<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-13150</id>
	<title>Nabble - Samba</title>
	<updated>2009-11-23T20:13:48Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Samba-f13150.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-f13150.html" />
	<subtitle type="html">Samba is software that can be run on a platform other than Microsoft Windows, for example, UNIX, Linux, IBM System 390, OpenVMS, and other operating systems. Samba uses the TCP/IP protocol that is installed on the host server. When correctly configured, it allows that host to interact with a Microsoft Windows client or server as if it is a Windows file and print server. Samba home is &lt;a href=&quot;http://samba.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26490247</id>
	<title>Re: [OT] Remote control powerboard</title>
	<published>2009-11-23T20:13:48Z</published>
	<updated>2009-11-23T20:13:48Z</updated>
	<author>
		<name>Kevin Pulo</name>
	</author>
	<content type="html">On Tue, Nov 24, 2009 at 12:17:19PM +1100, Rainer Klein wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; There are commercial products. 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; In mid October, Aldi had on special &amp;quot;Digital Home System&amp;quot; product with 4 
&lt;br&gt;&amp;gt; remote controlled powerboards and a simple remote. Each of those boards 
&lt;br&gt;&amp;gt; consume less than 1 Watt and come with a build-in on-/off-switch.
&lt;br&gt;&lt;br&gt;Do you know if there are any where the &amp;quot;simple remote&amp;quot; includes
&lt;br&gt;software monitoring and control, eg. usb/serial/whatever...?
&lt;br&gt;&lt;br&gt;Kev.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;.----------------------------------------------------------------------.
&lt;br&gt;| Kevin Pulo &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Quidquid latine dictum sit, altum viditur. |
&lt;br&gt;| &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26490247&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kev@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; _ll l_ng__g_e_ _r_ hi__ly p__d_ct__le. |
&lt;br&gt;| &lt;a href=&quot;http://www.kev.pulo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kev.pulo.com.au/&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;God casts the die, not the dice. |
&lt;br&gt;`--------------- Linux: The choice of a GNU generation. ---------------'
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26490247&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26490247/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OT--Remote-control-powerboard-tp26157082p26490247.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26490168</id>
	<title>Re: Fwd: Vista laptop in Samba 3.3.4 domain suddenly trying to use roaming profiles?</title>
	<published>2009-11-23T19:51:12Z</published>
	<updated>2009-11-23T19:51:12Z</updated>
	<author>
		<name>Paul Venzke</name>
	</author>
	<content type="html">On Mon November 23 2009 15:27, David Whitney wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;nbsp;Hi, and thanks for your interest!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am still using an smbpasswd backend because this is a very small
&lt;br&gt;&amp;gt; home network I maintain for my own educational purposes, although I
&lt;br&gt;&amp;gt; might migrate to LDAP at some point for the same reason.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have manually changed the troublesome profile type from roaming
&lt;br&gt;&amp;gt; to local, but when I logged back in from that same profile, it
&lt;br&gt;&amp;gt; switched back to roaming! The more I read about this bizarre
&lt;br&gt;&amp;gt; behavior, the more I start to suspect the possibility of malware or
&lt;br&gt;&amp;gt; virus, which is what I plan to investigate tonight.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; As far as the logon scripts go, the irony is that the script
&lt;br&gt;&amp;gt; actually fired from my admin-prived logon, but could not
&lt;br&gt;&amp;gt; access/load the &amp;quot;right&amp;quot; profile from the local box. They still
&lt;br&gt;&amp;gt; don't fire from my desktop boxes. Per your question, I can access
&lt;br&gt;&amp;gt; and execute the scripts from the desktop with no problem. Per other
&lt;br&gt;&amp;gt; sources, it appears that the necessary privs to the netlogon
&lt;br&gt;&amp;gt; directory should be 755, (rwxr-xr-x), which is what I have set and
&lt;br&gt;&amp;gt; verified.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Again, many thanks for your interest and suggestions.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Mon, Nov 23, 2009 at 1:16 PM, Gaiseric Vandal
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26490168&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gaiseric.vandal@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&amp;gt; &amp;gt; This happened to us when we switched from TDB to LDAP backend. &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt; (Samba 3.03x) &amp;nbsp; I suspect that for some users sambaProfilePath
&lt;br&gt;&amp;gt; &amp;gt; may have had space character but wasn't actually &amp;nbsp;null. &amp;nbsp; For
&lt;br&gt;&amp;gt; &amp;gt; some users we just deleted the sambaProfilePath attribute.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; You may need to change the profile type on the users computer
&lt;br&gt;&amp;gt; &amp;gt; from roaming back to local. &amp;nbsp;(On XP, right-click My Computer-&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Properties-&amp;gt;Advanced-&amp;gt;User Profiles.)
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Login scripts could be several things
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;share and file permissions for the netlogon directory
&lt;br&gt;&amp;gt; &amp;gt; should probably allow everyone read-only.
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;I usually add a &amp;quot;pause&amp;quot; command in the login script when
&lt;br&gt;&amp;gt; &amp;gt; troubleshooting
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;You need to specify the logon script as part of the user's
&lt;br&gt;&amp;gt; &amp;gt; account. (In LDAP, SambaLogonScript attribute &amp;nbsp;I don't think you
&lt;br&gt;&amp;gt; &amp;gt; can a default logon script.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; From an XP session, can you go to the netlogon share and run the
&lt;br&gt;&amp;gt; &amp;gt; logon script?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; On 11/23/09 10:03, David Whitney wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Grettings, all
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I have a bizarre problem on a laptop in my Samba 3.3.4 domain.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; This domain includes a mixture of XP Pro and Vista Ultimate
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; clients.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I had just completed a migration to this new domain (from a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Samba 2.2.8a domain), and all seemed happy and well - machines
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; had rebooted and were still active in the domain, users were
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; logging in with no problem, shares were working perfectly - all
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; over the span of a week or so - until last night.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Trying to log into my wife's laptop (Vista Ultimate) under her
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; account, I got an odd message that said &amp;quot;Your roaming profile
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; was not completely synchronized. Please contact your
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; administrator.&amp;quot; The only problem is I am *not* using roaming
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; profiles in my Samba domain! And this account had logged
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; into the domain several times on this laptop with no problem
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; after the migration.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I looked on the home shares for the particular account, and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; surely enough there is the &amp;quot;profile.V2&amp;quot; folder indicating what I
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; understand is the attempt
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; by a Vista box to build a first-time Vista-style roaming profile
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; on my Samba-defined user share. I logged in under a different
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; account that has admin privs, and sure enough, it tried to load
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; a roaming profile there, too.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; That told me, additionally, that Vista thought this was the
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; first time this
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; user had logged into that box/domain, which was obviously
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; incorrect. The profiles for each user that had used until that
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; point were on the machine, intact.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I've changed the local policy on that box to disallow roaming
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; profiles expressly, but now the local profiles that had been
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; working just fine are no
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; longer associated with their proper users, and I'm not sure how
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; to restore the association (or even if I can). I can browse the
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; machine remotely and copy the files from that local profile if I
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; have to, but I'd like to avoid it.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Could the learned folks here offer any suggestions on why this
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; laptop would
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; suddenly think it was supposed to use roaming profiles on my
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; non-roaming-profile Samba domain? Is there some mystery setting
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; in smb.conf
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I might possibly have set (or perhaps deleted??) that would
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; leave Samba thinking was trying to use roaming profiles? Based
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; on late-night research, I
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; expressly set &amp;quot;logon path&amp;quot; to be blank in smb.conf, which is
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; supposed to disable Samba roaming profiles. It had not been
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; expressly set before. I have
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; logged into a desktop box and it worked normally.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Appreciate any thoughts or suggestions. The desktop boxes, so
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; far, seem unaffected and are working normally. I'm thinking my
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; next step is to copy the files from the particular profile in
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; question, remove the machine from the domain, and then rejoin
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; it, but I'm not sure I still won't have the same
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; problem.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; The only other problem I've had in this migration was in getting
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; logon scripts to work (which I never did), but I don't think
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; this is related to that issue....and the fact that other than
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; scripts the domain was working fine is what really has me
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; puzzled.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Any thoughts or suggestions appreciated.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; -David
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; To unsubscribe from this list go to the following URL and read
&lt;br&gt;&amp;gt; &amp;gt; the instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;/div&gt;David;
&lt;br&gt;We have similar problems with Vista using the wrong profile. Although 
&lt;br&gt;the situations that caused the problem are a bit different from yours 
&lt;br&gt;the answer was to use &amp;quot;regedit&amp;quot; to adjust the profile path. &amp;nbsp;Before 
&lt;br&gt;you do this BACK UP the registry just in case you need to roll back.
&lt;br&gt;&lt;br&gt;Use regedit to change this key:
&lt;br&gt;&lt;br&gt;hkey_local_machine/software/Microsoft/WindowsNT/currentversion/Profilelist/&amp;lt;your 
&lt;br&gt;users SID&amp;gt;/ 
&lt;br&gt;&lt;br&gt;Local user have no entry: CentralProfile, if this is present I think 
&lt;br&gt;just removing it will keep the machine from looking on the server. &amp;nbsp;
&lt;br&gt;Make sure the entries here conform with the other local users. Make 
&lt;br&gt;sure the &amp;quot;ProfileImagePath&amp;quot; points to the local profile:
&lt;br&gt;C:Users\&amp;lt;username&amp;gt; 
&lt;br&gt;-- 
&lt;br&gt;PV
&lt;br&gt;&lt;br&gt;&amp;quot;We have met the enemy and he is us&amp;quot;; Pogo
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vista-laptop-in-Samba-3.3.4-domain-suddenly-trying-to-use-roaming-profiles--tp26479634p26490168.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26489851</id>
	<title>Re: samba 3.4.3  DC breaks Windows groups</title>
	<published>2009-11-23T19:06:34Z</published>
	<updated>2009-11-23T19:06:34Z</updated>
	<author>
		<name>Gaiseric Vandal</name>
	</author>
	<content type="html">On the assumption that Unix systems (solaris and linux) will not like spaces
&lt;br&gt;in names, I never created unix groups called &amp;quot;Domain Admins&amp;quot; and &amp;quot;Domain
&lt;br&gt;Users&amp;quot; etc. &amp;nbsp;Instead I had &amp;nbsp;created &amp;quot;smb_domadmins&amp;quot; and &amp;quot;smb_domusers&amp;quot; etc
&lt;br&gt;instead. &amp;nbsp; 
&lt;br&gt;&lt;br&gt;I don't know if Windows systems actually pay attention to the name of the
&lt;br&gt;group (e.g. &amp;quot;Domain Admins&amp;quot;) or just the SID (e.g. S-1-5-21-****-512.)
