search for: sambaprimarygroupsid

Displaying 20 results from an estimated 400 matches for "sambaprimarygroupsid".

2007 Dec 19
1
Problems adding a NTSp6a machine to a SAMBA PDC Domain + LDAP: sambaPrimaryGroupSID
...modify(1377) smbldap_modify: dn => [uid=windowsntldap $,ou=machines,ou=samba,dc=itdeusto,dc=local] [2007/12/19 14:38:03, 10] lib/smbldap.c:smbldap_modify(1397) Failed to modify dn: uid=windowsntldap $,ou=machines,ou=samba,dc=xxxxx,dc=local, error: 20 (Type or value exists) (modify/add: sambaPrimaryGroupSID: value #0 already exists) [2007/12/19 14:38:03, 5] rpc_parse/parse_prs.c:prs_debug(84) 000000 samr_io_r_set_userinfo The smbd proccess have a problem trying to modify the LDAP entry that have been created I have been using the Samba version that came with CentOS 5.1 (samba-3.0.25b) I also...
2007 Feb 05
1
smbldap machine account pb since 3.0.23c-1
Hello When a windows xp workstation join a domain, by windows gui parameters, ldap machine attributes are not filled correctly: - No attribute sambaprimarygroupsid (before, there was one terminated by 515) - rid (of sambasid) is not equal a 2*uid+1000 If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid terminated by 513) All the others samba attributes are ok Same problem if i use "smbldap-useradd -w" before joining th...
2007 Mar 06
0
SambaNextRid, SambaPrimaryGroupSid.
Hello All With Samba 3.0.24 with ldap backend, what can i do for using algorithm "rid = 2*uid + 1000", when samba create samba attributes (sambasid) of computer account, instead of SambaNextRid from SambaDomainName entry ? Is samba able to create SambaPrimaryGroupSid (with rid = 515) with other samba attributes ? Why 3.0.22 -> 3.0.23 upgrade has modified thoses two. thanks, regards P.S.I've already post this on the list -- Emmanuel musso technicien informatique I.U.T. Paul Sabatier D?pt G?nie ?lectrique 0562258241 Service informatique 0562258025...
2005 Dec 30
0
strange trusts in 3.0.21?
...ACDEV trusts DEVXP and DEVEX DEVXP trusts ACDEV and DEVEX DEVEX trusts ACDEV and DEVXP A machine INTDEV4 (INTDEV4$) joins ACDEV. INTDEV4 shows INTDEV4 (local machine), ACDEV, DEVEX and DEVXP as possible choices for logging in. Perfect. Three users are used for testing: billtest (sambaSID & sambaPrimaryGroupSID is in ACDEV) log on to ACDEV - YES log on to DEVXP - YES log on to DEVEX - YES edwartho (sambaSID & sambaPrimaryGroupSID is in DEVEX) log on to ACDEV - **NO** log on to DEVXP - YES log on to DEVEX - YES test1 (sambaSID & sambaPrimaryGroupSID is in DEVXP) log on to ACDEV - **NO** l...
2004 Sep 06
0
What is the correct SambaPrimaryGroupSID
Hi, I ask to you for a small question : I have some user with this SambaPrimaryGroiupSID = S-1-5-21-XXXXX-XXXXX-XXXX-1443 And other user with this SambaPrimaryGroiupSID = S-1-5-21-XXXXX-XXXXX-XXXX-513 What is correct SambaPrimaryGroiupSID ? The SambaSID of my primary group is S-1-5-21-XXXXX-XXXXX-XXXX-513 The S-1-5-21-XXXXX-XXXXX-XXXX-1443 is the result of GID 221*2 + 1001 RID algorithm I use
2009 Aug 12
1
sambaprimaryGroupSid
Hi all! I'm configuring a samba PDC with an LDAP sam. Everything is working great except that when I do pdbedit -Lv root (which is my "Domain Administrator" account) I see that it's getting a Primary Group SID value of S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-513 instead of the S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-512 that is stored in my LDAP tree. Does someone
2003 Aug 04
1
Group mapping... static ???
