<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-13150</id>
	<title>Nabble - Samba</title>
	<updated>2009-12-20T09:34:48Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Samba-f13150.xml;http://www.thezreview.co.uk/posters/posterimages/images/icon_small_profile.gif;http://www.thezreview.co.uk/posters/posterimages/w/weddingcrashers4.jpg&quot" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-f13150.html" />
	<subtitle type="html">Samba is software that can be run on a platform other than Microsoft Windows, for example, UNIX, Linux, IBM System 390, OpenVMS, and other operating systems. Samba uses the TCP/IP protocol that is installed on the host server. When correctly configured, it allows that host to interact with a Microsoft Windows client or server as if it is a Windows file and print server. Samba home is &lt;a href=&quot;http://samba.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26865462</id>
	<title>Samba + Vscan</title>
	<published>2009-12-20T09:34:48Z</published>
	<updated>2009-12-20T09:34:48Z</updated>
	<author>
		<name>Bruno Steven</name>
	</author>
	<content type="html">Hi
&lt;br&gt;&lt;br&gt;I am trying install Samba-Vscan. When run *make* show this message
&lt;br&gt;&lt;br&gt;[root@LinuxDefault samba-vscan]# make --debug
&lt;br&gt;GNU Make 3.81
&lt;br&gt;Copyright (C) 2006 &amp;nbsp;Free Software Foundation, Inc.
&lt;br&gt;This is free software; see the source for copying conditions.
&lt;br&gt;There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
&lt;br&gt;PARTICULAR PURPOSE.
&lt;br&gt;&lt;br&gt;*This program built for i686-redhat-linux-gnu*
&lt;br&gt;*Reading makefiles...*
&lt;br&gt;*Updating goal targets....*
&lt;br&gt;* File `default' does not exist.*
&lt;br&gt;* &amp;nbsp; File `all' does not exist.*
&lt;br&gt;* &amp;nbsp; &amp;nbsp; File `oav' does not exist.*
&lt;br&gt;* &amp;nbsp; &amp;nbsp; &amp;nbsp; File `vscan-oav.so' does not exist.*
&lt;br&gt;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; File `global/vscan-message.po' does not exist.*
&lt;br&gt;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Must remake target `global/vscan-message.po'.*
&lt;br&gt;*Compiling global/vscan-message.c with -fPIC*
&lt;br&gt;*global/vscan-message.c: In function âvscan_send_warning_messageâ:*
&lt;br&gt;*global/vscan-message.c:82: error: too many arguments to function
&lt;br&gt;âcli_initialiseâ*
&lt;br&gt;*global/vscan-message.c:82: error: wrong type argument to unary exclamation
&lt;br&gt;mark*
&lt;br&gt;*make: *** [global/vscan-message.po] Error 1*
&lt;br&gt;&lt;br&gt;*Somebody know about this message error ? How I can resolve this problem ? *
&lt;br&gt;&lt;br&gt;*Plus information *
&lt;br&gt;&lt;br&gt;The process *configure * run without any problems
&lt;br&gt;&lt;br&gt;./configure --with-samba-souce=/opt/source/samba-3.0.34/source/
&lt;br&gt;--with-samba-version=/opt/source/samba-3.0.34/source/include/version.h
&lt;br&gt;checking for gcc... gcc
&lt;br&gt;checking for C compiler default output... a.out
&lt;br&gt;checking whether the C compiler works... yes
&lt;br&gt;checking whether we are cross compiling... no
&lt;br&gt;checking for suffix of executables...
&lt;br&gt;checking for suffix of object files... o
&lt;br&gt;checking whether we are using the GNU C compiler... yes
&lt;br&gt;checking whether gcc accepts -g... yes
&lt;br&gt;checking for a BSD-compatible install... /usr/bin/install -c
&lt;br&gt;checking for library containing strerror... none required
&lt;br&gt;checking whether gcc and cc understand -c and -o together... yes
&lt;br&gt;checking build system type... i686-pc-linux-gnu
&lt;br&gt;checking host system type... i686-pc-linux-gnu
&lt;br&gt;checking target system type... i686-pc-linux-gnu
&lt;br&gt;checking config.cache system type... same
&lt;br&gt;checking how to run the C preprocessor... gcc -E
&lt;br&gt;checking for ANSI C header files... yes
&lt;br&gt;checking for sys/types.h... yes
&lt;br&gt;checking for sys/stat.h... yes
&lt;br&gt;checking for stdlib.h... yes
&lt;br&gt;checking for string.h... yes
&lt;br&gt;checking for memory.h... yes
&lt;br&gt;checking for strings.h... yes
&lt;br&gt;checking for inttypes.h... yes
&lt;br&gt;checking for stdint.h... yes
&lt;br&gt;checking for unistd.h... yes
&lt;br&gt;checking stdio.h usability... yes
&lt;br&gt;checking stdio.h presence... yes
&lt;br&gt;checking for stdio.h... yes
&lt;br&gt;checking for inet_aton... yes
&lt;br&gt;checking ability to build shared libraries... true
&lt;br&gt;checking linker flags for shared libraries... -shared
&lt;br&gt;checking compiler flags for position-independent code... -fPIC
&lt;br&gt;checking for suffix of position-independent code... po
&lt;br&gt;checking whether building shared libraries actually works... yes
&lt;br&gt;checking for Samba Version... &amp;quot;3.0.34&amp;quot;
&lt;br&gt;configure: WARNING: you specified
&lt;br&gt;--with-samba-version=&amp;quot;/opt/source/samba-3.0.34/source/include/version.h&amp;quot;
&lt;br&gt;configure: WARNING: this will have no effect because the used
&lt;br&gt;configure: WARNING: SAMBA Version &amp;quot;3.0.34&amp;quot; already
&lt;br&gt;configure: WARNING: includes the SAMBA_VERSION_{MAJOR,MINOR,RELEASE}
&lt;br&gt;define's
&lt;br&gt;checking whether to use libclamav... no
&lt;br&gt;checking whether use libmksd as builtin... auto
&lt;br&gt;checking libmksd.h usability... no
&lt;br&gt;checking libmksd.h presence... no
&lt;br&gt;checking for libmksd.h... no
&lt;br&gt;checking for mksd_connect in -lmksd... no
&lt;br&gt;checking whether to use libmksd as builtin or system... builtin
&lt;br&gt;checking whether use libkavdc as builtin... auto
&lt;br&gt;checking kavclient.h usability... no
&lt;br&gt;checking kavclient.h presence... no
&lt;br&gt;checking for kavclient.h... no
&lt;br&gt;checking for KAVConnect in -lkavdc... no
&lt;br&gt;checking for KAVConnect in /usr/lib/kavdclib.so... no
&lt;br&gt;checking whether to use libkavdc as builtin or system... builtin
&lt;br&gt;checking whether to build Symantec module... no
&lt;br&gt;checking whether to build only libmksd and libkavdc as shared libs... no
&lt;br&gt;checking for filetype support... auto
&lt;br&gt;checking magic.h usability... yes
&lt;br&gt;checking magic.h presence... yes
&lt;br&gt;checking for magic.h... yes
&lt;br&gt;checking for magic_load in -lmagic... yes
&lt;br&gt;checking whether to use filetype support... yes
&lt;br&gt;configure: creating ./config.status
&lt;br&gt;config.status: creating Makefile
&lt;br&gt;config.status: creating include/vscan-config.h
&lt;br&gt;&lt;br&gt;** Configuration summary for samba-vscan 0.3.6 :
&lt;br&gt;&lt;br&gt;&amp;nbsp;Compile samba-vscan for Samba &amp;nbsp; &amp;nbsp; &amp;nbsp;: &amp;quot;3.0.34&amp;quot;
&lt;br&gt;&amp;nbsp;Compile samba-vscan with sources in: ../../../source
&lt;br&gt;&amp;nbsp;Compile samba-vscan backends &amp;nbsp; &amp;nbsp; &amp;nbsp; : oav sophos fprotd fsav trend icap mksd
&lt;br&gt;kavp clamav nai antivir
&lt;br&gt;&amp;nbsp;Use GLOBAL_LIBS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: -lmagic
&lt;br&gt;&amp;nbsp;Use libmksd as &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : builtin
&lt;br&gt;&amp;nbsp;Use libkavdc as &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: builtin
&lt;br&gt;&lt;br&gt;Now type &amp;quot;make&amp;quot; to build all mentioned backends.
&lt;br&gt;Or &amp;quot;make &amp;lt;backend&amp;gt; {&amp;lt;backend&amp;gt;}&amp;quot; to build only specific backend(s).
&lt;br&gt;On *BSD systems please use GNU make (gmake) instead of BSD make (make).
&lt;br&gt;&lt;br&gt;Thanks for all .
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Bruno Steven - Administrador de sistemas.
&lt;br&gt;LPIC-1 - LPI ID: lpi000119659 / Code: p2e4wz47e4
&lt;br&gt;&lt;a href=&quot;https://www.lpi.org/caf/Xamman/certification&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.lpi.org/caf/Xamman/certification&lt;/a&gt;&lt;br&gt;&lt;br&gt;MCP-Windows 2003 - TranscriptID: 793804 / Access Code: 080089100
&lt;br&gt;&lt;a href=&quot;https://mcp.microsoft.com/authenticate/validatemcp.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://mcp.microsoft.com/authenticate/validatemcp.aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;P Antes de imprimir pense em sua responsabilidade e comprometimento com o
&lt;br&gt;Meio Ambiente. Before printing this message, think about your ecologic
&lt;br&gt;responsability and environment commitment.
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Vscan-tp26865462p26865462.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26865366</id>
	<title>Re: of SupportedEncTypes and msDS-SupportedEncryptionTypes</title>
	<published>2009-12-20T09:23:08Z</published>
	<updated>2009-12-20T09:23:08Z</updated>
	<author>
		<name>Tom Jebo</name>
	</author>
	<content type="html">Hi Matthieu, 
&lt;br&gt;&lt;br&gt;Thanks for the follow-up questions regarding the supported encryption types blog entry from September. &amp;nbsp;One of the Open Specification Documentation support team will be in touch with you shortly.
&lt;br&gt;&lt;br&gt;Best regards,
&lt;br&gt;Tom Jebo
&lt;br&gt;Microsoft Open Specification Documentation Support
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26865366&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;] 
&lt;br&gt;Sent: Sunday, December 20, 2009 7:01 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26865366&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26865366&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: of SupportedEncTypes and msDS-SupportedEncryptionTypes
&lt;br&gt;&lt;br&gt;Hello,
&lt;br&gt;&lt;br&gt;Back in august and september we discuss in case SRX090808600017 about supportedEncTypes and I was quite happy with your answer.
&lt;br&gt;&lt;br&gt;I'm coming back on this subject for two details:
&lt;br&gt;&lt;br&gt;* this blog entry (of msdn)
&lt;br&gt;&lt;a href=&quot;http://blogs.msdn.com/openspecification/archive/2009/09/12/msds-supportedencryptiontypes-episode-1-computer-accounts.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blogs.msdn.com/openspecification/archive/2009/09/12/msds-supportedencryptiontypes-episode-1-computer-accounts.aspx&lt;/a&gt;&lt;br&gt;says :&amp;quot; Although this attribute is present in all the computer objects of the domain regardless of the version of the OS the physical machines have installed, not all of them are aware of its existence hence, older versions (2003 and earlier) do not populate it at any time.&amp;quot; &amp;nbsp;It means that when I join a w2k8 domain with a XP workstation that the DC will create a computer object for this XP workstation and set the msDS-SupportedEncryptionTypes attribute ? if so to which value ? On my tests when I join a w2k3 server to a w2k8 domain the attribute SupportedEncryptionTypes is not set. Can this point be clarified and if possible written in a formal document
&lt;br&gt;&lt;br&gt;&lt;br&gt;This entry also state: &amp;quot;
&lt;br&gt;&lt;br&gt;When the KDC checks the attribute to decide what encryption algorithm to use in order to encrypt the ticket, it could find basically two scenarios:
&lt;br&gt;&lt;br&gt;1) &amp;nbsp; &amp;nbsp; &amp;nbsp;The attribute is populated
&lt;br&gt;&lt;br&gt;2) &amp;nbsp; &amp;nbsp; &amp;nbsp;The attribute is empty
&lt;br&gt;&lt;br&gt;If the attribute is populated, then the deal is done since the KDC can determine the best common algorithm to encrypt the ticket with the value present.
&lt;br&gt;&lt;br&gt;However, if the attribute is empty then the KDC will have to work harder being the next step to check another attribute. This attribute is defined in MS-ADA3 (section 2.341) and described in MS-ADTS (section
&lt;br&gt;2.2.15) and it's called userAccountControl. This attribute is also a 4 byte Bit Mask that defines many aspects of the account but the only one the KDC is interested in is the DK (ADS_UF_USE_DES_KEY_ONLY ) bit.
&lt;br&gt;&lt;br&gt;This bit defines what legacy encryption method will be used:
&lt;br&gt;&lt;br&gt;1) &amp;nbsp; &amp;nbsp; &amp;nbsp;If the bit is set, then only DES will be used
&lt;br&gt;&lt;br&gt;2) &amp;nbsp; &amp;nbsp; &amp;nbsp;If the bit is NOT set, then DES and RC4 can be used
&lt;br&gt;&lt;br&gt;This check is especially relevant in domains that have Win7 and Windows Server 2008 R2 machines joined because those two newer OSs disable their bit by default so older DES is not an option for them.&amp;quot;
&lt;br&gt;&lt;br&gt;* What is the exact meaning of ADS_UF_USE_DES_KEY_ONLY ? if a w2k8 server acting as a domain member within a w2k8 domain has this DK bit set, will the DC not use AES but only DES with it ?
&lt;br&gt;&lt;br&gt;* &amp;quot;This check is especially relevant in domains that have Win7 and Windows Server 2008 R2 machines joined because those two newer OSs disable their bit by default so older DES is not an option for them.&amp;quot;, well it seems that a w2k3 server member of w2k8 domain do not have this bit set also (userAccountControl=4096 =&amp;gt; only WT flag set).
&lt;br&gt;&lt;br&gt;* Also neither MS-LSAD nor MS-NRPC talk about the link between the attribute msDS-SupportedEncryptionTypes stored in the AD and the fact that it's returned as SupportedEncTypes in NETLOGON_DOMAIN_INFO &amp;nbsp;call.
&lt;br&gt;I can understand that it can be called &amp;quot;secret&amp;quot; of implementation but when after a workstation tries to update this attribute to let the DC know what are the supported encoding it's better to clarify the link.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thank you for help with clarifying those points.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26865366&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/of-SupportedEncTypes-and-msDS-SupportedEncryptionTypes-tp26862794p26865366.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26862800</id>
	<title>Re: Patch for supported encoding</title>
	<published>2009-12-20T04:03:04Z</published>
	<updated>2009-12-20T04:03:04Z</updated>
	<author>
		<name>Matthieu Patou-5</name>
	</author>
	<content type="html">On 19/12/2009 04:13, Andrew Bartlett wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Sat, 2009-12-19 at 01:05 +0300, Matthieu Patou wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; On 19/12/2009 00:05, Andrew Bartlett wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Sat, 2009-12-05 at 18:04 +0300, Matthieu Patou wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Please find attach a patch that try to reintroduced a good default value
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; for default encoding (my change was overwritten by tridge in september).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Can you give the commit it was overwritten by?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The next step is to honour this stuff in the KDC
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Andrew Bartlett
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; commit c94e3ff0
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; Given that, the only way to get your change back in is to have a torture
&lt;br&gt;&amp;gt; test that passes against Windows 2008R2, and to work with tridge to
&lt;br&gt;&amp;gt; determine the situation he originally needed this for. &amp;nbsp;The test should
&lt;br&gt;&amp;gt; handle the case before we set the supported encryption types, then
&lt;br&gt;&amp;gt; setting it and checking it changes from that value.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; These changes were made to get the bidirectional vampire code working,
&lt;br&gt;&amp;gt; so we should not revert things lightly.
&lt;/div&gt;Well after talking to tridge it's &amp;nbsp;like this that w2k8(r1/r2) answer so 
&lt;br&gt;we should stick to it. I'll ask a written confirmation from Microsoft as 
&lt;br&gt;the documentation is not very clear (well this point is missing) and I 
&lt;br&gt;made a different interpretation. &amp;nbsp;Sorry for the noise.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Patch-for-supported-encoding-tp26656371p26862800.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26862794</id>
	<title>of SupportedEncTypes and msDS-SupportedEncryptionTypes</title>
	<published>2009-12-20T04:01:26Z</published>
	<updated>2009-12-20T04:01:26Z</updated>
	<author>
		<name>Matthieu Patou-5</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;Back in august and september we discuss in case SRX090808600017 about 
&lt;br&gt;supportedEncTypes and I was quite happy with your answer.
&lt;br&gt;&lt;br&gt;I'm coming back on this subject for two details:
&lt;br&gt;&lt;br&gt;* this blog entry (of msdn) 
&lt;br&gt;&lt;a href=&quot;http://blogs.msdn.com/openspecification/archive/2009/09/12/msds-supportedencryptiontypes-episode-1-computer-accounts.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blogs.msdn.com/openspecification/archive/2009/09/12/msds-supportedencryptiontypes-episode-1-computer-accounts.aspx&lt;/a&gt;&amp;nbsp;
&lt;br&gt;says :&amp;quot; Although this attribute is present in all the computer objects 
&lt;br&gt;of the domain regardless of the version of the OS the physical machines 
&lt;br&gt;have installed, not all of them are aware of its existence hence, older 
&lt;br&gt;versions (2003 and earlier) do not populate it at any time.&amp;quot; &amp;nbsp;It means 
&lt;br&gt;that when I join a w2k8 domain with a XP workstation that the DC will 
&lt;br&gt;create a computer object for this XP workstation and set the 
&lt;br&gt;msDS-SupportedEncryptionTypes attribute ? if so to which value ? On my 
&lt;br&gt;tests when I join a w2k3 server to a w2k8 domain the attribute 
&lt;br&gt;SupportedEncryptionTypes is not set. Can this point be clarified and if 
&lt;br&gt;possible written in a formal document
&lt;br&gt;&lt;br&gt;&lt;br&gt;This entry also state: &amp;quot;
&lt;br&gt;&lt;br&gt;When the KDC checks the attribute to decide what encryption algorithm to 
&lt;br&gt;use in order to encrypt the ticket, it could find basically two scenarios:
&lt;br&gt;&lt;br&gt;1) &amp;nbsp; &amp;nbsp; &amp;nbsp;The attribute is populated
&lt;br&gt;&lt;br&gt;2) &amp;nbsp; &amp;nbsp; &amp;nbsp;The attribute is empty
&lt;br&gt;&lt;br&gt;If the attribute is populated, then the deal is done since the KDC can 
&lt;br&gt;determine the best common algorithm to encrypt the ticket with the value 
&lt;br&gt;present.
&lt;br&gt;&lt;br&gt;However, if the attribute is empty then the KDC will have to work harder 
&lt;br&gt;being the next step to check another attribute. This attribute is 
&lt;br&gt;defined in MS-ADA3 (section 2.341) and described in MS-ADTS (section 
&lt;br&gt;2.2.15) and it’s called userAccountControl. This attribute is also a 4 
&lt;br&gt;byte Bit Mask that defines many aspects of the account but the only one 
&lt;br&gt;the KDC is interested in is the DK (ADS_UF_USE_DES_KEY_ONLY ) bit.
