Displaying 20 results from an estimated 7000 matches similar to: "New ADS infrastructure with winbind - Which is the best ID-mapping: IDMAP_RID or IDMAP LDAP with ADS + SFU schema ?"
2005 May 31
1
winbind: idmap_rid - no user mapping
Hello,
I've some trouble with winbind and the idmap_rid feature in an ADS
environment. (Opteron with Debian 3.1pure64, official Samba/Winbind
packet 3.0.14a)
Without "idmap backend = idmap_rid:...." in the smb.conf a "getent
passwd" works fine.
Then I delete the /var/lib/samba/*.tdb-files, activate idmap_rid in
smb.conf (see below) and join the ADS-Domain once more -
2005 May 17
3
Linux integration with AD
Hi All,
I extended my AD schema (SFU 3.5) and migrated the users and groups from my
NIS domain.
The groups migrated from the NIS have the same GID like on the NIS.
I added linux machines to my AD domain using windbind, and define on the
smb.conf "idmap gid = 10000-20000".
I logged in using my AD user account, and when I'm doing "id", I see that
all the AD groups
2005 Feb 04
1
Samba RPMs for RedHat/FC and idmap_rid
As discussed previously on this list, Samba RPMs for
Fedora Core do not include idmap_rid support. This is
also true for older RedHat distributions. SuSE on the
other hand, seems to have been patching in idmap_rid
support since 3.0.5 or so; and with trusted domain
support, to boot. Harrumph.
I've been able to rebuild samba srpms on FC2 and
RedHat 8 by patching the samba distributed rpms,
2006 Sep 25
2
idmap ad and sfu anyone?
samba SVN 17972, Linux 2.6.16-1.2096
That should be about the same as 2.0.23c
getent passwd works to list domain accounts
getent group works to list domain groups
kinit works for domain accounts
wbinfo -u lists domain user accounts
wbinfo -g lists domain group accounts
In order to access roaming profiles and any shares from 2000 & XP
clients, I have to map DOMAIN\username to username in
2005 Aug 24
6
Wbinfo -Y couldn't work with idmap_rid for BUILTIN groups
Hi,
wbinfo -Y BUILTIN\group can work without idmap_rid in Samba-3.0.14a. But
I'm experiencing wbinfo -Y with idmap_rid failed for SID to GID
conversion of BUILTIN groups.
Since idmap_rid only works in a single domain, and captures workgroup's
domain sid as a real domain sid in rid_idmap_get_domains(), when running
"wbinfo -Y BUILTIN/System Operators", the function
2005 Dec 06
2
Help IDMAP_RID and trusted domains
hi,
it?s me again :(
i?m still not able to use idmap_rid in a trusted domain environment
(samba v3.0.20b Sernet).
well, to be clear: NSS is not working (id, getent passwd <user>, ...) so
samba does not find the posix information for any user from a foreign domain
it?s working in a single domain with
#####################################
# WINBIND - Settings
idmap backend =
2005 Feb 01
2
Auth failing - idmap_rid?
The samba server is FC3 / samba 3.0.10 (Fedora package w/ idmap_rid
compiled)
The samba server shows up in the browse list, but when you select it
from an XP machine windows spits up "\\ server is not accessable" yada
yada "The user name could not be found" The following shows up twice in
/var/log/samba/winbindd:
[2005/02/01 14:00:27, 0]
2006 Feb 25
1
Compiling Samba on AIX 5.3 with idmap_rid fails
Hi everyone,
I'm trying to use idmap_rid with Samba 3.0.21c on AIX 5.3. So far, I've
not been successful.
I've followed the method from
http://us5.samba.org/samba/ftp/Binary_Packages/AIX/README to compile Samba,
but added "--with-static-modules=idmap_rid". Also, I used IBM's compiler
and not gcc.
The compilation fails as follows:
[...]
Compiling sam/idmap.c
Compiling
2005 Jan 30
2
How to support idmap_rid on Fedora Core 3?
Hello,
Please forgive me if this has been discussed, I did not find any
references when I searched.
I'm trying to replace a W2K server with a samba member server in a
single ADS domain.
