similar to: RFC2307: Recommendations for mapping Administrator account

Displaying 20 results from an estimated 10000 matches similar to: "RFC2307: Recommendations for mapping Administrator account"

2018 Feb 08
3
RFC2307: Recommendations for mapping Administrator account
On Thu, 8 Feb 2018 10:55:30 +0100 Denis Cardon via samba <samba at lists.samba.org> wrote: > Hi Frederik, > > > I provisioned a new domain with "--use-rfc2307" as I want to use the > > "ad" idmap backend on my domain members. > > unless you have really specific requirements, you should really stick > with RID mapping, it will be easier on
2018 Feb 08
0
RFC2307: Recommendations for mapping Administrator account
Hi Frederik, > I provisioned a new domain with "--use-rfc2307" as I want to use the > "ad" idmap backend on my domain members. unless you have really specific requirements, you should really stick with RID mapping, it will be easier on the long run. > I am thinking of mapping the "Administrator" account to UID 10000 > (this is where my UID range for
2018 Sep 26
2
audit DC?
Good morning people from Argentine. again bothering with a doubt, It is posiblle, audit change password, create-delete-change users? and more? i have a file server with audit and works really really well and now I want more! any ideas? thanks for samba....i love it
2019 May 27
4
samba-tool group removemembers, not working
Because of other issues using ADUC, I tried to remove a domain member using: > samba-tool group removemembers "Domain Computers" MARKA\$ Removed members from group Domain Computers As shown, it say it "Removed members", but ... > samba-tool group listmembers "Domain Computers" : LABRAT$ : OHPRSSTORAGE$ MARKA$ : COMMON$ : listmembers still shows the computer
2018 May 02
2
Using samba AD in mixed OS environment
Hi Denis. Since we have "tricky" people working on the Linux machines we prefer NFS because it's less hassle to mount and requires no credentials. Basically because of the users we tend to choose the easiest possible way for them to access the needed resources. I guess pam-script module mounting is exactly for this purpose, but I'll to research more since I'm not familiar
2018 Feb 08
1
RFC2307: Recommendations for mapping Administrator account
Hi, thank you for your input guys. 2018-02-08 10:55 GMT+01:00 Denis Cardon <dcardon at tranquil.it>: > unless you have really specific requirements, you should really stick with > RID mapping, it will be easier on the long run. I think that would actually be more pain in the long run, as this pretty much rules out using Samba/AD with sssd/nss-ldap. 2018-02-08 11:25 GMT+01:00
2018 Apr 28
4
Using samba AD in mixed OS environment
Hi guys. I've got working samba AD server. It is playing nicely with Windows 10 and also successfully authenticating Linux machines with SSSD. On the Windows machines I have our EMC storage smb mounted via group policy. Managing permissions for users and groups there, as you know, happens with right click, security etc.. As you may have already guessed the troubles come when my Linux
2018 Feb 14
2
Is it possible to lower the domain and forest functional level
Hi Denis, We are using the latest version of sharepoint. samba-tool domain level show : Domain and forest function level for domain 'DC=removed,DC=com' Forest function level: (Windows) 2008 R2 Domain function level: (Windows) 2008 R2 Lowest function level of a DC: (Windows) 2008 R2 I did not have to change the revision attributes by hand. I think the MSAD2K3 was an upgrade from MSAD2K.
2019 Jun 17
2
Disabling or deleting domain "Administrator" account
Hello, A client is asking about disabling, deleting or renaming the domain "Administrator" account on a Samba AD. I've seen this done on Windows AD domains for security purposes. Assuming the risk of being locked-out is mitigated (i.e. an equivalent user is created and is a member of the same groups), is there any reason this can't be done on a Samba AD as well? Is the
2018 Jan 11
2
Deploy software in fileserver folder
Hi Elias, > I thought it worked, but after I uninstalled the software that I deployed > via user scope, it did not reinstall. I selected the "Redeploy application" > option, but it also did not work. The user scope GPO are run with the privileges and access tokens of the logged on user, so the user have local admin rights for install and need access rights to the share you
2018 Feb 15
1
Is it possible to lower the domain and forest functional level
Hello Denis, I checked all the attributes and objectclass defined in /usr/share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Attributes.txt and /usr/share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Classes.txt exists in my samba 4 ldap. Nothing is missing. Can you give me some inputs to "recreate a Samba 4.7 domain with same SID by piping in all the objects" ?