...) Created Group mapping : net groupmap add sid=<mySID>-513 unixgroup=domusers ntgroup="Domain Users" type=domain (then "net groupmap list", OK) 5) Finally, created LDAP (samba) user : smbpasswd -a foo Ok, no problem, foo gets the domain local sid + the domain users rid as SambaPrimaryGroupSid, he IS a Win Domain User. Here is what I don't understand : If I delete the groupmapping or modify it, the SambaPrimaryGroupSid of foo isn't modified ! Foo remains a Domain User... Another example : if I create first the user, then the mapping : the user doens't get the new SambaPrimar...
2006 Jan 26
1
Creating a machine account manually (EMC, Samba PDC)
...db/pdb_ldap.c:init_ldap_from_sam(1064) init_ldap_from_sam: Setting entry for user: boxer$ [2006/01/26 15:32:09, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1648) ldapsam_modify_entry: Failed to modify user dn= uid=boxer$,ou=Computers,dc=zapeng,dc=com with: No such attribute modify/delete: sambaPrimaryGroupSID: no such value [2006/01/26 15:32:09, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1873) ldapsam_update_sam_account: failed to modify user with uid = boxer$, error: modify/delete: sambaPrimaryGroupSID: no such value (Success) [2006/01/26 15:32:09, 2] passdb/pdb_ldap.c:init_sam_from_ldap(640)...
2005 May 10
1
Are the following cockups in ldap entries or normal behaviour now ?
...,<snip> objectClass: posixGroup objectClass: sambaGroupMapping gidNumber: 513 cn: Domain Users <snip> description: All domain users memberUid: administrator memberUid: deloitte memberUid: iusr_guests memberUid: template My machines all have a SID that ends in 513 the domain users RID: sambaPrimaryGroupSID: S-1-5-21-<snip>-513 My users have no passwords set eg: dn: uid=deloitte,ou=Users <snip> sambaLMPassword: XXX sambaPrimaryGroupSID: S-1-5-21-<snip>-513 sambaNTPassword: XXX Is this expected behaviour when vampiring from an NT server using the smbldap-tools-0.8.8.tgz ? Or does...
2006 Mar 18
1
problems adding machines after upgrade - sambaSID attribute incomplete!
...o 3.0.21c now we can't do that anymore!. In adding a machine, the "wellcome to domain XXX" message appears, but after rebooting the machine it doesn't works!. Looking the openldap entries, now we are having these kind of entries: sambaSID: S-1-5-21-2502698289-3639879065-4582 sambaPrimaryGroupSID: S-1-5-21-2502698289-3639879065-7544774837-515 note that "one part" of the Samba SID is missing, the correct should be: sambaSID: S-1-5-21-2502698289-3639879065-7544774837-4582 so, I tried to fix the sambaSID attribute by hand on the openldap server using phpldapadmin but no luck. Al...
2013 Jun 10
2
Samba + LDAP: Issue adding machine.
Greetings. I've run into a trouble when trying to add a new Win7 machine on a domain. The domain is controlled by a server running Samba + LDAP (samba compiled with ldap support), on a Debian 5 OS at the local network. I've added the machine name to the LDAP three through phpldapadmin using the option "Samba3 Machine" on the related submenu and via terminal on samba. Then I
2005 Mar 11
2
smbldap-useradd -w problem
...omputer either does not exist or is inaccessible". In the samba log I can see: [2005/03/09 13:15:26, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1479) ldapsam_modify_entry: Failed to modify user dn= uid=nt4box$,ou=People,dc=econo mists-inc,dc=com with: No such attribute modify/delete: sambaPrimaryGroupSID: no such value [2005/03/09 13:15:26, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1694) ldapsam_update_sam_account: failed to modify user with uid = nt4box$, error: m odify/delete: sambaPrimaryGroupSID: no such value (Success) In the smb.conf file I have: add machine script = /opt/IDEALX/sb...
2004 Jul 05
1
Accounts are getting disabled
...objectClass: top objectClass: sambaSamAccount cn: alexander-cristea sn: alexander-cristea uid: alexander-cristea homeDirectory: /home/kl-1g3/alexander-cristea gecos: "kl-1g3" loginShell: /bin/sh shadowMin: 1 shadowMax: 99999 shadowWarning: 14 sambaPwdMustChange: 1800000000 gidNumber: 112 sambaPrimaryGroupSID: S-1-5-21-3371203057-3264423045-2392767973-1225 uidNumber: 5248 sambaSID: S-1-5-21-3371203057-3264423045-2392767973-11496 sambaProfilePath: \\WILMA2\profile sambaAcctFlags: [UX ] The same user monday morning: # alexander-cristea, kl-1g3, people, wms-hn.de dn: uid=alexander-cristea,ou=kl-1g3...
