Displaying 20 results from an estimated 1000 matches similar to: "Samba CIFS Mounts with Kerberos Security: Write Access denied"
2018 Jun 14
2
No write access on new shares until smbd is restarted
Using the latest SerNet 4.8.1 build, I'm seeing users being unable to write
into newly created shares until smbd is restarted.
Here's the relevant log part:
[2018/06/14 16:04:29.229329, 5]
../source3/smbd/filename.c:662(unix_convert)
unix_convert begin: name = New folder, dirpath = , start = New folder
[2018/06/14 16:04:29.229375, 5]
../source3/smbd/vfs.c:1458(check_reduced_name)
2019 Mar 01
2
Using Access Control Lists with SMB2/SMB3 Mounts on Linux Clients
Hi Jeremy, Hi Steve, Hi Ronnie,
thanks for your replies and the profound discussion.
I think, it's best to demonstrate my problem case along an real world example:
The following log of a console sesssion shows how I am doing the mounts on behalf Linux Kernel CIFS-FS Module on the
client side against a Samba 4.5 file server (both running on Debian Stretch 9.8) via SMB/CIFS resp. SMB2 protocol:
2018 Jun 14
0
No write access on new shares until smbd is restarted
On Thu, 14 Jun 2018 19:06:37 +0200
Eugene Pankov via samba <samba at lists.samba.org> wrote:
> Using the latest SerNet 4.8.1 build, I'm seeing users being unable to
> write into newly created shares until smbd is restarted.
> Here's the relevant log part:
>
> [2018/06/14 16:04:29.229329, 5]
> ../source3/smbd/filename.c:662(unix_convert)
> unix_convert begin:
2019 Feb 26
2
Using Access Control Lists with SMB2/SMB3 Mounts on Linux Clients
Dear all,
what is about the support for POSIX ACL in Samba protocol implementation of SMB2 and SMB3?
>From what I extracted from SNIA and SambaXP developer conference talks and as well as the official Samba Wiki,
support for POSIX ACL in SMB2 and SMB3 has been completely abandonned. Am I right?
If so, is there any other possibility to allow Linux Clients to natively access access control lists
2019 Feb 27
2
Using Access Control Lists with SMB2/SMB3 Mounts on Linux Clients
On Tue, Feb 26, 2019 at 09:03:41AM -0800, Jeremy Allison via samba wrote:
>
> Check out the latest cifsfs code. I think Steve
> and Aurelian and Ronnie added an ioctl for this.
>
> I'm here at Vault in Boston with Steve, I'll ask
> him :-).
Steve says there are two utilities in Linux,
getcifsacl and setcifsacl that use a custom
ioctl inside the Linux cifsfs kernel
2019 Feb 26
2
Using Access Control Lists with SMB2/SMB3 Mounts on Linux Clients
Thanks for the first reply, Jeremy.
What about the (future) implementation of RichACL?
Will there be any native Linux Client support along with the SMB2/SMB3 protocol?
I know, there is a native implemenation for RichACLs in ext4 FS.
Unfortunately, smbcals is not a native Linux ACL Tool and has a very unhandy syntax.
I just tested some days ago. ;-)
I am looking for a solution that allows the
2018 Jan 22
3
SAMBA 4.7.4 with MIT Keberos
Hello,
i installed a SAMBA 4.7.4 AD Server on Ubuntu 18.04 (BETA). SAMBA4 was
compiled from source. For MIT Keberos i also installed libkrb5-dev and
krb5-kdc and compiled with the "--with-system-mitkrb5" option.
The installation runs pretty good (some dependencies problem, solved
manually). But now im not able to test kerberos:
# kinit administrator
--> kinit: Cannot find KDC
2020 Jul 02
5
Multiprotocol File Sharing via NFSv4 and Samba
Hi all,
are there any non-commercial solutions (apart from solutions like Dell EMC, IBM and NetApp) around that allow to simultaneously access the same file system via NFSv4 and Samba exports in a (nearly) non-conflicting manner, especially w.r.t. to NFSv4/Windows ACL incompatibilities?
Best
Sebatian
____________________
Sebastian Kraus
Team IT am Institut f?r Chemie
Geb?ude C, Stra?e des 17.
2018 Jun 14
3
No write access on new shares until smbd is restarted
Rowland,
Sorry - here are the globals and share config:
[global]
template shell=/bin/bash
log file=/var/log/samba/log.%m
log level=8
max log size=5000
passdb backend=tdbsam
load printers=no
printing=bsd
printcap name=/dev/null
map to guest=bad user
[2430_ram]
path=/data/fs/2430-ram
guest ok=no
browseable=yes
create mask=0775
directory mask=0775
read only=no
follow symlinks=yes
wide links=no
2004 May 12
2
i cannot find kinit
the name of my active directory domain is
niit.edu.pk
so what should i write in this parameter
default_relam = YOUR.KERBEROS.REALM
also while trying to join the domain i eecute this
command
kinit Administrator@your.keberos.REALM
My shell gives me the error cannot find kinit.
can any one tell me where in my file system can i find
kinit
Regards
=====
Sahibzada Junaid Noor
Ph #
2007 Apr 18
1
[Bridge] Google SoC proposal
Hello,
I am a student considering participating in Google Summer of Code program.