&lt;br&gt;&lt;br&gt;This bit defines what legacy encryption method will be used:
&lt;br&gt;&lt;br&gt;1) &amp;nbsp; &amp;nbsp; &amp;nbsp;If the bit is set, then only DES will be used
&lt;br&gt;&lt;br&gt;2) &amp;nbsp; &amp;nbsp; &amp;nbsp;If the bit is NOT set, then DES and RC4 can be used
&lt;br&gt;&lt;br&gt;This check is especially relevant in domains that have Win7 and Windows 
&lt;br&gt;Server 2008 R2 machines joined because those two newer OSs disable their 
&lt;br&gt;bit by default so older DES is not an option for them.&amp;quot;
&lt;br&gt;&lt;br&gt;* What is the exact meaning of ADS_UF_USE_DES_KEY_ONLY ? if a w2k8 
&lt;br&gt;server acting as a domain member within a w2k8 domain has this DK bit 
&lt;br&gt;set, will the DC not use AES but only DES with it ?
&lt;br&gt;&lt;br&gt;* &amp;quot;This check is especially relevant in domains that have Win7 and 
&lt;br&gt;Windows Server 2008 R2 machines joined because those two newer OSs 
&lt;br&gt;disable their bit by default so older DES is not an option for them.&amp;quot;, 
&lt;br&gt;well it seems that a w2k3 server member of w2k8 domain do not have this 
&lt;br&gt;bit set also (userAccountControl=4096 =&amp;gt; only WT flag set).
&lt;br&gt;&lt;br&gt;* Also neither MS-LSAD nor MS-NRPC talk about the link between the 
&lt;br&gt;attribute msDS-SupportedEncryptionTypes stored in the AD and the fact 
&lt;br&gt;that it's returned as SupportedEncTypes in NETLOGON_DOMAIN_INFO &amp;nbsp;call.
&lt;br&gt;I can understand that it can be called &amp;quot;secret&amp;quot; of implementation but 
&lt;br&gt;when after a workstation tries to update this attribute to let the DC 
&lt;br&gt;know what are the supported encoding it's better to clarify the link.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thank you for help with clarifying those points.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862794&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/of-SupportedEncTypes-and-msDS-SupportedEncryptionTypes-tp26862794p26862794.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26862116</id>
	<title>Re: Samba + Cups 2200 Laserjet printer</title>
	<published>2009-12-20T02:00:50Z</published>
	<updated>2009-12-20T02:00:50Z</updated>
	<author>
		<name>Scott Marshall-3</name>
	</author>
	<content type="html">Well, i think its time for me to go back to server 08.
&lt;br&gt;&lt;br&gt;Just got another issue with my backup batch script. It cant seem to check if
&lt;br&gt;the files have changed it just copies them all across on each boot.
&lt;br&gt;&lt;br&gt;Cheers for the help though, much appreciated.
&lt;br&gt;&lt;br&gt;On Sun, Dec 20, 2009 at 10:23 PM, Scott Marshall &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862116&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;s.dwag.nz@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; When i go to &lt;a href=&quot;http://192.168.1.1:631/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://192.168.1.1:631/&lt;/a&gt;&amp;nbsp;i get a 403. Any idea's?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Ive changed the localhost to the ip of the server (.1 as above).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Sun, Dec 20, 2009 at 10:03 PM, Scott Marshall &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862116&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;s.dwag.nz@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sorry about that, used gmal's reply without thinking.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Sun, Dec 20, 2009 at 8:42 PM, Jack Downes &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862116&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; First off, please reply to the list.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Okay, so you'll need to make sure that your cups.conf is setup to not
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; listen only to localhost. &amp;nbsp;you'll several sections on making cups listen
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; to what port and which IP... you'll see &amp;quot;Listen localhost:631&amp;quot; near the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; top of your cups.conf file which is in /etc/cups (on several distros
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; anyway), edit that to match your IP. &amp;nbsp;Cups.org has tons of info how to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; do this.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; As to the groups and such that I'm talking about...
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Here's what i have setup for our outfit:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; [printers]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;comment = Cupsys based printer
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;path = /var/spool/samba
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;create mask = 0700
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;guest ok = Yes
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;printable = Yes
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;browseable = No
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; [print$]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;comment = Printer Drivers
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;path = /var/lib/samba/KRH_drivers
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;valid users = @wheel, jax, admincis
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;force user = nobody
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;force group = nogroup
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;read only = No
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; So, as you can see, I've got it set so that anyone can print, but that
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; only admins and myself can update/change drivers. &amp;nbsp;Makes it easy and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; keeps the general users away from the drivers.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I'd suggest you put a valid users = scott in your [printers] section and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; make sure that your windows username/password matches the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; username/password in your linux setup. &amp;nbsp;Make sure that you create the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; same user with smbpasswd as well. you can sync those together pretty
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; easily. &amp;nbsp;I'm pretty sure you can also limit by IP if you like:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; hosts deny = 10.17.1.0/24, 10.6.27.5
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; or whatever ... &amp;nbsp;Hopefully this helps.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Jack
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Scott Marshall wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; I tried the address you stated (editing it where needed). It didnt
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; seem to work for me.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; Is there some thing i should be doing to activate/get this address to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; work?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; As for samba, the printer is under the right group and i have
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; installed the drivers manually on the machines yet i still cannot
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; print.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; Cheers for the help
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; Scott
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; On Sun, Dec 20, 2009 at 7:23 AM, Jack Downes &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862116&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26862116&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; So, unless you are using windows 2k or older, is there really a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; point to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; installing the printer via //server/hplj2200 ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Just use the windows[XP|Vista|7] printer wizard dialog and add a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; network
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; printer. &amp;nbsp;At that point you can use the url which if the name is
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; same, would be &lt;a href=&quot;http://server:631/printers/hplj2200&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://server:631/printers/hplj2200&lt;/a&gt;. &amp;nbsp;If you are
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; the only
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; one doing this, then it'll be fine. &amp;nbsp;You'll need to have the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; drivers
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; handy though. &amp;nbsp;And you can lock CUPS down via client IP, or client
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; username, or it can depend on SAMBA auth as well.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; If you still want to use SAMBA for printing, take a look at
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; groups. &amp;nbsp;As
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; I recall you can specify which users &amp; which groups can
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; read/write/see/whatever the printer much the same as you can for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; regular
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; shares. &amp;nbsp;I think there's a PrinterAdmins group that you'll need to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; setup
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; if you want to push a driver to the printer.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Good luck!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Jack
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Scott Marshall wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hi all,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hoping some one can help me out here.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have a 2200dn laser printer working on a centos 5 server
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; (using webmin for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; configuration).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have added it via webmin as a samba printer share with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; permissions to my
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; account.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Security is set to &amp;quot;user level&amp;quot; not &amp;quot;share level&amp;quot; (the default).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can access my samba shares fine, download and upload to them.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can also see the printer, but what i cannot do is print.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; When i try and add the printer via my general PCL5 drivers it
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; asks me for a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; username and password. I am currently logged into the computer
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; so i would of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; thought it didn't need it and i cannot enter in the username or
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; password
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; because i am already logged in.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I cannot figure out if it is possible to have the samba server
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; share my
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; printer by default to everyone with any security level yet not
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; open up my
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; shares to everyone.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Cheers
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Scott
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Cups-2200-Laserjet-printer-tp26856160p26862116.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26861926</id>
	<title>Re: Samba + Cups 2200 Laserjet printer</title>
	<published>2009-12-20T01:23:09Z</published>
	<updated>2009-12-20T01:23:09Z</updated>
	<author>
		<name>Scott Marshall-3</name>
	</author>
	<content type="html">When i go to &lt;a href=&quot;http://192.168.1.1:631/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://192.168.1.1:631/&lt;/a&gt;&amp;nbsp;i get a 403. Any idea's?
&lt;br&gt;&lt;br&gt;Ive changed the localhost to the ip of the server (.1 as above).
&lt;br&gt;&lt;br&gt;On Sun, Dec 20, 2009 at 10:03 PM, Scott Marshall &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861926&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;s.dwag.nz@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Sorry about that, used gmal's reply without thinking.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Sun, Dec 20, 2009 at 8:42 PM, Jack Downes &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861926&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; First off, please reply to the list.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Okay, so you'll need to make sure that your cups.conf is setup to not
&lt;br&gt;&amp;gt;&amp;gt; listen only to localhost. &amp;nbsp;you'll several sections on making cups listen
&lt;br&gt;&amp;gt;&amp;gt; to what port and which IP... you'll see &amp;quot;Listen localhost:631&amp;quot; near the
&lt;br&gt;&amp;gt;&amp;gt; top of your cups.conf file which is in /etc/cups (on several distros
&lt;br&gt;&amp;gt;&amp;gt; anyway), edit that to match your IP. &amp;nbsp;Cups.org has tons of info how to
&lt;br&gt;&amp;gt;&amp;gt; do this.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; As to the groups and such that I'm talking about...
&lt;br&gt;&amp;gt;&amp;gt; Here's what i have setup for our outfit:
&lt;br&gt;&amp;gt;&amp;gt; [printers]
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;comment = Cupsys based printer
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;path = /var/spool/samba
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;create mask = 0700
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;guest ok = Yes
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;printable = Yes
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;browseable = No
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; [print$]
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;comment = Printer Drivers
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;path = /var/lib/samba/KRH_drivers
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;valid users = @wheel, jax, admincis
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;force user = nobody
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;force group = nogroup
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;read only = No
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; So, as you can see, I've got it set so that anyone can print, but that
&lt;br&gt;&amp;gt;&amp;gt; only admins and myself can update/change drivers. &amp;nbsp;Makes it easy and
&lt;br&gt;&amp;gt;&amp;gt; keeps the general users away from the drivers.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'd suggest you put a valid users = scott in your [printers] section and
&lt;br&gt;&amp;gt;&amp;gt; make sure that your windows username/password matches the
&lt;br&gt;&amp;gt;&amp;gt; username/password in your linux setup. &amp;nbsp;Make sure that you create the
&lt;br&gt;&amp;gt;&amp;gt; same user with smbpasswd as well. you can sync those together pretty
&lt;br&gt;&amp;gt;&amp;gt; easily. &amp;nbsp;I'm pretty sure you can also limit by IP if you like:
&lt;br&gt;&amp;gt;&amp;gt; hosts deny = 10.17.1.0/24, 10.6.27.5
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; or whatever ... &amp;nbsp;Hopefully this helps.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Jack
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Scott Marshall wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; I tried the address you stated (editing it where needed). It didnt
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; seem to work for me.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; Is there some thing i should be doing to activate/get this address to
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; work?
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; As for samba, the printer is under the right group and i have
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; installed the drivers manually on the machines yet i still cannot print.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; Cheers for the help
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; Scott
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; On Sun, Dec 20, 2009 at 7:23 AM, Jack Downes &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861926&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861926&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; So, unless you are using windows 2k or older, is there really a
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; point to
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; installing the printer via //server/hplj2200 ?
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Just use the windows[XP|Vista|7] printer wizard dialog and add a
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; network
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; printer. &amp;nbsp;At that point you can use the url which if the name is the
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; same, would be &lt;a href=&quot;http://server:631/printers/hplj2200&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://server:631/printers/hplj2200&lt;/a&gt;. &amp;nbsp;If you are
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; the only
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; one doing this, then it'll be fine. &amp;nbsp;You'll need to have the drivers
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; handy though. &amp;nbsp;And you can lock CUPS down via client IP, or client
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; username, or it can depend on SAMBA auth as well.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; If you still want to use SAMBA for printing, take a look at
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; groups. &amp;nbsp;As
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; I recall you can specify which users &amp; which groups can
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; read/write/see/whatever the printer much the same as you can for
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; regular
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; shares. &amp;nbsp;I think there's a PrinterAdmins group that you'll need to
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; setup
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; if you want to push a driver to the printer.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Good luck!
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Jack
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Scott Marshall wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hi all,
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hoping some one can help me out here.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have a 2200dn laser printer working on a centos 5 server
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; (using webmin for
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; configuration).
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have added it via webmin as a samba printer share with
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; permissions to my
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; account.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Security is set to &amp;quot;user level&amp;quot; not &amp;quot;share level&amp;quot; (the default).
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can access my samba shares fine, download and upload to them.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can also see the printer, but what i cannot do is print.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; When i try and add the printer via my general PCL5 drivers it
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; asks me for a
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; username and password. I am currently logged into the computer
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; so i would of
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; thought it didn't need it and i cannot enter in the username or
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; password
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; because i am already logged in.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I cannot figure out if it is possible to have the samba server
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; share my
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; printer by default to everyone with any security level yet not
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; open up my
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; shares to everyone.
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Cheers
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Scott
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; --
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt;&amp;gt; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Cups-2200-Laserjet-printer-tp26856160p26861926.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26861568</id>
	<title>Re: Samba + Cups 2200 Laserjet printer</title>
	<published>2009-12-19T23:42:17Z</published>
	<updated>2009-12-19T23:42:17Z</updated>
	<author>
		<name>Jack Downes-2</name>
	</author>
	<content type="html">First off, please reply to the list.
&lt;br&gt;&lt;br&gt;Okay, so you'll need to make sure that your cups.conf is setup to not
&lt;br&gt;listen only to localhost. &amp;nbsp;you'll several sections on making cups listen
&lt;br&gt;to what port and which IP... you'll see &amp;quot;Listen localhost:631&amp;quot; near the
&lt;br&gt;top of your cups.conf file which is in /etc/cups (on several distros
&lt;br&gt;anyway), edit that to match your IP. &amp;nbsp;Cups.org has tons of info how to
&lt;br&gt;do this.
&lt;br&gt;&lt;br&gt;As to the groups and such that I'm talking about...
&lt;br&gt;Here's what i have setup for our outfit:
&lt;br&gt;[printers]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = Cupsys based printer
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; path = /var/spool/samba
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; create mask = 0700
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; guest ok = Yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; printable = Yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; browseable = No
&lt;br&gt;&lt;br&gt;[print$]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = Printer Drivers
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; path = /var/lib/samba/KRH_drivers
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; valid users = @wheel, jax, admincis
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; force user = nobody
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; force group = nogroup
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read only = No
&lt;br&gt;&lt;br&gt;So, as you can see, I've got it set so that anyone can print, but that
&lt;br&gt;only admins and myself can update/change drivers. &amp;nbsp;Makes it easy and
&lt;br&gt;keeps the general users away from the drivers. 
&lt;br&gt;&lt;br&gt;I'd suggest you put a valid users = scott in your [printers] section and
&lt;br&gt;make sure that your windows username/password matches the
&lt;br&gt;username/password in your linux setup. &amp;nbsp;Make sure that you create the
&lt;br&gt;same user with smbpasswd as well. you can sync those together pretty
&lt;br&gt;easily. &amp;nbsp;I'm pretty sure you can also limit by IP if you like:
&lt;br&gt;hosts deny = 10.17.1.0/24, 10.6.27.5
&lt;br&gt;&lt;br&gt;or whatever ... &amp;nbsp;Hopefully this helps.
&lt;br&gt;&lt;br&gt;Jack
&lt;br&gt;&lt;br&gt;Scott Marshall wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I tried the address you stated (editing it where needed). It didnt
&lt;br&gt;&amp;gt; seem to work for me.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Is there some thing i should be doing to activate/get this address to
&lt;br&gt;&amp;gt; work?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; As for samba, the printer is under the right group and i have
&lt;br&gt;&amp;gt; installed the drivers manually on the machines yet i still cannot print.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers for the help
&lt;br&gt;&amp;gt; Scott
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Sun, Dec 20, 2009 at 7:23 AM, Jack Downes &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861568&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861568&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jax@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; So, unless you are using windows 2k or older, is there really a
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; point to
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; installing the printer via //server/hplj2200 ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Just use the windows[XP|Vista|7] printer wizard dialog and add a
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; network
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; printer. &amp;nbsp;At that point you can use the url which if the name is the
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; same, would be &lt;a href=&quot;http://server:631/printers/hplj2200&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://server:631/printers/hplj2200&lt;/a&gt;. &amp;nbsp;If you are
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; the only
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; one doing this, then it'll be fine. &amp;nbsp;You'll need to have the drivers
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; handy though. &amp;nbsp;And you can lock CUPS down via client IP, or client
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; username, or it can depend on SAMBA auth as well.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; If you still want to use SAMBA for printing, take a look at
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; groups. &amp;nbsp;As
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I recall you can specify which users &amp; which groups can
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; read/write/see/whatever the printer much the same as you can for
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; regular
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; shares. &amp;nbsp;I think there's a PrinterAdmins group that you'll need to
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; setup
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; if you want to push a driver to the printer.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Good luck!
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Jack
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Scott Marshall wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hi all,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Hoping some one can help me out here.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have a 2200dn laser printer working on a centos 5 server
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; (using webmin for
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; configuration).
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I have added it via webmin as a samba printer share with
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; permissions to my
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; account.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Security is set to &amp;quot;user level&amp;quot; not &amp;quot;share level&amp;quot; (the default).
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can access my samba shares fine, download and upload to them.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I can also see the printer, but what i cannot do is print.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; When i try and add the printer via my general PCL5 drivers it
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; asks me for a
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; username and password. I am currently logged into the computer
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; so i would of
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; thought it didn't need it and i cannot enter in the username or
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; password
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; because i am already logged in.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; I cannot figure out if it is possible to have the samba server
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; share my
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; printer by default to everyone with any security level yet not
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; open up my
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; shares to everyone.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Cheers
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt; Scott
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; --
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Cups-2200-Laserjet-printer-tp26856160p26861568.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26861387</id>
	<title>RE: rsync hangs on big transfer Debian 5.0.3 pulling from WinXP SP3/Cygwin 1.5.25</title>
	<published>2009-12-19T22:42:51Z</published>
	<updated>2009-12-19T22:42:51Z</updated>
	<author>
		<name>David Christensen</name>
	</author>
	<content type="html">rsync:
&lt;br&gt;&lt;br&gt;I received three copies of my message from each of three lists. &amp;nbsp;If
&lt;br&gt;everyone else receives three copies, I apologize for the extraneous
&lt;br&gt;copies. &amp;nbsp;:-(
&lt;br&gt;&lt;br&gt;&lt;br&gt;Does anybody know why, and how to prevent such?
&lt;br&gt;&lt;br&gt;&lt;br&gt;TIA,
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Please use reply-all for most replies to avoid omitting the mailing list.
&lt;br&gt;To unsubscribe or change options: &lt;a href=&quot;https://lists.samba.org/mailman/listinfo/rsync&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/rsync&lt;/a&gt;&lt;br&gt;Before posting, read: &lt;a href=&quot;http://www.catb.org/~esr/faqs/smart-questions.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.catb.org/~esr/faqs/smart-questions.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---rsync-f13158.html&quot; embed=&quot;fixTarget[13158]&quot; target=&quot;_top&quot; &gt;Samba - rsync&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RE%3A-rsync-hangs-on-big-transfer-Debian-5.0.3-pulling-from-WinXP-SP3--Cygwin-1.5.25-tp26861183p26861387.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26861183</id>
	<title>RE: rsync hangs on big transfer Debian 5.0.3 pulling from WinXP SP3/ Cygwin 1.5.25</title>
	<published>2009-12-19T21:37:22Z</published>
	<updated>2009-12-19T21:37:22Z</updated>
	<author>
		<name>David Christensen</name>
	</author>
	<content type="html">Debian Users, Cygwin, &amp; Rsync:
&lt;br&gt;&lt;br&gt;I'm having trouble with rsync invoked on Debian 5.0.3 pulling files from
&lt;br&gt;Windows XP SP3/ Cygwin 1.5.25. &amp;nbsp;I posted to the Debian User and Cygwin
&lt;br&gt;mailing lists [1] and thought I was done two days ago, but I wasn't --
&lt;br&gt;after several hours of use of the Windows machine, rsync would again
&lt;br&gt;hang on Debian.
&lt;br&gt;&lt;br&gt;&lt;br&gt;To summarize, rsync pulls in perhaps 1,000 files from C:\Documents and
&lt;br&gt;Settings, and then hangs indefinitely.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Adding the --timeout parameter seemed to fix the problem last night, but
&lt;br&gt;it's back again tonight.
