Displaying 20 results from an estimated 700 matches similar to: "How does one "look at AD" in Samba4.1?"
2014 Mar 18
2
samba-tool illegal instruction setting up Kerberos auth for http
Hi all,
Has anyone noticed this behaviour in samba-tool? I was trying to do the
Apache Single Sign on authentication:
https://wiki.samba.org/index.php/Authenticating_other_services_against_AD#Apache_Single_Sign-On
> root at bnedevdc0:~# samba-tool domain exportkeytab /root/httpd.keytab --principal=HTTP/svn.myrealm.mydomain at MYREALM.MYDOMAIN -d10
> INFO: Current debug levels:
>
2014 Mar 17
1
Samba 4.1 Active Directory and Windows 2012 Standard Evaluation
Hi all,
I've been slowly coming to grips with ActiveDirectory, having set up a
test network to figure out its innards and rehearse setting up a network
in preparation of replacing our existing NT4-based domain.
One of the machines I'm trying to join as a member server, is running
Windows 2012 Standard Evaluation. It's actually an OpenStack image
retrieved from here:
2016 Feb 01
2
"samba-tool user add" and idmap shenanigans
Hi all,
We're in the process of finally moving from our aging Samba3-based
infrastructure across to Samba4.
Rather than trying to migrate, we're just making a clean break so that
we can do it properly from day one, as there were likely some mistakes
that were made years ago we want to leave behind.
The machines under test are virtual machines running Ubuntu 14.04 LTS
AMD64. I've
2016 Feb 01
0
"samba-tool user add" and idmap shenanigans
On 01/02/16 02:52, Stuart Longland wrote:
> Hi all,
>
> We're in the process of finally moving from our aging Samba3-based
> infrastructure across to Samba4.
>
> Rather than trying to migrate, we're just making a clean break so that
> we can do it properly from day one, as there were likely some mistakes
> that were made years ago we want to leave behind.
>
>
2014 Apr 25
1
Perf enhancements in Samba4.1 related to SMB2.1 / SMB3.0 protocol
Hi Everyone,
My doubts are for Samba4.1 performance related enhancements (SMB2.1 / SMB3.0).
My experimental samba server hardware is running 4.1 version. Want to
improve robocopy WRITE throughput from a two samba client machines
(win7 or win8 or server2012 x86 servers).
Someone please advice me how can I use SMB2.1 or SMB3.0 capabilities
to improve WRITE throughput. I tried samba4.1
2014 Jun 12
0
samba4.1 as domain member in a domain I don't be admin
Hi,
I bet this question was asked several times, but I'm honestly not able
to find a solution.
My samba4.1 (running on FreeBSD10) is part of a larger network/AD where
I only have very restricted rights.
Our network consists of a "toplevel" AD-Domain (top.foo.bar) and several
"subdomains" (in my case: sub1.top.foo.bar), which have their own
domaincontrollers (MS Windows
2014 Oct 15
1
Performance tuning of Samba4.1 LDAP CRUD operations
Hi, I would like to accelerate CURD operation of LDAP.
Please let me know a tuning setup of OS or Samba.
Although I am performing shift verification to Samba 4.1.12 from
OpenLDAP 2.3, the CURD operation using a LDAP interface becomes 1/10
or less speed compared with OpenLDAP.
Although this OpenLDAP is performing an optimized tuning setup, Samba
is in the default state immediately after carrying
2020 Aug 30
1
Need help in Samba4.1 mount
Hi,
I have configured a samba share following the below link in RHEL 7 VM in
Azure.
https://www.tecmint.com/install-samba4-on-centos-7-for-file-sharing-on-windows/
https://www.youtube.com/watch?v=IMPEjYoP3N4- followed steps in this video
While mounting the directory from windows 10 I am not able to mount
\\<Azure Server IP\sharename and after a long time it fails. I have enabled
SMB
2013 Nov 18
1
samba4.1 RODC with BIND as DNS backend
OK, further to my previous message I've configured BIND, but when I try
to run samba_dnsupdate I get the following:
Nov 18 16:19:23 sles-shire named[6112]: samba b9_putrr: unhandled record
type 0
Nov 18 16:19:24 sles-shire named[6112]: samba_dlz: starting transaction
on zone _msdcs.main.adlab.netdirect.ca
Nov 18 16:19:24 sles-shire named[6112]: samba_dlz: disallowing update of
2017 Mar 16
0
Joining Samba4 to Win 2008 AD domain breaks other kerberos functions
Samba expects the keytab file as /etc/krb5.keytab.
Solaris 11 looks for a keytab file in /etc/krb5/krb5.keytab
When samba joins the domain it (probably) updates the machine password
and then updates its krb5.keytab file. When connecting via ssh,
the system would use a keytab file that had the wrong kvno and probably
the wrong password key.
