Displaying 20 results from an estimated 20000 matches similar to: "File Server member DC ACL permissions"
2016 Aug 11
1
File Server member DC ACL permissions
Dear Rowland,
This Samba 4 domain was not provisioned from scratch.
Here in the company we had a DC Windows 2008. The Samba was provided to secondary DC.
Then, the primary DC remains Windows, but will be removed this weekend. Samba DC will be the primary DC.
In the file server file krb5.conf, I informed the KDC servers pointing to the Samba DC.
Follows the smb.conf my DC Samba 4:
# Global
2016 Aug 11
3
File Server member DC ACL permissions
> Hmm, the numbers seem extremely large, did you set this number in the
> users 'uidnumber' attribute in AD ?
How do I do this uidNumber configuration?
I'm running all services: smbd, nmbd and winbind
It's hard to run the file server as a domain member. When was a file server with DC was much more easy.
2016 Aug 11
0
File Server member DC ACL permissions
On Thu, 11 Aug 2016 19:51:07 +0000 (UTC)
Ricardo Pardim Claus via samba <samba at lists.samba.org> wrote:
>
>
>
> Follow the answers:
>
>
> > Yes wbinfo shows the user but does 'getent passwd iuser' show
> > anything ?
>
> # wbinfo -i iuser
> iuser:*:4294967295:4294967295:iuser:/home/DOMAIN/iuser:/bin/false
>
>
>
> #
2016 Aug 10
1
File Server member DC ACL permissions
I will choose to use the winbind.
Based on the link that Rowland said:
https://wiki.samba.org /index.php/Setup_Samba_as_an_AD_Domain_Member
I followed the steps as described in the tutorial.
I created symlinks.
In the main DC I added this line in smb.conf:
idmap_ldb: use RFC2307 = yes
Changed /etc/nsswitch.conf
passwd: files winbind
shadow: files
group: files winbind
hosts:
2016 Aug 10
1
File Server member DC ACL permissions
Greetings,
Previously I had set up a file server with DC on the same machine. As recommendations, created another machine to be the file server.
I made the settings as far as I could do, but I can not give permissions on shared folders. Must give permissions on shared folders for groups and users of the domain.
I'm using Samba 4.4.5 in DC's and also the file server. I joined the file
2016 Aug 12
0
File Server member DC ACL permissions
> > > Yes wbinfo shows the user but does 'getent passwd iuser' show
> > > anything ?
> >
> > # wbinfo -i iuser
> > iuser:*:4294967295:4294967295:iuser:/home/DOMAIN/iuser:/bin/false
> >
> >
> >
> > # getent passwd iuser
> > iuser:*:4294967295:4294967295:iuser:/home/DOMAIN/iuser:/bin/false
> >
> >
>
2016 Oct 24
4
Fix sharing ACL
Gentlemen,
I am struggling to solve this problem.
My file server Samba 4.4.5.
Even the administrator user (domain admin) could not write to the share.
Could someone give me a hint, in order to solve this problem?
shared folder: /mnt/data
Folder permissions:
# getfacl /mnt/data/teste/
getfacl: Removing leading '/' from absolute path names
# file: mnt/data/teste/
# owner: ricardo
2016 Oct 05
4
Failure gpupdate
Colleagues,
I come to seek help to solve this problem. I use Samba 4.4.5.
I'm getting errors when running gpupdate / force on local desktops.
I get the following error:
User policy could not be updated successfully. The following errors were encountered:
The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object
2017 Apr 28
6
Problems with the Full Audit module
> Is the 'vfs objects' line in the [global] section ? if so, try moving
> it to the shares, there have been reports that adding 'vfs objects' to
> [global] causes problems.
> Rowland
Dear Rowland
This host is a Samba 4.6.2 domain member server.
In the Global session of smb.conf, I have this line:
Vfs objects = acl_xattr
On Sharing:
Vfs objects = recycle,
2016 Oct 25
3
Fix sharing ACL
I removed the vestments of the DC user.map.
I had already trying to reset the permissions, following this session:
https://wiki.samba.org/index.php/Shares_with_Windows_ACLs#Troubleshooting
When I try to reset the permissions as shown in the bottom page of the ACL Windows page, nothing happens.
# ls -l /mnt/data
total 20
drwxrwxr-x+ 3 administrator domain admins 4096 Set 30 09:44 NTI
2017 Apr 13
2
Remove domain member Samba4
Dear,I need to remove a domain member, it is not a DC.