&lt;br&gt;&lt;br&gt;&lt;br&gt;I've tried adding ten levels of verboseness to rsync (-vvvvvvvvvv), but
&lt;br&gt;no additional information is produced beyond three (-vvv). &amp;nbsp;I don't see
&lt;br&gt;any clues in /var/log on either machine. &amp;nbsp;Are there any other means for
&lt;br&gt;giving visibility to what's going on, other than compiling a debugging
&lt;br&gt;version, running rsync in a debugger, etc.?
&lt;br&gt;&lt;br&gt;&lt;br&gt;A new cygcheck.txt and console session are attached.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Any suggestions?
&lt;br&gt;&lt;br&gt;&lt;br&gt;TIA,
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;&lt;br&gt;Ref:
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://lists.debian.org/debian-user/2009/12/msg00991.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.debian.org/debian-user/2009/12/msg00991.html&lt;/a&gt;&lt;br&gt;&lt;br /&gt;2009-12-19 20:52:19 dpchrist@a64x2deb ~/a64x2deb/tigerbackup/daily
&lt;br&gt;$ &amp;nbsp;/usr/bin/rsync -rt -vvv --stats --timeout=300 --delete --backup --backup-dir='/mnt/q/backup-old/holgerdanske.com/p43400e/cygdrive/c/documents_and_settings/' --delete-excluded --exclude='My Documents/accounts/' --exclude-from='/usr/local/share/perl/5.10.0/Dpchrist/Tigerbackup/winxp_Documents-and-Settings.exclude' &amp;nbsp; '&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861183&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Administrator@...&lt;/a&gt;:/cygdrive/c/documents_and_settings/' '/mnt/q/backup/holgerdanske.com/p43400e/cygdrive/c/documents_and_settings/' &amp;gt;rsync.out
&lt;br&gt;io timeout after 300 seconds -- exiting
&lt;br&gt;rsync error: timeout in data send/receive (code 30) at io.c(239) [receiver=3.0.3]
&lt;br&gt;rsync: connection unexpectedly closed (137 bytes received so far) [generator]
&lt;br&gt;rsync error: error in rsync protocol data stream (code 12) at io.c(635) [generator=3.0.3]
&lt;br&gt;&lt;br&gt;2009-12-19 21:03:02 dpchrist@a64x2deb ~/a64x2deb/tigerbackup/daily
&lt;br&gt;$ tail -n 20 rsync.out 
&lt;br&gt;recv_generator(dpchrist/My Documents/home/.cvsignore,17101)
&lt;br&gt;dpchrist/My Documents/home/.cvsignore is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/.signature-dc2008.txt,17102)
&lt;br&gt;dpchrist/My Documents/home/.signature-dc2008.txt is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/.signature-pe.txt,17103)
&lt;br&gt;dpchrist/My Documents/home/.signature-pe.txt is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/.signature.txt,17104)
&lt;br&gt;dpchrist/My Documents/home/.signature.txt is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/.vimrc,17105)
&lt;br&gt;dpchrist/My Documents/home/.vimrc is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/Makefile,17106)
&lt;br&gt;dpchrist/My Documents/home/Makefile is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/home-unix.tar.gz,17107)
&lt;br&gt;dpchrist/My Documents/home/home-unix.tar.gz is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/home-win32.tar.gz,17108)
&lt;br&gt;dpchrist/My Documents/home/home-win32.tar.gz is uptodate
&lt;br&gt;recv_generator(dpchrist/My Documents/home/CVS,17109)
&lt;br&gt;recv_generator(dpchrist/My Documents/home/home.tmp,17110)
&lt;br&gt;_exit_cleanup(code=30, file=io.c, line=239): about to call exit(30)
&lt;br&gt;_exit_cleanup(code=12, file=io.c, line=635): about to call exit(12)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt;&lt;br&gt;Cygwin Configuration Diagnostics
&lt;br&gt;Current System Time: Sun Dec 20 05:13:08 2009
&lt;br&gt;&lt;br&gt;Windows XP Professional Ver 5.1 Build 2600 Service Pack 3
&lt;br&gt;&lt;br&gt;Path:	C:\cygwin\usr\local\bin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:\cygwin\bin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:\cygwin\bin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:\cygwin\usr\X11R6\bin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; c:\WINDOWS\system32
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; c:\WINDOWS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; c:\WINDOWS\System32\Wbem
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:\cygwin\bin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:\cygwin\usr\sbin
&lt;br&gt;&lt;br&gt;Output from C:\cygwin\bin\id.exe (nontsec)
&lt;br&gt;UID: 500(Administrator) GID: 513(None)
&lt;br&gt;0(root) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 513(None) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 544(Administrators)
&lt;br&gt;545(Users) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1006(Debugger Users)
&lt;br&gt;&lt;br&gt;Output from C:\cygwin\bin\id.exe (ntsec)
&lt;br&gt;UID: 500(Administrator) GID: 513(None)
&lt;br&gt;0(root) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 513(None) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 544(Administrators)
&lt;br&gt;545(Users) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1006(Debugger Users)
&lt;br&gt;&lt;br&gt;SysDir: C:\WINDOWS\system32
&lt;br&gt;WinDir: C:\WINDOWS
&lt;br&gt;&lt;br&gt;USER = 'Administrator'
&lt;br&gt;PWD = '/home/Administrator'
&lt;br&gt;CYGWIN = 'ntsec'
&lt;br&gt;HOME = '/home/Administrator'
&lt;br&gt;MAKE_MODE = 'unix'
&lt;br&gt;&lt;br&gt;HOMEPATH = '\Documents and Settings\Administrator\My Documents'
&lt;br&gt;CPAN_AUTHORID = 'DPCHRIST'
&lt;br&gt;MANPATH = ':/home/Administrator/local/man'
&lt;br&gt;HOSTNAME = 'p43400e'
&lt;br&gt;RELEASE_ROOT = '/mnt/z/data/released'
&lt;br&gt;TERM = 'cygwin'
&lt;br&gt;SHELL = '/bin/bash'
&lt;br&gt;PROCESSOR_IDENTIFIER = 'x86 Family 15 Model 4 Stepping 1, GenuineIntel'
&lt;br&gt;WINDIR = 'C:\WINDOWS'
&lt;br&gt;SSH_CLIENT = '127.0.0.1 1163 22'
&lt;br&gt;CVSROOT = '&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26861183&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dpchrist@...&lt;/a&gt;:/cvs/dpchrist'
&lt;br&gt;OLDPWD = '/home/Administrator'
&lt;br&gt;USERDOMAIN = 'P43400E'
&lt;br&gt;SSH_TTY = '/dev/tty0'
&lt;br&gt;OS = 'Windows_NT'
&lt;br&gt;ALLUSERSPROFILE = 'C:\Documents and Settings\All Users'
&lt;br&gt;TEMP = '/cygdrive/c/WINDOWS/TEMP'
&lt;br&gt;COMMONPROGRAMFILES = 'C:\Program Files\Common Files'
&lt;br&gt;PAGER = '/usr/bin/less'
&lt;br&gt;PROCESSOR_LEVEL = '15'
&lt;br&gt;FTP_PASSIVE = '1'
&lt;br&gt;MAIL = '/var/spool/mail/Administrator'
&lt;br&gt;SYSTEMDRIVE = 'C:'
&lt;br&gt;EDITOR = 'vim'
&lt;br&gt;LANG = 'C'
&lt;br&gt;USERPROFILE = 'C:\Documents and Settings\Administrator'
&lt;br&gt;TZ = 'America/Los_Angeles'
&lt;br&gt;PS1 = '\D{%Y-%m-%d %H:%M:%S} \u@\h \w\n\$ '
&lt;br&gt;LOGONSERVER = '\\P43400E'
&lt;br&gt;PROCESSOR_ARCHITECTURE = 'x86'
&lt;br&gt;HISTCONTROL = 'ignoredups'
&lt;br&gt;SHLVL = '1'
&lt;br&gt;OSTYPE = 'cygwin'
&lt;br&gt;PATHEXT = '.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH'
&lt;br&gt;HOMEDRIVE = 'c:'
&lt;br&gt;COMSPEC = 'C:\WINDOWS\system32\cmd.exe'
&lt;br&gt;LESS = '-R'
&lt;br&gt;LOGNAME = 'Administrator'
&lt;br&gt;TMP = '/cygdrive/c/WINDOWS/TEMP'
&lt;br&gt;SYSTEMROOT = 'C:\WINDOWS'
&lt;br&gt;PRINTER = 'HP LaserJet P2050 Series PCL6'
&lt;br&gt;CVS_RSH = 'ssh'
&lt;br&gt;PROCESSOR_REVISION = '0401'
&lt;br&gt;SSH_CONNECTION = '127.0.0.1 1163 127.0.0.1 22'
&lt;br&gt;INFOPATH = '/usr/local/info:/usr/share/info:/usr/info:'
&lt;br&gt;PROGRAMFILES = 'C:\Program Files'
&lt;br&gt;NUMBER_OF_PROCESSORS = '2'
&lt;br&gt;COMPUTERNAME = 'P43400E'
&lt;br&gt;_ = '/usr/bin/cygcheck'
&lt;br&gt;&lt;br&gt;HKEY_CURRENT_USER\Software\Cygnus Solutions
&lt;br&gt;HKEY_CURRENT_USER\Software\Cygnus Solutions\Cygwin
&lt;br&gt;HKEY_CURRENT_USER\Software\Cygnus Solutions\Cygwin\mounts v2
&lt;br&gt;HKEY_CURRENT_USER\Software\Cygnus Solutions\Cygwin\Program Options
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2
&lt;br&gt;&amp;nbsp; (default) = '/cygdrive'
&lt;br&gt;&amp;nbsp; cygdrive flags = 0x00000022
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2\/
&lt;br&gt;&amp;nbsp; (default) = 'C:\cygwin'
&lt;br&gt;&amp;nbsp; flags = 0x0000000a
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2\/usr/bin
&lt;br&gt;&amp;nbsp; (default) = 'C:\cygwin/bin'
&lt;br&gt;&amp;nbsp; flags = 0x0000000a
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2\/usr/lib
&lt;br&gt;&amp;nbsp; (default) = 'C:\cygwin/lib'
&lt;br&gt;&amp;nbsp; flags = 0x0000000a
&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Cygnus Solutions\Cygwin\Program Options
&lt;br&gt;&lt;br&gt;a: &amp;nbsp;fd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;c: &amp;nbsp;hd &amp;nbsp;NTFS &amp;nbsp; &amp;nbsp; 76316Mb &amp;nbsp;31% CP CS UN PA FC &amp;nbsp; &amp;nbsp; p43400e
&lt;br&gt;d: &amp;nbsp;cd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;C:\cygwin &amp;nbsp; &amp;nbsp; &amp;nbsp;/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;system &amp;nbsp;binmode
&lt;br&gt;C:\cygwin/bin &amp;nbsp;/usr/bin &amp;nbsp; system &amp;nbsp;binmode
&lt;br&gt;C:\cygwin/lib &amp;nbsp;/usr/lib &amp;nbsp; system &amp;nbsp;binmode
&lt;br&gt;. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/cygdrive &amp;nbsp;system &amp;nbsp;binmode,cygdrive
&lt;br&gt;&lt;br&gt;Found: C:\cygwin\bin\awk.exe
&lt;br&gt;Found: C:\cygwin\bin\bash.exe
&lt;br&gt;Found: C:\cygwin\bin\cat.exe
&lt;br&gt;Found: C:\cygwin\bin\cp.exe
&lt;br&gt;Not Found: cpp (good!)
&lt;br&gt;Not Found: crontab
&lt;br&gt;Found: C:\cygwin\bin\find.exe
&lt;br&gt;Not Found: gcc
&lt;br&gt;Not Found: gdb
&lt;br&gt;Found: C:\cygwin\bin\grep.exe
&lt;br&gt;Found: C:\cygwin\bin\kill.exe
&lt;br&gt;Not Found: ld
&lt;br&gt;Found: C:\cygwin\bin\ls.exe
&lt;br&gt;Found: C:\cygwin\bin\make.exe
&lt;br&gt;Found: C:\cygwin\bin\mv.exe
&lt;br&gt;Not Found: patch
&lt;br&gt;Found: C:\cygwin\bin\perl.exe
&lt;br&gt;Found: C:\cygwin\bin\rm.exe
&lt;br&gt;Found: C:\cygwin\bin\sed.exe
&lt;br&gt;Found: C:\cygwin\bin\ssh.exe
&lt;br&gt;Found: C:\cygwin\bin\sh.exe
&lt;br&gt;Found: C:\cygwin\bin\tar.exe
&lt;br&gt;Found: C:\cygwin\bin\test.exe
&lt;br&gt;Not Found: vi
&lt;br&gt;Found: C:\cygwin\bin\vim.exe
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;61k 2009/03/02 C:\cygwin\bin\cygbz2-1.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygbz2-1.dll&amp;quot; v0.0 ts=2009/3/2 2:52
&lt;br&gt;&amp;nbsp; &amp;nbsp; 7k 2003/10/19 C:\cygwin\bin\cygcrypt-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygcrypt-0.dll&amp;quot; v0.0 ts=2003/10/19 8:57
&lt;br&gt;&amp;nbsp;1075k 2009/11/05 C:\cygwin\bin\cygcrypto-0.9.8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygcrypto-0.9.8.dll&amp;quot; v0.0 ts=2009/11/5 17:46
&lt;br&gt;&amp;nbsp; 943k 2007/12/17 C:\cygwin\bin\cygdb-4.5.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygdb-4.5.dll&amp;quot; v0.0 ts=2007/12/17 13:12
&lt;br&gt;&amp;nbsp;1296k 2007/12/17 C:\cygwin\bin\cygdb_cxx-4.5.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygdb_cxx-4.5.dll&amp;quot; v0.0 ts=2007/12/17 13:12
&lt;br&gt;&amp;nbsp; 118k 2008/05/09 C:\cygwin\bin\cygexpat-1.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygexpat-1.dll&amp;quot; v0.0 ts=2008/5/9 5:03
&lt;br&gt;&amp;nbsp; &amp;nbsp;40k 2009/03/01 C:\cygwin\bin\cygform-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygform-8.dll&amp;quot; v0.0 ts=2009/3/1 2:40
&lt;br&gt;&amp;nbsp; &amp;nbsp;42k 2009/11/21 C:\cygwin\bin\cygform-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygform-9.dll&amp;quot; v0.0 ts=2009/11/21 5:34
&lt;br&gt;&amp;nbsp; &amp;nbsp;42k 2009/03/12 C:\cygwin\bin\cyggcc_s-1.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cyggcc_s-1.dll&amp;quot; v0.0 ts=2009/3/6 11:54
&lt;br&gt;&amp;nbsp; &amp;nbsp;19k 2009/02/26 C:\cygwin\bin\cyggdbm-4.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cyggdbm-4.dll&amp;quot; v0.0 ts=2009/2/26 7:55
&lt;br&gt;&amp;nbsp; &amp;nbsp; 8k 2009/02/26 C:\cygwin\bin\cyggdbm_compat-4.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cyggdbm_compat-4.dll&amp;quot; v0.0 ts=2009/2/26 7:56
&lt;br&gt;&amp;nbsp; &amp;nbsp;24k 2009/06/23 C:\cygwin\bin\cyghistory6.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cyghistory6.dll&amp;quot; v0.0 ts=2009/6/23 13:20
&lt;br&gt;&amp;nbsp; 270k 2009/04/23 C:\cygwin\bin\cygicons-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygicons-0.dll&amp;quot; v0.0 ts=2009/4/23 3:25
&lt;br&gt;&amp;nbsp; 982k 2009/05/30 C:\cygwin\bin\cygiconv-2.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygiconv-2.dll&amp;quot; v0.0 ts=2009/5/30 19:38
&lt;br&gt;&amp;nbsp; 190k 2009/09/15 C:\cygwin\bin\cygidn-11.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygidn-11.dll&amp;quot; v0.0 ts=2009/9/8 12:17
&lt;br&gt;&amp;nbsp; &amp;nbsp;37k 2003/08/10 C:\cygwin\bin\cygintl-2.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygintl-2.dll&amp;quot; v0.0 ts=2003/8/10 22:50
&lt;br&gt;&amp;nbsp; &amp;nbsp;31k 2005/11/20 C:\cygwin\bin\cygintl-3.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygintl-3.dll&amp;quot; v0.0 ts=2005/11/20 2:04
&lt;br&gt;&amp;nbsp; &amp;nbsp;31k 2009/06/07 C:\cygwin\bin\cygintl-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygintl-8.dll&amp;quot; v0.0 ts=2009/6/7 22:42
&lt;br&gt;&amp;nbsp; &amp;nbsp;83k 2007/06/06 C:\cygwin\bin\cygmagic-1.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygmagic-1.dll&amp;quot; v0.0 ts=2007/6/6 11:41
&lt;br&gt;&amp;nbsp; &amp;nbsp;21k 2009/03/01 C:\cygwin\bin\cygmenu-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygmenu-8.dll&amp;quot; v0.0 ts=2009/3/1 2:38
&lt;br&gt;&amp;nbsp; &amp;nbsp;21k 2009/11/21 C:\cygwin\bin\cygmenu-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygmenu-9.dll&amp;quot; v0.0 ts=2009/11/21 5:33
&lt;br&gt;&amp;nbsp; &amp;nbsp;24k 2008/10/30 C:\cygwin\bin\cygminires.dll - os=4.0 img=1.2 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygminires.dll&amp;quot; v0.0 ts=2008/10/31 0:53
&lt;br&gt;&amp;nbsp; &amp;nbsp;66k 2009/03/01 C:\cygwin\bin\cygncurses++-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygncurses++-8.dll&amp;quot; v0.0 ts=2009/3/1 2:50
&lt;br&gt;&amp;nbsp; 335k 2009/11/21 C:\cygwin\bin\cygncurses++-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygncurses++-9.dll&amp;quot; v0.0 ts=2009/11/21 5:44
&lt;br&gt;&amp;nbsp; 237k 2009/03/01 C:\cygwin\bin\cygncurses-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygncurses-8.dll&amp;quot; v0.0 ts=2009/3/1 2:36
&lt;br&gt;&amp;nbsp; 190k 2009/11/21 C:\cygwin\bin\cygncurses-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygncurses-9.dll&amp;quot; v0.0 ts=2009/11/21 5:31
&lt;br&gt;&amp;nbsp; &amp;nbsp;11k 2009/03/01 C:\cygwin\bin\cygpanel-8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpanel-8.dll&amp;quot; v0.0 ts=2009/3/1 2:38
&lt;br&gt;&amp;nbsp; &amp;nbsp;11k 2009/11/21 C:\cygwin\bin\cygpanel-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpanel-9.dll&amp;quot; v0.0 ts=2009/11/21 5:32
&lt;br&gt;&amp;nbsp; 181k 2008/09/07 C:\cygwin\bin\cygpcre-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpcre-0.dll&amp;quot; v0.0 ts=2008/9/7 4:36
&lt;br&gt;&amp;nbsp; 302k 2008/09/07 C:\cygwin\bin\cygpcrecpp-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpcrecpp-0.dll&amp;quot; v0.0 ts=2008/9/7 4:36
&lt;br&gt;&amp;nbsp; &amp;nbsp; 7k 2008/09/07 C:\cygwin\bin\cygpcreposix-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpcreposix-0.dll&amp;quot; v0.0 ts=2008/9/7 4:36
&lt;br&gt;&amp;nbsp;1543k 2008/07/03 C:\cygwin\bin\cygperl5_10.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygperl5_10.dll&amp;quot; v0.0 ts=2008/6/30 17:06
&lt;br&gt;&amp;nbsp; &amp;nbsp;22k 2002/06/09 C:\cygwin\bin\cygpopt-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygpopt-0.dll&amp;quot; v0.0 ts=2002/6/9 6:45
&lt;br&gt;&amp;nbsp; 155k 2009/06/23 C:\cygwin\bin\cygreadline6.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygreadline6.dll&amp;quot; v0.0 ts=2009/6/23 13:20
&lt;br&gt;&amp;nbsp; 232k 2009/11/05 C:\cygwin\bin\cygssl-0.9.8.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygssl-0.9.8.dll&amp;quot; v0.0 ts=2009/11/5 17:46
&lt;br&gt;&amp;nbsp; &amp;nbsp;46k 2009/11/21 C:\cygwin\bin\cygtic-9.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygtic-9.dll&amp;quot; v0.0 ts=2009/11/21 5:31
&lt;br&gt;&amp;nbsp; &amp;nbsp;22k 2009/03/29 C:\cygwin\bin\cygwrap-0.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygwrap-0.dll&amp;quot; v0.0 ts=2009/3/29 7:09
&lt;br&gt;&amp;nbsp; &amp;nbsp;65k 2009/03/02 C:\cygwin\bin\cygz.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygz.dll&amp;quot; v0.0 ts=2009/3/2 1:19
&lt;br&gt;&amp;nbsp;1829k 2008/06/12 C:\cygwin\bin\cygwin1.dll - os=4.0 img=1.0 sys=4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;cygwin1.dll&amp;quot; v0.0 ts=2008/6/12 18:35
&lt;br&gt;&amp;nbsp; &amp;nbsp; Cygwin DLL version info:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL version: 1.5.25
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL epoch: 19
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL bad signal mask: 19005
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL old termios: 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL malloc env: 28
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; API major: 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; API minor: 156
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Shared data: 4
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DLL identifier: cygwin1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Mount registry: 2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygnus registry name: Cygnus Solutions
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygwin registry name: Cygwin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Program options name: Program Options
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygwin mount registry name: mounts v2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygdrive flags: cygdrive flags
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygdrive prefix: cygdrive prefix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cygdrive default prefix: 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Build date: Thu Jun 12 19:34:46 CEST 2008
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CVS tag: cr-0x5f1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Shared id: cygwin1S4
&lt;br&gt;&lt;br&gt;&lt;br&gt;Service &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : exim
&lt;br&gt;Display name &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Exim
&lt;br&gt;Description &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Mail Transfer Agent
&lt;br&gt;Current State &amp;nbsp; &amp;nbsp; &amp;nbsp; : Stopped
&lt;br&gt;Command &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /usr/bin/exim -bdf -q15m
&lt;br&gt;stdin path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: /dev/null
&lt;br&gt;stdout path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /var/log/exim/cygrunsrv_out.log
&lt;br&gt;stderr path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /var/log/exim/cygrunsrv_err.log
&lt;br&gt;Environment &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : CYGWIN=&amp;quot;ntsec notraverse&amp;quot; 
&lt;br&gt;Process Type &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Own Process
&lt;br&gt;Startup &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Automatic
&lt;br&gt;Dependencies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Tcpip
&lt;br&gt;Account &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : LocalSystem
&lt;br&gt;&lt;br&gt;Service &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : sshd
&lt;br&gt;Display name &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: CYGWIN sshd
&lt;br&gt;Current State &amp;nbsp; &amp;nbsp; &amp;nbsp; : Running
