Displaying 20 results from an estimated 349 matches for "unix_primary_group".
2019 Feb 06
1
unix_primary_group = yes don t work
I have the same conclusion
Anybody have a conf with "unix_primary_group = yes" working ?
Christian
Le 06/02/2019 à 15:39, Rowland Penny via samba a écrit :
> On Wed, 6 Feb 2019 13:25:08 +0100
> Christian Daré via samba <samba at lists.samba.org> wrote:
>
>> thanks for the answer, Louis.
>> i m talking about the userhome dir.
>> I...
2019 Feb 06
0
unix_primary_group = yes don t work
Hai,
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> Christian Daré via samba
> Verzonden: woensdag 6 februari 2019 11:54
> Aan: samba at lists.samba.org
> Onderwerp: [Samba] unix_primary_group = yes don t work
>
> Hi,
>
> On a samba 4.9.4 fileserver using ad backend with rfc2307 , when i
> create a file from a Win10 client, it s always created with
> the rights
> user:"domain users".
> I ve understood that with "unix_primary_group = yes"...
2019 Feb 06
2
unix_primary_group = yes don t work
Hi,
On a samba 4.9.4 fileserver using ad backend with rfc2307 , when i
create a file from a Win10 client, it s always created with the rights
user:"domain users".
I ve understood that with "unix_primary_group = yes" , the file should
be created with the rights user:gidNumber .
Here is my config :
[global]
security = ADS
workgroup = SAMBA494
realm = SAMBA494.UNIV-BREST.FR
log file = /var/log/samba/%m.log
log level = 1
idmap config * : backend = tdb...
2019 Dec 10
2
unix_primary_group=yes together with vfs objects=acl_xattr not working
Hello all,
we want to change the configuration of our Samba domain member file
servers to use
unix_primary_group=yes
After some experiments I was able to get it to work, but only with
vfs objects = acl_xattr
commented out.
With acl_xattr enabled the primary group is still displayed correctly in
the output of smbstatus, but new files are not created with with this
primary group. The created files have th...
2019 Dec 19
3
unix_primary_group and unix_nss_info for rfc2307 idmap backend
Hi,
In winbind, are there any plans to add the idmap_ad options "unix_primary_group" and "unix_nss_info" to the idmap_rfc2307 backend?
I am using an ldap proxy to preserve the UNIX uids and gids between two domains, and it would be nice to also share the shell setting and the UNIX primary group as well.
2019 Feb 06
0
unix_primary_group = yes don t work
...efault:mask::rwx
default:other::---
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> Rowland Penny via samba
> Verzonden: woensdag 6 februari 2019 15:39
> Aan: samba at lists.samba.org
> Onderwerp: Re: [Samba] unix_primary_group = yes don t work
>
> On Wed, 6 Feb 2019 13:25:08 +0100
> Christian Daré via samba <samba at lists.samba.org> wrote:
>
> > thanks for the answer, Louis.
> > i m talking about the userhome dir.
> > I ve already read https://wiki.samba.org/index.php/User_Home_Fold...
2019 Feb 06
6
unix_primary_group = yes don t work
...e via samba a écrit :
> Hai,
>
>> -----Oorspronkelijk bericht-----
>> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
>> Christian Daré via samba
>> Verzonden: woensdag 6 februari 2019 11:54
>> Aan: samba at lists.samba.org
>> Onderwerp: [Samba] unix_primary_group = yes don t work
>>
>> Hi,
>>
>> On a samba 4.9.4 fileserver using ad backend with rfc2307 , when i
>> create a file from a Win10 client, it s always created with
>> the rights
>> user:"domain users".
>> I ve understood that with "unix...
