similar to: Replication with a self-signed certificate

Displaying 20 results from an estimated 4000 matches similar to: "Replication with a self-signed certificate"

2017 Mar 11
2
Replication with a self-signed certificate
On Sat, 2017-03-11 at 13:39 +1300, Andrew Bartlett via samba wrote: > On Fri, 2017-03-10 at 16:17 -0600, Mircea Husz via samba wrote: > > > > Hello, > > > > I just configured a three-site DCs setup with Samba 4.6.0, and > > replication worked great. > > But then I added a custom cert to one of the DCs to authenticate > > various apps against it. I
2017 Mar 06
2
DC site replication issue ?
-------------------------------------------- On Mon, 3/6/17, lingpanda101 via samba <samba at lists.samba.org> wrote: Subject: Re: [Samba] DC site replication issue ? To: samba at lists.samba.org Date: Monday, March 6, 2017, 9:20 AM On 3/6/2017 9:56 AM, Mircea Husz via samba wrote: > All, > > I'm migrating a samba3 domain to a new samba4 AD version 4.5.5. Did a fair
2017 Mar 12
0
Replication with a self-signed certificate
On Sat, 2017-03-11 at 14:54 -0600, Mircea Husz wrote: > On Sat, 2017-03-11 at 13:39 +1300, Andrew Bartlett via samba wrote: > > On Fri, 2017-03-10 at 16:17 -0600, Mircea Husz via samba wrote: > > > > > > Hello, > > > > > > I just configured a three-site DCs setup with Samba 4.6.0, and > > > replication worked great. > > > But then I
2017 Mar 06
1
DC site replication issue ?
All, I'm migrating a samba3 domain to a new samba4 AD version 4.5.5. Did a fair amount of testing on isolated vlans including two sites and replication between two domain controllers. I'm now rolling out DCs intended to become production shortly. One is in Chicago, the other in NY, and each is configured in its own timezone with NTP synching up. I am looking at a potential replication
2018 Apr 17
1
tls verify peer with custom self-signed certificate
On 4/17/2018 3:56 AM, Marco Gaiarin via samba wrote: > Mandi! lingpanda101 via samba > In chel di` si favelave... > >>     When using a custom self-signed certificate, what is the appropriate >> value for 'tls verify peer ='? > ...AFAIk the same for every certificates; the CA's certificates have to > be in ''central store'', or have to be
2019 Mar 20
2
virsh snapshot-create-as: change umask on snapshots
I scripted the creation of snapshots and it works fine. Now I'd like to run the script as non-root. virsh snapshot-create-as --domain hq-live-v01 \      --name snappy \      --diskspec vda,file=/var/lib/libvirt/images/hq-live-v01.snappy,snapshot=external \      --diskspec vdb,file=/var/lib/libvirt/images/hq-live-storage.snappy,snapshot=external \      --disk-only --quiesce --atomic This
2019 Oct 29
2
Upgrade Samba versions on the domain
>On Tuesday, October 29, 2019, 03:41:35 PM CDT, Andrew Bartlett via samba <samba at lists.samba.org> wrote: >>On Tue, 2019-10-29 at 19:23 +0000, Mircea Husz via samba wrote: >> We're adding a new datacenter and am taking the opportunity to >> upgrade Samba version to 4.11. We have three AD servers currently on >> version 4.7.9. >> I plan to add a new AD
2018 Jan 31
4
How is initrd.img packed and compressed?
Hi, In order to work around a known upstream bug I needed to add a udev rule to pxeboot initrd.img on CentOS 7. The process is straightforward: 1 - extract the pxeboot initrd.img to a new directory 2 - add the udev rule needed to fix the bug 3 - pack and compress it back in initrd.img format The resulting updated image works, it fixes the upstream bug and life is good. But although it works,
2019 Mar 22
1
Re: virsh snapshot-create-as: change umask on snapshots
On Wed, Mar 20, 2019 at 15:48:43 -0500, Eric Blake wrote: > On 3/20/19 1:50 PM, Mircea Husz wrote: > > I scripted the creation of snapshots and it works fine. Now I'd like to run the script as non-root. > > > > virsh snapshot-create-as --domain hq-live-v01 \ > >      --name snappy \ > >      --diskspec
2017 Jun 06
2
samba-tool cannot add or remove group members
On Tue, 2017-05-30 at 12:18 +0100, Rowland Penny via samba wrote: > On Tue, 30 May 2017 13:09:38 +0200 (CEST) > > Sébastien QUESSON via samba <samba at lists.samba.org> wrote: > > > > > > All I can think of is, you have a user with > > > > > > > > > > 'sAMAccountName=username' and another with 'CN=username', this >
2017 Mar 06
1
DC site replication issue ?