I came across Stephen Hemminger's idea of implementing a RSTP posted on
http://developer.osdl.org/dev/soc/ and found it interesting.
In attachment there's my proposal, which I just submitted to google.
Please share your comments.
--
tadeusz andrzej kad?ubowski
-------------- next part --------------
2010 Mar 03
7
SSH Remote Execution - su?
Greetings All-
I'm about to embark on some remote management testing and need a way to login to a remote system running CentOS 4.x/5.x via SSH, su to root (using a password), then execute a command.
I currently login to the boxes using key based SSH like this:
ssh -i ~/remote_key admin@$REMOTEIP
Then, I SU to root. However, if I try to do this automatically like this:
ssh -i ~/remote_key
2018 Mar 02
2
nscd and winbindd
Dear samba folks,
I have a special question regarding the simultaneous operation of nscd and winbindd on the same host:
We are running in a Samba file server setup where the nsswitch.conf looks like this:
passwd: files ldap
group: files ldap
shadow: files ldap
hosts: files dns wins
networks: files
protocols: db files
services: db files
2010 Jan 04
2
Outgoing Calls Only -- Firewall Rules
I'm trying to move my Asterisk deployments under a Virtual IP address and
now remember why I dislike this. My primary Asterisk system is now behind a
firewall in private address space. My question is what ports are needed to
be opened just for the purpose of placing outgoing calls. I would have
assumed none, but I can't even get replies on registration from any of my 3
VoIP providers.
2015 Dec 01
2
Making icecast stream available outside my network?
Hi, yess its running on my local ip address.
I've loged in to the router, andf
orwarded
port 8000.
On 12/1/2015 2:17 AM, Marius Flage wrote:
> Hi!
>
> Are you even sure that your icecast server is exposed on the internet?
> Is your icecast server running on a public or private ip address? If
> it's running on a private ip address (192.168.0.0/16, 10.0.0.0/8 or
>
2020 Jul 02
1
Multiprotocol File Sharing via NFSv4 and Samba
FreeNAS / FreeBSD have native NFSv4 ACLs. They do however lack kernel
oplock support so there are perhaps some caveats in that regard.
On Thu, Jul 2, 2020 at 3:07 PM Strahil Nikolov via samba <
samba at lists.samba.org> wrote:
> Hi Kraus,
>
> I know that Gluster can be exported over NFS-Ganesha (supports v4.X),
> Samba (protocol 1.0 in order to get 'real'
2019 Oct 18
2
Coredump v2.3.8 specific msg fetch, corrupted record in index cache, Broken physical size
Hi, i'm getting a coredump on a specific msg, i've attached the gdb.
file on disk i noticed W=<vsize> is missing.
1571209735.M744550P1608.rwvirtual65,S=15886:2,S
Best regards,
mail.log
Oct 18 14:41:39 rwvirtual10 dovecot:
imap(johndoe at company.nl)<15868><qjTFpy6VPsMKAAok>:
Error: Mailbox INBOX.Debug: UID=1041: read(/data/mail/
2003 Sep 30
2
Trouble with 'NET ADS JOIN'
Hi All,
Any clues as to what is causing this? I have seen similar questions asked
before in regards to joining ADS domain but have not been able to find a
solution to my problem.
The domain is a Native mode ADS on win2k3 with signing required. Please let me
know if additional info or logs are required to diagnose the problem.
I did a 'net ads join ADSDOM -U
2015 Mar 20
2
Samba AD DC and browsing of shares
----- V?stule no Rowland Penny <rowlandpenny at googlemail.com> ---------
Datums: Thu, 19 Mar 2015 21:59:39 +0000
S?t?t?js: Rowland Penny <rowlandpenny at googlemail.com>
Temats: Re: [Samba] Samba AD DC and browsing of shares
Sa??m?js: samba at lists.samba.org
>>> You do not have to use samba 4 to create an AD DC, you can use
>>> samba 4 just like samba 3, as
2019 Feb 27
0
Using Access Control Lists with SMB2/SMB3 Mounts on Linux Clients
Dear Jeremy,
thanks for your instant reply. :-)
Along with Linux native getfacl/fetfacl, I also tested getcifsacl/setcifsacl (for sure thoroughly ;-)).
Unfortunately, these CIFS client tools seem to have been designed as part of the "old" CIFS
Unix Extensions, working only for SMB/CIFS mounts, and are not supposed to work with
SMB2/SMB3 mounts, as I guess.
During my tests, the