search for: unix_primary_group

Displaying 20 results from an estimated 329 matches for "unix_primary_group".

2019 Feb 06
1
unix_primary_group = yes don t work
I have the same conclusion Anybody have a conf with "unix_primary_group = yes" working ? Christian Le 06/02/2019 à 15:39, Rowland Penny via samba a écrit : > On Wed, 6 Feb 2019 13:25:08 +0100 > Christian Daré via samba <samba at lists.samba.org> wrote: > >> thanks for the answer, Louis. >> i m talking about the userhome dir. >> I...
2019 Feb 06
0
unix_primary_group = yes don t work
Hai, > -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Christian Daré via samba > Verzonden: woensdag 6 februari 2019 11:54 > Aan: samba at lists.samba.org > Onderwerp: [Samba] unix_primary_group = yes don t work > > Hi, > > On a samba 4.9.4 fileserver using ad backend with rfc2307  , when i > create a file from a Win10 client, it s always created with > the rights > user:"domain users". > I ve understood that with "unix_primary_group = yes"...
2019 Feb 06
2
unix_primary_group = yes don t work
Hi, On a samba 4.9.4 fileserver using ad backend with rfc2307  , when i create a file from a Win10 client, it s always created with the rights user:"domain users". I ve understood that with "unix_primary_group = yes" , the file should be created with the rights user:gidNumber . Here is my config : [global]        security = ADS        workgroup = SAMBA494        realm = SAMBA494.UNIV-BREST.FR        log file = /var/log/samba/%m.log        log level = 1        idmap config * : backend = tdb...
2019 Dec 10
2
unix_primary_group=yes together with vfs objects=acl_xattr not working
Hello all, we want to change the configuration of our Samba domain member file servers to use unix_primary_group=yes After some experiments I was able to get it to work, but only with vfs objects = acl_xattr commented out. With acl_xattr enabled the primary group is still displayed correctly in the output of smbstatus, but new files are not created with with this primary group. The created files have th...
2019 Dec 19
3
unix_primary_group and unix_nss_info for rfc2307 idmap backend
Hi, In winbind, are there any plans to add the idmap_ad options "unix_primary_group" and "unix_nss_info" to the idmap_rfc2307 backend? I am using an ldap proxy to preserve the UNIX uids and gids between two domains, and it would be nice to also share the shell setting and the UNIX primary group as well.
2019 Feb 06
0
unix_primary_group = yes don t work
...efault:mask::rwx default:other::--- Greetz, Louis > -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Rowland Penny via samba > Verzonden: woensdag 6 februari 2019 15:39 > Aan: samba at lists.samba.org > Onderwerp: Re: [Samba] unix_primary_group = yes don t work > > On Wed, 6 Feb 2019 13:25:08 +0100 > Christian Daré via samba <samba at lists.samba.org> wrote: > > > thanks for the answer, Louis. > > i m talking about the userhome dir. > > I ve already read https://wiki.samba.org/index.php/User_Home_Fold...
2019 Feb 06
6
unix_primary_group = yes don t work
...e via samba a écrit : > Hai, > >> -----Oorspronkelijk bericht----- >> Van: samba [mailto:samba-bounces at lists.samba.org] Namens >> Christian Daré via samba >> Verzonden: woensdag 6 februari 2019 11:54 >> Aan: samba at lists.samba.org >> Onderwerp: [Samba] unix_primary_group = yes don t work >> >> Hi, >> >> On a samba 4.9.4 fileserver using ad backend with rfc2307  , when i >> create a file from a Win10 client, it s always created with >> the rights >> user:"domain users". >> I ve understood that with "unix...
2019 Feb 06
0
unix_primary_group = yes don t work
...Feb 6 14:31 /home/giduser/test.txt However, if the user connects via SMB to a share and creates a file, I get this: root at testsmb:~# ls -la /home/data/test.txt -rwxrwxr-x+ 1 giduser domain users 0 Feb 6 13:48 /home/data/test.txt It looks like the Samba tools ignore 'idmap config SAMDOM : unix_primary_group = yes' Rowland
2019 Feb 06
0
unix_primary_group = yes don t work
...erence between our config/setups. Greetz, Louis > -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Christian Daré via samba > Verzonden: woensdag 6 februari 2019 17:09 > Aan: samba at lists.samba.org > Onderwerp: Re: [Samba] unix_primary_group = yes don t work > > OK for the test, i made a new share like you : > > [users] >     browseable = yes >     path = /srv/samba/users >     read only = no > > From windows, i ve changed the rights on the share and change the > homedir drive path from \\fileserve...
2019 Dec 10
0
unix_primary_group=yes together with vfs objects=acl_xattr not working
...00' for the range start number ? It looks like it is picking up the local Unix group 'users' which has the GID 100 > idmap config IPS:unix_nss_info = yes > ? idmap config IPS:default = yes I don't know where you got that line from, it doesn't exist > idmap config IPS:unix_primary_group = yes > ? # Use settings from AD for login shell and home directory > ? winbind nss info = rfc2307 That line is only used if you are using Samba < 4.8.0 > winbind enum users = yes > ? winbind enum groups = yes You should turn the two lines above off, they are not needed and can slow...
