Displaying 20 results from an estimated 8000 matches similar to: "access "claim types""
2019 Sep 05
2
migrated from gentoo to debian, DM throws errors ...
what do I miss here:
wbinfo -u / -g -/ -pPt works
[2019/09/05 17:15:25.963590, 1]
../source3/librpc/crypto/gse.c:658(gse_get_server_auth_token)
gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/SAMBA.noras.intra at NORAS.INTRA(kvno 54) in keytab
MEMORY:cifs_srv_keytab (aes256-cts-hmac-sha1-96)]
[2019/09/05 17:15:25.963681, 1]
2019 Jan 03
2
Windows ACLs on share
Am 03.01.19 um 15:29 schrieb Rowland Penny via samba:
> On Thu, 3 Jan 2019 15:08:46 +0100
> "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
>
>>
>> We are in the process of switching over shares from the old way of
>> doing this to Windows ACLs:
>>
>> disable "valid users" "write list" etc
>>
2018 Sep 11
2
"missing security tab" and related ACL issues
Am 07.09.18 um 20:07 schrieb Rowland Penny via samba:
> On Fri, 7 Sep 2018 19:09:37 +0200
> "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
>> But
>>
>> # net rpc rights grant "Domänen-Admins" SeDiskOperatorPrivilege -U
>> "mydomain\administrator"
>>
>> fails
>>
>> also for
2018 May 30
2
DM 3.6.25 -> 4.x
On Wed, 30 May 2018 16:03:30 +0200
"Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
> We see that it is old ("SWAT", date) and ugly ...
>
>
> # cat /etc/samba/smb.conf
> # Samba config file created using SWAT
> # from UNKNOWN (192.168.100.66)
> # Date: 2012/07/23 14:38:02
It isn't that old;-)
You wont be using swat again, it
2020 Feb 25
2
Windows ACLs : problems
Am 25.02.20 um 15:16 schrieb Rowland penny via samba:
> On 25/02/2020 14:01, Stefan G. Weichinger via samba wrote:
>> Am 25.02.20 um 14:54 schrieb Rowland penny via samba:
>>> You do not need it, it is only required if using the winbind 'ad'
>>> backend and only then if you don't want possible problems with sysvol.
>> What? Now I *don't* need it?
2018 May 30
3
DM 3.6.25 -> 4.x
Hai Stefan,
Yes, its always better to ask the list, that way everybody can learn from it. ;-)
> Do you think I will have to rejoin it to the domain?
No i dont think so.
Please note, o dont know anything about gentoo except that they have a good wiki/info pages.
If this was debian, then in this case, what i would extra do here, run :
samba -b and backup all folders of samba and any thing
2024 Oct 25
3
Kerberos ticket renew causes a brief network interruption
Hi Samba engineer,
We use an Ubuntu 20.04.6 systems as Samba server.
The Samba version is 4.15.13-Ubuntu.
The SMC-Client is a Windows Server 2022 Standard 21H2.
The hostname of the Ubuntu Samba server is "samba-srv"
On the Windows system, Samba disk is shared with the command:
C:>net use Y: \\samba-srv\customers /u:hans
Enter the password for 'hans' to connect to
2024 Oct 25
1
Kerberos ticket renew causes a brief network interruption
On Fri, 25 Oct 2024 08:35:08 +0000
Hans van Leeuwen via samba <samba at lists.samba.org> wrote:
> Hi Samba engineer,
>
> We use an Ubuntu 20.04.6 systems as Samba server.
> The Samba version is 4.15.13-Ubuntu.
> The SMC-Client is a Windows Server 2022 Standard 21H2.
>
> The hostname of the Ubuntu Samba server is "samba-srv"
> On the Windows system, Samba
2019 Jan 03
2
Windows ACLs on share
We are in the process of switching over shares from the old way of doing
this to Windows ACLs:
disable "valid users" "write list" etc
and set ACLs via Windows Explorer ...
And I struggle.
I am asking for a way to "start ACLs from scratch".
I ran "setfacl -b -R" on the dir on the samba server and did a "chown -R
root:10513" to hand it to
2019 Nov 26
2
moved DM config to new server : gids different etc
Am 26.11.19 um 17:37 schrieb Rowland penny via samba:
> How about 'getent group Domain\ Users' ?
no result = empty reply
The "admin" there is able to access stuff and reset his ACLs already.
So ... things work so far. thanks.
I will consider the config Louis suggested ... but not now
(my reply was rejected by some samba-ml-SMTP-server ... another problem)
2019 Sep 05
2
migrated from gentoo to debian, DM throws errors ...