&lt;br&gt;We would have a similar issue with a group like &amp;quot;Human Resources&amp;quot; but not
&lt;br&gt;with &amp;quot;Marketing.&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;On samba 3.0.x, setting &amp;quot;ldap group suffix&amp;quot; parameter is honored. &amp;nbsp;On Samba
&lt;br&gt;3.4.x it seems to be ignored- &amp;nbsp;instead samba seems to read the entire ldap
&lt;br&gt;tree (or at least from the &amp;quot;ldap suffix&amp;quot; parameter down.) &amp;nbsp; &amp;nbsp; &amp;quot;pbedit -Lv
&lt;br&gt;Administrator&amp;quot; on samba 3.4 will then complain about duplicate entries
&lt;br&gt;&lt;br&gt;BDC2# pdbedit -Lv Administrator
&lt;br&gt;smbldap_search_domain_info: Searching
&lt;br&gt;for:[(&amp;(objectClass=sambaDomain)(sambaDomainName=MYDOMAIN))]
&lt;br&gt;smbldap_open_connection: connection opened
&lt;br&gt;ldap_connect_system: successful connection to the LDAP server
&lt;br&gt;init_sam_from_ldap: Entry found for user: Administrator
&lt;br&gt;ldapsam_getgroup: Duplicate entries for filter
&lt;br&gt;(&amp;(objectClass=sambaGroupMapping)
&lt;br&gt;(gidNumber=512)): count=2
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Since in this case if have both of the following objects in ldap
&lt;br&gt;&lt;br&gt;dn: cn=Domain Admins,ou=smb_groups,o=mydomain.com
&lt;br&gt;objectClass: posixGroup
&lt;br&gt;objectClass: sambaGroupMapping
&lt;br&gt;objectClass: top
&lt;br&gt;cn: Domain Admins
&lt;br&gt;description: Domain Admins
&lt;br&gt;displayName: Domain Admins
&lt;br&gt;gidNumber: 512
&lt;br&gt;sambaGroupType: 2
&lt;br&gt;sambaSID: S-1-5-21-******-512
&lt;br&gt;&lt;br&gt;AND
&lt;br&gt;&lt;br&gt;dn: cn=smb_domadmins,ou=group,o=mydomain.com
&lt;br&gt;objectClass: top
&lt;br&gt;objectClass: posixGroup
&lt;br&gt;objectClass: sambaGroupMapping
&lt;br&gt;objectClass: groupOfUniqueNames
&lt;br&gt;cn: domadmins
&lt;br&gt;description: domadmins
&lt;br&gt;displayName: domadmins
&lt;br&gt;gidNumber: 512
&lt;br&gt;memberUid: Administrator
&lt;br&gt;.
&lt;br&gt;sambaGroupType: 2
&lt;br&gt;sambaSID:
&lt;br&gt;...
&lt;br&gt;&lt;br&gt;&lt;br&gt;I also noticed the following
&lt;br&gt;&lt;br&gt;Output from pdbedit on samba 3.4.x &amp;nbsp;includes
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; ldapsam_getgroup
&lt;br&gt;&lt;br&gt;Output from pdbedit on samba 3.0.x includes
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;init_group_from_ldap
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I am not sure if that is somehow related. &amp;nbsp;
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Gaiseric Vandal [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489851&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gaiseric.vandal@...&lt;/a&gt;] 
&lt;br&gt;Sent: Monday, November 23, 2009 4:41 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489851&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba@...&lt;/a&gt;
&lt;br&gt;Subject: samba 3.4.3 DC breaks Windows groups
&lt;br&gt;&lt;br&gt;I have the following setup:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;PDC: &amp;nbsp;Samba 3.0.37 on Solaris 10
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;BDC1: Samba 3.0.37 on Solaris 10
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;BDC2: Samba 3.4.3 on Solaris 10
&lt;br&gt;&lt;br&gt;&lt;br&gt;Samba 3.0.37 is the bundled version of Samba.
&lt;br&gt;Samba 3.4.3 is compiled from source.
&lt;br&gt;&lt;br&gt;BDC2 is a recent addition to the network.
&lt;br&gt;All machine use LDAP as the backend for everything. &amp;nbsp;They use winbind to
&lt;br&gt;handle a domain trust with another domain, but otherwise isn't needed.
&lt;br&gt;&lt;br&gt;On BDC2, &amp;nbsp;users do not appear to be in any groups &amp;nbsp;beyond Domain Users.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Group mapping seems OK on each DC.
&lt;br&gt;&lt;br&gt;BDC2# net groupmap list
&lt;br&gt;Domain Admins (S-1-5-21-xxxxx-xxxxx-512) -&amp;gt; smb_domadmins
&lt;br&gt;Domain Users (S-1-5-21-xxxxx-xxxxx-513) -&amp;gt; smb_domusers
&lt;br&gt;Domain Guests (S-1-5-21-xxxxx-xxxxx9-514) -&amp;gt; smb_domguests
&lt;br&gt;Domain Computers (S-1-5-21-xxxxx-xxxxx-515) -&amp;gt; smb_machines
&lt;br&gt;Domain Controllers (S-1-5-21-xxxxx-xxxxx-516) -&amp;gt; smb_dc
&lt;br&gt;Domain Certificate Admins (S-1-5-21-xxxxx-xxxxx-517) -&amp;gt; smb_domcertadmins
&lt;br&gt;Builtin Admins (S-1-5-21-xxxxx-xxxxx-544) -&amp;gt; smb_admins
&lt;br&gt;Builtin users (S-1-5-21-xxxxx-xxxxx-545) -&amp;gt; smb_users
&lt;br&gt;Builtin Guests (S-1-5-21-xxxxx-xxxxx-546) -&amp;gt; smb_guests
&lt;br&gt;Administrators (S-xxxx-544) -&amp;gt; xxxx
&lt;br&gt;Users (S-xxxx-545) -&amp;gt; xxxx
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;The last two in the listing above were automatically created by 
&lt;br&gt;winbind/idmap for a trusted domain.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Unix level group memberships are OK
&lt;br&gt;&lt;br&gt;BDC2# groups Administrator
&lt;br&gt;smb_domadmins smb_domusers
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;Windows/Samba level group memberships are not
&lt;br&gt;&lt;br&gt;BDC2# net rpc user info Administrator -U Administrator -S PDC
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;Domain Admins
&lt;br&gt;Domain Users
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc user info Administrator -U Administrator -S BDC2
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;Domain Users
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;&lt;br&gt;Same deal with regular users
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Nt. &amp;nbsp;Not all unix groups are mapped to Windows groups. &amp;nbsp;However I 
&lt;br&gt;believe all required &amp;quot;well known&amp;quot; windows groups are.
&lt;br&gt;&lt;br&gt;Ldap structure includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=people
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=group
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=smb_groups (where samba stores group mappings, ldap 
&lt;br&gt;objectClass=sambaGroupMapping)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;You can verify machine PDC or BDC is being used by an Windows client 
&lt;br&gt;with the &amp;quot;echo %LOGONSERVER%&amp;quot; command.
&lt;br&gt;&lt;br&gt;&lt;br&gt;If I logon as Domain Administrator to an &amp;nbsp;XP or Win 2003 machine that is 
&lt;br&gt;using BDC2, I will not have any Administrator privileges.
&lt;br&gt;&lt;br&gt;&lt;br&gt;smb.conf includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ldap group suffix = ou=smb_groups
&lt;br&gt;&lt;br&gt;&lt;br&gt;(When I converted from tdb to ldap backend, &amp;nbsp;I already had unix groups 
&lt;br&gt;in ldap and wasn't sure how stuff would import. &amp;nbsp; &amp;nbsp; I don't think 
&lt;br&gt;existing groups or group mappings imported so I had to manually retype 
&lt;br&gt;the &amp;quot;net group map commands.&amp;quot; &amp;nbsp;)
&lt;br&gt;&lt;br&gt;The &amp;quot;Domain Admins&amp;quot; sambaGroupMapping does include Administrator as a 
&lt;br&gt;member.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc group members &amp;quot;Domain Admins&amp;quot; -U Administrator -S PDC
&lt;br&gt;MYDOMAIN\Administrator
&lt;br&gt;MYDOMAIN\jsmith
&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc group members &amp;quot;Domain Admins&amp;quot; -U Administrator -S BDC2
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;MYDOMAIN\Administrator
&lt;br&gt;MYDOMAIN\jsmith
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/samba-3.4.3--DC-breaks-Windows-groups-tp26486416p26489851.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26489708</id>
	<title>Re: PATCHS: manipulation of NT ACL in command line</title>
	<published>2009-11-23T18:46:22Z</published>
	<updated>2009-11-23T18:46:22Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Fri, 2009-11-20 at 17:55 +0300, Matthieu Patou wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello, this is a rework of this,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 0001-s4-utils-recreate-setntacl-and-improve-setntacl.patch,Creation of 
&lt;br&gt;&amp;gt; the setntacl utils which allow to set the NTACL from commandline from 
&lt;br&gt;&amp;gt; its SDDL representation. It also add the option to export the NTACL as a 
&lt;br&gt;&amp;gt; SDDL
&lt;br&gt;&amp;gt; 0002-s4-Create-torture-test-for-samba-utils.patch: This patch a simple 
&lt;br&gt;&amp;gt; torture test for getntacl and setntacl.
&lt;br&gt;&amp;gt; 0003-s4-Create-a-library-for-xattr-python-bindings.patch: This patch 
&lt;br&gt;&amp;gt; allow to create a .so with the python binding generated code for xattr.idl
&lt;br&gt;&amp;gt; 0004-s4-add-python-bindings-for-wrap_-s-g-etxattr.patch: This patch 
&lt;br&gt;&amp;gt; allow to create a .so with the python binding generated code for xattr.idl
&lt;br&gt;&amp;gt; 0005-s4-Create-unit-tests-for-python-samba.xattr-module.patch: Unit 
&lt;br&gt;&amp;gt; tests for the above stuff
&lt;br&gt;&amp;gt; 0006-s4-regroup-gpo-modification-in-one-function-set-acl-.patch: Use the 
&lt;br&gt;&amp;gt; above functions for setacl on GPO objects.
&lt;/div&gt;&lt;/div&gt;What happens on systems without the xattrs?
&lt;br&gt;&lt;br&gt;You may need to skip the tests like we do on systems without gnutls
&lt;br&gt;&lt;br&gt;Otherwise, the patch looks good. &amp;nbsp;
&lt;br&gt;&lt;br&gt;Jelmer: Any comments?
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26489708/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PATCHS%3A-manipulation-of-NT-ACL-in-command-line-tp26279294p26489708.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26489621</id>
	<title>Re: Commit: 1169dd3b50dfefa59b56cd1897bcd0b6c2ffb3be</title>
	<published>2009-11-23T18:31:45Z</published>
	<updated>2009-11-23T18:31:45Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Mon, 2009-11-23 at 15:52 -0200, Crístian Viana wrote:
&lt;br&gt;&amp;gt; does the attached patch fix the problem? I'm not very familiar with talloc
&lt;br&gt;&amp;gt; memory stealing yet.
&lt;br&gt;&lt;br&gt;It looks alright. &amp;nbsp;I think it should consider that
&lt;br&gt;ldb_dn_alloc_linearized() might fail, and return an error in that case.
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26489621/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Commit%3A-1169dd3b50dfefa59b56cd1897bcd0b6c2ffb3be-tp26439784p26489621.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26489068</id>
	<title>Re: November Canberra Linux Users Group meeting [SEC=PERSONAL]</title>
	<published>2009-11-23T17:19:07Z</published>
	<updated>2009-11-23T17:19:07Z</updated>
	<author>
		<name>Roppola, Antti - BRS-2</name>
	</author>
	<content type="html">&lt;br&gt;I *suspect* that infinitely configurable is easy, but getting that
&lt;br&gt;precisely tuned heat uniformly applied to every bean in your roaster is
&lt;br&gt;the harder part. That'd be a mechanical engineering or physics problem.
&lt;br&gt;&lt;br&gt;Most roasters appear to fix this by randomising the beans so they don't
&lt;br&gt;linger in hot/cold spots. Like via a rotating drum or a hot air jet.
&lt;br&gt;&lt;br&gt;Unfortunately I have other commitments that night so it looks like I'll
&lt;br&gt;miss out. :o(
&lt;br&gt;&lt;br&gt;Antti
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;Jm's friend commented:
&lt;br&gt;&lt;br&gt;Even the pricey home roasters (Hottop for instance, ~$1700
&lt;br&gt;&lt;a href=&quot;http://www.dibartoli.com.au/product_details.asp?pid=340&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dibartoli.com.au/product_details.asp?pid=340&lt;/a&gt;) are still
&lt;br&gt;pretty clunky in their temp control. &amp;nbsp;Having something that is more
&lt;br&gt;infinitely configurable would be a good thing (and rather sellable, I
&lt;br&gt;would have thought).
&lt;br&gt;&lt;br&gt;&lt;br&gt;------
&lt;br&gt;IMPORTANT - This message has been issued by The Department of Agriculture, Fisheries and Forestry (DAFF). The information transmitted is for the use of the intended recipient only and may contain sensitive and/or legally privileged material. It is your responsibility to check any attachments for viruses and defects before opening or sending them on. 
