similar to: Issues demoting a samba DC.

Displaying 20 results from an estimated 5000 matches similar to: "Issues demoting a samba DC."

2023 Jan 08
1
Issues demoting a samba DC.
On 08/01/2023 11:04, Michael Tokarev via samba wrote: > Hello! > > I'm trying to remove a DC from our samba domain (samba 4.17.4). > It was the primary controller (with FSMO roles), - I successfully > transferred the roles to another DC.? Now it's time to demote: > > ai# samba-tool domain demote -U mjt-adm > Using svdcp.tls.msk.ru as partner server for the
2023 Jan 08
2
Issues demoting a samba DC.
08.01.2023 14:21, Rowland Penny via samba wrote: .. >> ai# samba-tool domain demote -U mjt-adm .. >> ERROR(ldb): Error while renaming CN=AI,OU=Domain Controllers,DC=tls,DC=msk,DC=ru to CN=AI,CN=Computers,DC=tls,DC=msk,DC=ru - LDAP error 50 >> LDAP_INSUFFICIENT_ACCESS_RIGHTS -? <acl:access_denied renaming CN=AI,OU=Domain Controllers,DC=tls,DC=msk,DC=ru> <> .. > If
2023 Jan 08
1
Issues demoting a samba DC.
On 08/01/2023 14:19, Michael Tokarev via samba wrote: > 08.01.2023 14:21, Rowland Penny via samba wrote: > .. >>> ai# samba-tool domain demote -U mjt-adm > .. >>> ERROR(ldb): Error while renaming CN=AI,OU=Domain >>> Controllers,DC=tls,DC=msk,DC=ru to >>> CN=AI,CN=Computers,DC=tls,DC=msk,DC=ru - LDAP error 50 >>>
2024 Dec 31
2
ef205f6b52e "s3:gse: get an explicit ccache_name" breaks kerberos auth in smbclient
FWIW, samba 4.20 broke kerberos auth in smbclient. Namely, this commit: commit ef205f6b52ea1fec13e647e15e4f3edf536fd93e Author: Stefan Metzmacher <metze at samba.org> Date: Thu Apr 14 15:23:13 2022 +0200 s3:gse: get an explicit ccache_name from creds and kinit if required This means we may call kinit multiple times for now, but we'll remove the kinit from the callers
2023 Jan 08
1
Issues demoting a samba DC.
08.01.2023 18:54, Michael Tokarev wrote: ... > And nope, after removing this stale A gc._msdcs record from samba DNS, it > still does not work and still logs the same error message, apparenlty when > trying to log in to the other DC for replication: > > [2023/01/08 18:50:43.390974,? 0] ../../source4/librpc/rpc/dcerpc_util.c:681(dcerpc_pipe_auth_recv) > ? Failed to bind to uuid
2024 Jul 08
2
samba-ad-dc from debian backports fails to start with /usr/sbin/samba missing
08.07.2024 17:18, Sonic wrote: > On Mon, Jul 8, 2024 at 6:46?AM Michael Tokarev <mjt at tls.msk.ru> wrote: > ... >> I think the main ingredient here is to have apt-listchanges package >> installed (which, while part of standard install, is optional). > ... > > I've always installed using the netinstall.iso which does not install > that package. Will add it
2024 Jun 20
1
leaving a domain?
On Thu, 20 Jun 2024 15:19:35 +0300 Michael Tokarev <mjt at tls.msk.ru> wrote: > 20.06.2024 15:16, Rowland Penny via samba wrote: > > On Thu, 20 Jun 2024 15:07:11 +0300 > > Michael Tokarev via samba <samba at lists.samba.org> wrote: > > > >> 20.06.2024 15:03, Michael Tokarev via samba wrote: > > >> Still, it'd be nice if samba-tool domain
2024 Jun 07
2
DC upgraded to 4.20.1 - issues
On Fri, 7 Jun 2024 08:50:11 +0200 "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote: > > on the problematic DC "systemctl status" doesn't even show > "samba-ad-dc". > > Although: > > # systemctl status samba-ad-dc.service > ? samba-ad-dc.service - LSB: Samba daemons for the AD DC > Loaded: loaded
2025 Jan 01
1
ef205f6b52e "s3:gse: get an explicit ccache_name" breaks kerberos auth in smbclient
Am 31.12.24 um 21:49 schrieb Michael Tokarev: > FWIW, samba 4.20 broke kerberos auth in smbclient.? Namely, this commit: > > commit ef205f6b52ea1fec13e647e15e4f3edf536fd93e > Author: Stefan Metzmacher <metze at samba.org> > Date:?? Thu Apr 14 15:23:13 2022 +0200 > > ??? s3:gse: get an explicit ccache_name from creds and kinit if required > > ??? This means we
2024 Jul 08
1
samba-ad-dc from debian backports fails to start with /usr/sbin/samba missing
On Mon, Jul 8, 2024 at 6:46?AM Michael Tokarev <mjt at tls.msk.ru> wrote: ... > I think the main ingredient here is to have apt-listchanges package > installed (which, while part of standard install, is optional). ... I've always installed using the netinstall.iso which does not install that package. Will add it from now on. Thank you, Chris
2024 Apr 05
1
samba as a domain member: a way to ignore groups?
