Displaying 20 results from an estimated 20000 matches similar to: "A proposal to the Samba developers: extension of the RID backend"
2016 Jan 10
0
Security permissions issues after changing idmap backend from RID to AUTORID
On 08/01/16 19:30, Partha Sarathi wrote:
> adding samba list
>
> On Fri, Jan 8, 2016 at 10:22 AM, Partha Sarathi <parthasarathi.bl at gmail.com>
> wrote:
>
>> Hi,
>>
>>
>> We have a customer who facing security issues after changing RID idmap
>> backend to AUTORID.
>>
>>
>> The History of the issue looks as below,
>>
2016 Jan 11
0
Security permissions issues after changing idmap backend from RID to AUTORID
Thanks Michael,
Please see the inline answers.
> On Jan 10, 2016, at 5:16 PM, Michael Adam <obnox at samba.org> wrote:
>
> On 2016-01-10 at 17:58 +0000, Rowland penny wrote:
>> On 10/01/16 17:05, Partha Sarathi wrote:
>>>
>>>> This could have a lot to do with the fact that idmap_rid &
>>>> idmap_autorid calculate the uids differently
2015 Feb 21
0
Winbind backend : rid is too much underappreciated
On 21/02/15 20:05, Miguel Medalha wrote:
> I just came to the conclusion that the rid backend has been very much underappreciated. Too much mental inertia about how things used to be made?
>
> After strugling for two days to configure a member server against a Samba Active Directory with the ad/RFC2307 backend, I turned to the rid backend and voil?! all my problems are gone. Having to
2016 Jan 10
0
Security permissions issues after changing idmap backend from RID to AUTORID
On 10/01/16 17:05, Partha Sarathi wrote:
> Thanks for the reply. Now we end-up with mix uid/gid from both ranges
> in cache TDBs. Few user logins are denied with below error in smbd.log,
>
> *[2016/01/07 11:39:44.475960, 1, pid=5202]
> ../source3/auth/token_util.c:430(add_local_groups
> *
> ** SID S-1-5-21-3082371790-1274690562-2878062458-5771 ->
> getpwuid(10005771)
2015 Feb 21
9
Winbind backend : rid is too much underappreciated
I just came to the conclusion that the rid backend has been very much underappreciated. Too much mental inertia about how things used to be made?
After strugling for two days to configure a member server against a Samba Active Directory with the ad/RFC2307 backend, I turned to the rid backend and voil?! all my problems are gone. Having to manually edit uids/gids in UNIX Attributes under RSAT
2016 Jan 11
2
Security permissions issues after changing idmap backend from RID to AUTORID
On 2016-01-10 at 17:58 +0000, Rowland penny wrote:
> On 10/01/16 17:05, Partha Sarathi wrote:
> >
> > > This could have a lot to do with the fact that idmap_rid &
> > > idmap_autorid calculate the uids differently i.e if you have RID
> > > '2025000', autorid would calculate this as '1102500000' , rid
> > > would calculate this as
2016 Jan 10
2
Security permissions issues after changing idmap backend from RID to AUTORID
Thanks for the reply. Now we end-up with mix uid/gid from both ranges in
cache TDBs. Few user logins are denied with below error in smbd.log,
*[2016/01/07 11:39:44.475960, 1, pid=5202]
../source3/auth/token_util.c:430(add_local_groups*
** SID S-1-5-21-3082371790-1274690562-2878062458-5771 -> getpwuid(10005771)
failed**
wbinfo --user-info=mariond
mariond:*:10015138:110000513:Marion,
2016 Jan 08
2
Security permissions issues after changing idmap backend from RID to AUTORID
adding samba list
On Fri, Jan 8, 2016 at 10:22 AM, Partha Sarathi <parthasarathi.bl at gmail.com>
wrote:
> Hi,
>
>
> We have a customer who facing security issues after changing RID idmap
> backend to AUTORID.
>
>
> The History of the issue looks as below,
>
> 1) When samba configured with RID idmap backend customer requested to
> change few permissions,
2012 Feb 23
1
rid/autorid issues 3.6.2
I'm having issues with idmap autorid and rid on 3.6.2. If I use tdb
backend, it works fine.
If I do "wbinfo -i testuser" when using rid/autorid, I get this:
failed to call wbcGetpwnam: WBC_ERR_DOMAIN_NOT_FOUND
Could not get info for user testuser
The same command with tdb returns the info as expected.
wbinfo -u and wbinfo -g work fine under all configurations.