&lt;br&gt;&lt;br&gt;Any reproduction, publication, communication, re-transmission, disclosure, dissemination or other use of the information contained in this e-mail by persons or entities other than the intended recipient is prohibited. The taking of any action in reliance upon this information by persons or entities other than the intended recipient is prohibited. If you have received this e-mail in error please notify the sender and delete all copies of this transmission together with any attachments. If you have received this e-mail as part of a valid mailing list and no longer want to receive a message such as this one advise the sender by return e-mail accordingly. Only e-mail correspondence which includes this footer, has been authorised by DAFF 
&lt;br&gt;&lt;br&gt;------
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489068&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/November-Canberra-Linux-Users-Group-meeting-tp26486760p26489068.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26489193</id>
	<title>Re: [OT] Remote control powerboard</title>
	<published>2009-11-23T17:17:19Z</published>
	<updated>2009-11-23T17:17:19Z</updated>
	<author>
		<name>Bugzilla from rklein@tpg.com.au</name>
	</author>
	<content type="html">There are commercial products. 
&lt;br&gt;&lt;br&gt;In mid October, Aldi had on special &amp;quot;Digital Home System&amp;quot; product with 4 
&lt;br&gt;remote controlled powerboards and a simple remote. Each of those boards 
&lt;br&gt;consume less than 1 Watt and come with a build-in on-/off-switch.
&lt;br&gt;&lt;br&gt;If someone is interested, I can bring an example to our next meeting.
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;&lt;br&gt;Rainer
&lt;br&gt;&lt;br&gt;On Wed, 18 Nov 2009, David Schoen wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I bought a switch just like the one you've linked to from one of the
&lt;br&gt;&amp;gt; Hardware stores in Belconnen. Most hardware/electrical stores (I've
&lt;br&gt;&amp;gt; even seen a couple of supermarkets stocking them) should have
&lt;br&gt;&amp;gt; something like that.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I didn't actually use my in line switch in line though.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I had somethign like (excuse ascii art):
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Junction |
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp;box &amp;nbsp; |
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Plug N ------------------- power board
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;E -------------------
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;A -------| &amp;nbsp;|--------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Switch
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Depending on the switch you should be easily able to block one end and
&lt;br&gt;&amp;gt; run both wires out one end of the switch. I think I had to reuse the
&lt;br&gt;&amp;gt; earth or the neutral terminator in my switch to avoid cutting/removing
&lt;br&gt;&amp;gt; bits of plastic, but from the outside it looks fairly normal. It's
&lt;br&gt;&amp;gt; been working for my Mum's lounge room set up for years now.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If you want really simple, there's a Cabac PB80 [0] sitting under my
&lt;br&gt;&amp;gt; desk at work right now that I can easily turn on and off with my foot.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers,
&lt;br&gt;&amp;gt; Dave
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [0] &lt;a href=&quot;http://www.dealsdirect.com.au/p/power-surge-protector-8-outlets/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dealsdirect.com.au/p/power-surge-protector-8-outlets/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2009/11/17 Alex Satrapa &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489193&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;alexsatrapa@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; &amp;gt; On 17/11/2009, at 08:55 , David Schoen wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; The simplest way is just to get a standard in line switch (like you
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; get on the cable running to a desk lamp) and run the active wire from
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; somewhere before it enters a power board and back again.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; That's the solution I was hoping to find, but I can't for the life of me
&lt;br&gt;&amp;gt; &amp;gt; find any extension cables that have inline switches.  There are options
&lt;br&gt;&amp;gt; &amp;gt; for DIY though[1]!
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Guess I'll go for the inline switch option, since there's much less
&lt;br&gt;&amp;gt; &amp;gt; chance of losing the switch and not being able to turn off the power ;)
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Alex
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; [1]
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.electusdistribution.com.au/productView.asp?ID=2411&amp;CATID=35&amp;ke&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.electusdistribution.com.au/productView.asp?ID=2411&amp;CATID=35&amp;ke&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt;ywords=&amp;SPECIAL=&amp;form=CAT&amp;SUBCATID=172
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; linux mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489193&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26489193&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OT--Remote-control-powerboard-tp26157082p26489193.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26488530</id>
	<title>Re: migrating NT4 PDC net rpc vampire errors with capital letters</title>
	<published>2009-11-23T16:17:17Z</published>
	<updated>2009-11-23T16:17:17Z</updated>
	<author>
		<name>John H Terpstra - Samba Team</name>
	</author>
	<content type="html">Ryan Davis wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have searched for days on Google and can't find a clear answer to my
&lt;br&gt;&amp;gt; question. &amp;nbsp;I have a &amp;nbsp;NT4 PDC which I am migrating to Samba 3 (Version
&lt;br&gt;&amp;gt; 3.4.2-47.fc12) on FC12 with kernel(2.6.31.5-127.fc12.i686). &amp;nbsp;I am using
&lt;br&gt;&amp;gt; tdbsam as my passdb backend.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I setup Samba as a BDC and then joined to NT4 Domain succesfully. &amp;nbsp;When I go
&lt;br&gt;&amp;gt; to vampire the accounts I get lots of errors and some user accounts get
&lt;br&gt;&amp;gt; transfered over. &amp;nbsp;It turns that all the user accounts that transfer are
&lt;br&gt;&amp;gt; those that don't have a capital letter in their username on the NT4 domain
&lt;br&gt;&amp;gt; server. &amp;nbsp;Most do and don't get transfered. &amp;nbsp;There seems to be errors with my
&lt;br&gt;&amp;gt; groups and Computer accounts. &amp;nbsp;I was able in the past to vampire all the
&lt;br&gt;&amp;gt; accounts (even capital letters) so any ideas would be great.
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;Some Linux systems will not allow creation of user or group accounts
&lt;br&gt;that have uppercase characters or spaces in them. &amp;nbsp;OpenSUSE 11.2 does
&lt;br&gt;not have this limitation. &amp;nbsp;Perhaps you can ask on the FedoraProject list
&lt;br&gt;to find how to disable the restriction against uppercase characters in
&lt;br&gt;user and group names. &amp;nbsp;While it is an admirable intention of some Linux
&lt;br&gt;distros to stop users from creating stupid account names, when migrating
&lt;br&gt;from MS Windows this is a real handicap.
&lt;br&gt;&lt;br&gt;- John T.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thanks in advance.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here is a type of error I get:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Creating account: Ryan
&lt;br&gt;&amp;gt; useradd: invalid user name 'Ryan'
&lt;br&gt;&amp;gt; fetch_account: Running the command `/usr/sbin/useradd -m 'Ryan'' gave 3
&lt;br&gt;&amp;gt; Could not create posix account info for 'Ryan'
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I get this error for groups:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Creating unix group: 'SophosDomainPowerUser'
&lt;br&gt;&amp;gt; groupadd: 'SophosDomainPowerUser' is not a valid group name
&lt;br&gt;&amp;gt; smb_create_group: Running the command `/usr/sbin/groupadd
&lt;br&gt;&amp;gt; 'SophosDomainPowerUser'' gave 3
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; and for Computer names:
&lt;br&gt;&amp;gt; Creating account: LIMS1$
&lt;br&gt;&amp;gt; useradd: invalid user name 'LIMS1$'
&lt;br&gt;&amp;gt; fetch_account: Running the command `/usr/sbin/useradd -s /bin/false -d
&lt;br&gt;&amp;gt; /dev/null 'LIMS1$'' gave 3
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here is my smb.conf
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [global]
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;workgroup = GENOME1
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;netbios name = HERCULES
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;passdb backend = tdbsam
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;domain master = No
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;domain logons = Yes
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;os level = 40
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;add user script = /usr/sbin/useradd &amp;quot;%u&amp;quot; -n -g users
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;delete user script = /usr/sbin/userdel &amp;quot;%u&amp;quot;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;add group script = /usr/sbin/groupadd &amp;quot;%g&amp;quot;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;delete group script = /usr/sbin/groupdel &amp;quot;%g&amp;quot;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;add machine script = /usr/sbin/useradd -n -c &amp;quot;Workstation (%u)&amp;quot; -M -d
&lt;br&gt;&amp;gt; /nohome -s /bin/false &amp;quot;%u&amp;quot;
&lt;br&gt;&amp;gt; # &amp;nbsp; &amp;nbsp; username map = /etc/samba/smbusers
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;logon path =
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;logon home =
&lt;br&gt;&amp;gt; # &amp;nbsp; &amp;nbsp; wins support = yes
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [files]
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = SAMBA File Server
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; path = /files
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read only = No
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/migrating-NT4-PDC-net-rpc-vampire-errors-with-capital-letters-tp26488444p26488530.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26488444</id>
	<title>migrating NT4 PDC net rpc vampire errors with capital letters</title>
	<published>2009-11-23T16:09:24Z</published>
	<updated>2009-11-23T16:09:24Z</updated>
	<author>
		<name>Ryan Davis-5</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I have searched for days on Google and can't find a clear answer to my
&lt;br&gt;question. &amp;nbsp;I have a &amp;nbsp;NT4 PDC which I am migrating to Samba 3 (Version
&lt;br&gt;3.4.2-47.fc12) on FC12 with kernel(2.6.31.5-127.fc12.i686). &amp;nbsp;I am using
&lt;br&gt;tdbsam as my passdb backend.
&lt;br&gt;&lt;br&gt;I setup Samba as a BDC and then joined to NT4 Domain succesfully. &amp;nbsp;When I go
&lt;br&gt;to vampire the accounts I get lots of errors and some user accounts get
&lt;br&gt;transfered over. &amp;nbsp;It turns that all the user accounts that transfer are
&lt;br&gt;those that don't have a capital letter in their username on the NT4 domain
&lt;br&gt;server. &amp;nbsp;Most do and don't get transfered. &amp;nbsp;There seems to be errors with my
&lt;br&gt;groups and Computer accounts. &amp;nbsp;I was able in the past to vampire all the
&lt;br&gt;accounts (even capital letters) so any ideas would be great.
&lt;br&gt;&lt;br&gt;Thanks in advance.
&lt;br&gt;&lt;br&gt;Here is a type of error I get:
&lt;br&gt;&lt;br&gt;Creating account: Ryan
&lt;br&gt;useradd: invalid user name 'Ryan'
&lt;br&gt;fetch_account: Running the command `/usr/sbin/useradd -m 'Ryan'' gave 3
&lt;br&gt;Could not create posix account info for 'Ryan'
&lt;br&gt;&lt;br&gt;I get this error for groups:
&lt;br&gt;&lt;br&gt;Creating unix group: 'SophosDomainPowerUser'
&lt;br&gt;groupadd: 'SophosDomainPowerUser' is not a valid group name
&lt;br&gt;smb_create_group: Running the command `/usr/sbin/groupadd
&lt;br&gt;'SophosDomainPowerUser'' gave 3
&lt;br&gt;&lt;br&gt;and for Computer names:
&lt;br&gt;Creating account: LIMS1$
&lt;br&gt;useradd: invalid user name 'LIMS1$'
&lt;br&gt;fetch_account: Running the command `/usr/sbin/useradd -s /bin/false -d
&lt;br&gt;/dev/null 'LIMS1$'' gave 3
&lt;br&gt;&lt;br&gt;&lt;br&gt;Here is my smb.conf
&lt;br&gt;&lt;br&gt;[global]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;workgroup = GENOME1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;netbios name = HERCULES
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;passdb backend = tdbsam
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;domain master = No
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;domain logons = Yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;os level = 40
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;add user script = /usr/sbin/useradd &amp;quot;%u&amp;quot; -n -g users
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;delete user script = /usr/sbin/userdel &amp;quot;%u&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;add group script = /usr/sbin/groupadd &amp;quot;%g&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;delete group script = /usr/sbin/groupdel &amp;quot;%g&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;add machine script = /usr/sbin/useradd -n -c &amp;quot;Workstation (%u)&amp;quot; -M -d
&lt;br&gt;/nohome -s /bin/false &amp;quot;%u&amp;quot;
&lt;br&gt;# &amp;nbsp; &amp;nbsp; username map = /etc/samba/smbusers
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;logon path =
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;logon home =
&lt;br&gt;# &amp;nbsp; &amp;nbsp; wins support = yes
&lt;br&gt;&lt;br&gt;[files]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = SAMBA File Server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; path = /files
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read only = No
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/migrating-NT4-PDC-net-rpc-vampire-errors-with-capital-letters-tp26488444p26488444.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26488348</id>
	<title>Re: [IPA] Disabling Heimdal service</title>
	<published>2009-11-23T15:59:12Z</published>
	<updated>2009-11-23T15:59:12Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Mon, 2009-11-23 at 12:56 -0500, Endi Sukma Dewata wrote:
&lt;br&gt;&amp;gt; Andrew,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Please take a look at the attached patches. The first one is the
&lt;br&gt;&amp;gt; implementation of the proposal. The second one copies some additional
&lt;br&gt;&amp;gt; setup files into the install dir. 