Am 05.09.19 um 17:37 schrieb Stefan G. Weichinger via samba:
> Am 05.09.19 um 17:19 schrieb Stefan G. Weichinger via samba:
>>
>> what do I miss here:
>
> update: maybe the reboot of the clients helped ... looks better now
>
>
>
Access works, but I still get
[2019/09/05 17:49:41.888422, 1]
../source3/librpc/crypto/gse.c:658(gse_get_server_auth_token)
2018 May 30
2
DM 3.6.25 -> 4.x
On Wed, 30 May 2018 09:48:04 +0200
"Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
> Am 2018-05-30 um 09:21 schrieb L.P.H. van Belle:
> > Hai Stefan,
> >
> > Yes, its always better to ask the list, that way everybody can
> > learn from it. ;-)
> >
> >> Do you think I will have to rejoin it to the domain?
> > No
2020 Feb 24
3
Windows ACLs : problems
Status:
domain member server, Samba version 4.10.11-Debian
[global]
dedicated keytab file = /etc/krb5.keytab
domain master = No
kerberos method = secrets and keytab
load printers = No
local master = No
preferred master = No
printcap name = /dev/null
realm = customer.INTRA
security = ADS
template homedir = /mnt/MSA2040/smb/Homes/%D/%U
unix charset = iso8859-15
unix extensions = No
2023 Feb 13
1
access "claim types"
On 13/02/2023 13:04, Stefan G. Weichinger via samba wrote:
> I am a bit confused right now (maybe always): you told me "Administrator
> shouldn't own anything on Unix"
From the Unix end, you should never find Administrator owning anything.
This is because, as my example showed. as a Unix use, Administrator is
just a normal, unprivileged user e.g. my example Unix
2023 Feb 13
1
access "claim types"
Am 13.02.23 um 12:14 schrieb Rowland Penny via samba:
>> # ls -n
>> insgesamt 24
>> drwxrwxr-x+ 4 0 10512 4096? 9. Dez 20:43 Test1
>> drwxrwxr-x+ 2 0 10512 4096? 9. Dez 20:41 test2
>> drwxrwxr-x+ 2 0 10512 4096? 9. Dez 20:41 test3
>>
>> gid 10512 should be "domain admins" or in this case german
>> "dom?nen-admins" with an ugly
2018 May 30
2
DM 3.6.25 -> 4.x
On Wed, 30 May 2018 15:26:37 +0200
"Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
> Am 2018-05-30 um 15:01 schrieb Rowland Penny via samba:
>
> > There are three main winbind backends, but only two are really used
> > on Unix domain members, the 'ad' and the 'rid' backends. Which you
> > use is really down to a simple
2018 Jun 30
2
DM 3.6.25 -> 4.x
That domain member server worked fine for about 2 weeks until today.
Somehow the DNS-record didn't work anymore, I did a rejoin and added
some kerberos-related lines to smb.conf
# 2 lines old
winbind cache time = 10
winbind use default domain = yes
# new lines
dedicated keytab file = /etc/krb5.keytab
kerberos method = secrets and keytab
winbind refresh tickets = Yes
created keytab,
2024 Sep 17
0
vfs_recycle missing deleted file?
Hi,
With smb.conf having full_audit and recycle, today I saw:
Sep 17 10:48:49 kantoor smbd_audit[2317861]:
hannah|192.168.1.26|ashare|unlinkat|ok|/home/ashare/Documents/20240917Workflow.ods
However, there's no /home/.recycle/hannah/Documents/ or any other hint
of 20240917Workflow.ods in her recycle directory. As there is a copy of
the last version of this file (in another users
2020 May 26
1
vfs_audit with Samba 4.12.3
Hello All,
now that the BUG 14343: (s3: vfs_full_audit: Add missing fcntl entry in
vfs_op_names[] array.) was fixed I wanted to try 4.12 again.
This is the relevant config which has been running for years:
vfs objects = acl_xattr full_audit shadow_copy2
full_audit:failure = none
full_audit:success = pwrite write rename unlink
full_audit:prefix = IP=%I|USER=%u|MACHINE=%m|VOLUME=%S
2018 Nov 09
2
"missing security tab" and related ACL issues
Am 11.09.18 um 10:06 schrieb Rowland Penny via samba:
> On Tue, 11 Sep 2018 09:54:32 +0200
> "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
>
>> Am 07.09.18 um 20:07 schrieb Rowland Penny via samba:
>>> On Fri, 7 Sep 2018 19:09:37 +0200
>>> "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote: