similar to: Listing AD group members

Displaying 20 results from an estimated 8000 matches similar to: "Listing AD group members"

2017 Oct 30
4
Listing AD group members
Oh, I assumed you meant -d10, since -d0 turns off all debug output, so the output is long, but I get:- . . . GENSEC backend 'gssapi_spnego' registered GENSEC backend 'gssapi_krb5' registered GENSEC backend 'gssapi_krb5_sasl' registered GENSEC backend 'spnego' registered GENSEC backend 'schannel' registered GENSEC backend 'naclrpc_as_system'
2017 Oct 30
1
Listing AD group members
It appears to hang for a very long time (up to 15 minutes) on "kinit for HOSTNAME$@DOMAIN.LOCAL succeeded" then it returns nothing. I'm somewhat confused! James October 30, 2017 12:27 PM, "Rowland Penny via samba" <samba at lists.samba.org> wrote: > On Mon, 30 Oct 2017 12:07:24 +0000 > "A. James Lewis" <james at fsck.co.uk> wrote: >
2018 Jun 21
2
WERR_BAD_NET_RESP on replication (--full-sync)
Hello, We have a Windows 2008 DC (inview-dc1 and a samba 4.4.16 (inview-dc2) server as a backup DC. The system for the most-part works OK, but occasionally the Samba DC goes wildly out of sync (with respect to group membership), normally after a change to a large group. I have noted previously before the out-of-sync event occurs, this command always fails thus : root at inview-dc2:~#
2018 Jun 22
2
WERR_BAD_NET_RESP on replication (--full-sync)
Thanks Garming. We currently use a standalone bind DNS server. Will the later version of samba work without the integrated DNS backend? Cheers Chris On 21/06/18 23:41, Garming Sam wrote: > Hi, > > Many of these syncing problems were solved in Samba 4.7 (and probably a > few more in 4.8). There were a number of unresolved locking issues that > we uncovered as well as some
2017 Oct 30
0
Listing AD group members
I did come up with that option from Google, but wondered if it was only suitable if Samba was the AD controller, since that was always the context it was used in. This is the result I get. root at hostname:~# samba-tool group listmembers groupname ERROR(ldb): Failed to list members of "groupname" group - ldb_search: invalid basedn '(null)' root at hostname:~# Samba 4.6.7,
2019 Mar 31
2
Fwd: password administrator
I optaing this ERROR: Failed to set password for user 'administrator': (34, "ldb_search: invalid basedn '(null)'") Il 31/03/2019 18:32, Stefan Kania via samba ha scritto: > As user "root" do "samba-tool user setpassword administrator" that's it ;-) > > Am 31.03.19 um 17:48 schrieb marco pirola via samba: >> I lost the password of
2019 Mar 31
2
Fwd: password administrator
root at dc:~# samba-tool user setpassword Administrator New Password: Retype Password: ERROR: Failed to set password for user 'Administrator': (34, "ldb_search: invalid basedn '(null)'") root at dc:~# Il 31/03/2019 19:35, Rowland Penny via samba ha scritto: > samba-tool user setpassword Administrator
2019 May 13
2
Samba4 changing a user's password from linux workstation
Hi I'm trying to find a way to change user passwords from ubuntu client workstation on a samba4 domain. I tried in CLI from the client workstation (ubuntu 14.04) with: - smbpasswd -U $user => In this case, password seemed to be updated, but "wbinfo -a" didn't worked with the new password, the old one was still active. - samba-tool user setpassword $user => In this
2019 May 14
2
Samba4 changing a user's password from linux workstation
Le 13/05/2019 à 18:44, Rowland penny via samba a écrit : > On 13/05/2019 16:11, Julien TEHERY via samba wrote: >> Hi >> >> I'm trying to find a way to change user passwords from ubuntu client >> workstation on a samba4 domain. >> I tried in CLI from the client workstation (ubuntu 14.04) with: >> >> - smbpasswd -U $user >> >> => In
2017 Aug 22
5
Windows pre-requisites for login with winbind?
On Tue, 22 Aug 2017 12:01:20 +0000 "A. James Lewis via samba" <samba at lists.samba.org> wrote: > Indeed!... you are correct... this does appear to be the kerberos > issue uncovered by Rowlands pointing out that I should not need to be > manually defining "kdc =", in my krb5.conf.... so with that resolved, > I'm hoping we can also find the cause of my
2017 Aug 21
6
Windows pre-requisites for login with winbind?