&lt;br&gt;&lt;br&gt;I'm not sure on this. &amp;nbsp;I'll push the ldap_backend_start.sh template into
&lt;br&gt;inline strings in the python code, I think it's too small and silly to
&lt;br&gt;bother having in a file. 
&lt;br&gt;&lt;br&gt;The copy of the schema is a bit more of a worry to me - where does it
&lt;br&gt;end up exactly? 
&lt;br&gt;&lt;br&gt;&amp;gt; The third one creates the default
&lt;br&gt;&amp;gt; location for custom LDB modules .so files.
&lt;br&gt;&lt;br&gt;That seems reasonable. 
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; ----- &amp;quot;Andrew Bartlett&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26488348&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://www.freeipa.org/page/Samba_4_Disabling_Heimdal_Service&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeipa.org/page/Samba_4_Disabling_Heimdal_Service&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; The approach of using 'kdc port = 0' to disable seems very reasonable.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I updated the wiki page with some clarifications about the parameters.
&lt;br&gt;&amp;gt; In this proposal I'm using existing parameters &amp;quot;krb5 port&amp;quot; and &amp;quot;kpasswd
&lt;br&gt;&amp;gt; port&amp;quot;. You'll need to set both to 0 to completely disable Heimdal ports.
&lt;br&gt;&amp;gt; Is this what you meant or should I add another &amp;quot;kdc port&amp;quot; parameter to
&lt;br&gt;&amp;gt; overwrite both?
&lt;/div&gt;&lt;/div&gt;No, it was just too many acronyms for the hour of night :-)
&lt;br&gt;&lt;br&gt;Your patch looks good, but I would prefer not to have two almost
&lt;br&gt;identical routines. &amp;nbsp;Instead, can we parametrise the listener?
&lt;br&gt;&lt;br&gt;ie, one 'listen on tcp and udp' function, which for kpassed (as an
&lt;br&gt;example) provides kpasswdd_tcp_stream_ops and kpasswdd_process as a
&lt;br&gt;parameter? &amp;nbsp;(Bonus points for rationalising it down to just
&lt;br&gt;kpasswd_process). 
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26488348/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-IPA--Disabling-Heimdal-service-tp26439650p26488348.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26487910</id>
	<title>Re: November Canberra Linux Users Group meeting</title>
	<published>2009-11-23T15:18:56Z</published>
	<updated>2009-11-23T15:18:56Z</updated>
	<author>
		<name>jm-13</name>
	</author>
	<content type="html">&lt;br&gt;Passing along a comment a friend made:
&lt;br&gt;&lt;br&gt;I'd be interested to see what he's done... &amp;nbsp;If somebody goes along,
&lt;br&gt;convince him to put some info up somewhere about it.
&lt;br&gt;&lt;br&gt;There's plenty of ppl who datalog their roast temps vs time so that they
&lt;br&gt;can repeat a roast exactly (or almost exactly). &amp;nbsp;I imagine he's PIDing
&lt;br&gt;the roast profile to get it to where he wants.
&lt;br&gt;&lt;br&gt;Even the pricey home roasters (Hottop for instance, ~$1700
&lt;br&gt;&lt;a href=&quot;http://www.dibartoli.com.au/product_details.asp?pid=340&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dibartoli.com.au/product_details.asp?pid=340&lt;/a&gt;) are still
&lt;br&gt;pretty clunky in their temp control. &amp;nbsp;Having something that is more
&lt;br&gt;infinitely configurable would be a good thing (and rather sellable, I
&lt;br&gt;would have thought).
&lt;br&gt;&lt;br&gt;&lt;br&gt;Jeff.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26487910&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;chris@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 	
&lt;br&gt;&amp;gt; Abstract:	
&lt;br&gt;&amp;gt; 		Tridge will be demonstrating his Linux powered coffee
&lt;br&gt;&amp;gt; 		roaster. &amp;nbsp;
&lt;br&gt;&amp;gt; 		
&lt;br&gt;&amp;gt; 		Tridge's description is simple yet profound: &amp;quot;It has a
&lt;br&gt;&amp;gt; 		bit of python, a bit of USB hackery, some circuit
&lt;br&gt;&amp;gt; 		building, a bit of control theory and of course coffee.
&lt;br&gt;&amp;gt; 		Should appeal to most geeks :-)&amp;quot; Please bring your own
&lt;br&gt;&amp;gt; 		coffee cup to sample the end product, as there will be
&lt;br&gt;&amp;gt; 		regular and decaf coffee available. 
&lt;br&gt;&amp;gt; 		
&lt;br&gt;&amp;gt; 	
&lt;/div&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26487910&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/November-Canberra-Linux-Users-Group-meeting-tp26486760p26487910.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26487566</id>
	<title>Re: including samba vfs module scannedonly in source tree</title>
	<published>2009-11-23T14:53:28Z</published>
	<updated>2009-11-23T14:53:28Z</updated>
	<author>
		<name>Volker Lendecke</name>
	</author>
	<content type="html">On Mon, Nov 23, 2009 at 10:18:05PM +0100, Olivier Sessink wrote:
&lt;br&gt;&amp;gt; Could you take a look at the code and see if things go in the right
&lt;br&gt;&amp;gt; direction? If so I'll branch, remove all the 3.0/3.2/3.4 compatibility
&lt;br&gt;&amp;gt; and create a 3.5-only version.
&lt;br&gt;&lt;br&gt;Yep, that looks better. Thanks!
&lt;br&gt;&lt;br&gt;Some more comments. Some of them are hints to make the code
&lt;br&gt;more readable, they would not be blockers for inclusion.
&lt;br&gt;Some are (IMHO) bugs.
&lt;br&gt;&lt;br&gt;For example, one thing that helps in avoiding deep nesting
&lt;br&gt;is to do early returns in functions. For example, in
&lt;br&gt;construct_full_path(), the &amp;quot;else&amp;quot; branch is not required.
&lt;br&gt;You always return in the &amp;quot;if&amp;quot; branch, so you can shift the
&lt;br&gt;code in the &amp;quot;else&amp;quot; branch one tab left.
&lt;br&gt;&lt;br&gt;Line 242 is missing a &amp;quot;return -1&amp;quot;?
&lt;br&gt;&lt;br&gt;In line 310 you should check for the return value of
&lt;br&gt;connect_to_scanner() I think.
&lt;br&gt;&lt;br&gt;Line 320 and 335: gcc does the clean tail recursion
&lt;br&gt;optimization, so you don't grow the stack, but other
&lt;br&gt;compilers don't. Can you turn that into a while loop?
&lt;br&gt;&lt;br&gt;Line 342: We have &amp;quot;bool&amp;quot; for free_tmp.
&lt;br&gt;&lt;br&gt;Line 436: Turning that into
&lt;br&gt;&lt;br&gt;if ((retval == 0) &amp;&amp; (sbuf1.st_mtime &amp;lt;= sbuf2.st_mtime)) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SAFE_FREE(cachefile);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; return 1;
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;reversing the if-condition and doing an early return gets
&lt;br&gt;rid of one indent and makes cleaner code. Similar for line
&lt;br&gt;566 for example.
&lt;br&gt;&lt;br&gt;Line 830: Reverse the condition and do a continue;
&lt;br&gt;&lt;br&gt;Volker
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26487566/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/including-samba-vfs-module-scannedonly-in-source-tree-tp26392113p26487566.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26486830</id>
	<title>Re: [s4] My recent work</title>
	<published>2009-11-23T14:05:12Z</published>
	<updated>2009-11-23T14:05:12Z</updated>
	<author>
		<name>Andrew Bartlett</name>
	</author>
	<content type="html">On Mon, 2009-11-23 at 15:20 +0100, Matthias Dieter Wallnöfer wrote:
&lt;br&gt;&amp;gt; Hi abartlet and other s4 developers,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I would like to bring to attention my recent work:
&lt;br&gt;&amp;gt; - &amp;quot;const&amp;quot; patches: I did improvements over the last weekend and some 
&lt;br&gt;&amp;gt; (those in common with s3) where merged - the s4 ones are outstanding: 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&lt;/a&gt;&lt;br&gt;&lt;br&gt;On these, I would still like a single, typesafe function that takes a
&lt;br&gt;(char **) and returns a (const char **), as then we don't risk missing a
&lt;br&gt;change in the type (rather than just the addition of a const). 
&lt;br&gt;&lt;br&gt;&amp;gt; - &amp;quot;operational&amp;quot; work: I changed the operational attributes to be 
&lt;br&gt;&amp;gt; read-only through a indeed very simple patch - I hope that's enough: 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&lt;/a&gt;&lt;br&gt;&lt;br&gt;I'll push this shortly. &amp;nbsp;I'll skip to 'remove useless init' however, as
&lt;br&gt;I've found a use for the init :-)
&lt;br&gt;&lt;br&gt;&amp;gt; - &amp;quot;index counters&amp;quot;: I corrected the patch for LDB 
&lt;br&gt;&amp;gt; (&lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad45440a612c23cd15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad45440a612c23cd15&lt;/a&gt;) 
&lt;br&gt;&amp;gt; - hope to have fixed it according to your suggestions
&lt;br&gt;&lt;br&gt;I've not looked at this yet. &amp;nbsp;
&lt;br&gt;&lt;br&gt;Thanks for putting these up for review!
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26486830/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-s4--My-recent-work-tp26478915p26486830.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26486760</id>
	<title>November Canberra Linux Users Group meeting</title>
	<published>2009-11-23T14:00:02Z</published>
	<updated>2009-11-23T14:00:02Z</updated>
	<author>
		<name>Chris Smart-7</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Canberra Linux Users Group Meeting - 26th November 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; =======================================================
&lt;br&gt;&lt;br&gt;Date:		26th November 2009 (Fourth Thursday of the month)
&lt;br&gt;&lt;br&gt;Time:		19:00 - 21:00 (or when it finishes)
&lt;br&gt;&lt;br&gt;Speaker:	Andrew Tridgell
&lt;br&gt;&lt;br&gt;Abstract:	
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tridge will be demonstrating his Linux powered coffee
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; roaster. &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tridge's description is simple yet profound: &amp;quot;It has a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bit of python, a bit of USB hackery, some circuit
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; building, a bit of control theory and of course coffee.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Should appeal to most geeks :-)&amp;quot; Please bring your own
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; coffee cup to sample the end product, as there will be
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; regular and decaf coffee available. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;Venue:		Room N101
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Computer Science and Information Technology Building
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; North Road
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The Australian National University
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; See &lt;a href=&quot;http://clug.org.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://clug.org.au/&lt;/a&gt;&amp;nbsp;for more directions and a map
&lt;br&gt;&lt;br&gt;Food/drink:	Pizza and soft drink/juice. Come hungry, and bring 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; about $6 to cover the cost of your share if you 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; want some.