&lt;br&gt;Controls Accepted &amp;nbsp; : Stop
&lt;br&gt;Command &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /usr/sbin/sshd -D
&lt;br&gt;stdin path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: /dev/null
&lt;br&gt;stdout path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /var/log/sshd.log
&lt;br&gt;stderr path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : /var/log/sshd.log
&lt;br&gt;Environment &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : CYGWIN=&amp;quot;ntsec&amp;quot; 
&lt;br&gt;Process Type &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Own Process
&lt;br&gt;Startup &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Automatic
&lt;br&gt;Dependencies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: tcpip
&lt;br&gt;Account &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : LocalSystem
&lt;br&gt;&lt;br&gt;&lt;br&gt;Cygwin Package Information
&lt;br&gt;Last downloaded files to: C:\cygwin\setup
&lt;br&gt;Last downloaded files from: ftp://mirrors.kernel.org/sourceware/cygwin/
&lt;br&gt;&lt;br&gt;Package &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Version
&lt;br&gt;_update-info-dir &amp;nbsp; &amp;nbsp; 00834-1
&lt;br&gt;alternatives &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.3.30c-3
&lt;br&gt;ash &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;20040127-4
&lt;br&gt;base-files &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.7-1
&lt;br&gt;base-passwd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.2-1
&lt;br&gt;bash &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.2.49-22
&lt;br&gt;bzip2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.0.5-3
&lt;br&gt;coreutils &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6.10-2
&lt;br&gt;crypt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1-1
&lt;br&gt;csih &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.2.0-1
&lt;br&gt;cvs &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.12.13-1
&lt;br&gt;cygrunsrv &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.34-1
&lt;br&gt;cygutils &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.3.4-1
&lt;br&gt;cygwin &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.5.25-15
&lt;br&gt;cygwin-doc &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.4-4
&lt;br&gt;diffutils &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.8.7-1
&lt;br&gt;editrights &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.01-2
&lt;br&gt;expat &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0.1-1
&lt;br&gt;file &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4.21-1
&lt;br&gt;findutils &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.4.0-3
&lt;br&gt;gawk &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.1.6-1
&lt;br&gt;gettext &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.17-4
&lt;br&gt;grep &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.5.3-1
&lt;br&gt;groff &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.19.2-2
&lt;br&gt;gzip &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.3.12-2
&lt;br&gt;less &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 382-1
&lt;br&gt;libbz2_1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.0.5-3
&lt;br&gt;libdb4.5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4.5.20.2-2
&lt;br&gt;libexpat1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0.1-1
&lt;br&gt;libexpat1-devel &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0.1-1
&lt;br&gt;libgcc1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.3.2-2
&lt;br&gt;libgdbm4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.8.3-9
&lt;br&gt;libiconv2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.13-1
&lt;br&gt;libidn11 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15-1
&lt;br&gt;libintl2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.12.1-3
&lt;br&gt;libintl3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.14.5-1
&lt;br&gt;libintl8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.17-4
&lt;br&gt;libncurses8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.5-4
&lt;br&gt;libncurses9 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.7-6
&lt;br&gt;libpcre0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7.8-1
&lt;br&gt;libpopt0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.6.4-4
&lt;br&gt;libreadline6 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5.2.14-12
&lt;br&gt;libwrap0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7.6-6
&lt;br&gt;login &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.10-1
&lt;br&gt;make &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.81-2
&lt;br&gt;man &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.6e-1
&lt;br&gt;minires &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.02-1
&lt;br&gt;ncurses &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.7-6
&lt;br&gt;openssh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.1p1-10
&lt;br&gt;openssl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.9.8l-1
&lt;br&gt;perl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5.10.0-5
&lt;br&gt;perl_manpages &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.10.0-5
&lt;br&gt;rebase &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.0-2
&lt;br&gt;rsync &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3.0.4-1
&lt;br&gt;run &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.12-2
&lt;br&gt;sed &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.1.5-2
&lt;br&gt;tar &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.21-1
&lt;br&gt;termcap &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.7_20091114-4
&lt;br&gt;terminfo &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5.7_20091114-4
&lt;br&gt;terminfo0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.5_20061104-3
&lt;br&gt;texinfo &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.13-3
&lt;br&gt;time &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7-2
&lt;br&gt;tzcode &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009k-1
&lt;br&gt;unzip &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.52-3
&lt;br&gt;vim &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7.2-3
&lt;br&gt;wget &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.11.4-3
&lt;br&gt;which &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.20-1
&lt;br&gt;whois &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.7.32-1
&lt;br&gt;zip &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3.0-2
&lt;br&gt;zlib &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.3-3
&lt;br&gt;zlib-devel &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.3-3
&lt;br&gt;zlib0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.3-3
&lt;br&gt;Use -h to see help about each section
&lt;br&gt;&lt;br /&gt;-- 
&lt;br&gt;Please use reply-all for most replies to avoid omitting the mailing list.
&lt;br&gt;To unsubscribe or change options: &lt;a href=&quot;https://lists.samba.org/mailman/listinfo/rsync&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/rsync&lt;/a&gt;&lt;br&gt;Before posting, read: &lt;a href=&quot;http://www.catb.org/~esr/faqs/smart-questions.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.catb.org/~esr/faqs/smart-questions.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---rsync-f13158.html&quot; embed=&quot;fixTarget[13158]&quot; target=&quot;_top&quot; &gt;Samba - rsync&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RE%3A-rsync-hangs-on-big-transfer-Debian-5.0.3-pulling-from-WinXP-SP3--Cygwin-1.5.25-tp26861183p26861183.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26861034</id>
	<title>Access Denied w/LDAP backend</title>
	<published>2009-12-19T20:53:58Z</published>
	<updated>2009-12-19T20:53:58Z</updated>
	<author>
		<name>jeff sacksteder</name>
	</author>
	<content type="html">When I connect to a Samba Member Server in my home network, I am
&lt;br&gt;prompted for credentials and am able establish a session(I have not
&lt;br&gt;yet joined the client machines to the domain). I see a list of shares
&lt;br&gt;and am able to browse down into them as I expect, based on the
&lt;br&gt;appropriate permissions. I can read the contents of files as well. If
&lt;br&gt;I attempt to make any changes (file creation, deletion, renaming,
&lt;br&gt;etc), I'm told that 'access is denied'.
&lt;br&gt;&lt;br&gt;I suspect that the issue has to do with mapping the domain user to the
&lt;br&gt;posix user.
&lt;br&gt;&lt;br&gt;This is a small home network with a Samba PDC and a ldap sam. There
&lt;br&gt;are two member servers and both posix and domain logons work with the
&lt;br&gt;same password as expected. I started with a NT4 PDC configured as I
&lt;br&gt;wanted it and vampired it into Samba+ldap. I made additional changes
&lt;br&gt;once the ldap schema was established and may have broken something.
&lt;br&gt;&lt;br&gt;I have turned up the log level, but nothing obviously wrong is
&lt;br&gt;apparent to me. There is an administrator account in the directory,
&lt;br&gt;but the root user is a local posix account. That part of the config is
&lt;br&gt;not finalized - I'm not sure that's relevant. I'm attaching a
&lt;br&gt;sanitized dump of the ldap structure.
&lt;br&gt;&lt;br&gt;Where should I be looking next? I'm stumped so far.
&lt;br&gt;&lt;br /&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Access-Denied-w-LDAP-backend-tp26861034p26861034.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26860896</id>
	<title>Re: mythtv : WriteAudio: buffer underrun</title>
	<published>2009-12-19T20:14:24Z</published>
	<updated>2009-12-19T20:14:24Z</updated>
	<author>
		<name>mtrax</name>
	</author>
	<content type="html">Thanks,
&lt;br&gt;&amp;nbsp; I'm stumped I was monitoring the CPU (AMD 3200+) and its sitting around 5-20% so no 
&lt;br&gt;probs there, memory ok too (I have 2Gb RAM ), MythTV is running with Realtime priority
&lt;br&gt;So it beats me why just CD-Audio is a problem, normal MP3 playback is fine.
&lt;br&gt;&lt;br&gt;Note I ran Gnome Mplayer and it runs without any issue, so just a MythTV problem
&lt;br&gt;&lt;br&gt;Paul
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On 20/12/2009 12:26 PM, steve jenkin wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Paul wrote on 20/12/09 8:04 AM:
&lt;br&gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Looking for some advise on how to verify my audio setup on MythTV is
&lt;br&gt;&amp;gt;&amp;gt; 100% ok.
&lt;br&gt;&amp;gt;&amp;gt; Note I've been running a Mythbox for at least 3 years on various
&lt;br&gt;&amp;gt;&amp;gt; versions of Fedora , currently F10.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I've been struck with these alot this past few months.
&lt;br&gt;&amp;gt;&amp;gt; but now I tried to play an audio CD using MythTV which I don't normally
&lt;br&gt;&amp;gt;&amp;gt; do, but none-the-less it still works but the audio start pausing
&lt;br&gt;&amp;gt;&amp;gt; outputing these msgs
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; WriteAudio: buffer underrun
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; what the heck does this mean, and how do I fix it?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Paul,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I've no idea about Myth and playing audio through linux :-(
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But I know in other contexts with a buffer 'underrun' is:
&lt;br&gt;&amp;gt; &amp;nbsp; - the buffer source (reader process) wasn't able to keep up
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; with the output. The buffer was emptied.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This means your box was busy doing other stuff, or if not, doesn't have
&lt;br&gt;&amp;gt; the grunt to play audio (unlikely).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This could be due, in my naivety not knowledge, to:
&lt;br&gt;&amp;gt; a) not enough CPU cycles
&lt;br&gt;&amp;gt; b) not enough RAM
&lt;br&gt;&amp;gt; c) CPU prioritising other tasks higher than audio
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; How to distinguish these?
&lt;br&gt;&amp;gt; Sorry, don't know :-(
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Usual approaches are rebooting (to untangle memory pools), increasing
&lt;br&gt;&amp;gt; debug levels and looking in logs, stopping/pausing other tasks.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; First step in any process is being able to reliably reproduce it...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; HTH
&lt;br&gt;&amp;gt; s
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; any clues anyone?
&lt;br&gt;&amp;gt;&amp;gt; Or can anyone run this test and get playback ok?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; thanks
&lt;br&gt;&amp;gt;&amp;gt; Paul
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26860896&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/mythtv-%3A-WriteAudio%3A-buffer-underrun-tp26858525p26860896.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26858831</id>
	<title>Re: OpenOffice</title>
	<published>2009-12-19T13:41:46Z</published>
	<updated>2009-12-19T13:41:46Z</updated>
	<author>
		<name>Brendan Jurd</name>
	</author>
	<content type="html">2009/12/19 keith sayers &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26858831&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;keiths@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt;        Would anyone here be familiar with Open Office - in particular Base and Calc?  I am
&lt;br&gt;&amp;gt; having an interesting time figuring out how they work and would much appreciate swapping
&lt;br&gt;&amp;gt; notes with someone more learned.
&lt;br&gt;&lt;br&gt;I have some experience with Calc and Writer, not so much with Base.
&lt;br&gt;Every time I've tried to use Base I got the impression that it wasn't
&lt;br&gt;quite ready for primetime.
&lt;br&gt;&lt;br&gt;Was there anything in particular you wanted to ask about?
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;BJ
&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26858831&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenOffice-tp26858671p26858831.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26858525</id>
	<title>mythtv : WriteAudio: buffer underrun</title>
	<published>2009-12-19T13:04:02Z</published>
	<updated>2009-12-19T13:04:02Z</updated>
	<author>
		<name>mtrax</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Looking for some advise on how to verify my audio setup on MythTV 
&lt;br&gt;is 100% ok.
&lt;br&gt;Note I've been running a Mythbox for at least 3 years on various 
&lt;br&gt;versions of Fedora , currently F10.
&lt;br&gt;&lt;br&gt;I've been struck with these alot this past few months.
&lt;br&gt;but now I tried to play an audio CD using MythTV which I don't normally 
&lt;br&gt;do, but none-the-less it still works but the audio start pausing 
&lt;br&gt;outputing these msgs
&lt;br&gt;&lt;br&gt;WriteAudio: buffer underrun
&lt;br&gt;&lt;br&gt;what the heck does this mean, and how do I fix it?
&lt;br&gt;&lt;br&gt;any clues anyone?
&lt;br&gt;Or can anyone run this test and get playback ok?
&lt;br&gt;&lt;br&gt;thanks
&lt;br&gt;Paul
&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26858525&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/mythtv-%3A-WriteAudio%3A-buffer-underrun-tp26858525p26858525.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26857974</id>
	<title>Re: --timeout not honoured</title>
	<published>2009-12-19T11:47:37Z</published>
	<updated>2009-12-19T11:47:37Z</updated>
	<author>
		<name>Wayne Davison-2</name>
	</author>
	<content type="html">On Fri, Dec 18, 2009 at 4:29 AM, Fabian Cenedese &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26857974&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Cenedese@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; 13:18:52 write(4, &amp;quot;\367\344\356\325UUM3\273*&amp;lt;17\7\256D\255\225x0\345^{\203&amp;quot;..., 4092) = 4092
&lt;br&gt;&amp;gt; 13:18:52 time(NULL)                     = 1261138732
&lt;br&gt;&amp;gt; 13:18:52 select(5, NULL, [4], [4], {60, 0}) = 0 (Timeout)
&lt;br&gt;&amp;gt; 13:19:52 time(NULL)                     = 1261138792
&lt;br&gt;&amp;gt; 13:19:52 write(2, &amp;quot;io timeout after 9720 seconds --&amp;quot;..., 40) = 40
&lt;br&gt;&lt;br&gt;That looks like it's the sending side. &amp;nbsp;It appears that the sender
&lt;br&gt;writes out a bunch of data to the socket (fd 4), does a select
&lt;br&gt;attempting to write more data, and when that times out after 30
&lt;br&gt;seconds, the lack of any reads since the start of the rsync process
&lt;br&gt;causes rsync to time (this is because rsync currently bases its
&lt;br&gt;timeout on last reception of data).
&lt;br&gt;&lt;br&gt;Sadly, the I/O code in 3.0.x (and 2.x) does not have the sender
&lt;br&gt;attempt to read data from the generator while it is trying to output a
&lt;br&gt;bunch of data, so even if the generator sent a keep-alive message to
&lt;br&gt;the sender, the sender was not even trying to read it. &amp;nbsp;Thus, if the
&lt;br&gt;NAS is so slow that the sending side ever pauses for 30 seconds
&lt;br&gt;waiting to output more data, it may timeout inappropriately. &amp;nbsp;This
&lt;br&gt;situation will be fixed in the (future) 3.1.0 release, which has a
&lt;br&gt;much-improved I/O setup.
&lt;br&gt;&lt;br&gt;In the meantime, you might try using --bwlimit, but if that doesn't
&lt;br&gt;help (or is undesirable), you may need to either stop specifying
&lt;br&gt;--timeout, or switch the client side to using the latest git (or
&lt;br&gt;nightly) 3.1.0dev release.
&lt;br&gt;&lt;br&gt;The 3.1.0dev release should avoid the timeout issue even when it is
&lt;br&gt;sending to an older rsync, since its sender will (#1) pay attention to
&lt;br&gt;the generator, and (#2) assume that any I/O over the socket is good
&lt;br&gt;I/O, and not timeout if I/O is succeeding. &amp;nbsp;The 3.1.0dev code is
&lt;br&gt;looking good so far, but may yet contain some errors that need to be
&lt;br&gt;shaken out. &amp;nbsp;Care should be taken when using it. &amp;nbsp;I will also see
&lt;br&gt;about a simple fix for the upcoming 3.0.7 release, which may be a
&lt;br&gt;better choice for you in the near term.
&lt;br&gt;&lt;br&gt;..wayne..
&lt;br&gt;-- 
&lt;br&gt;Please use reply-all for most replies to avoid omitting the mailing list.
&lt;br&gt;To unsubscribe or change options: &lt;a href=&quot;https://lists.samba.org/mailman/listinfo/rsync&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/rsync&lt;/a&gt;&lt;br&gt;Before posting, read: &lt;a href=&quot;http://www.catb.org/~esr/faqs/smart-questions.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.catb.org/~esr/faqs/smart-questions.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---rsync-f13158.html&quot; embed=&quot;fixTarget[13158]&quot; target=&quot;_top&quot; &gt;Samba - rsync&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/--timeout-not-honoured-tp26792092p26857974.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26857554</id>
	<title>Re: [PATCH] Output %p as unsigned in snprintf replacement.</title>
	<published>2009-12-19T10:46:34Z</published>
	<updated>2009-12-19T10:46:34Z</updated>
	<author>
		<name>Volker Lendecke</name>
	</author>
	<content type="html">On Thu, Dec 03, 2009 at 11:25:22PM +0100, Peter Rosin wrote:
&lt;br&gt;&amp;gt; Attached is a patch to output %p as an unsigned variable.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Please CC me if there are questions, I'm not subscribed...
