similar to: Winbind and caching - idmap, DC

Displaying 20 results from an estimated 20000 matches similar to: "Winbind and caching - idmap, DC"

2019 Oct 18
6
Winbind and caching - idmap, DC
On Friday, 18 October 2019 10:52:40 PDT Rowland penny via samba wrote: > On 18/10/2019 18:26, Alexey A Nikitin via samba wrote: > > Hi everyone, > > > > I have few questions about Winbind on AD DS domain member I'm having difficulty finding answers to in the docs on my own: > > * does Winbind remember the last DC it was connected to on shutdown, will it attempt to
2019 Oct 18
2
Winbind and caching - idmap, DC
On Friday, 18 October 2019 12:24:46 PDT Ralph Boehme wrote: > You won't loose connectivity anyway. winbindd will just have to go > through DC lookup again in certain scenarios. This is exactly what I'd like to avoid. As I wrote in another message in this thread, it appears that switching DC shortly after domain join causes machine authentication failures until the new machine
2019 Oct 18
0
Winbind and caching - idmap, DC
On 10/18/19 8:45 PM, Alexey A Nikitin via samba wrote: > On Friday, 18 October 2019 10:52:40 PDT Rowland penny via samba wrote: >> On 18/10/2019 18:26, Alexey A Nikitin via samba wrote: >>> Hi everyone, >>> >>> I have few questions about Winbind on AD DS domain member I'm having difficulty finding answers to in the docs on my own: >>> * does Winbind
2019 Oct 18
0
Winbind and caching - idmap, DC
On 18/10/2019 19:45, Alexey A Nikitin wrote: > On Friday, 18 October 2019 10:52:40 PDT Rowland penny via samba wrote: >> On 18/10/2019 18:26, Alexey A Nikitin via samba wrote: >>> Hi everyone, >>> >>> I have few questions about Winbind on AD DS domain member I'm having difficulty finding answers to in the docs on my own: >>> * does Winbind remember
2019 Nov 05
2
suddenly change: idmap uid + gid
On Tuesday, 5 November 2019 01:37:15 PST Rowland penny via samba wrote: > On 04/11/2019 18:52, Alexey A Nikitin wrote: > > On Sunday, 3 November 2019 01:41:18 PST Rowland penny via samba wrote: > >> As I said, you cannot use 'winbind use default domain = yes' with > >> 'autorid', it makes all users and groups members of the same domain, > >> this
2019 Nov 04
2
suddenly change: idmap uid + gid
On Sunday, 3 November 2019 01:41:18 PST Rowland penny via samba wrote: > As I said, you cannot use 'winbind use default domain = yes' with > 'autorid', it makes all users and groups members of the same domain, > this is probably what has happened here. > > Remove the line, this should stop it happening again > > If you have only one domain, then you
2019 Oct 18
0
Winbind and caching - idmap, DC
Howdy, On 10/18/19 7:26 PM, Alexey A Nikitin via samba wrote: > I have few questions about Winbind on AD DS domain member I'm having difficulty finding answers to in the docs on my own: > * does Winbind remember the last DC it was connected to on shutdown, will it attempt to connect to the same DC on restart or will it go through DC location process again? yes: # net cache list | grep
2016 Jan 11
2
Security permissions issues after changing idmap backend from RID to AUTORID
On 2016-01-10 at 17:58 +0000, Rowland penny wrote: > On 10/01/16 17:05, Partha Sarathi wrote: > > > > > This could have a lot to do with the fact that idmap_rid & > > > idmap_autorid calculate the uids differently i.e if you have RID > > > '2025000', autorid would calculate this as '1102500000' , rid > > > would calculate this as
2016 Jan 10
2
Security permissions issues after changing idmap backend from RID to AUTORID
Thanks for the reply. Now we end-up with mix uid/gid from both ranges in cache TDBs. Few user logins are denied with below error in smbd.log, *[2016/01/07 11:39:44.475960, 1, pid=5202] ../source3/auth/token_util.c:430(add_local_groups* ** SID S-1-5-21-3082371790-1274690562-2878062458-5771 -> getpwuid(10005771) failed** wbinfo --user-info=mariond mariond:*:10015138:110000513:Marion,
2019 Nov 02
7
suddenly change: idmap uid + gid
Hi The server suddenly changed the uid + gid. this happened to times, yesterday and the week after. The default group at example The samba is a AD member where we have many users (>20 000) and we use autorid in that way [global] security = ads workgroup = CUSTOMER realm = CUSTOMER.COM winbind use default domain = yes winbind enum users = yes winbind enum group = yes