&lt;br&gt;&lt;br&gt;If you would like to give a talk at a future meeting, please email me.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;linux mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26486760&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;linux@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/linux&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/linux&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---linux-f13154.html&quot; embed=&quot;fixTarget[13154]&quot; target=&quot;_top&quot; &gt;Samba - linux&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/November-Canberra-Linux-Users-Group-meeting-tp26486760p26486760.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26486416</id>
	<title>samba 3.4.3  DC breaks Windows groups</title>
	<published>2009-11-23T13:40:30Z</published>
	<updated>2009-11-23T13:40:30Z</updated>
	<author>
		<name>Gaiseric Vandal</name>
	</author>
	<content type="html">I have the following setup:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;PDC: &amp;nbsp;Samba 3.0.37 on Solaris 10
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;BDC1: Samba 3.0.37 on Solaris 10
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;BDC2: Samba 3.4.3 on Solaris 10
&lt;br&gt;&lt;br&gt;&lt;br&gt;Samba 3.0.37 is the bundled version of Samba.
&lt;br&gt;Samba 3.4.3 is compiled from source.
&lt;br&gt;&lt;br&gt;BDC2 is a recent addition to the network.
&lt;br&gt;All machine use LDAP as the backend for everything. &amp;nbsp;They use winbind to
&lt;br&gt;handle a domain trust with another domain, but otherwise isn't needed.
&lt;br&gt;&lt;br&gt;On BDC2, &amp;nbsp;users do not appear to be in any groups &amp;nbsp;beyond Domain Users.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Group mapping seems OK on each DC.
&lt;br&gt;&lt;br&gt;BDC2# net groupmap list
&lt;br&gt;Domain Admins (S-1-5-21-xxxxx-xxxxx-512) -&amp;gt; smb_domadmins
&lt;br&gt;Domain Users (S-1-5-21-xxxxx-xxxxx-513) -&amp;gt; smb_domusers
&lt;br&gt;Domain Guests (S-1-5-21-xxxxx-xxxxx9-514) -&amp;gt; smb_domguests
&lt;br&gt;Domain Computers (S-1-5-21-xxxxx-xxxxx-515) -&amp;gt; smb_machines
&lt;br&gt;Domain Controllers (S-1-5-21-xxxxx-xxxxx-516) -&amp;gt; smb_dc
&lt;br&gt;Domain Certificate Admins (S-1-5-21-xxxxx-xxxxx-517) -&amp;gt; smb_domcertadmins
&lt;br&gt;Builtin Admins (S-1-5-21-xxxxx-xxxxx-544) -&amp;gt; smb_admins
&lt;br&gt;Builtin users (S-1-5-21-xxxxx-xxxxx-545) -&amp;gt; smb_users
&lt;br&gt;Builtin Guests (S-1-5-21-xxxxx-xxxxx-546) -&amp;gt; smb_guests
&lt;br&gt;Administrators (S-xxxx-544) -&amp;gt; xxxx
&lt;br&gt;Users (S-xxxx-545) -&amp;gt; xxxx
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;The last two in the listing above were automatically created by 
&lt;br&gt;winbind/idmap for a trusted domain.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Unix level group memberships are OK
&lt;br&gt;&lt;br&gt;BDC2# groups Administrator
&lt;br&gt;smb_domadmins smb_domusers
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;Windows/Samba level group memberships are not
&lt;br&gt;&lt;br&gt;BDC2# net rpc user info Administrator -U Administrator -S PDC
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;Domain Admins
&lt;br&gt;Domain Users
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc user info Administrator -U Administrator -S BDC2
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;Domain Users
&lt;br&gt;BDC2#
&lt;br&gt;&lt;br&gt;&lt;br&gt;Same deal with regular users
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Nt. &amp;nbsp;Not all unix groups are mapped to Windows groups. &amp;nbsp;However I 
&lt;br&gt;believe all required &amp;quot;well known&amp;quot; windows groups are.
&lt;br&gt;&lt;br&gt;Ldap structure includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=people
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=group
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ou=smb_groups (where samba stores group mappings, ldap 
&lt;br&gt;objectClass=sambaGroupMapping)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;You can verify machine PDC or BDC is being used by an Windows client 
&lt;br&gt;with the &amp;quot;echo %LOGONSERVER%&amp;quot; command.
&lt;br&gt;&lt;br&gt;&lt;br&gt;If I logon as Domain Administrator to an &amp;nbsp;XP or Win 2003 machine that is 
&lt;br&gt;using BDC2, I will not have any Administrator privileges.
&lt;br&gt;&lt;br&gt;&lt;br&gt;smb.conf includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;ldap group suffix = ou=smb_groups
&lt;br&gt;&lt;br&gt;&lt;br&gt;(When I converted from tdb to ldap backend, &amp;nbsp;I already had unix groups 
&lt;br&gt;in ldap and wasn't sure how stuff would import. &amp;nbsp; &amp;nbsp; I don't think 
&lt;br&gt;existing groups or group mappings imported so I had to manually retype 
&lt;br&gt;the &amp;quot;net group map commands.&amp;quot; &amp;nbsp;)
&lt;br&gt;&lt;br&gt;The &amp;quot;Domain Admins&amp;quot; sambaGroupMapping does include Administrator as a 
&lt;br&gt;member.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc group members &amp;quot;Domain Admins&amp;quot; -U Administrator -S PDC
&lt;br&gt;MYDOMAIN\Administrator
&lt;br&gt;MYDOMAIN\jsmith
&lt;br&gt;&lt;br&gt;&lt;br&gt;BDC2# net rpc group members &amp;quot;Domain Admins&amp;quot; -U Administrator -S BDC2
&lt;br&gt;Enter Administrator's password:
&lt;br&gt;MYDOMAIN\Administrator
&lt;br&gt;MYDOMAIN\jsmith
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/samba-3.4.3--DC-breaks-Windows-groups-tp26486416p26486416.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26486203</id>
	<title>Fwd: Vista laptop in Samba 3.3.4 domain suddenly trying to use roaming profiles?</title>
	<published>2009-11-23T13:27:41Z</published>
	<updated>2009-11-23T13:27:41Z</updated>
	<author>
		<name>David Whitney-3</name>
	</author>
	<content type="html">&amp;nbsp;Hi, and thanks for your interest!
&lt;br&gt;&lt;br&gt;I am still using an smbpasswd backend because this is a very small home
&lt;br&gt;network I maintain for my own educational purposes, although I might migrate
&lt;br&gt;to LDAP at some point for the same reason.
&lt;br&gt;&lt;br&gt;I have manually changed the troublesome profile type from roaming to local,
&lt;br&gt;but when I logged back in from that same profile, it switched back to
&lt;br&gt;roaming! The more I read about this bizarre behavior, the more I start to
&lt;br&gt;suspect the possibility of malware or virus, which is what I plan to
&lt;br&gt;investigate tonight.
&lt;br&gt;&lt;br&gt;As far as the logon scripts go, the irony is that the script actually fired
&lt;br&gt;from my admin-prived logon, but could not access/load the &amp;quot;right&amp;quot; profile
&lt;br&gt;from the local box. They still don't fire from my desktop boxes. Per your
&lt;br&gt;question, I can access and execute the scripts from the desktop with no
&lt;br&gt;problem. Per other sources, it appears that the necessary privs to the
&lt;br&gt;netlogon directory should be 755, (rwxr-xr-x), which is what I have set and
&lt;br&gt;verified.
&lt;br&gt;&lt;br&gt;Again, many thanks for your interest and suggestions.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On Mon, Nov 23, 2009 at 1:16 PM, Gaiseric Vandal
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26486203&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gaiseric.vandal@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; This happened to us when we switched from TDB to LDAP backend. &amp;nbsp; (Samba
&lt;br&gt;&amp;gt; 3.03x) &amp;nbsp; I suspect that for some users sambaProfilePath may have had space
&lt;br&gt;&amp;gt; &amp;nbsp;character but wasn't actually &amp;nbsp;null. &amp;nbsp; For some users we just deleted the
&lt;br&gt;&amp;gt; sambaProfilePath attribute.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; You may need to change the profile type on the users computer from roaming
&lt;br&gt;&amp;gt; back to local. &amp;nbsp;(On XP, right-click My Computer-&amp;gt; Properties-&amp;gt;Advanced-&amp;gt;User
&lt;br&gt;&amp;gt; Profiles.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Login scripts could be several things
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;share and file permissions for the netlogon directory should probably
&lt;br&gt;&amp;gt; allow everyone read-only.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;I usually add a &amp;quot;pause&amp;quot; command in the login script when
&lt;br&gt;&amp;gt; troubleshooting
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;- &amp;nbsp;You need to specify the logon script as part of the user's account.
&lt;br&gt;&amp;gt; &amp;nbsp;(In LDAP, SambaLogonScript attribute &amp;nbsp;I don't think you can a default logon
&lt;br&gt;&amp;gt; script.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; From an XP session, can you go to the netlogon share and run the logon
&lt;br&gt;&amp;gt; script?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On 11/23/09 10:03, David Whitney wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Grettings, all
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I have a bizarre problem on a laptop in my Samba 3.3.4 domain. This domain
&lt;br&gt;&amp;gt;&amp;gt; includes a mixture of XP Pro and Vista Ultimate clients.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I had just completed a migration to this new domain (from a Samba 2.2.8a
&lt;br&gt;&amp;gt;&amp;gt; domain), and all seemed happy and well - machines had rebooted and were
&lt;br&gt;&amp;gt;&amp;gt; still active in the domain, users were logging in with no problem, shares
&lt;br&gt;&amp;gt;&amp;gt; were working perfectly - all over the span of a week or so - until last
&lt;br&gt;&amp;gt;&amp;gt; night.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Trying to log into my wife's laptop (Vista Ultimate) under her account, I
&lt;br&gt;&amp;gt;&amp;gt; got an odd message that said &amp;quot;Your roaming profile was not completely
&lt;br&gt;&amp;gt;&amp;gt; synchronized. Please contact your administrator.&amp;quot; The only problem is I am
&lt;br&gt;&amp;gt;&amp;gt; *not* using roaming profiles in my Samba domain! And this account had
&lt;br&gt;&amp;gt;&amp;gt; logged
&lt;br&gt;&amp;gt;&amp;gt; into the domain several times on this laptop with no problem after the
&lt;br&gt;&amp;gt;&amp;gt; migration.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I looked on the home shares for the particular account, and surely enough
&lt;br&gt;&amp;gt;&amp;gt; there is the &amp;quot;profile.V2&amp;quot; folder indicating what I understand is the
&lt;br&gt;&amp;gt;&amp;gt; attempt
&lt;br&gt;&amp;gt;&amp;gt; by a Vista box to build a first-time Vista-style roaming profile on my
&lt;br&gt;&amp;gt;&amp;gt; Samba-defined user share. I logged in under a different account that has
&lt;br&gt;&amp;gt;&amp;gt; admin privs, and sure enough, it tried to load a roaming profile there,
&lt;br&gt;&amp;gt;&amp;gt; too.
&lt;br&gt;&amp;gt;&amp;gt; That told me, additionally, that Vista thought this was the first time
&lt;br&gt;&amp;gt;&amp;gt; this
&lt;br&gt;&amp;gt;&amp;gt; user had logged into that box/domain, which was obviously incorrect. The
&lt;br&gt;&amp;gt;&amp;gt; profiles for each user that had used until that point were on the machine,
&lt;br&gt;&amp;gt;&amp;gt; intact.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I've changed the local policy on that box to disallow roaming profiles
&lt;br&gt;&amp;gt;&amp;gt; expressly, but now the local profiles that had been working just fine are
&lt;br&gt;&amp;gt;&amp;gt; no
&lt;br&gt;&amp;gt;&amp;gt; longer associated with their proper users, and I'm not sure how to restore
&lt;br&gt;&amp;gt;&amp;gt; the association (or even if I can). I can browse the machine remotely and
&lt;br&gt;&amp;gt;&amp;gt; copy the files from that local profile if I have to, but I'd like to avoid
&lt;br&gt;&amp;gt;&amp;gt; it.