&lt;br&gt;&lt;br&gt;Thanks, pushed. Will be in 3.5ff.
&lt;br&gt;&lt;br&gt;Volker
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26857554/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH--Output--p-as-unsigned-in-snprintf-replacement.-tp26634898p26857554.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26857450</id>
	<title>Re: Samba + Cups 2200 Laserjet printer</title>
	<published>2009-12-19T10:23:29Z</published>
	<updated>2009-12-19T10:23:29Z</updated>
	<author>
		<name>Jack Downes-2</name>
	</author>
	<content type="html">So, unless you are using windows 2k or older, is there really a point to
&lt;br&gt;installing the printer via //server/hplj2200 ?
&lt;br&gt;&lt;br&gt;Just use the windows[XP|Vista|7] printer wizard dialog and add a network
&lt;br&gt;printer. &amp;nbsp;At that point you can use the url which if the name is the
&lt;br&gt;same, would be &lt;a href=&quot;http://server:631/printers/hplj2200&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://server:631/printers/hplj2200&lt;/a&gt;. &amp;nbsp;If you are the only
&lt;br&gt;one doing this, then it'll be fine. &amp;nbsp;You'll need to have the drivers
&lt;br&gt;handy though. &amp;nbsp;And you can lock CUPS down via client IP, or client
&lt;br&gt;username, or it can depend on SAMBA auth as well. 
&lt;br&gt;&lt;br&gt;If you still want to use SAMBA for printing, take a look at groups. &amp;nbsp;As
&lt;br&gt;I recall you can specify which users &amp; which groups can
&lt;br&gt;read/write/see/whatever the printer much the same as you can for regular
&lt;br&gt;shares. &amp;nbsp;I think there's a PrinterAdmins group that you'll need to setup
&lt;br&gt;if you want to push a driver to the printer.
&lt;br&gt;&lt;br&gt;Good luck!
&lt;br&gt;Jack
&lt;br&gt;&lt;br&gt;Scott Marshall wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hoping some one can help me out here.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a 2200dn laser printer working on a centos 5 server (using webmin for
&lt;br&gt;&amp;gt; configuration).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have added it via webmin as a samba printer share with permissions to my
&lt;br&gt;&amp;gt; account.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Security is set to &amp;quot;user level&amp;quot; not &amp;quot;share level&amp;quot; (the default).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I can access my samba shares fine, download and upload to them.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I can also see the printer, but what i cannot do is print.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; When i try and add the printer via my general PCL5 drivers it asks me for a
&lt;br&gt;&amp;gt; username and password. I am currently logged into the computer so i would of
&lt;br&gt;&amp;gt; thought it didn't need it and i cannot enter in the username or password
&lt;br&gt;&amp;gt; because i am already logged in.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I cannot figure out if it is possible to have the samba server share my
&lt;br&gt;&amp;gt; printer by default to everyone with any security level yet not open up my
&lt;br&gt;&amp;gt; shares to everyone.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers
&lt;br&gt;&amp;gt; Scott
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Cups-2200-Laserjet-printer-tp26856160p26857450.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26856160</id>
	<title>Samba + Cups 2200 Laserjet printer</title>
	<published>2009-12-19T07:58:45Z</published>
	<updated>2009-12-19T07:58:45Z</updated>
	<author>
		<name>Scott Marshall-3</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;&lt;br&gt;Hoping some one can help me out here.
&lt;br&gt;&lt;br&gt;I have a 2200dn laser printer working on a centos 5 server (using webmin for
&lt;br&gt;configuration).
&lt;br&gt;&lt;br&gt;I have added it via webmin as a samba printer share with permissions to my
&lt;br&gt;account.
&lt;br&gt;&lt;br&gt;Security is set to &amp;quot;user level&amp;quot; not &amp;quot;share level&amp;quot; (the default).
&lt;br&gt;&lt;br&gt;I can access my samba shares fine, download and upload to them.
&lt;br&gt;&lt;br&gt;I can also see the printer, but what i cannot do is print.
&lt;br&gt;&lt;br&gt;When i try and add the printer via my general PCL5 drivers it asks me for a
&lt;br&gt;username and password. I am currently logged into the computer so i would of
&lt;br&gt;thought it didn't need it and i cannot enter in the username or password
&lt;br&gt;because i am already logged in.
&lt;br&gt;&lt;br&gt;I cannot figure out if it is possible to have the samba server share my
&lt;br&gt;printer by default to everyone with any security level yet not open up my
&lt;br&gt;shares to everyone.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;Scott
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-%2B-Cups-2200-Laserjet-printer-tp26856160p26856160.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26863830</id>
	<title>Issue Joining Win7 to Samba Domain (tried wiki instructions)</title>
	<published>2009-12-19T05:17:40Z</published>
	<updated>2009-12-19T05:17:40Z</updated>
	<author>
		<name>Maciej Czub</name>
	</author>
	<content type="html">&lt;br&gt;I have similar problem. I can join to domain but can't log in to user
&lt;br&gt;account.
&lt;br&gt;&lt;br&gt;Samba 3.4.3
&lt;br&gt;Windows 7 Professional x64
&lt;br&gt;&lt;br&gt;From WinXP workstation everything works great.
&lt;br&gt;&lt;br&gt;&amp;gt; Last time I saw something like this, it was because the client (Win XP)
&lt;br&gt;&amp;gt; did not have a WINS server set, and couldn’t find the domain. &amp;nbsp;Can you
&lt;br&gt;&amp;gt; ping the server from the problem client - by IP address and by name? &amp;nbsp;Is
&lt;br&gt;&amp;gt; its firewall blocking any SMB ports?
&lt;br&gt;&lt;br&gt;ping [serwerip] - works OK.
&lt;br&gt;ping [serverhostname] - works OK.
&lt;br&gt;&lt;br&gt;&amp;quot;ipconfig /all&amp;quot; on workstation displays [domainname] on DNS suffix search
&lt;br&gt;list.
&lt;br&gt;I've modified local DNS server configuration (new zone, new A record) to 
&lt;br&gt;handle &amp;quot;[serverhostname].[domainname]&amp;quot; requests.
&lt;br&gt;&lt;br&gt;ping [serverhostname].[domainname] - works OK.
&lt;br&gt;&lt;br&gt;Still - I can't log in to user account.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Maciej Czub
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Issue-Joining-Win7-to-Samba-Domain-%28tried-wiki-instructions%29-tp26863830p26863830.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26854026</id>
	<title>Re: [PATCH] Proposed merge of some NTLMSSP crypto</title>
	<published>2009-12-19T02:32:46Z</published>
	<updated>2009-12-19T02:32:46Z</updated>
	<author>
		<name>Kai Blin-4</name>
	</author>
	<content type="html">On Friday 11 December 2009 11:32:38 Andrew Bartlett wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; To be clear, while I understand your suggestion, the next patch I do
&lt;br&gt;&amp;gt; won't follow the steps you propose, but I'll mention here when it's
&lt;br&gt;&amp;gt; done, and it can be accepted, rejected or reworked (Kai has offered to
&lt;br&gt;&amp;gt; help on that) on it's merits at that time.
&lt;br&gt;&lt;br&gt;Ok, so after a solid 7 hours of watching code compile or fixing it if it 
&lt;br&gt;doesn't compile,
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://gitweb.samba.org/?p=kai/samba/wip.git;a=shortlog;h=refs/heads/ntlmssp-&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://gitweb.samba.org/?p=kai/samba/wip.git;a=shortlog;h=refs/heads/ntlmssp-&lt;/a&gt;&lt;br&gt;compile
&lt;br&gt;&lt;br&gt;(or the ntlmssp-compile branch in git://git.samba.org/kai/samba/wip.git) Has a 
&lt;br&gt;patchset that at least compiles at every step. I'm not sure if the code 
&lt;br&gt;actually works (as in passes make test), as that would have taken even longer.
&lt;br&gt;&lt;br&gt;Just as a comparison, I'd like to take the final version these patches arrive 
&lt;br&gt;at and try to reach the same stage using the steps metze proposed. That should 
&lt;br&gt;allow us to compare which method generates the more readable patches in what 
&lt;br&gt;time-scale. I'll drop an email to samba-technical once I'm done with that.
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Kai
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Kai Blin
&lt;br&gt;WorldForge developer &amp;nbsp;&lt;a href=&quot;http://www.worldforge.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.worldforge.org/&lt;/a&gt;&lt;br&gt;Wine developer &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://wiki.winehq.org/KaiBlin&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://wiki.winehq.org/KaiBlin&lt;/a&gt;&lt;br&gt;Samba team member &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.samba.org/samba/team/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.samba.org/samba/team/&lt;/a&gt;&lt;br&gt;--
&lt;br&gt;Will code for cotton.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26854026/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH--Proposed-merge-of-some-NTLMSSP-crypto-tp26694048p26854026.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26853766</id>
	<title>Re: LDAP_SERVER_SD_FLAGS_OID control and search request</title>
	<published>2009-12-19T01:42:46Z</published>
	<updated>2009-12-19T01:42:46Z</updated>
	<author>
		<name>Matthieu Patou-5</name>
	</author>
	<content type="html">Hi Sebastian,
&lt;br&gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If I have understood your question correctly, the answer for it can be found in section 3.1.1.3.4.1.11 &amp;nbsp; LDAP_SERVER_SD_FLAGS_OID of MS-ADTS.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The version online, already has this information on the section (&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/cc223323(PROT.10).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://msdn.microsoft.com/en-us/library/cc223323(PROT.10).aspx&lt;/a&gt;&amp;nbsp;).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please let me know if this addresses your question or if I have misunderstood your request.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;I read this page, maybe it's implicit that if this control is specified 
&lt;br&gt;then the nTSecurityDescriptor must be returned with requested parts 
&lt;br&gt;(accordingly to what has been requested) even if the this attribute has 
&lt;br&gt;not been requested explicitly in the attribute list.
&lt;br&gt;If so can you state it clearly, because as far as I understand (and see) 
&lt;br&gt;nTSecurityDescriptor is not returned by default if you do not explicitly 
&lt;br&gt;request it.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt; 7100 N Hwy 161, Irving, TX - 75039
&lt;br&gt;&amp;gt; &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Sebastian Canevari
&lt;br&gt;&amp;gt; Sent: Friday, December 18, 2009 1:55 PM
&lt;br&gt;&amp;gt; To: Matthieu Patou; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: LDAP_SERVER_SD_FLAGS_OID control and search request
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'll be helping you with this issue.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Friday, December 18, 2009 10:36 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: LDAP_SERVER_SD_FLAGS_OID control and search request
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; While testing ADUC I found that this tool is using the control LDAP_SERVER_SD_FLAGS_OID when requesting object with no attributes (ie.
&lt;br&gt;&amp;gt; CN=Users,DC=home,DC=matws,DC=net) and expect to receive the nTSecurityDescriptor.
&lt;br&gt;&amp;gt; Of course if you do not provide this control the nTSecurityDescriptor is not returned.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I tested this behavior with w2k3r2 and it is how this server behave.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can you confirm that it's the expected behavior for this control and if possible can you document it if it's not already done.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853766&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/LDAP_SERVER_SD_FLAGS_OID-control-and-search-request-tp26846063p26853766.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26858671</id>
	<title>OpenOffice</title>
	<published>2009-12-19T01:39:33Z</published>
	<updated>2009-12-19T01:39:33Z</updated>
	<author>
		<name>Keith Sayers</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Would anyone here be familiar with Open Office - in particular Base and Calc? &amp;nbsp;I am 
&lt;br&gt;having an interesting time figuring out how they work and would much appreciate swapping 
&lt;br&gt;notes with someone more learned.
&lt;br&gt;&lt;br&gt;__________________________________________________________________
&lt;br&gt;Keith Sayers &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26858671&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;keiths@...&lt;/a&gt;
&lt;br&gt;6 Clambe Place
&lt;br&gt;CHARNWOOD, ACT 2615 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.apex.net.au/~keiths&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.apex.net.au/~keiths&lt;/a&gt;&lt;br&gt;__________________________________________________________________
&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26858671&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenOffice-tp26858671p26858671.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26852342</id>
	<title>Re: Cannot see server in win Neighborhood (again)</title>
	<published>2009-12-18T18:59:19Z</published>
	<updated>2009-12-18T18:59:19Z</updated>
	<author>
		<name>Kevin Keane-2</name>
	</author>
	<content type="html">Are you listening on port 139, or only on port 445?
&lt;br&gt;&lt;br&gt;Microsoft had a great idea when they implemented SMB over TCP on port 445 and eliminated the ancient and inefficient NETBIOS over TCP, or NetBT (on port 139). Unfortunately, they didn't think it all the way through - you still need NETBIOS to populate the network neighborhood, so if your Samba server only listens on port 445, you won't get happy in your network neighborhood.
&lt;br&gt;&lt;br&gt;In Vista and Windows 7, this problem is fixed: they now use UPnP (renamed to Network Discovery) to populate the network neighborhood (and do a lot of other neat stuff). Samba does not yet support UPnP, though.
&lt;br&gt;&lt;br&gt;Bottom line: even though Samba supports turning off NetBT, DON'T.
&lt;br&gt;&lt;br&gt;This problem is exacerbated if you are using an IPv6 network, because Microsoft no longer even supports NETBIOS at all.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26852342&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-bounces@...&lt;/a&gt; [mailto:samba-
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26852342&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bounces@...&lt;/a&gt;] On Behalf Of Matias Morawicki
&lt;br&gt;&amp;gt; Sent: Friday, December 18, 2009 7:16 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26852342&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: [Samba] Cannot see server in win Neighborhood (again)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hello u all, sorry to bring this issue back again, but I´ve been
&lt;br&gt;&amp;gt; searching and trying all the advices suggested in previous posts and I
&lt;br&gt;&amp;gt; still can´t see the samba server in the win network neighborhood.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I can see the samba shares from win via net view \\servername
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; but if I issue a plain &amp;quot;net view&amp;quot; samba won´t show up. only the win
&lt;br&gt;&amp;gt; machines, the same i can see on the Neighborhood...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I´ve tried stopping iptables, different smb.conf from the simple
&lt;br&gt;&amp;gt; examples of t first chapters of samba by example, &amp;nbsp;to plenty of
&lt;br&gt;&amp;gt; options... that´s why I´m not including my smb.conf, because I´ve
&lt;br&gt;&amp;gt; tried many variations, always with the same results. I even tried a
&lt;br&gt;&amp;gt; working smb.conf from another linux box which was showing in win
&lt;br&gt;&amp;gt; Neighborhood...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; and when I select local master = no &amp;nbsp;Samba would stay without master!
&lt;br&gt;&amp;gt; I issue smbclient -L servername -U% and the master section remains
&lt;br&gt;&amp;gt; empty.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; It´s like samba is not being able to &amp;quot;talk&amp;quot; to the rest of the
&lt;br&gt;&amp;gt; workgroup. (of course they are all in the same workgroup)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Btw, the server is a Centos 5.3, with samba 3.2.15 (it also happened
&lt;br&gt;&amp;gt; with the default samba, so I´ve upgraded just in case...)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I hope someone can point me some directions...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; thanks in advance!!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Matias
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;/div&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Cannot-see-server-in-win-Neighborhood-%28again%29-tp26844874p26852342.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26851850</id>
	<title>Re: Patch for supported encoding</title>
	<published>2009-12-18T17:13:50Z</published>
	<updated>2009-12-18T17:13:50Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Sat, 2009-12-19 at 01:05 +0300, Matthieu Patou wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On 19/12/2009 00:05, Andrew Bartlett wrote:
&lt;br&gt;&amp;gt; &amp;gt; On Sat, 2009-12-05 at 18:04 +0300, Matthieu Patou wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Please find attach a patch that try to reintroduced a good default value
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; for default encoding (my change was overwritten by tridge in september).
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt; Can you give the commit it was overwritten by?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; The next step is to honour this stuff in the KDC
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Andrew Bartlett
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; commit c94e3ff0
&lt;/div&gt;&lt;/div&gt;Given that, the only way to get your change back in is to have a torture
&lt;br&gt;test that passes against Windows 2008R2, and to work with tridge to
&lt;br&gt;determine the situation he originally needed this for. &amp;nbsp;The test should
&lt;br&gt;handle the case before we set the supported encryption types, then
&lt;br&gt;setting it and checking it changes from that value. 
&lt;br&gt;&lt;br&gt;These changes were made to get the bidirectional vampire code working,
&lt;br&gt;so we should not revert things lightly. 
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26851850/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Patch-for-supported-encoding-tp26656371p26851850.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26851373</id>
	<title>srvtools -- are these really useful?</title>
	<published>2009-12-18T15:46:43Z</published>
	<updated>2009-12-18T15:46:43Z</updated>
	<author>
		<name>Raymond Lillard</name>
	</author>
	<content type="html">I have installed 3.4.3 on a CentOS 5.4 box as a PDC with tdbsam
&lt;br&gt;for a backend. &amp;nbsp;All seems to be working as expected in the
&lt;br&gt;Samba world.
&lt;br&gt;&lt;br&gt;With the intention of getting ordinary maintenance off of
&lt;br&gt;my back, I downloaded and installed usrmgr and srvmgr in
&lt;br&gt;/root/bin.
&lt;br&gt;&lt;br&gt;When I launch either of them from a WinXP workstation member
&lt;br&gt;while logged into the domain as root, the domain is not found.
&lt;br&gt;I can find the domain from the menu and look at various settings,
&lt;br&gt;but cannot do much of anything that can be made permanent.
&lt;br&gt;&lt;br&gt;Question: &amp;nbsp;Have I omitted some critical setting to make these
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;tools useful? &amp;nbsp;Should I not be able to add users to
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;groups, for example?
&lt;br&gt;&lt;br&gt;&lt;br&gt;What follows is some output that shows thing to be configured
&lt;br&gt;correctly. &amp;nbsp;I think.
&lt;br&gt;&lt;br&gt;&lt;br&gt;root@foobar {~} net rpc group MEMBERS &amp;quot;Domain Admins&amp;quot;
&lt;br&gt;Enter root's password:
&lt;br&gt;PS2\root
&lt;br&gt;PS2\b0fh
&lt;br&gt;&lt;br&gt;&lt;br&gt;root@foobar {~} net groupmap list
&lt;br&gt;... cut several local groups from this list ...
&lt;br&gt;Domain Users (S-1-5-21-2487701501-27877076-1099799052-513) -&amp;gt; staff
&lt;br&gt;Domain Guests (S-1-5-21-2487701501-27877076-1099799052-514) -&amp;gt; nobody
&lt;br&gt;Domain Admins (S-1-5-21-2487701501-27877076-1099799052-512) -&amp;gt; wheel
&lt;br&gt;Administrators (S-1-5-32-544) -&amp;gt; 10000
&lt;br&gt;Users (S-1-5-32-545) -&amp;gt; 10001
&lt;br&gt;&lt;br&gt;Note: I'm not sure what the groups Administrators and Users are about.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;root@foobar {~} net rpc rights list
&lt;br&gt;Enter root's password:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;SeMachineAccountPrivilege &amp;nbsp;Add machines to domain
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; SeTakeOwnershipPrivilege &amp;nbsp;Take ownership of files or other objects
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SeBackupPrivilege &amp;nbsp;Back up files and directories
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SeRestorePrivilege &amp;nbsp;Restore files and directories
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;SeRemoteShutdownPrivilege &amp;nbsp;Force shutdown from a remote system
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; SePrintOperatorPrivilege &amp;nbsp;Manage printers
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SeAddUsersPrivilege &amp;nbsp;Add users and groups to the domain
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SeDiskOperatorPrivilege &amp;nbsp;Manage disk shares
&lt;br&gt;&lt;br&gt;Note: I see no priv to add users to an existing group?