2019 Feb 06
0
unix_primary_group = yes don t work
...Feb 6 14:31 /home/giduser/test.txt
However, if the user connects via SMB to a share and creates a file, I
get this:
root at testsmb:~# ls -la /home/data/test.txt
-rwxrwxr-x+ 1 giduser domain users 0 Feb 6 13:48 /home/data/test.txt
It looks like the Samba tools ignore 'idmap config SAMDOM :
unix_primary_group = yes'
Rowland
2019 Feb 06
0
unix_primary_group = yes don t work
...erence between our config/setups.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> Christian Daré via samba
> Verzonden: woensdag 6 februari 2019 17:09
> Aan: samba at lists.samba.org
> Onderwerp: Re: [Samba] unix_primary_group = yes don t work
>
> OK for the test, i made a new share like you :
>
> [users]
> browseable = yes
> path = /srv/samba/users
> read only = no
>
> From windows, i ve changed the rights on the share and change the
> homedir drive path from \\fileserve...
2019 Dec 10
0
unix_primary_group=yes together with vfs objects=acl_xattr not working
...00' for the range start number ?
It looks like it is picking up the local Unix group 'users' which has
the GID 100
> idmap config IPS:unix_nss_info = yes
> ? idmap config IPS:default = yes
I don't know where you got that line from, it doesn't exist
> idmap config IPS:unix_primary_group = yes
> ? # Use settings from AD for login shell and home directory
> ? winbind nss info = rfc2307
That line is only used if you are using Samba < 4.8.0
> winbind enum users = yes
> ? winbind enum groups = yes
You should turn the two lines above off, they are not needed and can
slow...
2019 Dec 19
1
unix_primary_group and unix_nss_info for rfc2307 idmap backend
On Thu, Dec 19, 2019 at 10:19:28PM +0000, Rowland penny via samba wrote:
> On 19/12/2019 21:46, Sebastian Lisic wrote:
> >Thanks for the quick reply, Rowland!
> >
> >The problem I have is that the clients of each domain do not have access to the other domain's DC. Only the DCs of each domain can talk to one another. With Microsoft no longer allowing POSIX attributes to be
2018 Jul 23
2
winbind behavior question
On Mon, 23 Jul 2018 16:46:50 +0800
d tbsky <tbskyd at gmail.com> wrote:
> 2018-07-23 16:04 GMT+08:00 Rowland Penny via samba
> <samba at lists.samba.org>:
> >> >>> idmap config SAMDOM:range = 1000-999999
> >> idmap config SAMDOM:unix_primary_group = yes
> >
> > That isn't a bug, it is a feature ;-)
> > Before 4.6.0 everyone got 'Domain Users' as their primary Unix
> > group, but from 4.6.0, you can give users a gidNumber attribute
> > and, with the line above, this will be used for the users primary...
2019 Dec 10
1
unix_primary_group=yes together with vfs objects=acl_xattr not working
...9;t the Primary Group GID entry of the user in AD have
precedence over the 'Domain Users' membership?
>> idmap config IPS:unix_nss_info = yes
>> ? idmap config IPS:default = yes
> I don't know where you got that line from, it doesn't exist
>> idmap config IPS:unix_primary_group = yes
>> ? # Use settings from AD for login shell and home directory
>> ? winbind nss info = rfc2307
> That line is only used if you are using Samba < 4.8.0
>> winbind enum users = yes
>> ? winbind enum groups = yes
> You should turn the two lines above off, they ar...
2019 Feb 06
4
unix_primary_group = yes don t work
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> Rowland Penny via samba
> Verzonden: woensdag 6 februari 2019 16:33
> Aan: samba at lists.samba.org
> Onderwerp: Re: [Samba] unix_primary_group = yes don t work
>
> On Wed, 6 Feb 2019 15:58:52 +0100
> L.P.H. van Belle <belle at bazuin.nl> wrote:
>
> > Hai Rowland,
> >
> > Thats strange.. my test shows different things.
> >
> > A SSH login, SSO/kerberos on domain member with nfsv4 kerber...