&lt;br&gt;&amp;gt;&amp;gt; Could the learned folks here offer any suggestions on why this laptop
&lt;br&gt;&amp;gt;&amp;gt; would
&lt;br&gt;&amp;gt;&amp;gt; suddenly think it was supposed to use roaming profiles on my
&lt;br&gt;&amp;gt;&amp;gt; non-roaming-profile Samba domain? Is there some mystery setting in
&lt;br&gt;&amp;gt;&amp;gt; smb.conf
&lt;br&gt;&amp;gt;&amp;gt; I might possibly have set (or perhaps deleted??) that would leave Samba
&lt;br&gt;&amp;gt;&amp;gt; thinking was trying to use roaming profiles? Based on late-night research,
&lt;br&gt;&amp;gt;&amp;gt; I
&lt;br&gt;&amp;gt;&amp;gt; expressly set &amp;quot;logon path&amp;quot; to be blank in smb.conf, which is supposed to
&lt;br&gt;&amp;gt;&amp;gt; disable Samba roaming profiles. It had not been expressly set before. I
&lt;br&gt;&amp;gt;&amp;gt; have
&lt;br&gt;&amp;gt;&amp;gt; logged into a desktop box and it worked normally.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Appreciate any thoughts or suggestions. The desktop boxes, so far, seem
&lt;br&gt;&amp;gt;&amp;gt; unaffected and are working normally. I'm thinking my next step is to copy
&lt;br&gt;&amp;gt;&amp;gt; the files from the particular profile in question, remove the machine from
&lt;br&gt;&amp;gt;&amp;gt; the domain, and then rejoin it, but I'm not sure I still won't have the
&lt;br&gt;&amp;gt;&amp;gt; same
&lt;br&gt;&amp;gt;&amp;gt; problem.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The only other problem I've had in this migration was in getting logon
&lt;br&gt;&amp;gt;&amp;gt; scripts to work (which I never did), but I don't think this is related to
&lt;br&gt;&amp;gt;&amp;gt; that issue....and the fact that other than scripts the domain was working
&lt;br&gt;&amp;gt;&amp;gt; fine is what really has me puzzled.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any thoughts or suggestions appreciated.
&lt;br&gt;&amp;gt;&amp;gt; -David
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; To unsubscribe from this list go to the following URL and read the
&lt;br&gt;&amp;gt; instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vista-laptop-in-Samba-3.3.4-domain-suddenly-trying-to-use-roaming-profiles--tp26479634p26486203.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26485981</id>
	<title>Re: including samba vfs module scannedonly in source tree</title>
	<published>2009-11-23T13:18:05Z</published>
	<updated>2009-11-23T13:18:05Z</updated>
	<author>
		<name>Olivier Sessink</name>
	</author>
	<content type="html">Volker Lendecke wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Sun, Nov 22, 2009 at 01:00:54PM +0100, Olivier Sessink wrote:
&lt;br&gt;&amp;gt;&amp;gt; that is correct, I've tried to keep the VFS module as simple and generic
&lt;br&gt;&amp;gt;&amp;gt; as possible, it only uses a domain socket or it talks over UDP.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Ok, thanks for that info.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; Where can I find the new interface documentation?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Nowhere, sorry. It's much as it was before: Look at the
&lt;br&gt;&amp;gt; examples in modules/vfs*.c
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; ok, I'll first correct these first pointers and send a
&lt;br&gt;&amp;gt;&amp;gt; corrected vfs module.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks! Looking forward to that!
&lt;/div&gt;&lt;br&gt;The latest revision
&lt;br&gt;&lt;a href=&quot;http://scannedonly.svn.sourceforge.net/viewvc/scannedonly/trunk/src/vfs_scannedonly.c?revision=46&amp;view=markup&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://scannedonly.svn.sourceforge.net/viewvc/scannedonly/trunk/src/vfs_scannedonly.c?revision=46&amp;view=markup&lt;/a&gt;&lt;br&gt;has all requested changes, except for the 3.5 changes, because I
&lt;br&gt;couldn't get autoconf to run in the 3.5 tree.
&lt;br&gt;/usr/bin/m4:configure.in:23: cannot open `pkg.m4': No such file or directory
&lt;br&gt;&lt;br&gt;Could you take a look at the code and see if things go in the right
&lt;br&gt;direction? If so I'll branch, remove all the 3.0/3.2/3.4 compatibility
&lt;br&gt;and create a 3.5-only version.
&lt;br&gt;&lt;br&gt;thanks,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Olivier Sessink
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/including-samba-vfs-module-scannedonly-in-source-tree-tp26392113p26485981.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26484203</id>
	<title>Re: Vista laptop in Samba 3.3.4 domain suddenly trying to use roaming profiles?</title>
	<published>2009-11-23T11:16:55Z</published>
	<updated>2009-11-23T11:16:55Z</updated>
	<author>
		<name>Gaiseric Vandal</name>
	</author>
	<content type="html">This happened to us when we switched from TDB to LDAP backend. &amp;nbsp; (Samba 
&lt;br&gt;3.03x) &amp;nbsp; I suspect that for some users sambaProfilePath may have had 
&lt;br&gt;space &amp;nbsp;character but wasn't actually &amp;nbsp;null. &amp;nbsp; For some users we just 
&lt;br&gt;deleted the sambaProfilePath attribute.
&lt;br&gt;&lt;br&gt;You may need to change the profile type on the users computer from 
&lt;br&gt;roaming back to local. &amp;nbsp;(On XP, right-click My Computer-&amp;gt; 
&lt;br&gt;Properties-&amp;gt;Advanced-&amp;gt;User Profiles.)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Login scripts could be several things
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- &amp;nbsp;share and file permissions for the netlogon directory should 
&lt;br&gt;probably allow everyone read-only.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- &amp;nbsp;I usually add a &amp;quot;pause&amp;quot; command in the login script when 
&lt;br&gt;troubleshooting
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- &amp;nbsp;You need to specify the logon script as part of the user's 
&lt;br&gt;account. &amp;nbsp;(In LDAP, SambaLogonScript attribute &amp;nbsp;I don't think you can a 
&lt;br&gt;default logon script.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;From an XP session, can you go to the netlogon share and run the logon 
&lt;br&gt;script?
&lt;br&gt;&lt;br&gt;On 11/23/09 10:03, David Whitney wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Grettings, all
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a bizarre problem on a laptop in my Samba 3.3.4 domain. This domain
&lt;br&gt;&amp;gt; includes a mixture of XP Pro and Vista Ultimate clients.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I had just completed a migration to this new domain (from a Samba 2.2.8a
&lt;br&gt;&amp;gt; domain), and all seemed happy and well - machines had rebooted and were
&lt;br&gt;&amp;gt; still active in the domain, users were logging in with no problem, shares
&lt;br&gt;&amp;gt; were working perfectly - all over the span of a week or so - until last
&lt;br&gt;&amp;gt; night.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Trying to log into my wife's laptop (Vista Ultimate) under her account, I
&lt;br&gt;&amp;gt; got an odd message that said &amp;quot;Your roaming profile was not completely
&lt;br&gt;&amp;gt; synchronized. Please contact your administrator.&amp;quot; The only problem is I am
&lt;br&gt;&amp;gt; *not* using roaming profiles in my Samba domain! And this account had logged
&lt;br&gt;&amp;gt; into the domain several times on this laptop with no problem after the
&lt;br&gt;&amp;gt; migration.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I looked on the home shares for the particular account, and surely enough
&lt;br&gt;&amp;gt; there is the &amp;quot;profile.V2&amp;quot; folder indicating what I understand is the attempt
&lt;br&gt;&amp;gt; by a Vista box to build a first-time Vista-style roaming profile on my
&lt;br&gt;&amp;gt; Samba-defined user share. I logged in under a different account that has
&lt;br&gt;&amp;gt; admin privs, and sure enough, it tried to load a roaming profile there, too.
&lt;br&gt;&amp;gt; That told me, additionally, that Vista thought this was the first time this
&lt;br&gt;&amp;gt; user had logged into that box/domain, which was obviously incorrect. The
&lt;br&gt;&amp;gt; profiles for each user that had used until that point were on the machine,
&lt;br&gt;&amp;gt; intact.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I've changed the local policy on that box to disallow roaming profiles
&lt;br&gt;&amp;gt; expressly, but now the local profiles that had been working just fine are no
&lt;br&gt;&amp;gt; longer associated with their proper users, and I'm not sure how to restore
&lt;br&gt;&amp;gt; the association (or even if I can). I can browse the machine remotely and
&lt;br&gt;&amp;gt; copy the files from that local profile if I have to, but I'd like to avoid
&lt;br&gt;&amp;gt; it.
&lt;br&gt;&amp;gt; Could the learned folks here offer any suggestions on why this laptop would
&lt;br&gt;&amp;gt; suddenly think it was supposed to use roaming profiles on my
&lt;br&gt;&amp;gt; non-roaming-profile Samba domain? Is there some mystery setting in smb.conf
&lt;br&gt;&amp;gt; I might possibly have set (or perhaps deleted??) that would leave Samba
&lt;br&gt;&amp;gt; thinking was trying to use roaming profiles? Based on late-night research, I
&lt;br&gt;&amp;gt; expressly set &amp;quot;logon path&amp;quot; to be blank in smb.conf, which is supposed to
&lt;br&gt;&amp;gt; disable Samba roaming profiles. It had not been expressly set before. I have
&lt;br&gt;&amp;gt; logged into a desktop box and it worked normally.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Appreciate any thoughts or suggestions. The desktop boxes, so far, seem
&lt;br&gt;&amp;gt; unaffected and are working normally. I'm thinking my next step is to copy
&lt;br&gt;&amp;gt; the files from the particular profile in question, remove the machine from
&lt;br&gt;&amp;gt; the domain, and then rejoin it, but I'm not sure I still won't have the same
&lt;br&gt;&amp;gt; problem.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The only other problem I've had in this migration was in getting logon
&lt;br&gt;&amp;gt; scripts to work (which I never did), but I don't think this is related to
&lt;br&gt;&amp;gt; that issue....and the fact that other than scripts the domain was working
&lt;br&gt;&amp;gt; fine is what really has me puzzled.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any thoughts or suggestions appreciated.
&lt;br&gt;&amp;gt; -David
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vista-laptop-in-Samba-3.3.4-domain-suddenly-trying-to-use-roaming-profiles--tp26479634p26484203.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26482967</id>
	<title>Re: [IPA] Disabling Heimdal service</title>
	<published>2009-11-23T09:56:29Z</published>
	<updated>2009-11-23T09:56:29Z</updated>
	<author>
		<name>Endi Sukma Dewata-3</name>
	</author>
	<content type="html">Andrew,
&lt;br&gt;&lt;br&gt;Please take a look at the attached patches. The first one is the
&lt;br&gt;implementation of the proposal. The second one copies some additional
&lt;br&gt;setup files into the install dir. The third one creates the default
&lt;br&gt;location for custom LDB modules .so files.
&lt;br&gt;&lt;br&gt;----- &amp;quot;Andrew Bartlett&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482967&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.freeipa.org/page/Samba_4_Disabling_Heimdal_Service&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeipa.org/page/Samba_4_Disabling_Heimdal_Service&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;gt; The approach of using 'kdc port = 0' to disable seems very reasonable.
&lt;br&gt;&lt;br&gt;I updated the wiki page with some clarifications about the parameters.
&lt;br&gt;In this proposal I'm using existing parameters &amp;quot;krb5 port&amp;quot; and &amp;quot;kpasswd
&lt;br&gt;port&amp;quot;. You'll need to set both to 0 to completely disable Heimdal ports.