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thank you for your time,
&lt;br&gt;Ray
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/srvtools----are-these-really-useful--tp26851373p26851373.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26851305</id>
	<title>[PATCH] DsReplGetInfo() - infoType == DS_REPL_INFO_NEIGHBORS</title>
	<published>2009-12-18T15:46:36Z</published>
	<updated>2009-12-18T15:46:36Z</updated>
	<author>
		<name>hzine</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;This is the patch for the implementation of the DsGetReplInfo()
&lt;br&gt;MS-DRSR 4.1.13) for the case infoType == DS_REPL_INFO_NEIGHBORS
&lt;br&gt;(request information about the repsFrom neighbors of the target DC).
&lt;br&gt;There is also a torture test for this call.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;On the tests I made using smbtorture (with RPC-DSGETINFO test) it
&lt;br&gt;looks like the values on the fields of the reply message are consistent
&lt;br&gt;with what Windows 2008 fill in those fields.
&lt;br&gt;&lt;br&gt;I'm planning to send one patch for each of the infoTypes. I can't
&lt;br&gt;implement some of them now, because the information needed is
&lt;br&gt;not available yet on drs. The next patch will be for infoType
&lt;br&gt;DS_REPL_INFO_REPSTO.
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;Erick Nogueira do Nascimento
&lt;br&gt;Institute of Computing
&lt;br&gt;Campinas State University
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;0001-s4-drs-DsGetReplInfo-for-infoType-DS_REPL_INFO.patch&lt;/strong&gt; (42K) &lt;a href=&quot;http://old.nabble.com/attachment/26851305/0/0001-s4-drs-DsGetReplInfo-for-infoType-DS_REPL_INFO.patch&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH--DsReplGetInfo%28%29---infoType-%3D%3D-DS_REPL_INFO_NEIGHBORS-tp26851305p26851305.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26850535</id>
	<title>Re: LDAP_SERVER_SD_FLAGS_OID control and search request</title>
	<published>2009-12-18T14:26:20Z</published>
	<updated>2009-12-18T14:26:20Z</updated>
	<author>
		<name>Sebastian Canevari</name>
	</author>
	<content type="html">Hi Matthieu,
&lt;br&gt;&lt;br&gt;If I have understood your question correctly, the answer for it can be found in section 3.1.1.3.4.1.11 &amp;nbsp; LDAP_SERVER_SD_FLAGS_OID of MS-ADTS.
&lt;br&gt;&lt;br&gt;The version online, already has this information on the section (&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/cc223323(PROT.10).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://msdn.microsoft.com/en-us/library/cc223323(PROT.10).aspx&lt;/a&gt;&amp;nbsp;).
&lt;br&gt;&lt;br&gt;Please let me know if this addresses your question or if I have misunderstood your request.
&lt;br&gt;&lt;br&gt;Thanks and regards,
&lt;br&gt;&lt;br&gt;Sebastian Canevari
&lt;br&gt;Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;7100 N Hwy 161, Irving, TX - 75039
&lt;br&gt;&amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;Tel: +1 469 775 7849
&lt;br&gt;e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Sebastian Canevari 
&lt;br&gt;Sent: Friday, December 18, 2009 1:55 PM
&lt;br&gt;To: Matthieu Patou; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: RE: LDAP_SERVER_SD_FLAGS_OID control and search request
&lt;br&gt;&lt;br&gt;Hi Matthieu,
&lt;br&gt;&lt;br&gt;I'll be helping you with this issue.
&lt;br&gt;&lt;br&gt;Thanks and regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Sebastian Canevari
&lt;br&gt;Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;Tel: +1 469 775 7849
&lt;br&gt;e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;Sent: Friday, December 18, 2009 10:36 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: LDAP_SERVER_SD_FLAGS_OID control and search request
&lt;br&gt;&lt;br&gt;Hello,
&lt;br&gt;&lt;br&gt;While testing ADUC I found that this tool is using the control LDAP_SERVER_SD_FLAGS_OID when requesting object with no attributes (ie. 
&lt;br&gt;CN=Users,DC=home,DC=matws,DC=net) and expect to receive the nTSecurityDescriptor.
&lt;br&gt;Of course if you do not provide this control the nTSecurityDescriptor is not returned.
&lt;br&gt;&lt;br&gt;I tested this behavior with w2k3r2 and it is how this server behave.
&lt;br&gt;&lt;br&gt;Can you confirm that it's the expected behavior for this control and if possible can you document it if it's not already done.
&lt;br&gt;&lt;br&gt;Regards.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850535&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/LDAP_SERVER_SD_FLAGS_OID-control-and-search-request-tp26846063p26850535.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26850337</id>
	<title>Re: Patch for supported encoding</title>
	<published>2009-12-18T14:05:07Z</published>
	<updated>2009-12-18T14:05:07Z</updated>
	<author>
		<name>Matthieu Patou-5</name>
	</author>
	<content type="html">On 19/12/2009 00:05, Andrew Bartlett wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Sat, 2009-12-05 at 18:04 +0300, Matthieu Patou wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please find attach a patch that try to reintroduced a good default value
&lt;br&gt;&amp;gt;&amp;gt; for default encoding (my change was overwritten by tridge in september).
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; Can you give the commit it was overwritten by?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The next step is to honour this stuff in the KDC
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Andrew Bartlett
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;commit c94e3ff0
&lt;br&gt;&lt;br&gt;@@ -1124,8 +1133,7 @@ static NTSTATUS 
&lt;br&gt;dcesrv_netr_LogonGetDomainInfo(struct dcesrv_call_state *dce_cal
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;struct netr_DomainInformation *domain_info;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;struct netr_LsaPolicyInformation *lsa_policy_info;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;struct netr_OsVersionInfoEx *os_version;
&lt;br&gt;- &amp;nbsp; &amp;nbsp; &amp;nbsp; uint32_t default_supported_enc_types =
&lt;br&gt;- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ENC_CRC32|ENC_RSA_MD5|ENC_RC4_HMAC_MD5;
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; uint32_t default_supported_enc_types = 0xFFFFFFFF;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;int ret1, ret2, i;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NTSTATUS status;
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Patch-for-supported-encoding-tp26656371p26850337.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26850294</id>
	<title>Re: FW:  Group Policy questions</title>
	<published>2009-12-18T14:01:19Z</published>
	<updated>2009-12-18T14:01:19Z</updated>
	<author>
		<name>Matthieu Patou-5</name>
	</author>
	<content type="html">Hello Sebastian and Hongwei,
&lt;br&gt;&lt;br&gt;Sorry for being silent on this.
&lt;br&gt;&lt;br&gt;So if I try to sum up we agreed that:
&lt;br&gt;&lt;br&gt;* in order to allow modification of ACL on files sdeffectiverights must 
&lt;br&gt;have the flag &amp;nbsp;DACL_SECURITY_INFORMATION set, and the ACL must have the 
&lt;br&gt;SE_DACL_PROTECTED set in the control flags.
&lt;br&gt;* in order to avoid a warning message ACL of Policy object must be 
&lt;br&gt;synchronized with ACL in the files following this logic for the translation:
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The specific rights in access mask for Active Directory object 
&lt;br&gt;are defined in &amp;nbsp;5.1.3.2 of MS-ADTS as follows.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_CREATE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000001
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_DELETE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000002
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_LIST_CONTENTS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000004
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define ACTRL_DS_SELF &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000008
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_READ_PROPERTY &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000010
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_WRITE_PROPERTY &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000020
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_DELETE_TREE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000040
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_LIST_OBJECT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000080
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define RIGHT_DS_CONTROL_ACCESS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000100
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The specific rights in access mask for a file or directory object
&lt;br&gt;&amp;nbsp; &amp;nbsp;are defined as
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/aa364399(VS.85).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://msdn.microsoft.com/en-us/library/aa364399(VS.85).aspx&lt;/a&gt;&amp;nbsp;)
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_READ_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0001 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_LIST_DIRECTORY &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0001 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_WRITE_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0002 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_ADD_FILE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0002 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_APPEND_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0004 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_ADD_SUBDIRECTORY &amp;nbsp; &amp;nbsp; ( 0x0004 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_CREATE_PIPE_INSTANCE ( 0x0004 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_READ_EA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0008 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_WRITE_EA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0010 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_EXECUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0020 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_TRAVERSE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0020 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_DELETE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0040 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_READ_ATTRIBUTES &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0080 )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define FILE_WRITE_ATTRIBUTES &amp;nbsp; &amp;nbsp; ( 0x0100 )
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; The generic access rights that are common to all objects are
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define DELETE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(0x00010000L)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define READ_CONTROL &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(0x00020000L)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define WRITE_DAC &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00040000L)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define WRITE_OWNER &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00080000L)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define SYNCHRONIZE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00100000L)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#define STANDARD_RIGHTS_ALL &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x001F0000L)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The following logic is used by GPMC to convert a access mask for 
&lt;br&gt;DS object to a access mask for SYSVOL.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DSAccessMask as Input;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask as Output;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask &amp;nbsp;= DSAccessMask;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask&amp;= &amp;nbsp;STANDARD_RIGHTS_ALL ;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if ((DSAccessMask&amp; &amp;nbsp; RIGHT_DS_READ_PROPERTY) AND
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(DSAccessMask&amp; &amp;nbsp; RIGHT_DS_LIST_CONTENTS))
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask &amp;nbsp;|= (SYNCHRONIZE | FILE_LIST_DIRECTORY |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FILE_READ_ATTRIBUTES | FILE_READ_EA |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FILE_READ_DATA | FILE_EXECUTE);
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (DSAccessMask&amp; &amp;nbsp; RIGHT_DS_WRITE_PROPERTY)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask &amp;nbsp;|= (SYNCHRONIZE | FILE_WRITE_DATA |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FILE_APPEND_DATA | FILE_WRITE_EA |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FILE_WRITE_ATTRIBUTES | FILE_ADD_FILE |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FILE_ADD_SUBDIRECTORY);
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if (DSAccessMask&amp; &amp;nbsp; RIGHT_DS_CREATE_CHILD)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask &amp;nbsp;|= (FILE_ADD_SUBDIRECTORY |
&lt;br&gt;&amp;nbsp; &amp;nbsp;FILE_ADD_FILE);
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if (DSAccessMask&amp; &amp;nbsp; RIGHT_DS_DELETE_CHILD)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask &amp;nbsp;|= FILE_DELETE_CHILD;
&lt;br&gt;&lt;br&gt;&lt;br&gt;* All ACE for allowed object are wipped out when &amp;quot;translating&amp;quot; AD ACL to 
&lt;br&gt;File ACL
&lt;br&gt;* For the following ACE OI and CI flags are always set in the resulting 
&lt;br&gt;file ACE:
&lt;br&gt;&lt;br&gt;ACCESS_ALLOWED_ACE_TYPE
&lt;br&gt;ACCESS_DENIED_ACE_TYPE
&lt;br&gt;SYSTEM_AUDIT_ACE_TYPE
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Am I right ?
&lt;br&gt;&lt;br&gt;For the part that are &amp;quot;hardcoded&amp;quot; like this will it change any time soon 
&lt;br&gt;? Also do you plan to document this in any kind of document ? if so 
&lt;br&gt;which and when ?
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Regards.
&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 12/12/2009 01:00, Sebastian Canevari wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; With regards to ACCESS_ALLOWED_OBJECT_ACE, we do wipe it in the process. That's hardcoded.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; With regards to the RU...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I need further clarification on what you are actually seeing.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; It is my understanding and that since prew2k clients will not download policies, the ACEs will be cleared if they contain that well known SID.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We are still investigating but please let me know if that explains what you are seeing.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt; 7100 N Hwy 161, Irving, TX - 75039
&lt;br&gt;&amp;gt; &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Sebastian Canevari
&lt;br&gt;&amp;gt; Sent: Thursday, December 10, 2009 2:19 PM
&lt;br&gt;&amp;gt; To: 'Matthieu Patou'
&lt;br&gt;&amp;gt; Cc: Hongwei Sun; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; With regards of the OI and CI flags, we always set those flags on if the ACE type is any of the following 3 types:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ACCESS_ALLOWED_ACE_TYPE
&lt;br&gt;&amp;gt; ACCESS_DENIED_ACE_TYPE
&lt;br&gt;&amp;gt; SYSTEM_AUDIT_ACE_TYPE
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This is hardcoded.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'll provide you with the answer to your other question soon.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sebastian
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Friday, December 04, 2009 3:32 PM
&lt;br&gt;&amp;gt; To: Sebastian Canevari
&lt;br&gt;&amp;gt; Cc: Hongwei Sun; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On 04/12/2009 23:00, Sebastian Canevari wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Just a clarification to ask you for:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We are discussing with Hongwei and the PGs &amp;nbsp;if it is that you are seeing GPMC &amp;quot;expect&amp;quot; the inheritance to happen OR if it is that you are dumping the ACLs and &amp;quot;seeing&amp;quot; the flags always.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; What I see if when I dump the SD of the files modified by GPMC after it realize that there was a mismatch between the SD in AD and the SD in the Policy folder.
&lt;br&gt;&amp;gt; Note: it was with XP sp2 as a client.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please clarify because we were under the impression that we had to look into the client tool, but if the latter is what your question means, then we need to look into AD.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N
&lt;br&gt;&amp;gt;&amp;gt; Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: Sebastian Canevari
&lt;br&gt;&amp;gt;&amp;gt; Sent: Thursday, December 03, 2009 4:18 PM
&lt;br&gt;&amp;gt;&amp;gt; To: 'Matthieu Patou'; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability
&lt;br&gt;&amp;gt;&amp;gt; Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: RE: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We are still actively working on this and I do have the PG engaged.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please accept my apologies if we are delaying a little longer than expected. I guess we can say that the holidays affected the timing a little without trying to use that as an excuse.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'll keep you posted as soon as I have news.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sebastian
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt; Sent: Thursday, December 03, 2009 4:05 PM
&lt;br&gt;&amp;gt;&amp;gt; To: Sebastian Canevari; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability
&lt;br&gt;&amp;gt;&amp;gt; Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hello sebastian
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; And last but not least question, it seems that GPMC whats to have OI and CI flags on every ACL entries is it due to the presence of the &amp;quot;SDDL_AUTO_INHERITED&amp;quot;&amp;gt;control in the SDDL &amp;nbsp;?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any news on this ?
&lt;br&gt;&amp;gt;&amp;gt; More exactly my question is why this flag appear on each ACE ?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Also do you plan to document this in a WSPP document ?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards.
&lt;br&gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; On 13/11/2009 02:40, Sebastian Canevari wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hi Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I'll be working with you on these questions.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I will keep you updated.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sebastian
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sebastian Canevari
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM 7100 N
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hwy 161, Irving, TX - 75039 &amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Tel: +1 469 775 7849
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; From: Hongwei Sun
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sent: Wednesday, November 11, 2009 9:35 PM
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; To: Matthieu Patou
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=16&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; Sebastian Canevari
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Subject: RE: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; I double checked the logic and your assumption is right. &amp;nbsp; The return value for SYSVOL access mask should be assigned to the input value first. &amp;nbsp; For your other questions, &amp;nbsp;since I am out of office , Sebastian will work on them and let you know.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hongwei
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=17&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sent: Wednesday, November 11, 2009 12:22 AM
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; To: Hongwei Sun
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=18&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=19&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Subject: Re: FW: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hello Hongwei,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I've been working on the translation function, I am getting quite similar ACL right now but I have some remarks and questions.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The pseudo code contains this:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; DSAccessMask as Input;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SYSVOLAccessMask as Output;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SYSVOLAccessMask&amp;= &amp;nbsp;STANDARD_RIGHTS_ALL ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I have impression that it should be
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; DSAccessMask as Input;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SYSVOLAccessMask as Output;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SYSVOLAccessMask &amp;nbsp;= DSAccessMask;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SYSVOLAccessMask&amp;= &amp;nbsp;STANDARD_RIGHTS_ALL ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Maybe the third line is implied in this kind of pseudo code.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Also it seems to me that GPMC is discarding any ACL of type ACCESS_ALLOWED_OBJECT_ACE (OA) and also everything related to SID SID_BUILTIN_PREW2K (RU).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; And last but not least question, it seems that GPMC whats to have OI and CI flags on every ACL entries is it due to the presence of the &amp;quot;SDDL_AUTO_INHERITED&amp;quot; control in the SDDL &amp;nbsp;?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thanks for your answers.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On 29/10/2009 05:31, Hongwei Sun wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;I keep receiving the message from our e-mail server about the undeliverable e-mail to one of the address(&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=20&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;), which is in your original e-mail. &amp;nbsp;In order to make sure you receive the email, I just forward it again.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;If you already received it, please let me know if it resolved your issue.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hongwei
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; From: Hongwei Sun
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Sent: Monday, October 26, 2009 6:14 PM
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; To: Matthieu Patou; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=21&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=22&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: RE: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; The attached GPMC log shows the problem of inconsistency
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; between ACLs of the policy object and that of SYSVOL folders. &amp;nbsp;The
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; log shows that
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; [6bc.678] 10/25/2009 00:55:47:359 &amp;nbsp;[VERBOSE]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; CGPMGPO::IsAclConsistent():Checking Aces for SID
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S-1-5-21-2212615479-2695158682-2101375467-512
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; [6bc.678] 10/25/2009 00:55:47:359 &amp;nbsp;[VERBOSE]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; GetSysvolPermissionsFromDSPermissions: DS access mask is 0xf00ff ......
