Displaying 20 results from an estimated 8000 matches similar to: "best way to write group membership to a file"
2019 Jun 04
2
How to fix mapping Administrator to root
Hi Rowland ,
I have followed the wiki's step, the DNS works OK and I have use the fileserver for 2 years.
here's a share folder "IT"'s acl
getfacl IT/
# file: IT/
# owner: root
# group: domain\040admins
user::rwx
user:root:rwx
group::rwx
group:domain\040admins:rwx
group:it:rwx
mask::rwx
other::---
default:user::rwx
default:user:root:rwx
default:group::---
2019 Jun 03
2
How to fix mapping Administrator to root
Hi Rowland,
Yes. all users primary group is "domain users".
my "domain admins" has a gidNumber.
Best,
yours Adam
From: Rowland penny via samba
Date: 2019-06-03 22:44
To: sambalist
Subject: Re: [Samba] How to fix mapping Administrator to root
On 03/06/2019 15:29, adam_xu at adagene.com.cn wrote:
> Hi Rowland,
>
> I have checked that Adinistrator is a member of
2019 Jun 03
3
How to fix mapping Administrator to root
Thanks, Rowland , 'net cache flush' solved my problem. but I found that I can't access any share in \\myshare.
some related configurations in my smb,conf
....
access based share enum = yes
hide unreadable = yes
username map = /etc/samba/user.map
I can't see any share folder of my fileserver in fsmgmt.msc. and I run "smbstatus -b"
PID Username Group
2019 Jun 03
2
How to fix mapping Administrator to root
Hi Rowland,
I have checked that Adinistrator is a member of "Domain Admins" in ADUC.
Base Permission of the share folder is 0770 and own is root and the groups is "domain admins" in linux.
since "smbstatus -b" show that administrator's group is root. Is this related to my previous configuration? I once give a uidNumber to administrator.
here's full contant
2019 Jun 05
2
How to fix mapping Administrator to root
On 05/06/2019 03:22, adam_xu--- via samba wrote:
> Hi sambalist,
>
> I set up a new test environment to test the problem. still the same result. It seems that if I didn't give administrator a uidNumber in unix attributes and only map this user to root. it can manage the share folder in fsmgmt.msc, but after I remove everyone's share permission and add share permissions to
>
2019 Jun 05
2
How to fix mapping Administrator to root
On 05/06/2019 09:08, adam_xu at adagene.com.cn wrote:
> Hi Rowland,
>
> I can manage the security permission, but I can't manage the share
> permission after I remove the user "everyone"'s share permission and
> add "domain admins" and "domain user" share permission.
> Do you have any advice?
>
I take it you are referring to the
2019 Jun 05
2
How to fix mapping Administrator to root
On 05/06/2019 08:37, adam_xu at adagene.com.cn wrote:
> Hi Rowland ,
>
> I used to manage file or folder permissions using administrator
> account in Windows Client. So how could I do this task if the
> administrator can't do this after I mapped it to root in fileserver
> and remove it's uidNumber in ADUC? should I create another user in
> Domain Adams"?
>
2019 Jun 05
2
How to fix mapping Administrator to root
On 05/06/2019 09:26, adam_xu at adagene.com.cn wrote:
> Hi Rowland,
>
> English?is?not?my?native?language.It?seems?that?the?communication?between?us
> was a?misunderstanding. what I want is just
> "IGNORE?the?'share'?tab,?do?not?touch?it,?forget?it?is?there."
> Thank?you?for?your?patience.
>
No problem, I sort of thought this was the case ;-)
To be clear:
2019 Jun 05
2
How to fix mapping Administrator to root
On 05/06/2019 09:51, adam_xu at adagene.com.cn wrote:
> Hi Rowland ,
>
> In?some scenarios,?we?have?hundreds
> of?shared?folders.?We?don't?want?users?to?see?too?many?folders,?so?we?configure?share?permissions?and?set
> "hide unreadable = yes" in smb.conf. then users can only see the
> folder that he or she has permissions. This?is?why?we?do something in
>
2017 Oct 30
5
Listing AD group members
Hi,
Ive been trying to work out how to get wbinfo to list members of a specific
AD group, rather than list groups a specific user is in.