&lt;br&gt;Is this what you meant or should I add another &amp;quot;kdc port&amp;quot; parameter to
&lt;br&gt;overwrite both?
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;Endi S. Dewata
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;&lt;tt&gt;[0002-s4-script-Install-setup-scripts-and-examples.patch]&lt;/tt&gt;&lt;br /&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;tt&gt;From 7be7cacb2fe6d35953fae831df802624f92dce84 Mon Sep 17 00:00:00 2001
&lt;br&gt;From: Endi S. Dewata &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482967&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;edewata@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: Fri, 20 Nov 2009 14:16:47 -0600
&lt;br&gt;Subject: [PATCH] s4:script - Install setup scripts and examples.
&lt;br&gt;&lt;br&gt;---
&lt;br&gt;&amp;nbsp;source4/script/installmisc.sh | &amp;nbsp; &amp;nbsp;2 ++
&lt;br&gt;&amp;nbsp;1 files changed, 2 insertions(+), 0 deletions(-)
&lt;br&gt;&lt;br&gt;diff --git a/source4/script/installmisc.sh b/source4/script/installmisc.sh
&lt;br&gt;index 8e3f723..7bff2e2 100755
&lt;br&gt;--- a/source4/script/installmisc.sh
&lt;br&gt;+++ b/source4/script/installmisc.sh
&lt;br&gt;@@ -26,8 +26,10 @@ cp setup/*.zone $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/*.conf $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/*.php $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/*.txt $SETUPDIR || exit 1
&lt;br&gt;+cp setup/*.sh $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/provision.smb.conf.dc $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/provision.smb.conf.member $SETUPDIR || exit 1
&lt;br&gt;&amp;nbsp;cp setup/provision.smb.conf.standalone $SETUPDIR || exit 1
&lt;br&gt;+cp -r ../examples $SETUPDIR/../.. || exit 1
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;exit 0
&lt;br&gt;-- 
&lt;br&gt;1.6.0.6
&lt;br&gt;&lt;br&gt;&lt;/tt&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;br /&gt;&lt;tt&gt;[0003-s4-Create-default-modules-directory.patch]&lt;/tt&gt;&lt;br /&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;tt&gt;From bc411082471cf7773ba969910010613e05e83e86 Mon Sep 17 00:00:00 2001
&lt;br&gt;From: Endi S. Dewata &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482967&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;edewata@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: Fri, 20 Nov 2009 14:57:11 -0600
&lt;br&gt;Subject: [PATCH] s4 - Create default modules directory.
&lt;br&gt;&lt;br&gt;---
&lt;br&gt;&amp;nbsp;source4/Makefile | &amp;nbsp; &amp;nbsp;1 +
&lt;br&gt;&amp;nbsp;1 files changed, 1 insertions(+), 0 deletions(-)
&lt;br&gt;&lt;br&gt;diff --git a/source4/Makefile b/source4/Makefile
&lt;br&gt;index 03b4e73..3aea791 100644
&lt;br&gt;--- a/source4/Makefile
&lt;br&gt;+++ b/source4/Makefile
&lt;br&gt;@@ -221,6 +221,7 @@ installdirs::
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(torturedir) \
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(libdir) \
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(modulesdir) \
&lt;br&gt;+		$(DESTDIR)$(modulesdir)/ldb \
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(mandir) \
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(localstatedir) \
&lt;br&gt;&amp;nbsp;		$(DESTDIR)$(localstatedir)/lib \
&lt;br&gt;-- 
&lt;br&gt;1.6.0.6
&lt;br&gt;&lt;br&gt;&lt;/tt&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;0001-s4-kdc-Disable-KDC-port-when-it-s-set-to-0.patch&lt;/strong&gt; (5K) &lt;a href=&quot;http://old.nabble.com/attachment/26482967/0/0001-s4-kdc-Disable-KDC-port-when-it-s-set-to-0.patch&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-IPA--Disabling-Heimdal-service-tp26439650p26482967.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26482921</id>
	<title>Re: Commit: 1169dd3b50dfefa59b56cd1897bcd0b6c2ffb3be</title>
	<published>2009-11-23T09:52:43Z</published>
	<updated>2009-11-23T09:52:43Z</updated>
	<author>
		<name>cd1</name>
	</author>
	<content type="html">does the attached patch fix the problem? I'm not very familiar with talloc
&lt;br&gt;memory stealing yet.
&lt;br&gt;&lt;br&gt;On Mon, Nov 23, 2009 at 8:37 AM, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482921&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tridge@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Andrew,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;gt; Yes, I think it should be ldb_msg_add_linearized_dn(). &amp;nbsp;That would match
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;gt; the current nomenclature of the ldb_dn.c code, and not add an extended
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;gt; DN (which is another, quite valid DN form).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; yep, you're right.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;gt; Perhaps just use ldb_msg_add_steal_string() and
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;gt; ldb_dn_alloc_linearized()?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; good suggestion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers, Tridge
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Crístian Deives dos Santos Viana [aka CD1]
&lt;br&gt;Sent from Campinas, SP, Brazil
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;0001-changed-function-name-and-fixed-memory-issue.patch&lt;/strong&gt; (5K) &lt;a href=&quot;http://old.nabble.com/attachment/26482921/0/0001-changed-function-name-and-fixed-memory-issue.patch&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Commit%3A-1169dd3b50dfefa59b56cd1897bcd0b6c2ffb3be-tp26439784p26482921.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26482917</id>
	<title>Re: [PATCH] s4-drs: replmd_delete implementation</title>
	<published>2009-11-23T09:52:20Z</published>
	<updated>2009-11-23T09:52:20Z</updated>
	<author>
		<name>Eduardo Lima-6</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;&amp;gt;your code is doing a ldb modify, so in the modify you would need toget
&lt;br&gt;&amp;gt;list them as LDB_FLAG_MOD_DELETE. So you actually should use a
&lt;br&gt;&amp;gt;db_msg_add_*() call, but sets the element flags to mark it as an
&lt;br&gt;&amp;gt;element to delete.
&lt;br&gt;&lt;br&gt;I'm inserting a new element to the &amp;quot;msg&amp;quot; using ldb_msg_add_empty():
&lt;br&gt;&lt;br&gt;ret = ldb_msg_add_empty(msg, &amp;quot;badPwdCount&amp;quot;, LDB_FLAG_MOD_DELETE, &amp;el);
&lt;br&gt;if (ret != LDB_SUCCESS) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; DEBUG(0,(__location__ &amp;quot;: Failed to remove badPwdCount element\n&amp;quot;));
&lt;br&gt;&amp;nbsp; &amp;nbsp; ret = LDB_ERR_OTHER;
&lt;br&gt;&amp;nbsp; &amp;nbsp; goto done;
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;But when I run this code, the field is not deleted and isDeleted and
&lt;br&gt;lastKnownParent are not added to the object. (If I don't use this code,
&lt;br&gt;isDeleted and lastKnownParent are inserted correctly).
&lt;br&gt;&lt;br&gt;Is that what I was expected to do?
&lt;br&gt;&lt;br&gt;Another question, how can I find the element &amp;quot;badPwdCount&amp;quot;?
&lt;br&gt;&lt;br&gt;I've already tried to do :
&lt;br&gt;&lt;br&gt;element = ldb_msg_find_element(msg, &amp;quot;badPwdCount&amp;quot;);
&lt;br&gt;&lt;br&gt;but I think I'm using the wrong ldb_message var. How can I find it? If I
&lt;br&gt;have the element, can I use ldb_msg_remove_element() ?
&lt;br&gt;&lt;br&gt;Thanks.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;Eduardo Lima
&lt;br&gt;Sent from Campinas, SP, Brazil
&lt;br&gt;&lt;br&gt;On Wed, Nov 18, 2009 at 23:40, Eduardo Lima &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482917&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;eduardoll@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Tridge,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My GIT tree was not updated.. I just did a commit with a newer (but not the
&lt;br&gt;&amp;gt; latest) version..
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The version that is now on the git tree is the one that I was doing tests
&lt;br&gt;&amp;gt; to remove some fields from a deleted object.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Tomorrow I will ready more carefully your email.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Eduardo Lima
&lt;br&gt;&amp;gt; Sent from Campinas, SP, Brazil
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Wed, Nov 18, 2009 at 23:16, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482917&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tridge@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi Eduardo,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; I created this utility function that gets the defaultNamingContext and
&lt;br&gt;&amp;gt;&amp;gt; put
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; &amp;quot;CN=Deleted Objects&amp;quot; in front of the DN.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I found your git tree at git://repo.or.cz/Samba/eduardoll.git and had
&lt;br&gt;&amp;gt;&amp;gt; a look at the function. It has a couple of problems:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;1) it suffers from the very common cut&amp;paste problem with error
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;messages - I think 'dsServiceName' in the error message should be
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;'defaultNamingContext'
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;2) it doesn't add the &amp;quot;Deleted Objects&amp;quot; rDN to the returned
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;result. You could use ldb_dn_add_child_fmt() to add it like this:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; deleted_dn = ldb_dn_add_child_fmt(base_dn, &amp;quot;Deleted Objects&amp;quot;);
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;3) I don't think you actually need to do the search for
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;defaultNamingContext. Take a look at the function
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;samdb_partitions_dn() for what would be a closer example to what you
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;need. That one adds &amp;quot;CN=Partitions&amp;quot; to samdb_config_dn(). If you
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;instead add &amp;quot;CN=Deleted Objects&amp;quot; to samdb_base_dn() then I think
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;you'll have what you want.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; Will this work for every type of object? (every object in the
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; domain - even if it's in the deepest depth - should be moved
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; directly to CN=Deleted Objects,DC=w2k8... when deleted?)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; hmm, looking at a w2k8 server, it looks like there is a separate
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot;Deleted Objects&amp;quot; container in the configuration partition. That means
&lt;br&gt;&amp;gt;&amp;gt; my suggestion above is wrong, and you'll instead need to work out the
&lt;br&gt;&amp;gt;&amp;gt; correct &amp;quot;Deleted Objects&amp;quot; location based upon the DN of the object
&lt;br&gt;&amp;gt;&amp;gt; being deleted.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; One curious thing is that there is no &amp;quot;Deleted Objects&amp;quot; container in
&lt;br&gt;&amp;gt;&amp;gt; the schema partition on w2k8. I think you should investigate what
&lt;br&gt;&amp;gt;&amp;gt; happens to deleted objects in the schema partition. Perhaps if a
&lt;br&gt;&amp;gt;&amp;gt; partition does not have a Deleted Objects container then
&lt;br&gt;&amp;gt;&amp;gt; the repl_meta_data module should not do the rename/modify change and
&lt;br&gt;&amp;gt;&amp;gt; instead should just delete it? Or maybe it get moved into the Deleted
&lt;br&gt;&amp;gt;&amp;gt; Objects container of the next partition up?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; You should investigate this by creating and then deleting an object in
&lt;br&gt;&amp;gt;&amp;gt; a schema partitino of a w2k8 server and see what happens to the
&lt;br&gt;&amp;gt;&amp;gt; object. If you run something like this:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;bin/ldbsearch -H ldap://w2k8 -Uadministrator%password --controls
&lt;br&gt;&amp;gt;&amp;gt; show_deleted:1,search_options:1:2 'isDeleted=TRUE' dn objectclass
&lt;br&gt;&amp;gt;&amp;gt; lastKnownParent
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; then it will give you an idea of where the deleted objects are going.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Once you've done that, you'll need to add a function in
&lt;br&gt;&amp;gt;&amp;gt; repl_meta_data.c that works out the DN of the Deleted Objects
&lt;br&gt;&amp;gt;&amp;gt; container given the DN of an object being deleted. There are several
&lt;br&gt;&amp;gt;&amp;gt; ways to do this. One reasonable approach would be to add a function in
&lt;br&gt;&amp;gt;&amp;gt; dsdb/common/util.c like this:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;struct ldb_dn *dsdb_find_nc_root(struct ldb_context *samdb, struct ldb_dn
&lt;br&gt;&amp;gt;&amp;gt; *dn);
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; it would work by chopping off components from the DN (using
&lt;br&gt;&amp;gt;&amp;gt; ldb_dn_get_parent()) one at a time until it found a DN that has an
&lt;br&gt;&amp;gt;&amp;gt; instanceType with INSTANCE_TYPE_IS_NC_HEAD set. You'll need to do a