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; [6bc.678] 10/25/2009 00:55:47:359 &amp;nbsp;[VERBOSE]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; CGPMGPO::IsAclConsistent(): ACLs not consistent for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; SID&amp;lt;S-1-5-21-2212615479-2695158682-2101375467-512&amp;gt;. Mask: Expected
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 0x1f01ff, Found 0xf00ff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; The access mask for the ace of Active Directory policy object is 0xf00ff. &amp;nbsp;When the GPMO converts the access mask to a corresponding file system access mask, it expects 0x1f01ff. For SYSVOL, you set the access mask to 0xf00ff. &amp;nbsp;They don't match and that is why inconsistency is declared. &amp;nbsp; In the SYSVOL access mask you set, you missed 0x100000(SYNCHRONIZE) and 0x100(FILE_WRITE_ATTRIBUTES).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; Since AD objects and SYSVOL file/folder objects are different objects, &amp;nbsp;their specific rights in access mask are not &amp;nbsp;one-to-one matched. The following are the definitions of bits for both objects.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; The specific rights in access mask for Active Directory object are defined in &amp;nbsp;5.1.3.2 of MS-ADTS as follows.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_CREATE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000001
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_DELETE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000002
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_LIST_CONTENTS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000004
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define ACTRL_DS_SELF &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000008
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_READ_PROPERTY &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000010
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_WRITE_PROPERTY &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000020
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_DELETE_TREE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000040
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_LIST_OBJECT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x00000080
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define RIGHT_DS_CONTROL_ACCESS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0x00000100
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; The specific rights in access mask for a file or directory
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; object are defined as
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/aa364399(VS.85).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://msdn.microsoft.com/en-us/library/aa364399(VS.85).aspx&lt;/a&gt;&amp;nbsp;)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_READ_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0001 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_LIST_DIRECTORY &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0001 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_WRITE_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0002 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_ADD_FILE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0002 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_APPEND_DATA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0004 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_ADD_SUBDIRECTORY &amp;nbsp; &amp;nbsp; ( 0x0004 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_CREATE_PIPE_INSTANCE ( 0x0004 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_READ_EA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0008 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_WRITE_EA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0010 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_EXECUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0020 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_TRAVERSE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0020 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_DELETE_CHILD &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( 0x0040 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_READ_ATTRIBUTES &amp;nbsp; &amp;nbsp; &amp;nbsp;( 0x0080 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define FILE_WRITE_ATTRIBUTES &amp;nbsp; &amp;nbsp; ( 0x0100 )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;The generic access rights that are common to all objects are
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define DELETE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(0x00010000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define READ_CONTROL &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(0x00020000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define WRITE_DAC &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00040000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define WRITE_OWNER &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00080000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define SYNCHRONIZE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x00100000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #define STANDARD_RIGHTS_ALL &amp;nbsp; &amp;nbsp; &amp;nbsp; (0x001F0000L)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following logic is used by GPMC to convert a access mask for DS object to a access mask for SYSVOL.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;DSAccessMask as Input;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask as Output;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask&amp;= &amp;nbsp;STANDARD_RIGHTS_ALL ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if ((DSAccessMask&amp; &amp;nbsp; &amp;nbsp; RIGHT_DS_READ_PROPERTY) AND
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (DSAccessMask&amp; &amp;nbsp; &amp;nbsp; RIGHT_DS_LIST_CONTENTS))
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSVOLAccessMask &amp;nbsp;|= (SYNCHRONIZE | FILE_LIST_DIRECTORY |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FILE_READ_ATTRIBUTES | FILE_READ_EA |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FILE_READ_DATA | FILE_EXECUTE);
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if (DSAccessMask&amp; &amp;nbsp; &amp;nbsp; RIGHT_DS_WRITE_PROPERTY)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask &amp;nbsp;|= (SYNCHRONIZE | FILE_WRITE_DATA |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FILE_APPEND_DATA | FILE_WRITE_EA |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FILE_WRITE_ATTRIBUTES | FILE_ADD_FILE |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FILE_ADD_SUBDIRECTORY);
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (DSAccessMask&amp; &amp;nbsp; &amp;nbsp; RIGHT_DS_CREATE_CHILD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask &amp;nbsp;|= (FILE_ADD_SUBDIRECTORY |
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; FILE_ADD_FILE);
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (DSAccessMask&amp; &amp;nbsp; &amp;nbsp; RIGHT_DS_DELETE_CHILD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SYSVOLAccessMask &amp;nbsp;|= FILE_DELETE_CHILD;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; Please let me know if this solves your problem. &amp;nbsp;I will file a request to update the document accordingly.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hongwei
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=23&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Sent: Sunday, October 25, 2009 5:48 AM
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=24&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Hongwei Sun; Interoperability
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=25&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: Re: [cifs-protocol] Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello hongwei,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On 10/20/2009 01:05 PM, Matthieu Patou wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hi Hongwei,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; For the moment it's quite clear why we fail as we do not set any
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ACL by default on the sysvol volume.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I will already fix this + the sDRightsEffective attribute and I'll
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; see if it do the job.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I worked a little bit on the ACL and still face &amp;quot;unsynchronized&amp;quot; ACL despite the fact that now our Policy folder are created with the same ACL as in AD.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Let's take the following
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; policy:{7557D70F-14C9-4EA5-8369-10AE7C2C31D3}
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I face the message that the ACL is unconsitent with the one stored
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; in the AD, after clicking on yes GPMC changed the ACL for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-2212615479-2695158682-2101375467-512G:S-1-5-21-2212615479
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 695158682-2101375467-512D:PAI(A;OICI;0x001f01ff;;;S-1-5-21-221261547
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 9
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2695158682-2101375467-512)(A;OICI;0x001f01ff;;;S-1-5-21-2212615479-2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 6
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 9
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 5158682-2101375467-519)(A;OICI;0x001f01ff;;;S-1-5-21-2212615479-2695
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 5
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 8682-2101375467-512)(A;OICI;0x001f01ff;;;S-1-5-21-2212615479-2695158
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 6
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 8
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2-2101375467-512)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;SY)(
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; A
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED)(A;OICI;0x001f01bf;;;BA
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; A;OICI;0x001f01ff;;;S-1-5-21-2212615479-2695158682-2101375467-519)S:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; A
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; a285-00aa003049e2;WD)(OU;CIIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f8036
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 7
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; c
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Before it was:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-2212615479-2695158682-2101375467-512G:S-1-5-21-2212615479
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 695158682-2101375467-512D:PAI(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 212615479-2695158682-2101375467-512)(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -5-21-2212615479-2695158682-2101375467-519)(A;;RPWPCCDCLCLORCWOWDSDD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; T
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; W;;;S-1-5-21-2212615479-2695158682-2101375467-512)(A;;RPWPCCDCLCLORC
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; W
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; WDSDDTSW;;;S-1-5-21-2212615479-2695158682-2101375467-512)(A;CIIO;RPW
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; P
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; C
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; CDCLCLORCWOWDSDDTSW;;;CO)(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; R
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; C;;;AU)(OA;;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;RPLCLORC
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;ED)(A;CIID;RPWPCRCCLCLORCWOWDSDSW;;;BA)(A;CIID;RPWPCRCCDCLCLORCWOWD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; D
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; DTSW;;;S-1-5-21-2212615479-2695158682-2101375467-519)(A;CIID;LC;;;RU
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; :AI(OU;CIIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; d0-a285-00aa003049e2;WD)(OU;CIIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f8
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 3
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 67c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; And if I request the nTSecurityDescriptor for this object in the AD I get:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; {7557D70F-14C9-4EA5-8369-10AE7C2C31D3}
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-2212615479-2695158682-2101375467-512G:S-1-5-21-2212615479
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 695158682-2101375467-512D:PAI(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 212615479-2695158682-2101375467-512)(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -5-21-2212615479-2695158682-2101375467-519)(A;;RPWPCCDCLCLORCWOWDSDD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; T
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; W;;;S-1-5-21-2212615479-2695158682-2101375467-512)(A;;RPWPCCDCLCLORC
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; W
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; WDSDDTSW;;;S-1-5-21-2212615479-2695158682-2101375467-512)(A;CIIO;RPW
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; P
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; C
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; CDCLCLORCWOWDSDDTSW;;;CO)(A;;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; R
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; C;;;AU)(OA;;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;RPLCLORC
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ;ED)(A;CIID;RPWPCRCCLCLORCWOWDSDSW;;;BA)(A;CIID;RPWPCRCCDCLCLORCWOWD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; D
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; DTSW;;;S-1-5-21-2212615479-2695158682-2101375467-519)(A;CIID;LC;;;RU
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; :AI(OU;CIIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; d0-a285-00aa003049e2;WD)(OU;CIIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f8
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 3
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 67c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Which looks like the ACL that were present for the file.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I also made a tcpdump capture (attached to this mail) and it's clear that the nTSecurityDescriptor is like the one just above. (packet 927).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; So what's going on, with an ACL that is the same when stored in the AD, transmitted through LDAP and stored in the file we have at the end GPMC that change the value but it's hard to understand how it construct this ACL.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I attached also the GPMC log when I clicked on &amp;quot;OK&amp;quot; so that the ACL in AD and ACL for the file are synchronized (well from GPMC point of view).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I will try to use also the same SSDL as in w2k3 to see if I have
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the same resulting delagation or not.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; For the moment I have some tests to do before going back to you.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Regards.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On 10/20/2009 03:11 AM, Hongwei Sun wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; For Problem #1, only the SE_DACL_PROTECTED(0x1000) has to be set
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; for ControlFlag in Security Descriptor in order to pass the step 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; in consistency testing. This is translated to &amp;quot;P&amp;quot; flag in SDDL.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; With this said, it is normal to have D:PAI since this will
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; indicate that the SE_DACL_PROTECTED bit is set. It seems that your
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Security Descriptor is right in this regard. We have to get more
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; information to see why the consistency checking fails. Could you
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; enable GPMC logging as described in my previous mail? Please
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; enable VERBOSE for Gpmgmttracelevel.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Just for your reference, you can also use ldp.exe to display the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; security descriptor of a policy object in SSDL string format and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; parsed display format.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hongwei
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=26&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Sent: Saturday, October 17, 2009 11:33 AM
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; To: Hongwei Sun
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=27&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=28&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: Re: Group Policy questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello Hongwei,Matthieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thank you for the answers. I have a few more questions:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; After testing, I think that I have some information to help you
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; resolve all the problems.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Problem #1:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; As described in the following link
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (&lt;a href=&quot;http://support.microsoft.com/default.aspx?scid=kb;en-us;828760&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;828760&lt;/a&gt;&amp;nbsp;)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; , GPMO will check the consistency between ACLs in GPO in Active
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Directory and ACLs of policy folders in SYSVOL when a GPO object
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; is clicked in GPMC. The logic is something like the following:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1. Get the security descriptor (SD) for GOP in AD and folders in
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; SYSVOL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2. Check both security descriptors to make sure they are DACL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; protected (PD bit in Control flag is set). If not, ACL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; consistency check will fail.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 3. For every permission in AD DACL, there should be the same
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; permission in SYSVOL DACL. If all permissions have be checked
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; through in AD ACL and there is still extra permission in SYSVOL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ACL, ACLs are not consistent.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Looking at the your attached SSDL of the new policy, it doesn't
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; have PD bit set. (D:PAI means DI bit is set, which is not DACL protected).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This will fail the second step of consistency checking.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I did an extraction of a W2K3 policy and got the following SDDL:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-3208502064-746857408-2662927446-512G:S-1-5-21-320850206
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 4
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 746857408-2662927446-512
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; D:PAI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-266
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 9
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 27446-512)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-266
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 9
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 27446-519)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 7
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 446-512)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;CO)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S:AI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1d0-a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1d0-a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; And you say that we should not have AI flag (because it's related
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to SE_DACL_AUTO_INHERITED aka DI bit) just the P flag (because
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; it's related to DE_DACL_PROTECTED aka PD bit) right ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; But the above SDDL seems to show the opposite, I can't exclude the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; fact that we have bugs when reading ACL and/or when converting
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; them into SDDL but before to trying to check this I would like to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; be sure of which flag we should see.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I even tweaked XCACLS.vbs (attached to this email) from
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://support.microsoft.com/default.aspx?scid=kb;en-us;828760&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;828760&lt;/a&gt;&amp;nbsp;to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; make it show the value of the control and it appear that the ACL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; for the c:\windows\sysvol has both PD and DI bit sets
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ie.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Directory: C:\WINDOWS\SYSVOL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ControlFlags: 37892
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Do gpmc pass some controls while making its LDAP request because I
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; had a look at the delegated permission through GPMC and through
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; dsa.msc they are really different (a lot of inherited from parents objects).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Problem #2:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In GPMO, if the attribute sDRightsEffective of selected GPO
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; object has DACL_SECURITY_INFORMATION bit (0x04) set, users will
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; be prompted for ACL correction if ACLs inconsistency between AD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; GPO and SYSVOL is detected when a GPO node is selected. You
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; should check the attribute for the GOP object in AD.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Problem #3:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is basically the same logic as in (2). The &amp;quot;Add&amp;quot; and &amp;quot;Remove&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; buttons in Delegation dialog are enabled only when the attribute
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; sDRightsEffective of selected GPO object has
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; DACL_SECURITY_INFORMATION (0x04) bit set. You should check the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; attribute for the GOP object in AD.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Yeah for this it seems that the obvious problem is the lack of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; sDRightsEffective in SAMBA 4.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Debugging Information:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; By the way, you can follow the instruction in this link
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (&lt;a href=&quot;http://technet.microsoft.com/en-us/library/cc737379(WS.10).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://technet.microsoft.com/en-us/library/cc737379(WS.10).aspx&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ) to enable GPMC logging, if you want to troubleshoot the issues
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; related to operations in GPMC. For example, the logging will show
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; you in which step the consistency checking fails.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; You can look for the text &amp;quot;CGPMGPO::IsAclConsistent()&amp;quot; in the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; logs generated.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; If you need more information, please let us know.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; cifs-protocol mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=29&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26850294&amp;i=30&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FW%3A--Group-Policy-questions-tp26105336p26850294.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26849972</id>
	<title>Re: [s4] Passwords work</title>
	<published>2009-12-18T13:20:51Z</published>
	<updated>2009-12-18T13:20:51Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Fri, 2009-12-18 at 10:38 +0100, Matthias Dieter Wallnöfer wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I would like to inform you (s4 developers) that my password work has 
&lt;br&gt;&amp;gt; been finished. The &amp;quot;samdb_set_password&amp;quot; call is cleaned up (only the 
&lt;br&gt;&amp;gt; essential instructions) and all the other checks moved to the 
&lt;br&gt;&amp;gt; &amp;quot;password_hash&amp;quot; LDB module.
&lt;br&gt;&amp;gt; The reason for this is that AD supports the password handling not only 
&lt;br&gt;&amp;gt; over the RPCs or KERBEROS (&amp;quot;samdb_set_password&amp;quot; in our case) but also 
&lt;br&gt;&amp;gt; directly by LDAP attribute manipulation. With my patchset we should 
&lt;br&gt;&amp;gt; always be safe now regarding the policies (since previously we weren't 
&lt;br&gt;&amp;gt; on direct LDAP changes).
&lt;br&gt;&amp;gt; To be interoperable with the &amp;quot;real AD&amp;quot; I implemented the behaviour 
&lt;br&gt;&amp;gt; according to MS-ADTS 3.1.1.3.1.5. In addition to the specification which 
&lt;br&gt;&amp;gt; seems to allow password changes only by the &amp;quot;unicodePwd&amp;quot; and 
&lt;br&gt;&amp;gt; &amp;quot;userPassword&amp;quot; attribute, my patch supports them also through 
&lt;br&gt;&amp;gt; &amp;quot;clearTextPassword&amp;quot; and &amp;quot;dBCSPwd&amp;quot; (if LANMAN auth is enabled). I added 
&lt;br&gt;&amp;gt; this for completeness and it didn't make a lot of difference to 
&lt;br&gt;&amp;gt; implement also this.
&lt;br&gt;&amp;gt; The tree is located at 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/passwords&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/passwords&lt;/a&gt;&amp;nbsp;and 
&lt;br&gt;&amp;gt; passes &amp;quot;make test&amp;quot;.
&lt;/div&gt;&lt;/div&gt;Thankyou so much for your persistence with this work. &amp;nbsp;This looks really
&lt;br&gt;good, and I look forward to merging it!
&lt;br&gt;&lt;br&gt;The things I would suggest need to be done before we merge:
&lt;br&gt;&amp;nbsp;- Tests: - we need tests of the LDAP password set and change behaviour
&lt;br&gt;&amp;nbsp;- unicodePwd - we need to get rid of the 'autodetection' between
&lt;br&gt;&amp;quot;password&amp;quot; and 16 byte hash value. &amp;nbsp;This I think should be replaced with
&lt;br&gt;a control indicating 'hash values being set' (which scripts such as the
&lt;br&gt;upgradeprovision and parts of the SAMR password change code could then
&lt;br&gt;set). 
&lt;br&gt;&lt;br&gt;I also just need to look over the patch more carefully, with a
&lt;br&gt;particular eye to security holes. 
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26849972/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-s4--Passwords-work-tp26841125p26849972.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26849968</id>
	<title>Re: Patch for supported encoding</title>
	<published>2009-12-18T13:05:13Z</published>
	<updated>2009-12-18T13:05:13Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Sat, 2009-12-05 at 18:04 +0300, Matthieu Patou wrote:
&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Please find attach a patch that try to reintroduced a good default value 
&lt;br&gt;&amp;gt; for default encoding (my change was overwritten by tridge in september).
&lt;br&gt;&lt;br&gt;Can you give the commit it was overwritten by?
&lt;br&gt;&lt;br&gt;The next step is to honour this stuff in the KDC
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26849968/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Patch-for-supported-encoding-tp26656371p26849968.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26849525</id>
	<title>Disabling Roaming Profile Support Removes Logon (Home) Drive</title>
	<published>2009-12-18T12:47:21Z</published>
	<updated>2009-12-18T12:47:21Z</updated>
	<author>
		<name>adam.tompkins</name>
	</author>
	<content type="html">This is my first attempt at setting up a PDC (Ubuntu Server 9.10 + Samba 3.4.3). I'm keeping it simple - no AD support or LDAP just a basic NT4 domain.
&lt;br&gt;&lt;br&gt;I have everything configured and working well - I can join Windows clients to the domain and access shares etc. &amp;nbsp;However I realized that roaming profiles were enabled, which I don't want, so I modifed the config to set logon home = &amp;nbsp;and logon path = . &amp;nbsp;As expected, it stopped the roaming profiles but it also removed the logon (home) drive which had worked previously.
&lt;br&gt;&lt;br&gt;Is there any way to disable roaming profiles but keep the logon drive?
&lt;br&gt;&lt;br&gt;&amp;nbsp;logon script = logon.cmd
&lt;br&gt;&amp;nbsp;logon path =
&lt;br&gt;&amp;nbsp;logon drive = H:
&lt;br&gt;&amp;nbsp;logon home =
&lt;br&gt;&lt;br&gt;Thanks.&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Disabling-Roaming-Profile-Support-Removes-Logon-%28Home%29-Drive-tp26849525p26849525.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26849392</id>
	<title>Re: new user can't log</title>
	<published>2009-12-18T12:36:58Z</published>
	<updated>2009-12-18T12:36:58Z</updated>
	<author>
		<name>Leonardo Carneiro-2</name>
	</author>
	<content type="html">The database from ldap was a copy from another domain, that existed in 
&lt;br&gt;another network. i've done a slapcat in the old domain and did a slapadd 
&lt;br&gt;in this new one (both domain have the same name). But this happened 
&lt;br&gt;about 2 years ago. After a samba and ldap upgrade via apt-get, the 
&lt;br&gt;duplicated domains message start to pop (abouth 3 months ago). Just now 
&lt;br&gt;i've solved, but now, this =S.
&lt;br&gt;&lt;br&gt;I'll try some of the stuff you guys sugested me.
&lt;br&gt;&lt;br&gt;tks and sorry for my poor english.
&lt;br&gt;&lt;br&gt;*Leonardo de Souza Carneiro*
&lt;br&gt;*Veltrac - Tecnologia em Logística.*
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26849392&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lscarneiro@...&lt;/a&gt; &amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26849392&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lscarneiro@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;a href=&quot;http://www.veltrac.com.br&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.veltrac.com.br&lt;/a&gt;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://www.veltrac.com.br/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.veltrac.com.br/&lt;/a&gt;&amp;gt;
&lt;br&gt;/Fone Com.: (43)2105-5601/
&lt;br&gt;/Av. Higienópolis 1601 Ed. Eurocenter Sl. 803/
&lt;br&gt;/Londrina- PR/
&lt;br&gt;/Cep: 86015-010/
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;David Whitney escreveu:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Unless I've blown my memory on Windows internals, each user's SID is
&lt;br&gt;&amp;gt; comprised of the domain's SID, then a &amp;quot;self-refential&amp;quot; RID portion. That
&lt;br&gt;&amp;gt; means a user from the domain DOMINIOS should NOT have what amounts to a
&lt;br&gt;&amp;gt; &amp;quot;prefix&amp;quot; that looks as though it came from a different domain. But unless
&lt;br&gt;&amp;gt; I'm mistaken, your logs are telling you exactly that - the domain portion of
&lt;br&gt;&amp;gt; the group and user SID's indicate different domains, and that indicates a
&lt;br&gt;&amp;gt; problem.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; One theory is that perhaps your domain was created, groups and users were
&lt;br&gt;&amp;gt; created, but then for some reason your domain SID changed, and perhaps that
&lt;br&gt;&amp;gt; led to your described duplicate domain entry (?) problem.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Anyway, I'd take a look at the SIDS of other users and groups and see if
&lt;br&gt;&amp;gt; this problem exists for other users or groups on your domain.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -David
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/new-user-can%27t-log-tp26849114p26849392.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26849114</id>
	<title>new user can't log</title>
	<published>2009-12-18T12:16:31Z</published>
	<updated>2009-12-18T12:16:31Z</updated>
	<author>
		<name>David Whitney-3</name>
	</author>
	<content type="html">Unless I've blown my memory on Windows internals, each user's SID is
&lt;br&gt;comprised of the domain's SID, then a &amp;quot;self-refential&amp;quot; RID portion. That
&lt;br&gt;means a user from the domain DOMINIOS should NOT have what amounts to a
&lt;br&gt;&amp;quot;prefix&amp;quot; that looks as though it came from a different domain. But unless
&lt;br&gt;I'm mistaken, your logs are telling you exactly that - the domain portion of
&lt;br&gt;the group and user SID's indicate different domains, and that indicates a
&lt;br&gt;problem.