2003 Aug 05
0
How does group mapping function ?
...) Created Group mapping : net groupmap add sid=<mySID>-513 unixgroup=domusers ntgroup="Domain Users" type=domain (then "net groupmap list", OK) 5) Finally, created LDAP (samba) user : smbpasswd -a foo Ok, no problem, foo gets the domain local sid + the domain users rid as SambaPrimaryGroupSid, he IS a Win Domain User. Here is what I don't understand : If I delete the groupmapping or modify it, the SambaPrimaryGroupSid of foo isn't modified ! Foo remains a Domain User... Another example : if I create first the user, then the mapping : the user doens't get the new SambaPrimar...
2003 Sep 15
1
domain admin
...I use FreeBSD-5.1+samba3.0RC3. My group maps: Admins du domaine (S-1-5-21-xxxx-512) -> domainadmins Utilisa. du domaine (S-1-5-21-xxxx-513) -> domainusers Invites du domaine (S-1-5-21-xxxx-514) -> domainguests Ordinateurs du domaine (S-1-5-21-xxxx-515) -> domaincomputers All my users sambaPrimaryGroupSID are set to 513. Now, I added some users to the "domainadmins" group (with the memberUid attribute in LDAP) but they do not get admin priviledges on NT workstations... What am I missing here ? I also added "@domainadmins" to the "user admins" parameter in smb.conf, b...
2003 Sep 19
0
samba-3.0.0-rc4 and Domain Admins
...dmin) to the "Domain Admins" group on my samba-PDC using the ldapsam backend. When I add "Domain Admins" as a supplementary group, the Windows 2000 client doesn't treat smbadmin as an admin. However, using "Domain Admins" as the primary group (including setting sambaPrimaryGroupSID as "$SID-512") works as expected, the user has administrative rights. Additional information is attached below. Is this a limitation or have I missed anything? Thanks in advance, --leo P.S.: showgrps from the Resource Kit shows "Domain Admins" regardless of wether "Do...
2003 Oct 07
1
userGroupRid and groupmapping
Hi ! When I create a user with samba-ldap tools, the userRid is calculated if the -x option is set. The userGroupRid is calculated too. But is the groumapping is enabled, the SambaPrimaryGroupSID not correspond with SambaSID of groupmapping Example : Groupe "Domain Users" : gidNumber 100 displayName Domain Users objectClass sambaGroupMapping sambaSID S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxxx-513 sambaGroupType 2 cn Users User Toto : sambaPrimaryGroupSID S-1-...
2007 Jan 30
0
ldap machine attributes not filled correctly when join a domain
Hello When a windows xp workstation join a domain, by windows gui parameters, ldap machine attributes are not filled correctly: - No attribute sambaprimarygroupsid (before, there was one terminated by 515) - rid (of sambasid) is not equal a 2*uid+1000 If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid terminated by 513) All the others samba attributes are ok Same problem if i use "smbldap-useradd -w" before joining th...
2007 Feb 27
0
ldap machine account: bad RID, no SambaPrimaruGroupSID, since 3.0.23c
Hello all When a windows xp workstation join a domain, by windows gui parameters, ldap machine attributes are not filled correctly: - No attribute sambaprimarygroupsid (before, there was one terminated by 515) - rid (of sambasid) is not equal a 2*uid+1000 gid attribute is ok (515) If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid terminated by 513) All the others samba attributes are ok Same problem if i use "smbldap-useradd...
2010 Jul 12
1
smbldap-groupmod problem
...tput: server:~# smbldap-groupmod -x user1 -m user2 testgroup Can't call method "get_value" on an undefined value at /usr/sbin/smbldap-groupmod line 146. The line in question is: if ($group_entry->get_value('sambaSID') eq $user_entry->get_value('sambaPrimaryGroupSID')) { What this means? Tks in advance. -- Leonardo Carneiro