I could not find
2015 Mar 03
1
idmap backends, clean slates and the AD DC
Am 22.02.2015 um 02:18 schrieb Andrew Bartlett:
> On Sat, 2015-02-21 at 20:05 +0000, Miguel Medalha wrote:
>> I just came to the conclusion that the rid backend has been very much
>> underappreciated. Too much mental inertia about how things used to be
>> made?
>>
>> After strugling for two days to configure a member server against a
>> Samba Active Directory
2017 Aug 08
0
member server idmap config (auto)rid
Hi,
Could you post the whole smb.conf? That should help...
Did you install libpam-winbind? libpam-krb5?
Kerberos is working? It should as you mentioned join was ok.
Anyway and in short, to help we need information.
And playing with wbinfo could help to understand what you missed (wbinfo -n
username; wbinfo -S userSID; wbnifo -i username; for a start)
2017-08-07 16:44 GMT+02:00 Neil Price via
2020 Oct 29
0
question about winbind rid idmaping
On 29/10/2020 13:32, Ralph Boehme wrote:
> Am 10/29/20 um 1:07 PM schrieb Rowland penny via samba:
>> On 29/10/2020 11:56, Andrew Walker wrote:
>>> Several of the idmap backends (including idmap_rid) in samba support
>>> id_type_both (the ID is both a user and a group). This is ultimately
>>> needed for accurately producing Windows-style behavior regarding
2017 Aug 08
0
member server idmap config (auto)rid
Ok debian stretch..
Go here.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862580#39
Review all steps there. ( message 39, Date: Mon, 22 May 2017 10:21:18 +0200 )
And if you change something, mark it so you can find it back, but that config works.
If it fails, post you smb.conf and post where you see errors based on the steps of above link.
Without smb.conf is a guessing game.
2020 Oct 29
2
question about winbind rid idmaping
Am 10/29/20 um 1:07 PM schrieb Rowland penny via samba:
> On 29/10/2020 11:56, Andrew Walker wrote:
>> Several of the idmap backends (including idmap_rid) in samba support
>> id_type_both (the ID is both a user and a group). This is ultimately
>> needed for accurately producing Windows-style behavior regarding
>> permissions (where a group can be the owner of a file).
2017 Aug 09
0
member server idmap config (auto)rid
Hi Niel,
First I've no knowledge about clustering Samba. I'll read what gave Louis
but for now, I didn't.
Anyway, several suggestions:
About hostname, if it is really an issue, you should be able to cheat using
/etc/hosts and configuring /etc/nsswitch with:
"hosts: files dns myhostname"
or
"hosts: files dns"
as I'm not sure what really means this
2017 Aug 08
4
member server idmap config (auto)rid
If you use the debian package 4.5.8 is can suggest you upgrade to 4.6.5 from buster or use my 4.6.6
Go through this changelog.
http://metadata.ftp-master.debian.org/changelogs/main/s/samba/samba_4.6.5+dfsg-8_changelog
My 4.6.6 is based on 4.6.5+dfsg-6
But i cant tell much jet about clustering setups.
Except this page:
https://wiki.samba.org/index.php/Clustered_Samba
And
2015 Feb 22
0
idmap backends, clean slates and the AD DC
On Sat, 2015-02-21 at 20:05 +0000, Miguel Medalha wrote:
> I just came to the conclusion that the rid backend has been very much
> underappreciated. Too much mental inertia about how things used to be
> made?
>
> After strugling for two days to configure a member server against a
> Samba Active Directory with the ad/RFC2307 backend, I turned to the
> rid backend and voil!
2024 Jun 14
2
Choosing a backend idamp and example scenarios for each one
hi,
Knowing the 3 idmap backends (ad, rid and autorid) available to configure
samba as a domain member, could you give examples of scenarios in which
each backend would be more suitable?
--
Elias Pereira
2017 Aug 08
2
member server idmap config (auto)rid
(forwarding as I forgot to reply-all)
-----Original Message-----
From: Lange Norbert
Sent: Dienstag, 08. August 2017 12:26
To: 'mathias dufresne'
Subject: RE: [Samba] member server idmap config (auto)rid
>Did you install libpam-winbind? libpam-krb5?
Nope, I did try installing them now, made no difference.
I have backup-scripts running on the server for months, and it worked before.
2015 Feb 21
0
Winbind backend : rid is too much underappreciated
Hello Miguel,
Am 21.02.2015 um 21:05 schrieb Miguel Medalha:
> After strugling for two days to configure a member server against a
> Samba Active Directory with the ad/RFC2307 backend, I turned
> to the rid backend and voil?! all my problems are gone.
What problems did you had to get it running? I find it simple to setup.
And there's documentation about it in the Wiki, too. For