&lt;br&gt;&lt;br&gt;One theory is that perhaps your domain was created, groups and users were
&lt;br&gt;created, but then for some reason your domain SID changed, and perhaps that
&lt;br&gt;led to your described duplicate domain entry (?) problem.
&lt;br&gt;&lt;br&gt;Anyway, I'd take a look at the SIDS of other users and groups and see if
&lt;br&gt;this problem exists for other users or groups on your domain.
&lt;br&gt;&lt;br&gt;-David
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/new-user-can%27t-log-tp26849114p26849114.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26848918</id>
	<title>Re: LDAP_SERVER_SD_FLAGS_OID control and search request</title>
	<published>2009-12-18T11:55:28Z</published>
	<updated>2009-12-18T11:55:28Z</updated>
	<author>
		<name>Sebastian Canevari</name>
	</author>
	<content type="html">Hi Matthieu,
&lt;br&gt;&lt;br&gt;I'll be helping you with this issue.
&lt;br&gt;&lt;br&gt;Thanks and regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Sebastian Canevari
&lt;br&gt;Senior Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;7100 N Hwy 161, Irving, TX - 75039
&lt;br&gt;&amp;quot;Las Colinas - LC2&amp;quot;
&lt;br&gt;Tel: +1 469 775 7849
&lt;br&gt;e-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848918&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sebastc@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Matthieu Patou [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848918&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat+Informatique.Samba@...&lt;/a&gt;] 
&lt;br&gt;Sent: Friday, December 18, 2009 10:36 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848918&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; Interoperability Documentation Help; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848918&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: LDAP_SERVER_SD_FLAGS_OID control and search request
&lt;br&gt;&lt;br&gt;Hello,
&lt;br&gt;&lt;br&gt;While testing ADUC I found that this tool is using the control LDAP_SERVER_SD_FLAGS_OID when requesting object with no attributes (ie. 
&lt;br&gt;CN=Users,DC=home,DC=matws,DC=net) and expect to receive the nTSecurityDescriptor.
&lt;br&gt;Of course if you do not provide this control the nTSecurityDescriptor is not returned.
&lt;br&gt;&lt;br&gt;I tested this behavior with w2k3r2 and it is how this server behave.
&lt;br&gt;&lt;br&gt;Can you confirm that it's the expected behavior for this control and if possible can you document it if it's not already done.
&lt;br&gt;&lt;br&gt;Regards.
&lt;br&gt;&lt;br&gt;Matthieu.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848918&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/LDAP_SERVER_SD_FLAGS_OID-control-and-search-request-tp26846063p26848918.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26848395</id>
	<title>Re: [Pfif] SMB1 Trans2SetPathInfo() FileEndOfFileInformation is not enforcing share modes</title>
	<published>2009-12-18T11:22:01Z</published>
	<updated>2009-12-18T11:22:01Z</updated>
	<author>
		<name>Bill Wesse</name>
	</author>
	<content type="html">My pleasure - this was - and is - a very interesting topic!
&lt;br&gt;&lt;br&gt;By the way, I will be continuing my study of SMB_INFO_PASSTHROUGH and the Nt*Info calls. I expect to post a blog entry on the 'Microsoft Open Specification Support Team Blog' (&lt;a href=&quot;http://blogs.msdn.com/OpenSpecification/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blogs.msdn.com/OpenSpecification/&lt;/a&gt;) sometime in January.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Bill Wesse
&lt;br&gt;MCSE, MCTS / Senior Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;8055 Microsoft Way
&lt;br&gt;Charlotte, NC 28273
&lt;br&gt;TEL:  +1(980) 776-8200
&lt;br&gt;CELL: +1(704) 661-5438
&lt;br&gt;FAX:  +1(704) 665-9606
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Tim Prouty [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tim.prouty@...&lt;/a&gt;] 
&lt;br&gt;Sent: Friday, December 18, 2009 2:07 PM
&lt;br&gt;To: Bill Wesse
&lt;br&gt;Cc: Zachary Loafman; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Pfif] SMB1 Trans2SetPathInfo() FileEndOfFileInformation is not enforcing share modes
&lt;br&gt;&lt;br&gt;Bill, Thank you for diving into this issue and bringing clarity to how &amp;nbsp;
&lt;br&gt;others should be implementing this. &amp;nbsp;I sincerely appreciate your &amp;nbsp;
&lt;br&gt;dilligence!
&lt;br&gt;&lt;br&gt;-Tim
&lt;br&gt;&lt;br&gt;On Dec 18, 2009, at 5:38 AM, Bill Wesse wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Good morning Tim - development has responded to the TDI - thank you &amp;nbsp;
&lt;br&gt;&amp;gt; very much for finding and reporting this - as well as for the &amp;nbsp;
&lt;br&gt;&amp;gt; opportunity for us to improve our implementation and documentation! &amp;nbsp;
&lt;br&gt;&amp;gt; Please let me know if this answers your question satisfactorily; if &amp;nbsp;
&lt;br&gt;&amp;gt; so, I will consider your question resolved.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ==========
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The behavior exhibited on SMB1 regarding not receiving a sharing &amp;nbsp;
&lt;br&gt;&amp;gt; violation when doing a set of FileEndOfFileInformation when write &amp;nbsp;
&lt;br&gt;&amp;gt; sharing is disallowed is a bug in our server implementation.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This is something we will pursue fixing, and the behavior does not &amp;nbsp;
&lt;br&gt;&amp;gt; exist for the FID-based set info in SMB1 or the set-info command in &amp;nbsp;
&lt;br&gt;&amp;gt; SMB2. &amp;nbsp;We are investigating the best path to fix the issue and then &amp;nbsp;
&lt;br&gt;&amp;gt; update the documentation accordingly. &amp;nbsp;It seems to exist inside the &amp;nbsp;
&lt;br&gt;&amp;gt; Path-based SetInfo path.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ==========
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Bill Wesse
&lt;br&gt;&amp;gt; MCSE, MCTS / Senior Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt; 8055 Microsoft Way
&lt;br&gt;&amp;gt; Charlotte, NC 28273
&lt;br&gt;&amp;gt; TEL: &amp;nbsp;+1(980) 776-8200
&lt;br&gt;&amp;gt; CELL: +1(704) 661-5438
&lt;br&gt;&amp;gt; FAX: &amp;nbsp;+1(704) 665-9606
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Bill Wesse
&lt;br&gt;&amp;gt; Sent: Wednesday, December 16, 2009 2:05 PM
&lt;br&gt;&amp;gt; To: 'Tim Prouty'
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: [Pfif] SMB1 Trans2SetPathInfo() &amp;nbsp;
&lt;br&gt;&amp;gt; FileEndOfFileInformation is not enforcing share modes
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Indeed it is possible; NtQueryInformationFile with standard &amp;nbsp;
&lt;br&gt;&amp;gt; information levels does translate into passthrough levels on the &amp;nbsp;
&lt;br&gt;&amp;gt; wire (for SMB).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But, as I mentioned, I am still working on the test code, and &amp;nbsp;
&lt;br&gt;&amp;gt; haven't invoked NtSetInformationFile or other functions yet; I am &amp;nbsp;
&lt;br&gt;&amp;gt; iterating on test cases to gather error return information (which is &amp;nbsp;
&lt;br&gt;&amp;gt; a subject always dear to everyone's heart!). Of course, named pipes, &amp;nbsp;
&lt;br&gt;&amp;gt; directories and the various flavors of junction points do complicate &amp;nbsp;
&lt;br&gt;&amp;gt; this somewhat...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Bill Wesse
&lt;br&gt;&amp;gt; MCSE, MCTS / Senior Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt; 8055 Microsoft Way
&lt;br&gt;&amp;gt; Charlotte, NC 28273
&lt;br&gt;&amp;gt; TEL: &amp;nbsp;+1(980) 776-8200
&lt;br&gt;&amp;gt; CELL: +1(704) 661-5438
&lt;br&gt;&amp;gt; FAX: &amp;nbsp;+1(704) 665-9606
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Tim Prouty [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tim.prouty@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Wednesday, December 16, 2009 1:59 PM
&lt;br&gt;&amp;gt; To: Bill Wesse
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: [Pfif] SMB1 Trans2SetPathInfo() &amp;nbsp;
&lt;br&gt;&amp;gt; FileEndOfFileInformation is not enforcing share modes
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thank you for the update! &amp;nbsp;So if I understand what you're saying, it
&lt;br&gt;&amp;gt; is possible for a windows app to cause the the smb client to send the
&lt;br&gt;&amp;gt; passthrough levels over the wire using NtQueryInformationFile?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -Tim
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Dec 16, 2009, at 10:55 AM, Bill Wesse wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Good day Tim. I have just filed a Technical Documentation Issue
&lt;br&gt;&amp;gt;&amp;gt; (TDI) against the share mode issue requesting document update /
&lt;br&gt;&amp;gt;&amp;gt; guidance concerning SMB_INFO_PASSTHROUGH.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; My examination of our implementation indicates this situation should
&lt;br&gt;&amp;gt;&amp;gt; exist for all SET_PATH_INFORMATION information levels with
&lt;br&gt;&amp;gt;&amp;gt; SMB_INFO_PASSTHROUGH. I have not examined
&lt;br&gt;&amp;gt;&amp;gt; TRANS2_SET_FILE_INFORMATION or TRANS2_SET_FS_INFORMATION.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; [MS-SMB] and [MS-FSCC] provide no guidance concerning share
&lt;br&gt;&amp;gt;&amp;gt; circumvention for this or any other SMB_COM_TRANSACTION2
&lt;br&gt;&amp;gt;&amp;gt; subcommand / information level with SMB_INFO_PASSTHROUGH, other than
&lt;br&gt;&amp;gt;&amp;gt; to say 'the client is requesting a native Windows NT operating
&lt;br&gt;&amp;gt;&amp;gt; system information level' ([MS-SMB] 6 Appendix A: Product Behavior,
&lt;br&gt;&amp;gt;&amp;gt; note &amp;lt;155&amp;gt;).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Also, I have nearly completed a test app (C++) to exercise these as
&lt;br&gt;&amp;gt;&amp;gt; much as possible - NtQueryInformationFile indeed uses
&lt;br&gt;&amp;gt;&amp;gt; SMB_INFO_PASSTHROUGH values. I intend to profile Windows behavior
&lt;br&gt;&amp;gt;&amp;gt; against the information levels, and will provide all of that to you
&lt;br&gt;&amp;gt;&amp;gt; as soon as I can.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;&amp;gt; Bill Wesse
&lt;br&gt;&amp;gt;&amp;gt; MCSE, MCTS / Senior Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt;&amp;gt; 8055 Microsoft Way
&lt;br&gt;&amp;gt;&amp;gt; Charlotte, NC 28273
&lt;br&gt;&amp;gt;&amp;gt; TEL: &amp;nbsp;+1(980) 776-8200
&lt;br&gt;&amp;gt;&amp;gt; CELL: +1(704) 661-5438
&lt;br&gt;&amp;gt;&amp;gt; FAX: &amp;nbsp;+1(704) 665-9606
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: Bill Wesse
&lt;br&gt;&amp;gt;&amp;gt; Sent: Wednesday, December 09, 2009 10:56 AM
&lt;br&gt;&amp;gt;&amp;gt; To: 'Tim Prouty'
&lt;br&gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: RE: [Pfif] SMB1 Trans2SetPathInfo()
&lt;br&gt;&amp;gt;&amp;gt; FileEndOfFileInformation is not enforcing share modes
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Tim, - thanks for the updated smbtorture. I have reproduced the
&lt;br&gt;&amp;gt;&amp;gt; truncated SMB error response - see frames 132 &amp; 133 in the attached
&lt;br&gt;&amp;gt;&amp;gt; capture. I will create a new case for this, and begin debugging
&lt;br&gt;&amp;gt;&amp;gt; today (after verifying whether or not this happens against older
&lt;br&gt;&amp;gt;&amp;gt; Windows versions).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Frame: Number = 133, Captured Frame Length = 102, MediaType =
&lt;br&gt;&amp;gt;&amp;gt; ETHERNET
&lt;br&gt;&amp;gt;&amp;gt; + Ethernet: Etype = Internet IP
&lt;br&gt;&amp;gt;&amp;gt; + (IPv4),DestinationAddress:[00-15-5D-04-7B-03],SourceAddress:
&lt;br&gt;&amp;gt;&amp;gt; [00-15-5D-
&lt;br&gt;&amp;gt;&amp;gt; + 04-7B-09]
&lt;br&gt;&amp;gt;&amp;gt; + Ipv4: Src = 192.168.0.10, Dest = 192.168.0.21, Next Protocol = TCP,
&lt;br&gt;&amp;gt;&amp;gt; + Packet ID = 1552, Total IP Length = 88
&lt;br&gt;&amp;gt;&amp;gt; + Tcp: Flags=...AP..., SrcPort=Microsoft-DS(445), DstPort=47152,
&lt;br&gt;&amp;gt;&amp;gt; + PayloadLen=36, Seq=3281756320 - 3281756356, Ack=267797329, Win=510
&lt;br&gt;&amp;gt;&amp;gt; + (scale factor 0x8) = 130560
&lt;br&gt;&amp;gt;&amp;gt; + SMBOverTCP: Length = 32
&lt;br&gt;&amp;gt;&amp;gt; - Smb: R - DOS OS Error, (124) INVALID_LEVEL
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; Protocol: SMB
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; Command: Transact2 50(0x32)
&lt;br&gt;&amp;gt;&amp;gt; + DOSError: DOS OS Error - (124) INVALID_LEVEL
&lt;br&gt;&amp;gt;&amp;gt; - SMBHeader: Response, TID: 0x0800, PID: 0x77C9, UID: 0x0800, MID:
&lt;br&gt;&amp;gt;&amp;gt; 0x0008
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;+ Flags: 136 (0x88)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;+ Flags2: 34819 (0x8803)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;PIDHigh: 0 (0x0)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;SecuritySignature: 0x0
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;Unused: 0 (0x0)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;TreeID: 2048 (0x800)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;ProcessID: 30665 (0x77C9)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;UserID: 2048 (0x800)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;MultiplexID: 8 (0x8)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;&amp;gt; Bill Wesse
&lt;br&gt;&amp;gt;&amp;gt; MCSE, MCTS / Senior Escalation Engineer, US-CSS DSC PROTOCOL TEAM
&lt;br&gt;&amp;gt;&amp;gt; 8055 Microsoft Way
&lt;br&gt;&amp;gt;&amp;gt; Charlotte, NC 28273
&lt;br&gt;&amp;gt;&amp;gt; TEL: &amp;nbsp;+1(980) 776-8200
&lt;br&gt;&amp;gt;&amp;gt; CELL: +1(704) 661-5438
&lt;br&gt;&amp;gt;&amp;gt; FAX: &amp;nbsp;+1(704) 665-9606
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: Tim Prouty [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tim.prouty@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt; Sent: Tuesday, December 08, 2009 12:55 PM
&lt;br&gt;&amp;gt;&amp;gt; To: Bill Wesse
&lt;br&gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: [Pfif] SMB1 Trans2SetPathInfo()
&lt;br&gt;&amp;gt;&amp;gt; FileEndOfFileInformation is not enforcing share modes
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thank you for your diligence on this Bill and the answers you have
&lt;br&gt;&amp;gt;&amp;gt; provided. &amp;nbsp;I have some responses inline below.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Dec 8, 2009, at 6:07 AM, Bill Wesse wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Is #3 actually correct behavior that other servers should implement?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; If so, can the cases where share modes are not enforced be &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; enumerated
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; in the documentation?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Response:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; #3 is correct behavior. Sending an SMB_COM_TRANSACTION2 request for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SET_PATH_INFORMATION with SMB_INFO_PASSTHROUGH +
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; FileEndOfFileInformation is functionally equivalent to a remote call
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; to NtSetInformationFile.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; NtSetInformationFile sends an IRP_MJ_SET_INFORMATION request to the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; file system driver in question; this does not involve the usual I/O
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Manager ShareMode checks.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I share the same sentiment as Zach on this behavior, but it is
&lt;br&gt;&amp;gt;&amp;gt; definitely useful to know how windows handles this. &amp;nbsp;Are there plans
&lt;br&gt;&amp;gt;&amp;gt; for this to be documented anywhere or does it receive documentation
&lt;br&gt;&amp;gt;&amp;gt; exemption since this is passthrough-speceific?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; = 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ====================================================================
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Question:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; If a client can send a particular info level and windows implements
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; it, then we have a compatibility problem if we choose not to support
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; it. &amp;nbsp;What I would really like to know is if other SMB &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; implementations
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; need to circumvent share-mode checks for this pass through level &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; maybe others?).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Response:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; This should be the case for all supported SMB_INFO_PASSTHROUGH
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; levels,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; as they run through the same essential logic.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; However, I have additional testing to perform before I can &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; completely
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; confirm this.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I am interested to know the results of your testing. &amp;nbsp;I believe
&lt;br&gt;&amp;gt;&amp;gt; there are some tests in RAW-OPLOCKS that use the rename passthrough
&lt;br&gt;&amp;gt;&amp;gt; level to test oplocks, but implicitly rely on share modes not being
&lt;br&gt;&amp;gt;&amp;gt; enforced for the rename passthrough. &amp;nbsp;RAW-OPLOCK-BATCH19, 20 and 21
&lt;br&gt;&amp;gt;&amp;gt; are good ones to look at.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; = 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ====================================================================
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Question:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 1. Packet 40 appears to have the WordCount and ByteCount truncated,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp;making the packet smaller than normal minimum size of 35? &amp;nbsp;Is this
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp;intended behavior that other servers should implement?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Additionally a DOS Error is returned instead of a standard NT_STATUS
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; error. &amp;nbsp;MS-CIFS does say that a DOS error or an NT_STATUS error may
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; be
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; returned, but I don't see any indication in the documentation of &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; when
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; a DOS error should be returned instead of an NT_STATUS error. &amp;nbsp;Is it
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; possible to make this explicit in the docs or is this a case where
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; it's purposefully left ambiguous?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Response:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The WordCount/ByteCount truncation against the Dos INVALID_LEVEL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; error
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; problem
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (trans2setpathinfo_against_win7_2.pcap) you saw did not reproduce
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; my clients (who succeeded against the call).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I have attached a zip file with your trace
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (trans2setpathinfo_against_win7_2.pcap), and my equivalent trace
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (test_trans2setpathinfo_Win7.pcap). Mine does not have that second
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Set
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; EOF call. Do I need a newer build of smbtorture (my current one from
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; you is samba.2009.12.01.tar.gz)?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In comparing the pcaps, it does indeed appear that the version of
&lt;br&gt;&amp;gt;&amp;gt; smbtorture you're running doesn't include the most recent version of
&lt;br&gt;&amp;gt;&amp;gt; RAW-SFILEIFNO-END-OF-FILE. &amp;nbsp;Packet 54 in your trace corresponds to
&lt;br&gt;&amp;gt;&amp;gt; packet 33 in my trace which is sending the SNIA CIFS EOF level
&lt;br&gt;&amp;gt;&amp;gt; rather than the passthrough. &amp;nbsp;Packet 39 in my trace is the
&lt;br&gt;&amp;gt;&amp;gt; setpathinfo EOF passthrough level that is actually getting the
&lt;br&gt;&amp;gt;&amp;gt; strange error, and there is no corresponding packet in your trace.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'll get you the most recent code drop in a private channel.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -Tim
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26848395&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SMB1-Trans2SetPathInfo%28%29-FileEndOfFileInformation-is-not-enforcing-share-modes-tp26505065p26848395.html" />
</entry>

</feed>