2019 Oct 18
0
Winbind and caching - idmap, DC
On 18/10/2019 18:26, Alexey A Nikitin via samba wrote: > Hi everyone, > > I have few questions about Winbind on AD DS domain member I'm having difficulty finding answers to in the docs on my own: > * does Winbind remember the last DC it was connected to on shutdown, will it attempt to connect to the same DC on restart or will it go through DC location process again? I don't
2019 Nov 03
2
suddenly change: idmap uid + gid
Am 03.11.2019 um 09:42 schrieb Rowland penny via samba <samba at lists.samba.org>: > > ?On 02/11/2019 23:18, Hilberg via samba wrote: >> Hi >> >> The server suddenly changed the uid + gid. this happened to times, yesterday and the week after. The default group at example >> The samba is a AD member where we have many users (>20 000) and we use autorid in
2016 Jan 08
2
Security permissions issues after changing idmap backend from RID to AUTORID
adding samba list On Fri, Jan 8, 2016 at 10:22 AM, Partha Sarathi <parthasarathi.bl at gmail.com> wrote: > Hi, > > > We have a customer who facing security issues after changing RID idmap > backend to AUTORID. > > > The History of the issue looks as below, > > 1) When samba configured with RID idmap backend customer requested to > change few permissions,
2017 Aug 07
6
member server idmap config (auto)rid
I've joined a samba 4.48 (debian stretch) to a Windows 2008R2 AD domain according to https://wiki.samba.org/index.php/Setting_up_Samba_as_a_Domain_Member It joins OK but I cannot get idmap rid (or autorid) to work idmap config * : backend = autorid idmap config * : range = 1000000-1199999 Nothing is returned for getent "SAMDOM\user" log.winbindd shows: [2017/08/07
2020 Sep 29
3
[CTDB] "use mmap = no" Causes wibind to fail
On 29/09/2020 08:35, Ralph Boehme via samba wrote: > Am 9/29/20 um 7:44 AM schrieb Christian Kuntz via samba: >> Is the wiki information still accurate? If so, what needs to change about >> my configuration to fix this issue? >> If the information is out of date and the modern utility of "use mmap = no" >> is unknown, how can I test it? > hm, I guess the
2020 Oct 29
2
question about winbind rid idmaping
Am 10/29/20 um 1:07 PM schrieb Rowland penny via samba: > On 29/10/2020 11:56, Andrew Walker wrote: >> Several of the idmap backends (including idmap_rid) in samba support >> id_type_both (the ID is both a user and a group). This is ultimately >> needed for accurately producing Windows-style behavior regarding >> permissions (where a group can be the owner of a file).
2019 Nov 03
2
suddenly change: idmap uid + gid
On Sun, 2019-11-03 at 08:39 +0000, Rowland penny via samba wrote: > On 02/11/2019 23:18, Hilberg via samba wrote: > > Hi > > > > The server suddenly changed the uid + gid. this happened to times, > > yesterday and the week after. The default group at example > > The samba is a AD member where we have many users (>20 000) and we > > use > > autorid
2019 Feb 22
6
winbind causing huge timeouts/delays since 4.8
On Fri, 22 Feb 2019 16:40:46 +0100 Alexander Spannagel via samba <samba at lists.samba.org> wrote: > Am 22.02.19 um 15:42 schrieb Rowland Penny via samba: > > On Fri, 22 Feb 2019 15:35:53 +0100 > > Ralph Böhme via samba <samba at lists.samba.org> wrote: > > > >> Hi, > >> > >> On Fri, Feb 22, 2019 at 01:59:15PM +0100, Alexander Spannagel
2019 Mar 12
3
sometimes users fails to login
Hello, I have Samba 4.6 as AD domain member and sometime the users fails to login, the issue disappear after some minutes. I have enabled log leve 10 and I can see the following errors: 2019/03/12 09:20:32.280799,  5, pid=15466, effective(0, 0), real(0, 0)] ../source3/lib/username.c:181(Get_Pwnam_alloc)   Finding user BITINTRA\U002489 [2019/03/12 09:20:32.281111,  5, pid=15466, effective(0,
2020 Sep 29
3
[CTDB] "use mmap = no" Causes wibind to fail
On Tue, 29 Sep 2020 11:22:08 +0200, Ralph Boehme via samba <samba at lists.samba.org> wrote: > Am 9/29/20 um 10:33 AM schrieb Rowland penny: > > Ralph, the wikipage, that Christian referred to, says to use: > > > > netbios name = something > > clustering = yes > > idmap config *?: backend = autorid > > idmap config *?: range = 1000000-1999999 >