Displaying 20 results from an estimated 5000 matches similar to: "a thing similar to su"
2020 Sep 25
1
a thing similar to su
For testing shares, you can use the "effective access" tab in Windows, or
"su -/bin/bash - EXAMPLEDOMAIN\\user" and navigate to the share
On Fri., Sep. 25, 2020, 12:24 a.m. Marco Gaiarin via samba, <
samba at lists.samba.org> wrote:
> Mandi! Andrea Zagli via samba
> In chel di` si favelave...
>
> > i want to do the same thing, as domain admin, when i
2019 Oct 16
4
vfs_recycle permission bug?!
Samba 4.8 (Louis debian repo), DM.
Today i've had to recovery a deleted file in that share, that use
'vfs_recycle' modules:
[Work]
comment = Spazio di Lavoro Utente
map acl inherit = Yes
path = /srv/work
read only = No
store dos attributes = Yes
vfs objects = acl_xattr recycle full_audit
volume = Work
full_audit:failure = none
full_audit:success = mkdir rmdir read pread
2019 Oct 01
5
Upgrade DC 4.5 -> 4.8, timings?
I've read all docs on upgrades, from wiki to Louis notes, and i think
i'm ready to upgrade.
First step, move from stretch to jessie, and from 4.5 to 4.8, upgrade
in place.
But having a domain with 6 DCs, i'm a bit scared to upgrade all DC in
one turn, and i'm think about something like:
a) upgrade DC with FSMO roles, then wait 1-2 day to spot troubles
b) then upgrade all DC in
2019 Sep 23
4
testparm comaprison
On 23/09/2019 13:42, Trenta sis via samba wrote:
> Thanks, ntlm auth is temporary until we have solved some issues
> getent is needed by filesystem acl
>
If you think you need the 'winbind enum' lines so that 'getent' works,
then think again ;-)
If you do not have the 'winbind enum 'lines 'getent passwd username'
will still work.
'getent passwd'
2019 Jul 31
5
winbind seems to hang when the DC goes down instead of switching to the other available DC
Hello,
I'm running Samba 4.9.5 as domain member, when I bring down the current
Window DC (10.50.50.187) the winbind seems to hang instead of switching
to the other available DC (10.50.50.25)
The "net ads" command show that Samba switched to the other available DC:
net ads join -U 'administrator' -S 'PAVONE.HYPERFILE.LOCAL'
'HYPERFILE.LOCAL'^C
root at
2019 Dec 10
2
DC in trash...
Debian stretch, louis packages 4.9.16+dfsg-0.1~stretch~1 .
After some time (roughly: two weeks) my DC with FSMO roles (seems that
other DC are unaffected) goes suddenly on trash: memory jump from 50%
(3GB) to 100%, container start to swap and slow down (load 10-15) al
the phisical server.
A simple restart solve all the troubles.
Some hint on how to debug that? Thanks.
--
dott. Marco Gaiarin
2019 Aug 28
4
[OT?] W10, SYSTEM, guest access.
[ I've just asked abut that, here, but now seems a simpler things, so i
retry... ]
This seems NON a samba touble, but a different behaviour in M$
client OS. But, really, i've not clue how to find an answer...
Suppose to have a Win7 and a Win10 machine, both NOT joined to a
domain. Suppose to have a share, with guest access enabled, where only
readonly access are needed.
Suppose also
2019 Sep 23
2
testparm comaprison
On 23/09/2019 15:18, Marco Gaiarin via samba wrote:
> Mandi! Rowland penny via samba
> In chel di` si favelave...
>
>> I repeat (louder this time): NO ONE NEEDS THE 'WINBIND ENUM' LINES IN
>> SMB.CONF
> While it is true that i can live happily without 'winbind enum', it is
> not completely true that 'no one needs' that.
>
> For example,
2019 Sep 13
4
NT domain, Win10 1903 and profiles...
Not only NT domains, but also Samba 3.6! Wow! I'm a retro-sysadmin! ;-)
I know i'm asking a rather hard thinks but... we are upgrading, but
also solving some troubles.
We have ''decently'' integrated some W10 1803 in a NT domain, but now
with some other 1903 there's no way to make roaming profiles work.
Looking at samba logs, seems that the client don't try at
2019 Jun 26
2
<printername>.tdb error management...
Sometimes (rarely, very rarely) i spot a <printername>.tdb error that
seems to prevent the communication between samba and CUPS.