The following symlink command fixed ssh
2017 Mar 09
2
Joining Samba4 to Win 2008 AD domain breaks other kerberos functions
I have a Windows 2008 domain (one Win 2008 DC, one Win 2012 R2 DC.)
I am trying to join a Solaris 11 machine to the domain for both Samba
and other services. For "unix" logins and ssh, Solaris 11 is configured
to use LDAP for user and group lookup and kerberos for authentication.
The "kclient -T ms_ad" command joins the Solaris machine to the AD
domain. It even
2004 Dec 06
0
errors from ads_krb5_mk_req errors and util_sock.c:send_smb
After 2 weeks of trying to configure samba as a member server in a
native AD domain, with winbind+nss+kerberose following the Samba
Collection and (Samba-3 By Exmaple) docuentation, with RedHat AS3,
samba 3.0.9, krb5 1.3.1, where 2 KDC's are Windows 2003 and one is
Windows 2000, and smb-signing has been turned off,...
when a user tries to access a share, they are prompted for a password,
and
2006 Mar 22
2
Authentication problems with win2k3 domain controller
Hi
I'm having problems with samba-3.0.21b and Windows Server 2003 domain
controllers.
When I try to access the samba server from a client (\\sambasrv) I
only get a login prompt, no username/password combination works.
Accessing the samba server through its IP-number instead of
using the netbios name works.
This together with the log message "Failed to verify incoming ticket!"
2017 Apr 20
5
Samba authentication using non-AD Kerberos?
On 2017-04-16, 19:06, S P Arif Sahari Wibowo via samba wrote:
> I was looking into samba wiki pages and cannot find
> documentation for this. Generally most the documentation pages
> either discussing samba as AD member or standalone.
So still looking at this.
So this is the state currently: kerberos setup (krb5.conf and
keytab) is working in the server, I can do kinit properly. But
2017 Oct 02
0
System load problem with samba 4.4.2 caused by many ntlm auth client requests
On Mon, 2 Oct 2017 14:51:54 +0200
Rainer Krienke via samba <samba at lists.samba.org> wrote:
> Hello,
> ....
> [2017/10/02 11:07:47.046715, 2]
> ../source3/auth/auth.c:315(auth_check_ntlm_password)
> check_ntlm_password: Authentication for user [HOSTNAME$] ->
> [HOSTNAME$] FAILED with error NT_STATUS_NO_SUCH_USER
>
It looks fairly obvious to me, the Samba
2006 Feb 01
0
Fwd: ADS and samba domain member: ads_connect: Cannot resolve network address for KDC in requested realm
I forgot the smb.conf file:
[global]
workgroup = MYDOMAIN
netbios name = svcanimp
socket options = TCP_NODELAY SO_RCVBUF=16384 SO_SNDBUF=16384
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users = yes
winbind gid = 10000-20000
os level = 20
winbind enum groups = yes
winbind separator = /
2006 Feb 01
1
ADS and samba domain member: ads_connect: Cannot resolve network address for KDC in requested realm
Hello,
I am having a problem getting my server to join our realm as a domain
member server. I have read through google, yahoo, and this list, but I
cannot find the answer yet.
When I run: net join ads -Uadministrator and try to login it gives the
following error:
kerberos_kinit_password Administrator@MYREALM.COM failed: Cannot
resolve network address for KDC in requested realm
2017 Jun 19
1
Bit SGID on directories
Hello,
I have a samba server v4.6.5, it’s a member of a Windows 2003 domain.
I setup a share, in this share I want to set sgid bit on directories.
I created a directory with SGID bit on the top of the share, but when I create inside new directories didn’t have SGID bits.
Here is my smb.conf :
[global]
use sendfile = no
gpfs:getrealfilename = no
smb ports = 445 139
dos charset =
2005 Jan 31
3
NAT and SIP
Hi,
Does Asterisk have a limit to how many NAT'ed SIP clients it supports behind a
single IP?
I have the weirdest problem ever. I have three SIP endpoints. SNOM phones, if
it matters. Their extensions are 200, 201 and 202. Apart from the
username/password, the sip entries in sip.conf all have identical
configuration. They're all NAT'ed behind the same IP. 200 and 202 registers
2017 Oct 02
2
System load problem with samba 4.4.2 caused by many ntlm auth client requests
Hello,
since a while I experience a strange problem with my samba 4.4.2 running
on a SLES12SP2 system. The server does what it is supposed to do, so
users can work without any problems and access their files via smb but
since some weeks the server shows a strange and unusual very high
system load.
The samba server is not the domaincrontroller (which is a windows
machine) but member of the