Can I use the same command that is used to demote a DC?
# samba-tool domain demote -Uadministrator
Thank you!
2016 Jul 06
3
Compatibility with Windows Server 2012 R2
Dear,The FAQ Samba 4 states that it is not compatible with Windows Server 2012, as the link below:
https://wiki.samba.org/index.php/Joining_a_Windows_Server_2012_/_2012_R2_DC_to_a_Samba_AD
My question is, is incompatible with the Server 2012 or the functional level of 2012?Here we have a Windows Server 2012 R2 with AD level of Windows 2008 R2 functionality.Samba 4 is compatible with this
2016 Aug 18
4
Allow unencrypted TLS LDAP query
Dear
It is possible to configure Samba 4.4.5 to accept queries that do not use TLS?
I'm having trouble authenticating the Proxy / SquidGuard in AD Samba 4.4.5.
I get this error:
(squidGuard): ldap_simple_bind_s failed: Strong(er) authentication required
I read the wiki Samba, the new versions are working with authentication TLS encrypted connections.
It is possible to configure Samba
2016 Jul 10
4
Compatibility with Windows Server 2012 R2
I had joined the Samba as a secondary DC. At first he imported all (accounts, groups, users and gpo).I can see all the objects that were imported. But the version of Schema Samba came as 69. The errors that I notice is regarding DNS and ForestDNS synchronization.It seems that the error is displayed when you synchronize Samba for Windows. When Windows to Samba, the commands do not return error.
2016 Oct 25
4
Fix sharing ACL
Dear Rowland,
I changed smb.conf as its tip.
I had already read about the ACL's Windows and Posix.
Even changing the smb.conf and using the ACL methods, I still do not write access to the folder.
Example:
# mkdir /mnt/data/teste1
# ls -all /mnt/data/teste1
total 12
drwxrws---+ 2 administrator domain admins 6 Out 25 10:05 .
drwxrwxr-x+ 10 root domain admins 4096 Out 25
2016 Jul 18
2
Migrate File Server MS for Samba
Dear Marc,
Thanks for initial contact.
The file server that need to migrate is a Windows 2012 R2. He's just a domain member.
Being Win 2012, I can face any problems in the migration?
Once the shares are ready, I plan to use Robocopy to copy the files and also the permissions of users and groups from Windows to Samba.
De: Marc Muehlfeld <mmuehlfeld at samba.org>
Para: Ricardo
2016 Jul 09
2
Compatibility with Windows Server 2012 R2
Dear Marc,In the field we have only simple objects (GPO desktop, file server, users and groups).In total, there are approximately 100 desktops +120 users. Only one site.
How to create a new domain in the Samba with the same SID of the current domain?
So I could create a new DC with the same domain and SID, and import objects (users and desktops accounts).
De: Marc Muehlfeld <mmuehlfeld
2016 Jul 08
2
Compatibility with Windows Server 2012 R2
Dear Regards,
Confirmed here, the AD schema is at version 69.
Other settings: Domain Level and Forest Functional Level could downgrade to Windows 2008.
We need to replace this DC MS by Samba, but keeping the same domain.
Does anyone have any suggestions or tips?
De: Marc Muehlfeld <mmuehlfeld at samba.org>
Para: Ricardo Pardim Claus <ricardo.claus at yahoo.com.br>; "samba
2016 Jul 25
4
NT_STATUS_INTERNAL_ERROR
Dear,Samba updated to 4.4.5 version.The Samba is a secundary DC.I'm getting some authentication errors.
smbclient -k -L //domain.localsession setup failed: NT_STATUS_INTERNAL_ERROR
Using my PC when I try to access the \\sambadc, is asking User and Password.The logs appears this:
ctx setting sec (0, 0) - 0 = sec_ctx_stack_ndx[25/07/2016 14: 08: 04.581532, 5]
2016 Jul 18
2
Migrate File Server MS for Samba
Dear,We are in MS migration phase to Samba 4.Besides replacing the AD MS by Samba 4, we must also migrate the file server MS to Samba 4.
I have some doubts and I ask the opinion of you:
1 - Is there any way to migrate MS folder permissions for Samba 4? 2 - We will need a secondary domain control. Based on best practices in this Samba 4 is that the file server, we can use it as a secondary DC?