In log i see:
[2019/06/26 15:15:49.633876, 0] ../source3/lib/util_tdb.c:316(tdb_log)
tdb(/var/cache/samba/printing/sml5010-2.tdb): tdb_rec_read bad magic 0x25 at offset=26096
the only solution i've found, pretty drastic, is:
systemctl stop
2015 Jan 05
2
Info/Feedback on Samba bug #8744...
Happy new year to the list!
I'm using Debian wheezy, standard Samba packages, version
2:3.6.6-6+deb7u4.
I've hit bug #8744
https://bugzilla.samba.org/show_bug.cgi?id=8744
(referenced in debian BTS as
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=658707) that prevent
me to use machine account auth; i'm using it with freeradius, to
automatically connect some wireless clients.
2019 Oct 17
3
Offline logon and NSS...
Mandi! Rowland penny via samba
In chel di` si favelave...
> Yes, somebody moved the cache to a different directory and it now gets wiped
> every time Samba is restarted, we have a bug report for it:?
> https://bugzilla.samba.org/show_bug.cgi?id=14074
Ok, thanks.
I suppose that cache get controlled by:
idmap cache time = 604800
winbind cache time = 300
so, for a portable system,
2019 Oct 17
3
Offline logon and NSS...
Mandi! Rowland penny via samba
In chel di` si favelave...
> > Considering a 'full offline' DM client (supposing a portable), there's
> > a 'winbind permanent nss cache' or a general nss cache (like
> > nss-updatedb):
> > https://wiki.debian.org/LDAP/NSS#Offline_caching_of_NSS_with_nscd
> > have to be used? Thanks.
> No, you cannot use
2019 Oct 01
3
Removed a DC but...
Some month ago a local branch office closed; the local branch had a DC,
that i've simply removed the dc with:
samba-tool domain demote --server=vdcsv1.ad.fvg.lnf.it -U gaio
(see https://lists.samba.org/archive/samba/2019-February/221195.html)
But this leave some old DNS records, eg:
root at vdcsv1:~# host -t SRV _kerberos._udp.ad.fvg.lnf.it | awk '{print $NF}'| sed
2019 Nov 07
3
Samba, Debian and upgrade path...
Yesterday, after a long run, i've finally upgraded my DCs to
stretch/samba4.9, using Louis repos. Hurrah! ;-)
Looking forward, eg:
http://apt.van-belle.nl/debian/dists/
seems to me that i can advance to 4.10 in stretch, but to go further i
need buster (probably because of python deps, right?).
Louis, i think we need a matrix of debian-samba compatibility... ;-)
--
dott. Marco Gaiarin
2020 Sep 11
4
Winbind offline cache and strangeness...
I've setup a portable system (ubuntu 16.04) joined to my AD domain,
that in their primary network works as expected.
But in this 'COVID time', the portable start to roam around, and users
say me that, suddenly after some days of use, get incredibly
sloooowww... after that users reboot, and cannot get back in, login
refused.
I've setup a VPN, but clearly if users cannot login
2019 Oct 17
4
Offline logon and NSS...
I'm revising some docs, and i've returned on the 'offline logon' tema.
Looking at:
https://wiki.samba.org/index.php/PAM_Offline_Authentication
and smb.conf manpage, it is clear that 'offline logon' is
a pam/authentication only, does not involve NSS.
Considering a 'full offline' DM client (supposing a portable), there's
a 'winbind permanent nss
2018 Dec 19
2
smbclient v3 against samba server v4
Il giorno mer 19 dic 2018 11:46:56 CET, Rowland Penny via samba ha scritto:
> On Wed, 19 Dec 2018 09:31:38 +0000
> Andrea Zagli via samba <samba at lists.samba.org> wrote:
>
>> hi all
>>
>> i'm trying to use smbclient v3 with a samba server v4 configured as ad
>>
>> with anonymous login it works; but it doesn't using a user
>>
>> i
2019 Sep 24
6
Windows 10 temporary profile error, when domain remote profile directory exists and is empty
Hello,
The below happens with Samba 4.7.* (didn't checked with other Samba 4
versions):
Setup: Samba 4.7.* AD, two domain controllers, 'computer A' and
'computer B' are Windows 10 domain members.
1. A user (login 'username') logs in into domain for the first time, on
a 'computer A'.
Samba DC doesn't find existing profile directory and creates an empty
2020 Aug 27
3
accessing foreign AD users to NT domain
No, the point is..
User verfications
Computer verification
And Authentication.
These are 3 different things.
The differences, in terms.
NTLM KERBEROS DNS-lookups and how this all works together.
But i only type with lots of errors, this is better to read ;-)
https://docs.microsoft.com/en-us/windows-server/security/windows-authentication/credentials-processes-in-windows-authentication
I