similar to: Group membership update

Displaying 20 results from an estimated 20000 matches similar to: "Group membership update"

2007 May 08
0
Two Permissions Issues: null session shares and group membership
I have Samba 3.0.25rc3 running on OpenSolaris build 67. Samba is integrated with our Active Directory via Kerberos. I do not have nsswitch running with winbind at this time. Issue #1: Samba denies access to a share set up with "public = yes" when accessed by an AD integrated user account. The share is defined as follows: [open] comment = Null Session Share path =
2018 Mar 13
0
Windows doesn't prevent directory deletion
Hi Samba team, I'm currently building a Samba Domaincontroller with a seperate domain joined Samba Fileserver in my environment. On my fileserver share which root directory is /srv/Share I don't use Windows ACLs, so just the default Linux permissions and Posix ACLs Let's assume that I've a group employees which should have rwx permissions to a group specific share. So I've
2008 Aug 12
0
BDC returning wrong Domain Group membership ?
Hi all, I have just noticed the following situation: Our NT4-style domain users are often (not always) seen by Windows XP as members of Domain Users and Domain Guests and Domain Admins and Domain Computers although they are definitely only members of "Domain Users". This gives us a security problem as "Domain Admins" become local Administrators. They are no real
2017 Sep 26
1
Winbind group membership not updating
On 26/09/17 11:53, Rowland Penny via samba wrote: > I don't think you can work around this, I am fairly sure if you try > this against a windows server, you would get the same result, unless > the user logs out, they will still think they are members of the group > and will get access. > > Rowland > ...huh. Yes, of course. I was fixated on the *NIX side and didn't
2016 Mar 23
0
Samba 4 with sssd - primary Windows group membership not honored
See inline comments On 23/03/16 15:32, Joseph Dickson wrote: > Greetings! > > I am working with Samba 4 as a domain member fileserver (not a domain > controller, just a normal ads member fileserver). Operating system is > Centos 7. SSSD is configured and pulling information correctly. > > I had to work around a bug that wasn't fixed in a released version, so I am >
2005 Jan 04
0
group membership + acl
During the last two years our fileserver was a VERITAS Samba-2.0.10-VRTS server. This Veritas version of samba contains a special ACL component for the uid <-> sid and gid <-> sid mapping. It also transparently converts Windows access rights to Unix access rights and vice versa. The recent changes in the Windows mbx driver forced us to move to Samba3. The uid mapping works without
2024 Jan 31
1
time based group membership in FL 2016
Am 31.01.24 um 17:45 schrieb Kees van Vloten via samba: > > Op 31-01-2024 om 17:21 schreef Stefan Kania via samba: >> Hi all, >> >> it's again a question about FL 2016 and if samba supports it. If yes, >> how can I use it without powershell. >> >> In FL 2016 there is the possibility to put a user into a group and the >> membership is time
2015 Jun 08
2
Active Directory group membership changes not reflected in winbind information
Hi, I?ve added an existing group (?2d3d?) to an existing user (?jschopp?) on our AD server. When I execute ?id jschopp? the new group membership is not reflected: # id jschopp uid=1333(jschopp) gid=2020(dom?nen-benutzer) groups=2020(dom?nen-benutzer),610(BUILTIN+users) This is a strange behavior. Is this a caching issue? Kind regards, Martin AD: Windows Server 2008 RC2 with Windows Services
2016 Mar 23
0
Samba 4 with sssd - primary Windows group membership not honored
On 23/03/16 20:16, Joseph Dickson wrote: >> OK, you should use the standard 'rwx' permissions *or* ACLs, not both. If >> you create a directory on Unix that you want to share, set the owner:group >> to root:'Domain Admins' and permissions to 0770. You will then be able to >> set the permissions from windows or with setfacl on the Unix machine, you >>
2018 Aug 24
3
Samba fileserver member corrupt smb.ldb after joining 4.8.4 Samba DC
Hi again, I think I found out something interesting: When running "ntacl get" with debug = 10, I get the following output on the machine where it works: posix_get_nt_acl: called for file /srv/profiles/ Opening cache file at /var/cache/samba/gencache.tdb Opening cache file at /var/run/samba/gencache_notrans.tdb uid 0 -> sid S-1-22-1-0 <12210> gid 100513 -> sid
