Displaying 20 results from an estimated 5000 matches similar to: "Samba 4.1. creates group rights for not existing group."
2015 Nov 16
2
Samba 4.1. creates group rights for not existing group.
On 2015-11-16 at 11:14 +0000, Rowland Penny wrote:
> On 16/11/15 10:11, Alex Sviridov wrote:
> > I use samba 4.1 as dc with acl. I have user with uid 3000023. However, I don't have group with guid 3000023. However, when this user creates a folder samba in acl list creates permissions for group 3000023 and as result I have broken link. How to fix it?
> >
> >
>
> Hi,
2015 Nov 16
2
Samba 4.1. creates group rights for not existing group.
On 2015-11-16 at 12:57 +0000, Rowland Penny wrote:
> On 16/11/15 12:53, Michael Adam wrote:
> >On 2015-11-16 at 11:14 +0000, Rowland Penny wrote:
> >>On 16/11/15 10:11, Alex Sviridov wrote:
> >>> I use samba 4.1 as dc with acl. I have user with uid 3000023. However, I don't have group with guid 3000023. However, when this user creates a folder samba in acl list
2015 Nov 16
1
Change default samba 4.1. ACL behaviour
I use samba 4.1 as dc with acl. I have user with uid 3000023. However, I don't have group with guid 3000023. However, when this user creates a folder samba in acl list creates permissions for group 3000023 and as result I have broken link.
Rowland Penny (thanks to him) said that I could see the type: ID_TYPE_BOTH setting in /usr/local/samba/private/idmap.ldb.
As I understood I must change
2015 Nov 16
0
Samba 4.1. creates group rights for not existing group.
On 16/11/15 12:53, Michael Adam wrote:
> On 2015-11-16 at 11:14 +0000, Rowland Penny wrote:
>> On 16/11/15 10:11, Alex Sviridov wrote:
>>> I use samba 4.1 as dc with acl. I have user with uid 3000023. However, I don't have group with guid 3000023. However, when this user creates a folder samba in acl list creates permissions for group 3000023 and as result I have broken
2015 Nov 16
0
Samba 4.1. creates group rights for not existing group.
On 16/11/15 13:28, Michael Adam wrote:
> On 2015-11-16 at 12:57 +0000, Rowland Penny wrote:
>> On 16/11/15 12:53, Michael Adam wrote:
>>> On 2015-11-16 at 11:14 +0000, Rowland Penny wrote:
>>>> On 16/11/15 10:11, Alex Sviridov wrote:
>>>>> I use samba 4.1 as dc with acl. I have user with uid 3000023. However, I don't have group with guid 3000023.
2016 Jun 20
3
Rights issue on GPO
Hi Rowland, list,
On 20-6-2016 20:04, Rowland penny wrote:
> If you are using Sernet 4.4.4 packages, you must have a Sernet
> subscription, you may get quicker help there.
Well I'm not sure this kind of support is included, but even if it were,
then others would not benefit from the dialogue with their support. :-)
> I was wrong, if you are using 4.2.0 or later, you do not need to
2016 Jun 20
2
Rights issue on GPO
Hi,
> OK, I take it that 3000009 points to CN=S-1-5-11 and it is just
> CN=S-1-5-18 that is wrong by pointing at proxmox$ (which incidentally,
> is one of your computers)
> Try backing up idmap.ldb, then open idmap.ldb in ldbedit, find and
> delete the stanza that holds CN=S-1-5-18, it will look like this:
>
> dn: CN=S-1-5-18
> cn: S-1-5-18
> objectClass: sidMap
>
2015 Jul 17
2
"wbinfo --sid-to-gid" returns false gids
I've got this on the backup DC
root at bdc:~# wbinfo --sid-to-gid S-1-5-21-1166961617-3197558402-3341820450-516
3000000
while
root at bdc:~# ldbedit -H /usr/local/samba/private/idmap.ldb objectsid=S-1-5-21-1166961617-3197558402-3341820450-516
shows correct xid 3000019
and on the primary DC I've got
itk at dc:/$ wbinfo --sid-to-gid S-1-5-21-1166961617-3197558402-3341820450-516
3000019
2003 Feb 20
2
[Apt-rpm] I: [PATCH] 0.5.4cnc9: rsync method support
Sviatoslav Sviridov [mailto:svd@ns1.lintec.minsk.by] wrote:
>It would be good if attached patch will be included in upstream. This
>patch adds option --apt-support for rsync and with this option rsync
>will print some additional information about file being transfered. No
>program logic changed. Having this option in rsync we can have apt with
>rsync method support.
1. What is apt?
2003 Aug 28
1
Fw: Re: GZIP, ZIP, ISO, RPM files and rsync, tar, cpio
On Thu, Aug 28, 2003 at 12:51:16PM +0300, Sviatoslav Sviridov/Lintec Project wrote:
>
> Sorry for direct reply, but mail server at samba.org blocks my messages.
Postmasters, Martin, For your consideration.