On Fri, 5 Apr 2024 17:24:33 +0300 Michael Tokarev <mjt at tls.msk.ru> wrote: > 05.04.2024 17:16, Rowland Penny via samba wrote: > > On Fri, 5 Apr 2024 16:43:42 +0300 > > Michael Tokarev via samba <samba at lists.samba.org> wrote: > > > >> Hi! > >> > >> We had stand-alone anonymous samba server serving a read-only share > >> as
2010 Aug 23
6
[Bug 29766] New: suspend-to-ram problem on GF7600 notebook
https://bugs.freedesktop.org/show_bug.cgi?id=29766 Summary: suspend-to-ram problem on GF7600 notebook Product: xorg Version: unspecified Platform: x86 (IA32) OS/Version: Linux (All) Status: NEW Severity: normal Priority: medium Component: Driver/nouveau AssignedTo: nouveau at lists.freedesktop.org
2024 Apr 05
1
samba as a domain member: a way to ignore groups?
05.04.2024 17:50, Rowland Penny via samba: > On Fri, 5 Apr 2024 17:24:33 +0300 > Michael Tokarev <mjt at tls.msk.ru> wrote: > >> 05.04.2024 17:16, Rowland Penny via samba wrote: >>> On Fri, 5 Apr 2024 16:43:42 +0300 >>> Michael Tokarev via samba <samba at lists.samba.org> wrote: >>> >>>> Hi! >>>> >>>> We had
2022 Nov 14
1
Replication between Samba DCs (on different sites)?
Hi! Should replication between two Samba DCs Just Work after joining a second DC to the domain? We always were running a single DC (historically it was just a single server anyway), now I've added another DC, located in a remove office, but there's no replication of any kind. Should it be configured somehow? The initial data seems to be copied fine at the time of domain join, but no
2023 Aug 10
1
Samba domain time sync woes (Debian Bookworm)
FWIW, I looked at the settings in our domain (all of which I did myself). I used to explicitly set up ntp time sources in our network for all windows workstations before, and I continued to provide these after conversion from nt4-style domain to samba AD-DC. The NTP records are provided by DHCP, and are configured in the GPO, both with regional differences (choosing the local NTP servers within
2024 Jun 20
1
leaving a domain?
20.06.2024 15:16, Rowland Penny via samba wrote: > On Thu, 20 Jun 2024 15:07:11 +0300 > Michael Tokarev via samba <samba at lists.samba.org> wrote: > >> 20.06.2024 15:03, Michael Tokarev via samba wrote: >> Still, it'd be nice if samba-tool domain leave displayed some more >> appropriate error message, and no insecure-password-on-command-line >> warning
2015 Jul 29
2
CentOS 7.1 + qemu-kvm-ev + SLIC acpitable windows bug workaround
On 29.07.2015 21:34, Nux! wrote: > Yes, you can. > In fact you can use the binaries from the ovirt repo itself, no need to rebuild. Thank you! In fact - I can't use raw binaries from the ovirt repo itself, because these qemu-kvm binaries contains one bug, which is already fixed in Debian: If you want to migrate Windows from hardware node to VM using CentOS 7.1 on hardware node and
2024 Aug 12
1
bind9 failure when using dlz_bind
On Sun, 11 Aug 2024 10:29:14 +0300 Michael Tokarev <mjt at tls.msk.ru> wrote: > 11.08.2024 00:53, Franta Hanzl?k via samba wrote: > > > I have about the same crash on Fedora 40 x86_64/bind-9.18.28 and > > Samba 4.20.4 (own build with internal Heimdal, as Fedora build it with > > MIT Kerberos - which (IMO) not stable yet). > > What is not stable with
2024 Jul 08
1
samba-ad-dc from debian backports fails to start with /usr/sbin/samba missing
07.07.2024 16:05, Sonic via samba wrote: > On Fri, Jul 5, 2024 at 3:55?AM Michael Tokarev via samba > <samba at lists.samba.org> wrote: > ... >> Please don't suppress *NEWS* entries. > ... > > As someone that was bitten by this change I have to admit I've never > seen these NEWS entries, or never realized I had. My Debian servers > are cli only (no X or
2023 Apr 10
1
4.18.x on bullseye-security update?
10.04.2023 21:38, Elias Pereira via samba ?????: > Hi, > > Any ETA for the inclusion of 4.18.x in bullseye-security? There will be no 4.18.x on bullseye or bullseye-backports. Maybe bullseye-backports-sloppy but very unlikely too. /mjt