2019 Mar 11
2
AD administrator can't administer
Over time I have ignored the fact that my AD administrator has stopped being able to administer. For example, the Ad administrator cannot install drivers or updates. Once a week now, I logout as workstation user and login as the "local administrator" to install drivers or run windows updates (in today's case a printer driver on the workstation.) Does this falls into that "gray
2018 Mar 08
3
LDAP BDC- Classic Domain
Hi Guys, We're trying to add a BDC in Samb4 classic domain setup. The Samba 3 How -To and Samb3 by Example covers this but uses the old slapd.conf option, we are using the slapd.d config. I couldn't find a similar document for Samba4 Can you please advise that the following steps will work? LDAP in the existing PDC is working using the smbldap tools - Setup the LDAP in BDC
2018 Nov 27
2
Debian Stretch Samba 4.8.7 packages available amd64/i386
Hai,   The Debian Stretch packages for samba 4.8.7 are now available for amd64 and i386.   ----------- THE REPO SETUP --------------- 1) Choose http or https for you apt, both work, for https you need to : apt-get install apt-transport-https   2) Import my public key wget -O - http://apt.van-belle.nl/louis-van-belle.gpg-key.asc | apt-key add -   3) (optional) setup a header line for the repo
2019 Jun 12
3
(no subject)
Sorry for the repost: my message delivery was set to digest, and that was hard to manage use for conversation. I changed that setting. So starting clean with the same subject... I don't care about SSSD or whether it's even on the machine or not. Right now, it's only used by the machine for login. It isn't used by Samba, and I am very careful to let libwbclient-sssd nowhere near
2019 Apr 08
6
Debian Stretch, Samba 4.10.2, 4.9.6 and 4.8.11 Available (amd64/i386)
Hai guys, I've updated the Debian Stretch package for Samba 4.10.2, 4.9.6 and 4.8.11. Repo info : https://apt.van-belle.nl Build logs: http://downloads.van-belle.nl/samba4/Buildlogs/stretch/ Quick repo setup: Optional: apt-get install apt-transport-https Import my public key: wget -O - http://apt.van-belle.nl/louis-van-belle.gpg-key.asc | apt-key add - # Example repo stretch samba
2018 Sep 26
5
Upgrade 4.8 to 4.9 with Backend-Change to lmdb?
Hi list, are there preparations for upgrading a samba 4.8.5 to 4.9.1 via van-belle-repository to change the backend db? Is there some handwork necessary? Regards, Oliver
2019 Jul 18
1
Can't add DNS records when joining Windows DC (Was Can't find machine account)
On 18/07/19 7:12 AM, Rowland penny via samba wrote: > On 17/07/2019 19:31, Robert A Wooldridge via samba wrote: >> >> Here's the full error: >> >> Could not find machine account in secrets database: Failed to fetch >> machine account password for EDM from both secrets.ldb (Could not >> find entry to match filter: >>
2018 Feb 14
4
Is it possible to lower the domain and forest functional level
I don't know exactly, but there were problems with indexes ( as the user said ). We did not try with the current release and our manager wants to go back to Microsoft :-( Our samba version is 4.7.5. I've been able to go one step further. We first were not able to join a Windows 2008 R2 as a domain controller because it was asking for adprep. I found the missing datas in the ldap and added
2020 Jan 10
1
SCCM and other MS tools compatibility with Samba 4.x.x (Functional level 2008R2)
Hello Folks, We're using Samba as AD servers along with Windows AD Servers (2008R2 FL). We also use SCCM (Current Branch) that is dependent on AD for lab deployments (Windows 10). Currently, SCCM (current branch) supports 2008R2 FL, but for how long??? Samba does not support 2012R2, 2016, 2019 FL. We'd like to remove the Windows Servers from our AD infrastructure, but would also like