2019 Dec 19
1
unix_primary_group and unix_nss_info for rfc2307 idmap backend
On Thu, Dec 19, 2019 at 10:19:28PM +0000, Rowland penny via samba wrote: > On 19/12/2019 21:46, Sebastian Lisic wrote: > >Thanks for the quick reply, Rowland! > > > >The problem I have is that the clients of each domain do not have access to the other domain's DC. Only the DCs of each domain can talk to one another. With Microsoft no longer allowing POSIX attributes to be
2018 Jul 23
2
winbind behavior question
On Mon, 23 Jul 2018 16:46:50 +0800 d tbsky <tbskyd at gmail.com> wrote: > 2018-07-23 16:04 GMT+08:00 Rowland Penny via samba > <samba at lists.samba.org>: > >> >>> idmap config SAMDOM:range = 1000-999999 > >> idmap config SAMDOM:unix_primary_group = yes > > > > That isn't a bug, it is a feature ;-) > > Before 4.6.0 everyone got 'Domain Users' as their primary Unix > > group, but from 4.6.0, you can give users a gidNumber attribute > > and, with the line above, this will be used for the users primary...
2019 Dec 10
1
unix_primary_group=yes together with vfs objects=acl_xattr not working
...9;t the Primary Group GID entry of the user in AD have precedence over the 'Domain Users' membership? >> idmap config IPS:unix_nss_info = yes >> ? idmap config IPS:default = yes > I don't know where you got that line from, it doesn't exist >> idmap config IPS:unix_primary_group = yes >> ? # Use settings from AD for login shell and home directory >> ? winbind nss info = rfc2307 > That line is only used if you are using Samba < 4.8.0 >> winbind enum users = yes >> ? winbind enum groups = yes > You should turn the two lines above off, they ar...
2019 Feb 06
4
unix_primary_group = yes don t work
> -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Rowland Penny via samba > Verzonden: woensdag 6 februari 2019 16:33 > Aan: samba at lists.samba.org > Onderwerp: Re: [Samba] unix_primary_group = yes don t work > > On Wed, 6 Feb 2019 15:58:52 +0100 > L.P.H. van Belle <belle at bazuin.nl> wrote: > > > Hai Rowland, > > > > Thats strange.. my test shows different things. > > > > A SSH login, SSO/kerberos on domain member with nfsv4 kerber...
2019 Dec 10
2
unix_primary_group=yes together with vfs objects=acl_xattr not working
Hi Rowland, Am 10.12.19 um 13:05 schrieb Rowland penny via samba: > On 10/12/2019 11:41, Klaus Jaensch via samba wrote: >> Hello all, >> >> we want to change the configuration of our Samba domain member file >> servers to use >> >> unix_primary_group=yes >> >> After some experiments I was able to get it to work, but only with >> >> vfs objects = acl_xattr >> >> commented out. >> >> With acl_xattr enabled the primary group is still displayed correctly >> in the output of smbstatus, but new f...
2019 Feb 13
3
idmap backend ad well-known-sids 512 & 513
...hing works as expected and we get the correct group with the correct GID: root at fileserv2:~# getent group SOMEDOM\\stas SOMEDOM\stas:x:10165: We can use getent passwd and wbinfo -i fine for all our ldap created users and get the correct UID/GID if we are using the config: idmap config SOMEDOM:unix_primary_group = yes root at fileserv2:~# getent passwd SOMEDOM\\test.zweimal SOMEDOM\test.zweimal:*:10409:10000::/home/test.zweimal:/bin/false root at fileserv2:~# wbinfo -i SOMEDOM\\test.zweimal SOMEDOM\test.zweimal:*:10409:10000::/home/test.zweimal:/bin/false 10000 is the default GID we were using in ldap fo...
2019 May 06
2
Samba with AD : SID rejected
...rrect. >>> >>> You originally posted this: >>> >>> idmap config FOO:backend = ad >>> idmap config FOO:schema_mode = rfc2307 >>> idmap config FOO:range = 10000-999999 >>> idmap config FOO:unix_nss_info = yes >>> idmap config FOO:unix_primary_group = yes >>> >>> So, does 'vincent' have a uidNumber attribute containing a number >>> inside the range '10000-99999999' AND either a gidnumber attribute >>> containing the gidNumber of an AD group, or does Domain >>> Users have gidNumber at...
2017 Jun 05
1
RPC Server is unavailable
...; idmap config * : range = 50000-60000 >> idmap config * : backend = tdb >> idmap config XYZ : range = 50000-60000 >> idmap config XYZ : backend = rid > > The ranges shouldn't overlap > >> >> idmap config * : unix_primary_group = yes > > I think you can only use the above line with the 'ad' backend. When i set backet to 'ad' i can't start winbindd Output: "main: FATAL: Invalid idmap backend ad configured as the default backend!" > > Rowland > Best regards, Supporter 3eb
2019 May 06
2
Samba with AD : SID rejected
...hows a user, doesn't mean that a Unix OS will know the user, even if the smb.conf appears to be correct. You originally posted this: idmap config FOO:backend = ad idmap config FOO:schema_mode = rfc2307 idmap config FOO:range = 10000-999999 idmap config FOO:unix_nss_info = yes idmap config FOO:unix_primary_group = yes So, does 'vincent' have a uidNumber attribute containing a number inside the range '10000-99999999' AND either a gidnumber attribute containing the gidNumber of an AD group, or does Domain Users have gidNumber attribute ? The gidNumber must be inside the same range. Rowland
2019 Jul 09
2
Winbind issues with AD member file server
...= system keytab template homedir = /soe/%U workgroup = BSOE template shell = /bin/bash security = ads realm = AD.SOE.UCSC.EDU idmap config BSOE : schema_mode = rfc2307 idmap config BSOE : range = 100-999999 idmap config BSOE : backend = ad idmap config BSOE : unix_nss_info = yes idmap config BSOE : unix_primary_group = yes idmap config * : range = 10000000-10999999 idmap config * : backend = tdb winbind use default domain = no winbind refresh tickets = yes winbind offline logon = yes winbind enum groups = no winbind enum users = no ###############################################################################...