Displaying 20 results from an estimated 10000 matches similar to: "Users suddenly have no access"
2005 Jun 06
1
Problem listing group membership from Windows
I planned using ifmember.exe from Windows 2000 resource kit to map the right
drive-mappings to the right shares with logon-scripts. Unfortunately it seems
as ifmember simply doesnt report the right groups for the users.
Even tho "id user1" shows the right groups;
"uid=2082(user1) gid=1002(Group1)roups=1002(Group1),545(Users),1000(Group0)",
User is a member of group
2010 Jun 29
0
winbindd GETGRENT results in trusted domains environment
Good day.
1. We have configured two domain controllers on Windows 2003 R2. We
named them TEST.LOCAL and CHILD.TEST.LOCAL respectively and made a
trust relationships between them. 2. We have installed Samba 3.5.3 on
Ubuntu 9.10, kernel 2.6.31-14 and configured it for using winbindd.
We have encountered a problem with results that winbind returns
upon a command GETGRENT. We
2011 Feb 03
0
Need advises on mixed-effect model ( a concrete example)
Dear R-help members,
I'm trying to run LME model on some behavioral data and need
confirmations about what I'm doing...
Here's the story...
I have some behavioral reaction time (RT) data (participants have to
detect dome kind of auditory stimuli). the dependant variable is RT
measured in milliseconds. 61 participants were tested separated in 4 age
groups (unblanced groups,
2011 Jul 11
2
Help! permission denied when accessing folder
Hi all,
Running samba 3.5.5 in a Solaris non-global zone. I have created a folder (StudentJobApplications) on a share which I want to make accessible only to members of a Unix group (studempl). I have added myself to the group but when I or other group members try to access the folder via Windows Explorer I get the following:
I:\StudentJobApplications is not accessible
Access is denied
Here
2009 Aug 03
0
sub-directory permissions and active directory group membership
I'm not sure where the problem is, but security group membership and
access to sub-directories is giving me fits.
Take 2 unique security groups as example, group1 and group2. If within
my top level share there is a directory labeled marketing and a second
directory labeled legal, where group1 and group2 are assigned to
marketing and legal respectively, then the group1 members should not
2005 Nov 07
0
Group mapping doesn't seem to be working
Hi everyone,
I'm having some trouble getting group mapping to work. I want to have a
Samba share that contains a number of different folders, and some of those
folders will be restricted depending on the user's membership to certain
Active Directory groups. I thought this could be done by mapping the Active
Directory groups to equivalent UNIX groups, and then using standard UNIX
2006 Jun 07
2
See if authenticated user is in group XYZ
I have winbindd running.
I run wbinfo -a userXYZ%pass and it succeeds
Now I want to know if userXYZ is in group "monkeys", but I dont want
to have to have to map anything. Is this possible? Is there a way to
just say "give me the windows group names that userXYZ is in?" or "is
userXYZ in windows group name 'monkeys'?"
Thanks!
- Jeremiah
2015 Nov 04
0
Pam_mount not working with "sec=krb5"
First please note the following is not really linked to your NFS question,
it's more related to automation, credentials everywhere and how to secure
them a little bit.
The point dealing with keytab or credentials in general when used for
automation, as these credentials can potentially used by some attacker, is
to create dedicated user which can perform only what it is supposed to
perform.
2015 Nov 04
0
Pam_mount not working with "sec=krb5"
2015-11-04 13:58 GMT+01:00 Ole Traupe <ole.traupe at tu-berlin.de>:
> Mathias, thanks again! This sounds like a very reasonable approach. I know
> that with remote ssh and public key authentication you can set the limit to
> a single possible command. is this also possible with AD users?
>
I'm interested by the restriction to only one command for users. The only I
see that
2015 Nov 04
0
Pam_mount not working with "sec=krb5"
Very interesting thread! Thank you all for sharing your thoughts and knowledge.
