box$,
error: m
odify/delete: sambaPrimaryGroupSID: no such value (Success)
In the smb.conf file I have:
add machine script = /opt/IDEALX/sb...
2004 Jul 05
1
Accounts are getting disabled
...objectClass: top
objectClass: sambaSamAccount
cn: alexander-cristea
sn: alexander-cristea
uid: alexander-cristea
homeDirectory: /home/kl-1g3/alexander-cristea
gecos: "kl-1g3"
loginShell: /bin/sh
shadowMin: 1
shadowMax: 99999
shadowWarning: 14
sambaPwdMustChange: 1800000000
gidNumber: 112
sambaPrimaryGroupSID: S-1-5-21-3371203057-3264423045-2392767973-1225
uidNumber: 5248
sambaSID: S-1-5-21-3371203057-3264423045-2392767973-11496
sambaProfilePath: \\WILMA2\profile
sambaAcctFlags: [UX ]
The same user monday morning:
# alexander-cristea, kl-1g3, people, wms-hn.de
dn: uid=alexander-cristea,ou=kl-1g3...
2003 Aug 05
0
How does group mapping function ?
...) Created Group mapping : net groupmap add sid=<mySID>-513
unixgroup=domusers ntgroup="Domain Users" type=domain (then "net groupmap
list", OK)
5) Finally, created LDAP (samba) user : smbpasswd -a foo
Ok, no problem, foo gets the domain local sid + the domain users rid as
SambaPrimaryGroupSid, he IS a Win Domain User.
Here is what I don't understand : If I delete the groupmapping or modify
it, the SambaPrimaryGroupSid of foo isn't modified ! Foo remains a Domain
User...
Another example : if I create first the user, then the mapping : the user
doens't get the new SambaPrimar...
2003 Sep 15
1
domain admin
...I use FreeBSD-5.1+samba3.0RC3.
My group maps:
Admins du domaine (S-1-5-21-xxxx-512) -> domainadmins
Utilisa. du domaine (S-1-5-21-xxxx-513) -> domainusers
Invites du domaine (S-1-5-21-xxxx-514) -> domainguests
Ordinateurs du domaine (S-1-5-21-xxxx-515) -> domaincomputers
All my users sambaPrimaryGroupSID are set to 513. Now, I added some
users to the "domainadmins" group (with the memberUid attribute in LDAP)
but they do not get admin priviledges on NT workstations...
What am I missing here ?
I also added "@domainadmins" to the "user admins" parameter in smb.conf,
b...
2003 Sep 19
0
samba-3.0.0-rc4 and Domain Admins
...dmin) to the "Domain
Admins" group on my samba-PDC using the ldapsam backend.
When I add "Domain Admins" as a supplementary group, the Windows 2000
client doesn't treat smbadmin as an admin. However, using "Domain
Admins" as the primary group (including setting sambaPrimaryGroupSID as
"$SID-512") works as expected, the user has administrative rights.
Additional information is attached below.
Is this a limitation or have I missed anything?
Thanks in advance,
--leo
P.S.:
showgrps from the Resource Kit shows "Domain Admins" regardless of
wether "Do...
2003 Oct 07
1
userGroupRid and groupmapping
Hi !
When I create a user with samba-ldap tools, the userRid is calculated if
the -x option is set.
The userGroupRid is calculated too. But is the groumapping is enabled, the
SambaPrimaryGroupSID not correspond with SambaSID of groupmapping
Example :
Groupe "Domain Users" :
gidNumber 100
displayName Domain Users
objectClass sambaGroupMapping
sambaSID S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxxx-513
sambaGroupType 2
cn Users
User Toto :
sambaPrimaryGroupSID S-1-...
2007 Jan 30
0
ldap machine attributes not filled correctly when join a domain
Hello
When a windows xp workstation join a domain, by windows gui parameters, ldap
machine attributes are not filled correctly:
- No attribute sambaprimarygroupsid (before, there was one terminated by 515)
- rid (of sambasid) is not equal a 2*uid+1000
If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid
terminated by 513)
All the others samba attributes are ok
Same problem if i use "smbldap-useradd -w" before joining th...
2007 Feb 27
0
ldap machine account: bad RID, no SambaPrimaruGroupSID, since 3.0.23c
Hello all
When a windows xp workstation join a domain, by windows gui parameters, ldap
machine attributes are not filled correctly:
- No attribute sambaprimarygroupsid (before, there was one terminated by 515)
- rid (of sambasid) is not equal a 2*uid+1000
gid attribute is ok (515)
If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid
terminated by 513)
All the others samba attributes are ok
Same problem if i use "smbldap-useradd...
2010 Jul 12
1
smbldap-groupmod problem
...tput:
server:~# smbldap-groupmod -x user1 -m user2 testgroup
Can't call method "get_value" on an undefined value at
/usr/sbin/smbldap-groupmod line 146.
The line in question is:
if ($group_entry->get_value('sambaSID') eq
$user_entry->get_value('sambaPrimaryGroupSID')) {
What this means? Tks in advance.
--
Leonardo Carneiro