Also, I see the following repeated in syslog:- ==> syslog <== Aug 21 15:25:41 hostname01 winbindd[691]: [2017/08/21 15:25:41.438959, 0] ../source3/libsmb/cliconnect.c:1895(cli_session_setup_spnego_send) Aug 21 15:25:41 hostname01 winbindd[691]: Kinit for HOSTNAME01$@DOMAIN.LOCAL to access cifs/LOCAL_AD02.domain.local at DOMAIN.LOCAL failed: Cannot contact any KDC for requested realm
2017 Aug 25
4
AD Group update lag / cache, firewall related?
August 25, 2017 3:12 PM, "Rowland Penny via samba" <samba at lists.samba.org> wrote: > On Fri, 25 Aug 2017 13:54:21 +0000 > "A. James Lewis" <james at fsck.co.uk> wrote: > >> It's not offline.... and groups do usually filter through... >> sometimes immediately, sometimes never... but usually with a >> significant delay... >>
2017 Aug 22
6
Windows pre-requisites for login with winbind?
Hi! Indeed!, this sounds like good advice... there are certainly bugs, I had to get the 7.04.5 package from "proposed" to get resolve a PAM library issue!... although I suppose that's a packaging problem. What is the best way to get an updated Samba package here, I'm trying to make this system reproduceable, I have a single script that builds the entire container, and sets up
2019 May 16
2
SRV records.
Hi all, A slightly hypothetical one here... but after Samba (Winbind actually)... looks up the list of AD server for a doman from DNS... what method does it use to decide which is the correct (most local?) domain controller to connect to/log in to? What will it's behaviour be if it connects to one, or two which don't have connectivity. -- A. James Lewis (james at fsck.co.uk
2017 Aug 22
5
Windows pre-requisites for login with winbind?
I have krb5-config krb5-user, but not libpam-krb5... I'm slightly fuzzy about how this works, but I thought the interaction with kerberos was implemented via winbind, so I wasn't expecting this package to be installed... certainly there is no dependency that has pulled it in. James August 22, 2017 1:15 PM, "Rowland Penny via samba" <samba at lists.samba.org> wrote: >
2020 Aug 21
4
Using Samba AD/DC as an Active Directory OAuth provider for OpenShift
On 21/08/2020 21:40, vincent at cojot.name wrote: > On Fri, 21 Aug 2020, Rowland penny via samba wrote: > >> This works for me: >> >> rowland at devstation:~$ sudo ldapsearch -H >> ldaps://dc01.samdom.example.com -D 'SAMDOM\Administrator' -w >> 'xxxxxxxxxx' -b 'dc=samdom,dc=example,dc=com' >>
2015 Mar 10
2
net ads join fails
Hi, i've got a problem joining a domain with samba 4.1.17 on freebsd. Everytime I try it, the join fails with a core dump. Debugging it, it seems that it is stuck on authentication. Kerberos works, I get credentials, but if I try to join the domain, it fails. The problem seems to be somwhere in this debug-output: 1. net ads join: Doing spnego session setup (blob length=96) got
2014 Dec 22
2
Net groupmap list strange result
Guys, In my lab test when I run the command "net groupmap list" the result is as follows: *# net groupmap list* *Domain Admins (S-1-5-21-187220369-3628530160-3539241734-512) -> 512* *Domain Users (S-1-5-21-187220369-3628530160-3539241734-513) -> 513* *Domain Guests (S-1-5-21-187220369-3628530160-3539241734-514) -> 514* *Domain Computers
2019 May 26
2
GPO problem ACL permission
Hello. I have a problem with GPO manage. Sorry for my english is not the best. On the windows, GPO manage, the system send me this error: "The permissions for this GPO in the SYSVOL folder are inconsistent with those in Active Directory. It is recommended that these permissions be consistent. To change the SYSVOL permissions to those in Active Directory, click OK. For more
2017 Aug 21
6
Windows pre-requisites for login with winbind?
August 21, 2017 5:34 PM, "Rowland Penny via samba" <samba at lists.samba.org> wrote: > On Mon, 21 Aug 2017 15:37:03 +0000 > "A. James Lewis" <james at fsck.co.uk> wrote: > >> OK, obviously I am slightly sanitising the output here, but I'm >> preserving the case, and just replacing local names with generic ones >> as I did for the