So far I have had no luck... In fact im not sure its possible with wbinfo.
Is there another tool which could do this?
James
--
Sent using Dekko from my Ubuntu device
2016 Mar 07
6
classicupgrade migration issues
Sorry for the long post but attempted this several over the past year
with no success but staying on an NT4 domain is no longer viable. Need
to get this resolved so hopefully there will be a clue somewhere in
this montage.
The current PDC is samba-3.6.25 running on Gentoo using tdbsam backend.
The new AD will be a Debian LXC container running on Debian Jessie
using samba compiled from git
2019 Jun 03
2
How to fix mapping Administrator to root
Hi sambalist,
I'm using samba ad dc for about 2 years. I have 2 DCs and One file server. I didn't map the Administrator to root because the wiki said:
"Mapping the domain administrator to the local root account is optional. Only configure the mapping if the domain administrator must be able to execute file operations on the domain member using root permissions. You should be aware
2019 Jun 05
0
How to fix mapping Administrator to root
Hi sambalist,
I set up a new test environment to test the problem. still the same result. It seems that if I didn't give administrator a uidNumber in unix attributes and only map this user to root. it can manage the share folder in fsmgmt.msc, but after I remove everyone's share permission and add share permissions to
domain admins full control
domain users RW
then, the administrator
2017 Oct 30
1
Listing AD group members
It appears to hang for a very long time (up to 15 minutes) on "kinit for HOSTNAME$@DOMAIN.LOCAL succeeded"
then it returns nothing.
I'm somewhat confused!
James
October 30, 2017 12:27 PM, "Rowland Penny via samba" <samba at lists.samba.org> wrote:
> On Mon, 30 Oct 2017 12:07:24 +0000
> "A. James Lewis" <james at fsck.co.uk> wrote:
>
2017 Oct 30
4
Listing AD group members
Oh, I assumed you meant -d10, since -d0 turns off all debug output, so the output is long, but I get:-
.
.
.
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'spnego' registered
GENSEC backend 'schannel' registered
GENSEC backend 'naclrpc_as_system'
2019 Jul 10
4
error in sernet samba
Hi sambalist,
I'm using sernet samba for several years. I found that there's error in the log.samba file like this:
[2019/07/10 14:55:25.892988, 0] ../../lib/util/fault.c:79(fault_report)
===============================================================
[2019/07/10 14:55:25.893187, 0] ../../lib/util/fault.c:80(fault_report)
INTERNAL ERROR: Signal 11 in pid 9906
2019 Jul 10
2
error in sernet samba
Reindl/Harald,
What is your first name? Sorry for asking, but always wondered about it.
I just wanted to note here that...
1) I have seen this also if samba is upgraded and not restarted.
Or
2) if a packages is not upgrade because an extra package is also needed at install.
And that should be tested/checked/tried out first and if that all fails,
then its needed to contact sernet support.
2018 Apr 20
2
administrator's unix attributes is missing
Hello, Rowland. what I set in RSAT is:
nis domain "ntbaobei"
uid "10000"
login shell "/sbin/nologin"
home dir "/home/Administrator"
primary group "domain admins"
I never used user map beacuse everything worked ok before. I knew the "root" user can granting the SeDiskOperatorPrivilege Privilege.
Is there any changelog in samba 4.7.7 that
2019 May 27
4
samba-tool group removemembers, not working
Because of other issues using ADUC, I tried to remove a domain member using:
> samba-tool group removemembers "Domain Computers" MARKA\$
Removed members from group Domain Computers
As shown, it say it "Removed members", but ...
> samba-tool group listmembers "Domain Computers"
:
LABRAT$
:
OHPRSSTORAGE$
MARKA$
:
COMMON$
:
listmembers still shows the computer
2018 May 25
3
Does samba support Administrative Templates
Hello, everyone. After some windows 10 client join to our samba AD DC. A lot of setting is missing in the windows 10 PCs. so I need to import some windows 10 Administrative Templates to samba dc like that:
https://support.microsoft.com/en-us/help/3087759/how-to-create-and-manage-the-central-store-for-group-policy-administra
Unfortunately, I didn't see any dir named