It seems that the Fedora rpms do not support idmap_rid so I am trying to
compile from the Fedora SRPM. After following the docs for building and
configuring idmap_rid I get no ADS users from `getent
2017 Nov 14
2
Confbridge SFU for Asterisk 15
I am trying to get the "Mega Phone" demo working on my office PBX
but there seems to be a problem when trying to set the default bridge to
sfu mode. I have the following configuration in confbridge.conf in the
default_bridge section: video_mode = sfu but when I do a "confbridge
show profile bridge default_bridge" I see:
Video Mode: no video
I can change it
2008 Mar 28
1
Problems with Samba(idmap_ad/sfu on AIX
I'm unabe to use idmap_ad and sfu nss info with Samba on AIX. The
configuration as it is works on a Linux build.
workgroup = DOMAIN
realm = DOMAIN.TLD
server string = SERVER
security = ADS
idmap domains = DOMAIN
idmap config DOMAIN:default = yes
idmap config DOMAIN:backend = ad
idmap config DOMAIN:range = 1000 - 60000
2010 Mar 22
1
IDMAP_RID with Winbind works for groups but not users
Hi,
I've setup samba 3.4.7 to use idmap_rid as per the documentation:
idmap backend = rid:DOMAIN=500-100000000
idmap gid = 500-100000000
imap uid = 500-100000000
It seems to work for groups:
wbinfo --group-info="domain admins"
domain admins:x:100512
PsGetSid v1.43 - Translates SIDs to names and vice versa
Copyright (C) 1999-2006 Mark Russinovich
Sysinternals -
2004 Feb 11
1
SFU?
Hello!
I just compiled rsync 2.6.0 on SFU 3.5 and it works :-)
Did somebody test it for real work?
Thank you!
2009 Nov 11
3
idmap_rid/idmap_hash collisions?
Is it possible for the uid/gid numbers that are generated by the
idmap_rid and idmap_hash to collide if there are a large number of
users or groups? I cannot seem to find any documentation on the
limitations of these plugins. Before using I want to make absolutely
sure that there won't be any collisions.
In doing some research about Likewise Open, I see it's hashing routine
can have
2006 Mar 24
2
SFU Permission Denied
This appears to be an old problem, but is a complete show stopper for us
at the moment.
We are trying to access an NFS file system, via Samba, from a WinXP
client. Within Windows itself everything is fine, but when accessing the
shares from within an SFU cshell, an error is returned when a file is
created. The file is successfully created, but a "Permission Denied"
error is returned.
2005 Jul 14
0
error: net ads join - Debian AMD64 sarge
Can anybody from our experts help please?
I had some trouble with joining a Win2003SP1 (SFU Schema is also
installed) domain in ADS mode - config files and error logs are listed
at the end.
the goal is:
-joining a Win2003SP1 domain (with SFU Schema) in ADS-mode
-authenticate with winbind / PADL against this ads-dc (also offline for
notebooks with padl cache plugin)
It would be great, if
2007 Aug 02
1
rsync 3.0 for SFU
hi, I having problems with a knowed bug in rsync, it hangs during
transfers in the SFU version (services for unix), I read in this page
http://www.mail-archive.com/rsync@lists.samba.org/msg18807.html
that if I use the --no-ir option in the rsync 3.0 version, it will
avoid the hang bug...
the problem is that I dont know where to download that version of rsync
for the SFU... or when will be
2004 Sep 21
1
SFU Samba Permission Denied
I recently ran into a problem accessing Samba shares from SFU. From
SFU's /net directory, I could read from files, move files, create
directories and even append to files using >>. But, when I tried to
create a file, I received a "Permission Denied" message.
After looking at the logs I found something which looked out of place.
I am currently using (I tried many different
2005 May 10
2
Using ldap for permissions/authenication
Hi all:
I am currently using Active Directories (via openldap client) to
authenicate my linux clients and would like to have samba use AD (ldap -
not winbind) as well. I really haven't seen any documentation on how to
implement, however. Does anyone have any information regarding ldap and
samba (redhat rpm)?
Thanks!
Kind Regards,
Jennifer Fountain
Systems Administrator/Security
R&B
2017 Nov 14
2
Confbridge SFU for Asterisk 15
On 11/14/17 3:55 PM, Joshua Colp wrote:
> On Tue, Nov 14, 2017, at 05:47 PM, Carlos Chavez wrote:
>> I followed the blog post and I can get video from the conference if
>> I configure the bridge as follow_talker so I know everything is working
>> on the pjsip side. The only problem is that video_mode = sfu is
>> apparently not valid in either confbridge.conf or