2019 Dec 10
2
unix_primary_group=yes together with vfs objects=acl_xattr not working
Hi Rowland,
Am 10.12.19 um 13:05 schrieb Rowland penny via samba:
> On 10/12/2019 11:41, Klaus Jaensch via samba wrote:
>> Hello all,
>>
>> we want to change the configuration of our Samba domain member file
>> servers to use
>>
>> unix_primary_group=yes
>>
>> After some experiments I was able to get it to work, but only with
>>
>> vfs objects = acl_xattr
>>
>> commented out.
>>
>> With acl_xattr enabled the primary group is still displayed correctly
>> in the output of smbstatus, but new f...
2019 Feb 13
3
idmap backend ad well-known-sids 512 & 513
...hing works as expected and we get the
correct group with the correct GID:
root at fileserv2:~# getent group SOMEDOM\\stas
SOMEDOM\stas:x:10165:
We can use getent passwd and wbinfo -i fine for all our ldap created
users and get the correct UID/GID if we are using the config:
idmap config SOMEDOM:unix_primary_group = yes
root at fileserv2:~# getent passwd SOMEDOM\\test.zweimal
SOMEDOM\test.zweimal:*:10409:10000::/home/test.zweimal:/bin/false
root at fileserv2:~# wbinfo -i SOMEDOM\\test.zweimal
SOMEDOM\test.zweimal:*:10409:10000::/home/test.zweimal:/bin/false
10000 is the default GID we were using in ldap fo...
2019 May 06
2
Samba with AD : SID rejected
...rrect.
>>>
>>> You originally posted this:
>>>
>>> idmap config FOO:backend = ad
>>> idmap config FOO:schema_mode = rfc2307
>>> idmap config FOO:range = 10000-999999
>>> idmap config FOO:unix_nss_info = yes
>>> idmap config FOO:unix_primary_group = yes
>>>
>>> So, does 'vincent' have a uidNumber attribute containing a number
>>> inside the range '10000-99999999' AND either a gidnumber attribute
>>> containing the gidNumber of an AD group, or does Domain
>>> Users have gidNumber at...
2017 Jun 05
1
RPC Server is unavailable
...; idmap config * : range = 50000-60000
>> idmap config * : backend = tdb
>> idmap config XYZ : range = 50000-60000
>> idmap config XYZ : backend = rid
>
> The ranges shouldn't overlap
>
>>
>> idmap config * : unix_primary_group = yes
>
> I think you can only use the above line with the 'ad' backend.
When i set backet to 'ad' i can't start winbindd
Output: "main: FATAL: Invalid idmap backend ad configured as the default
backend!"
>
> Rowland
>
Best regards,
Supporter 3eb
2019 May 06
2
Samba with AD : SID rejected
...hows a user, doesn't mean that a Unix OS will
know the user, even if the smb.conf appears to be correct.
You originally posted this:
idmap config FOO:backend = ad
idmap config FOO:schema_mode = rfc2307
idmap config FOO:range = 10000-999999
idmap config FOO:unix_nss_info = yes
idmap config FOO:unix_primary_group = yes
So, does 'vincent' have a uidNumber attribute containing a number
inside the range '10000-99999999' AND either a gidnumber attribute
containing the gidNumber of an AD group, or does Domain
Users have gidNumber attribute ? The gidNumber must be inside the same
range.
Rowland
2019 Jul 09
2
Winbind issues with AD member file server
...= system keytab
template homedir = /soe/%U
workgroup = BSOE
template shell = /bin/bash
security = ads
realm = AD.SOE.UCSC.EDU
idmap config BSOE : schema_mode = rfc2307
idmap config BSOE : range = 100-999999
idmap config BSOE : backend = ad
idmap config BSOE : unix_nss_info = yes
idmap config BSOE : unix_primary_group = yes
idmap config * : range = 10000000-10999999
idmap config * : backend = tdb
winbind use default domain = no
winbind refresh tickets = yes
winbind offline logon = yes
winbind enum groups = no
winbind enum users = no
###############################################################################...