On Mon, 2017-03-06 at 15:48 -0500, lingpanda101 via samba wrote: > On 3/6/2017 12:53 PM, Mircea Husz wrote: > > > > -------------------------------------------- > > On Mon, 3/6/17, lingpanda101 via samba <samba at lists.samba.org> > > wrote: > > > >   Subject: Re: [Samba] DC site replication issue ? > >   To: samba at lists.samba.org > >  
2017 Mar 06
3
DNS and DC replication clarification
All, I configured two DCs (Samba version 4.5.5) replicating ad.corp.com in two sites ( https://wiki.samba.org/index.php/Active_Directory_Sites) Following 'DNS configuration on Domain Controllers' section from this wiki https://wiki.samba.org/index.php/Joining_a_Samba_DC_to_an_Existing_Active_Directory If I configure nameserver DC1 to be the first resolver for DC2, samba_dnsupdate
2020 Nov 09
2
How to configure samba domain member to use LDAPS instead of LDAP
Hello, is there any documented procedure to configure a samba domain member (AD windows domain) to use LDAPS instead of LDAP Thanks Andrea
2017 Apr 18
2
Centos 7 Samba4 SSL/TLS Support?
Hi. Following this document: https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC I have a Centos 7.x with samba4.4.4 with openldap 2.4.40. If I run the command: smbd -b | grep "ENABLE_GNUTLS" I don't get any answer, this mean that samba doesn't have ssl support? Thanks for your time. -- LIving the dream...
2018 Aug 08
2
LDAPS is not working
Hi, after a successfully migrating my NT4 with OpenLDAP to a Samba4 AD...I got a problem. Like in the sambawiki tutorial (https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC) I tried to configure LDAPS. I used the auto-configured certs. They are located in "/var/lib/samba/private/tls". My smb.conf: # Global parameters [global] netbios name = PDC
2019 Oct 29
2
Upgrade Samba versions on the domain
We're adding a new datacenter and am taking the opportunity to upgrade Samba version to 4.11. We have three AD servers currently on version 4.7.9.? I plan to add a new AD DC, version 4.11, by joining it to the domain. Can the domain function in production with three DCs on 4.7.9, and a new one running 4.11 ? Thanks,-Mike
2018 Sep 05
2
Authenticating against Samba 4 AD LDAP service
Also: -H ldap://10.100.0.4 should probably be ldaps://URI You can potentially this in smb.conf, but that is definitely not recommended. https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC Kris Lou klou at themusiclink.net On Wed, Sep 5, 2018 at 2:10 AM, Rowland Penny via samba < samba at lists.samba.org> wrote: > On Wed, 05 Sep 2018 15:46:04 +0700
2017 Jan 27
2
winbind BUILTIN config
Hi Roland, Thank you for the explanation. Allow me to press the point, I'd like to understand what I'm doing. Is there value in me remapping them from their 3000000 - range default as I see it on the AD server? What is the reason for specifying a lower range such as 3000-7999 ? Thank you, -Mike On Friday, January 27, 2017 3:42 PM, Rowland Penny via samba <samba at
2020 Nov 11
2
Samba 4.11 with SSL authority CA role
I have OpenSSL forgenrate the CA root file in my server and work fine. My question is, ?howto i say to Samba (configuration) for work with CA certificates? . I dont find information about this. Thanks. Saludos. --- Miguel El mar., 10 nov. 2020 a las 15:22, S?rgio Basto (<sergio at serjux.com>) escribi?: > On Tue, 2020-11-10 at 14:48 -0300, Miguel Angel Coa M. via samba wrote: >
2020 Aug 06
4
Problem with intermediate certificate (tls cafile)
If I were guessing, based on some experience with certificate usage in other apps, concatenate your certificate and intermediate certificates into a single file which is then your "tls certfile" then point "tls cafile" to your issuers proper CA or just to your distro's CA bundle, e.g /etc/pki/tls/certs/ca-bundle.crt. Nick On 06/08/2020 16:36, MAS Jean-Louis via samba