> Begin forwarded message:
>
> Date: Thu, 28 Aug 2003 12:43:54 +0300
> From: Sviatoslav Sviridov/Lintec Project <svd@lintec.minsk.by>
> To: rsync@lists.samba.org
2017 Jan 11
4
Corrupted idmap...
Rowland, no domain user can authenticate on any system and running
sysvolreset followed by sysvolcheck results in a crash. If the sysvol
permissions are correct, sysvolcheck does not crash. If I attempt to
join a NAS or workstation to the domain I get NT_STATUS_INVALID_SID.
Researching these symptoms turns up a thread about a corrupt idmap.ldb
where a group SID and user SID may be the same or
2015 Jul 17
1
"wbinfo --sid-to-gid" returns false gids
17.07.2015, 17:30, "Rowland Penny" <rowlandpenny241155 at gmail.com>:
> On 17/07/15 12:03, Andrej Surkov wrote:
>> I've got this on the backup DC
>>
>> root at bdc:~# wbinfo --sid-to-gid S-1-5-21-1166961617-3197558402-3341820450-516
>> 3000000
>
> OK, you have problems there, but not what you think. On my first DC
> (note I don't have
2015 Mar 30
2
Unable to browse system shares of a newly migrated AD DC
Greetings, Rowland Penny!
>>> Hi Louis, It works for me
>>> This appears in log.smbd on my DC when I run the same command:
>>> [2015/03/30 10:15:42.442881, 3]
>>> ../source3/smbd/service.c:856(make_connection_snum)
>>> dc01 (ipv6:::1:43602) connect to service IPC$ initially as user NT
>>> AUTHORITY\ANONYMOUS LOGON (uid=65534, gid=3000013)
2015 Jul 03
3
Clients unable to get group policy...
On 03/07/15 15:18, Ryan Ashley wrote:
> The only Unix client I can think of would be the Buffalo NAS. It runs
> Samba3 and hosts various shares via SMB. DNS is handled by BIND9 on the
> Samba4 DC. DNS does work and the domain name resolves to the IP address
> of the server. DHCP is also handled on the DC. As for the GPO's, they're
> in the correct place as far as I can tell.
2015 Jul 02
5
Clients unable to get group policy...
On 02/07/15 16:55, Ryan Ashley wrote:
> Rowland, here is what I found in the ldb.
>
> # record 68
> dn: CN=S-1-5-32-544
> cn: S-1-5-32-544
> objectClass: sidMap
> objectSid: S-1-5-32-544
> type: ID_TYPE_BOTH
> xidNumber: 3000000
> distinguishedName: CN=S-1-5-32-544
>
> # record 70
> dn: CN=S-1-5-32-549
> cn: S-1-5-32-549
> objectClass: sidMap
>
2020 Nov 03
2
ID Mapping
On 03/11/2020 13:05, O'Connor, Daniel wrote:
>
>> On 3 Nov 2020, at 23:21, Rowland penny via samba <samba at lists.samba.org> wrote:
>> On 03/11/2020 12:17, O'Connor, Daniel wrote:
>>> I tried setting uidNumber et al via the active directory editor and samba-ldbedit, however the mapping doesn't seem to change so I am wondering if it ends up stored
2016 Sep 07
2
ACL wrong category user for group and group for user
Hello Rowland!
The users and group are only on the AD, and there are only one entry on
each user...
In the Windows side all seems ok :
but not the result of getfacl ...
root at Samba4:/Fichiers# getfacl /Fichiers/SA/Nouveau\ document\ texte.txt
getfacl : suppression du premier « / » des noms de chemins absolus
# file: Fichiers/SA/Nouveau document texte.txt
# owner: ciril
# group:
2015 Mar 30
1
Unable to browse system shares of a newly migrated AD DC
Greetings, Rowland Penny!
>>>>> Hi Louis, It works for me
>>>>> This appears in log.smbd on my DC when I run the same command:
>>>>> [2015/03/30 10:15:42.442881, 3]
>>>>> ../source3/smbd/service.c:856(make_connection_snum)
>>>>> dc01 (ipv6:::1:43602) connect to service IPC$ initially as user NT
>>>>>
2015 Jul 03
2
Clients unable to get group policy...
On 03/07/15 15:58, Ryan Ashley wrote:
> They left a PC on, so I got the info. The info pissed me off, but not
> because of the issue. This time it worked flawlessly, but I got the
> error from the event log from prior attempts. First, today's results.
>
> C:\Users\reachfp.KIGM>gpupdate
> Updating Policy...
>
> User Policy update has completed successfully.
>
2015 Mar 30
2
Unable to browse system shares of a newly migrated AD DC
Greetings, Rowland Penny!
<Trying to resend, sorry for possible duplicates.>
> On 30/03/15 10:06, L.P.H. van Belle wrote:
Please don't top-post. It make messages very hard to read.
>> I think this wont work since the user connectig isnt known in the AD,
>> since the user connecting is mapped to user nobody.
I'm doing s simple check (anonymous listing of DC shares)