2018 Jan 30
2
Samba 4.7.4 + bind9 DLZ /backend/ dropping delegated domain
Hai, Check the content of : /etc/logrotate.d/named If you see postrotate /etc/init.d/smbd reload > /dev/null endscript Change that to postrotate if [ -d /run/systemd/system ]; then; systemctl -q is-active named && systemctl reload named; else; /etc/init.d/named reload ; fi'; endscript Its something like that, so who pointing.. That does not matter, because this is OS
2024 Jan 31
1
time based group membership in FL 2016
On 31-01-2024 20:36, Rowland Penny via samba wrote: > On Wed, 31 Jan 2024 20:02:55 +0100 > Stefan Kania via samba <samba at lists.samba.org> wrote: > >> >> Am 31.01.24 um 17:45 schrieb Kees van Vloten via samba: >>> Op 31-01-2024 om 17:21 schreef Stefan Kania via samba: >>>> Hi all, >>>> >>>> it's again a question about FL
2024 May 02
1
Group Membership Retrieval not using kerberos authentication
Hello, I have an Active Directory domain to which a Linux machine with Ubuntu 20.04 LTS is joined using Winbind. The version of Winbind is 4.15.13. On this machine, users authenticate via SSH using PAM (pam_winbind), and I need to know their group membership. NSS is configured for this purpose. When users authenticate via username and password, there's no issue retrieving the list of groups
2024 May 02
1
Group Membership Retrieval not using kerberos authentication
Op 02-05-2024 om 10:39 schreef Oscar Alonso | MailTecK via samba: > Hello, > > I have an Active Directory domain to which a Linux machine with Ubuntu 20.04 LTS is joined using Winbind. The version of Winbind is 4.15.13. > On this machine, users authenticate via SSH using PAM (pam_winbind), and I need to know their group membership. > NSS is configured for this purpose. > When
2018 Aug 24
2
Samba fileserver member corrupt smb.ldb after joining 4.8.4 Samba DC
On Fri, 24 Aug 2018 22:06:01 +0200 Waishon <waishon009 at gmail.com> wrote: > Hi, > > thanks for your suggestions. Do you think this is causes the > stacktrace above? . I just added "REALM" as a placeholder and it > worked on a DC that was provisioned using Samba 4.7.3 and upgraded > afterwards to Samba 4.8.4 absolutely fine with this config and the > command
2024 Jan 31
2
time based group membership in FL 2016
On Wed, 31 Jan 2024 20:02:55 +0100 Stefan Kania via samba <samba at lists.samba.org> wrote: > > > Am 31.01.24 um 17:45 schrieb Kees van Vloten via samba: > > > > Op 31-01-2024 om 17:21 schreef Stefan Kania via samba: > >> Hi all, > >> > >> it's again a question about FL 2016 and if samba supports it. If > >> yes, how can I use
2018 Aug 24
3
Samba fileserver member corrupt smb.ldb after joining 4.8.4 Samba DC
Hello, I'm trying to join a samba-fileserver to a 4.8.4 Domain Controller. Both are installed from the Debian Unstable Sources. I've setup some scripts that allows me to provision the latest samba-version for testing purposes on two VMs. The following configs where working absolutly fine when provisioning a Samba-DC version 4.7.3 and I was able to do profile roaming, but since the DC is
2004 May 13
0
Cannot set a "Domain group" membership with ldapSAM
Hello everybody! I should have an error on the LDAP entries of my ldapSAM, but I've read several times chapters 11 & 12 of the Samba HOWTO Collection and I cannot fix it. Let's explain: I've got a StandAlone fileserver (not PDC) samba-3.0.4 with ldapSAM working on a RedHat Enterprise 3.0 (linux kernel 2.4.25). The directory server version shouldn't be important, but
2018 Aug 24
2
Samba fileserver member corrupt smb.ldb after joining 4.8.4 Samba DC
On Fri, 24 Aug 2018 21:07:54 +0200 Waishon via samba <samba at lists.samba.org> wrote: > If it's imported here's the DC-Provision log too: > > service-samba-dc | Looking up IPv4 addresses > service-samba-dc | More than one IPv4 address > found. Using 192.168.188.2 > service-samba-dc | Looking up IPv6
2014 May 16
1
User accounts not getting complete group membership (getent group / groups mismatch)
We recently added a new LDAP/AD group to our domain, but have found that only some accounts on a Linux (Ubuntu 12.04.4, Samba 3.6.3) machine are getting the membership: "getent group <groupname>" shows them as being in the group, but "groups <username>" doesn't. I've tried restarting winbindd with the "-n" option to bypass caching, and deleting the