Regards
Davor
-- Skickat från mobilusken! --
----- Ursprungligt meddelande -----
Från: "Ole Traupe" <ole.traupe at tu-berlin.de>
Skickat: 2015-11-04 15:29
Till: "samba at lists.samba.org" <samba at lists.samba.org>
Ämne: Re: [Samba] Pam_mount not working with "sec=krb5"
2015 Nov 04
3
Pam_mount not working with "sec=krb5"
>
> If by "key" you meant keytab then you were right. A keytab is a file
> dedicated to contains credentials (https://kb.iu.edu/d/aumh or
> http://web.mit.edu/Kerberos/krb5-1.12/doc/basic/keytab_def.html).
>
> Keytab are used when you want to automate actions which need
> authentication. When some automated action requires credentials you
> have to provide
2015 Nov 04
2
Pam_mount not working with "sec=krb5"
So finally here is the solution that works for me. If you have any
questions, just ask.
I use pam_mount with the following volume definition in the
"/etc/security/pam_mount.conf.xml":
<volume fstype="cifs" server="server" path="home/%(USER)"
mountpoint="/home/%(USER)" sgrp="domain users"
1999 Aug 17
2
smbclient does not show.....
Hi,
this is a new user who is trying to reach the local network, managed by a windows NT server. I have edited my smb.conf
file (which I include) so to be able to reach the network drives and the printers on the ntserver locally. When I try to
see what is available using smbclient at the prompt, I cannot see which are the Services available (sharename fields
empty), but I do see a lot of things
2003 Apr 15
0
ACL group permissions only work on primary group (RickSegeberg)
I appreciate your response and I tried your solution. However, it does not seem to help.
I am using MS Active Directory on a Windows 2000 server for the authentication and rights for the users. I realize AD is based on LDAP, but it's been changed to suit Microsoft's needs - meaning it's not "pure ldap".
Based on what you said, I made sure to create a user and a few groups
2012 Aug 21
2
Iterative sampling with restrictions
Hi all,
I'm working on a seemingly trivial problem that I can't figure out how
to implement in R. I'd be most grateful for any help here.
I want to do the following: first, randomly assign each of n units to
one of g groups of size n/g. Then, randomly re-assign each of the n
units to a different group (i.e., same as the first step, but the unit
can't be assigned to a group to
2002 Oct 18
3
Host Key Verification failed - ssh via cgi
hi, my scenario is this:
i have a cgi (on host1) that executes ssh (as userxyz) to a remote server (host2), executes a command to retrieve some data and outputs them to the local browser.
on host1:
#!/usr/bin/perl -w
...
$output = `/usr/local/bin/ssh -l userxyz -x host2 ls -l`
...
but i get "Host Key Verification failed" on my apache's error_log. i can do it on the command line,
2015 Nov 04
2
Pam_mount not working with "sec=krb5"
Am 04.11.2015 um 14:49 schrieb mathias dufresne:
> 2015-11-04 13:58 GMT+01:00 Ole Traupe <ole.traupe at tu-berlin.de>:
>
>> Mathias, thanks again! This sounds like a very reasonable approach. I know
>> that with remote ssh and public key authentication you can set the limit to
>> a single possible command. is this also possible with AD users?
>>
> I'm
2015 Nov 04
3
Pam_mount not working with "sec=krb5"
Mathias, thanks again! This sounds like a very reasonable approach. I
know that with remote ssh and public key authentication you can set the
limit to a single possible command. is this also possible with AD users?
Unfortunately, I don't have 'multiuser' support in my current cifs-utils
version 4.8. So I would end up with your designated user being the owner
of all the files and
2011 Feb 09
1
Questions about dovecot-shared in 1.2 and inherit group membership from parent mailbox
Hi,
I read the Wiki about dovecot-shared a few times but it is not 100%
clear to me (at least for 1.2).
First, if I want shared keywords I *must* have a dovecot-shared. In this
case, the permissions are not taken any longer from the parent folder
(what is exactly this parent folder?) but from the dovecot-shared file.
So in some sense dovecot-shared is always required (since everyone would
2020 Feb 09
0
wbinfo -r reports strange gids on AD member
On 24.01.2020 14:01, Christian wrote:
> On 23.01.2020 10:26, L.P.H. van Belle via samba wrote:
>> Hai Christian,
>>
>>>>> Thism, this is just strange, Christian, did you already
>>> run and if not, can you run it and post the ouputs. :
>>>>> net cache flush
>>>>> systemctl stop samba winbind
>>>>> systemctl