&lt;br&gt;&amp;gt;&amp;gt; base search for instanceType for each DN as you loop.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Then you'd add the &amp;quot;CN=Deleted Objects&amp;quot; to that, and see if it
&lt;br&gt;&amp;gt;&amp;gt; exists. If it does then you can do the rename/modify. If not then just
&lt;br&gt;&amp;gt;&amp;gt; pass the original delete request down to the next module.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; You will also need to change our provision to add a &amp;quot;Deleted Objects&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; container for the configuration partition. If you look at
&lt;br&gt;&amp;gt;&amp;gt; setup/provision.ldif you'll see that it has adds &amp;quot;Deleted Objects&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; container for the DOMAINDN, but not for the configuration
&lt;br&gt;&amp;gt;&amp;gt; partition. You'll need to add it to
&lt;br&gt;&amp;gt;&amp;gt; setup/provision_configuration_basedn.ldif.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; This is the part that I'm having more difficulty. I still can't
&lt;br&gt;&amp;gt;&amp;gt; understand
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; well what the modules are and the way that they work in the Samba
&lt;br&gt;&amp;gt;&amp;gt; source. &amp;nbsp;I
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; saw that ldb_module structure has *prev and *next fields and modules
&lt;br&gt;&amp;gt;&amp;gt; might
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; be linked together but why would all the modules be renamed if I use
&lt;br&gt;&amp;gt;&amp;gt; the
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; ldb_rename with the top level ldb context? When I do a bin/ldbdel
&lt;br&gt;&amp;gt;&amp;gt; operation,
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;&amp;gt; what is the execution's flow that the modules follow?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; This is one of the more complex aspects of Samba. I'll try and explain
&lt;br&gt;&amp;gt;&amp;gt; it, and if you have any more questions then please ask.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Plain ldb is very simple. It knows nothing about the complexities of
&lt;br&gt;&amp;gt;&amp;gt; active directory. It knows nothing about schemas, or objectclasses or
&lt;br&gt;&amp;gt;&amp;gt; any of the things that go to make up a AD compatible system. It just
&lt;br&gt;&amp;gt;&amp;gt; knows how to store, retrieve and modify objects in a dumb fashion.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The way it becomes more like AD is to have a series of modules. If you
&lt;br&gt;&amp;gt;&amp;gt; do this search:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;bin/ldbsearch -H $PREFIX/private/sam.ldb -b @MODULES -s base
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; then you'll see the list of modules that are in your database. That
&lt;br&gt;&amp;gt;&amp;gt; list currently looks like this:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; @LIST:
&lt;br&gt;&amp;gt;&amp;gt; resolve_oids,rootdse,lazy_commit,paged_results,ranged_results,anr,server_sort,asq,extended_dn_store,extended_dn_in,rdn_name,objectclass,descriptor,acl,samldb,password_hash,operational,kludge_acl,instancetype,repl_meta_data,subtree_rename,subtree_delete,linked_attributes,extended_dn_out_ldb,show_deleted,schema_load,new_partition,partition
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; as you can see, there are a lot of modules!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; When you call an ldb operation, for example a ldb_delete() call, then
&lt;br&gt;&amp;gt;&amp;gt; the ldb code will check with each of these modules in the order they
&lt;br&gt;&amp;gt;&amp;gt; are listed, and if the module has a registered 'delete' function then
&lt;br&gt;&amp;gt;&amp;gt; that function is called.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If you look at the first module in the list (the resolve_oids module)
&lt;br&gt;&amp;gt;&amp;gt; and look near the bottom of resolve_oids.c you'll see that it doesn't
&lt;br&gt;&amp;gt;&amp;gt; have a function for delete. That means that the resolve_oids module
&lt;br&gt;&amp;gt;&amp;gt; will not affect delete operations.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; It does however have a method for 'add'. So let's look at what that
&lt;br&gt;&amp;gt;&amp;gt; does.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Imagine we called ldb_add() to add an object to the database. The ldb
&lt;br&gt;&amp;gt;&amp;gt; code will see that the resolve_oids module has an 'add' method, so it
&lt;br&gt;&amp;gt;&amp;gt; will call resolve_oids_add(). If you look inside that function you'll
&lt;br&gt;&amp;gt;&amp;gt; see that it can complete in a number of ways:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;1) if it decides that it doesn't need to do anything, it can call
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;ldb_next_request() passing the original request (the 'req'
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;argument). That asks ldb to call the next module in the list that has
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;an 'add' method.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;2) it can return an error. You can see for examples places where it
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;returns LDB_ERR_OPERATIONS_ERROR when it fails to allocate some
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;memory.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;3) it can construct a new request which does something different, and
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;then call ldb_next_request() with that new request. This is what it
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;does in this line:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;return ldb_next_request(module, down_req);
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;That asks ldb to pass a newly constructed request down to the next
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;module. Notice that it has specified a callback
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;(resolve_oids_callback) that should be called when this new request
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;is finished.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In this way, each ldb request passes through each of the modules that
&lt;br&gt;&amp;gt;&amp;gt; wants to be involved with that type of request. Eventually the request
&lt;br&gt;&amp;gt;&amp;gt; gets down to the last module in the chain, which is the ldb_tdb module
&lt;br&gt;&amp;gt;&amp;gt; that actually implements the backend (that is not shown in the @LIST
&lt;br&gt;&amp;gt;&amp;gt; above, it is implied). The ldb_tdb module, which just implements dumb
&lt;br&gt;&amp;gt;&amp;gt; message storage, does the actual change to the database.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; So, back to my original comment on using ldb_rename() with a ldb
&lt;br&gt;&amp;gt;&amp;gt; context. The way you had done it will work, but it probably isn't
&lt;br&gt;&amp;gt;&amp;gt; quite the right thing to do. You are calling it from within the
&lt;br&gt;&amp;gt;&amp;gt; repl_meta_data module. That means you are half way through the list of
&lt;br&gt;&amp;gt;&amp;gt; modules above. All of the modules above have either done what they
&lt;br&gt;&amp;gt;&amp;gt; want to do to this request, or don't want to do anything.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; By calling ldb_rename() you are starting at the top of the module list
&lt;br&gt;&amp;gt;&amp;gt; again. This means every module above you will see the rename. Do you
&lt;br&gt;&amp;gt;&amp;gt; want that? I think in this case you probably don't, and what you
&lt;br&gt;&amp;gt;&amp;gt; really want to do is pass the rename down to the modules below you,
&lt;br&gt;&amp;gt;&amp;gt; skipping the ones above.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; One of the reasons we try to do this is to avoid looping forever. If
&lt;br&gt;&amp;gt;&amp;gt; we go to the top of the stack for this rename, then that means the
&lt;br&gt;&amp;gt;&amp;gt; rename will come back down to the repl_meta_data module again. So
&lt;br&gt;&amp;gt;&amp;gt; we'll be calling our own module. I think in this case it will work,
&lt;br&gt;&amp;gt;&amp;gt; but it can be a bit hard to follow sometimes!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If you look at dsdb/samdb/ldb_modules/util.c then you can see some
&lt;br&gt;&amp;gt;&amp;gt; helper functions have been added to make this sort of &amp;quot;do an operation
&lt;br&gt;&amp;gt;&amp;gt; on the rest of the modules&amp;quot; call a bit easier. The helper functions
&lt;br&gt;&amp;gt;&amp;gt; are currently only for search, but you could add a new one for doing a
&lt;br&gt;&amp;gt;&amp;gt; rename starting at the current module. Following the pattern in that
&lt;br&gt;&amp;gt;&amp;gt; file, you'd add a new function:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;int dsdb_module_rename(struct ldb_module *module,
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;struct ldb_dn *olddn, struct ldb_dn *newdn);
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; it would call ldb_build_rename_req() to build a new rename request
&lt;br&gt;&amp;gt;&amp;gt; structure, then it would call ldb_next_request() and then call
&lt;br&gt;&amp;gt;&amp;gt; ldb_wait(), in much the same way that dsdb_module_search() works.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If you then use dsdb_module_rename() in your new code, then you will
&lt;br&gt;&amp;gt;&amp;gt; be doing the rename only on the modules below you in the stack. You
&lt;br&gt;&amp;gt;&amp;gt; should similarly add a dsdb_module_modify() call that follows the same
&lt;br&gt;&amp;gt;&amp;gt; pattern.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The only caveat to this is if there is a module above you in the stack
&lt;br&gt;&amp;gt;&amp;gt; that you actually want to see the rename. For example, the rdn_name
&lt;br&gt;&amp;gt;&amp;gt; module (in lib/ldb/modules/rdn_name.c) has special handling for rename
&lt;br&gt;&amp;gt;&amp;gt; operations to fix the 'name' field. If you follow my suggestion above
&lt;br&gt;&amp;gt;&amp;gt; then this special handling won't happen. What you need to do is check
&lt;br&gt;&amp;gt;&amp;gt; on a w2k8 server and see if the 'name' attribute is changed when you
&lt;br&gt;&amp;gt;&amp;gt; delete an object.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If I do this:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;bin/ldbsearch -H ldap://w2k8 -Uadministrator%password --controls
&lt;br&gt;&amp;gt;&amp;gt; show_deleted:1,search_options:1:2 'isDeleted=TRUE' dn objectclass
&lt;br&gt;&amp;gt;&amp;gt; lastKnownParent name --show-binary
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; then I can see that, yes, the 'name' attribute does look like it is
&lt;br&gt;&amp;gt;&amp;gt; being modified when you do a delete. That means we have two choices:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;1) also fix the 'name' attribute in the modify operation that you
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;will do as part of the delete handling in repl_meta_data.c. Add it
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;to the same modify that adds the isDeleted=TRUE attribute.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;2) forget what I said above and just use ldb_rename(). That means
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;that the rdn_name modules will do the fixup of 'name' for you.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I think that (1) is a better choice, as I think it makes it clearer
&lt;br&gt;&amp;gt;&amp;gt; exactly what a delete does in the repl_meta_data module.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I hope this helps!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Cheers, Tridge
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH--s4-drs%3A-replmd_delete-implementation-tp26345560p26482917.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26482343</id>
	<title>Re: [Release Planning 3.5] Samba 3.5.0pre1 on October 26?</title>
	<published>2009-11-23T09:21:17Z</published>
	<updated>2009-11-23T09:21:17Z</updated>
	<author>
		<name>Jeremy Allison</name>
	</author>
	<content type="html">On Mon, Nov 23, 2009 at 09:13:09AM +0100, Karolin Seeger wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Jeremy,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Thu, Nov 12, 2009 at 02:29:36PM -0800, Jeremy Allison wrote:
&lt;br&gt;&amp;gt; &amp;gt; On Tue, Nov 10, 2009 at 10:21:44AM +0100, Karolin Seeger wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; I am wondering when we can ship the first 3.5.0 preview tarball.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Do you still estimate mid November for your &amp;quot;create time&amp;quot; store?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Would November 26 be a realistic release date for pre1?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Yes, I'll try and get this fix done and included by the
&lt;br&gt;&amp;gt; &amp;gt; end of next week (20th).
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; have you finished the create time stuff?
&lt;br&gt;&amp;gt; Would you like to provide some information on your 3.5 changes for the
&lt;br&gt;&amp;gt; release notes, please?
&lt;/div&gt;&lt;br&gt;Yes it's done - I'm still testing of course but the
&lt;br&gt;code is in :-).
&lt;br&gt;&lt;br&gt;I'll write something this before 26th.
&lt;br&gt;&lt;br&gt;Thanks !
&lt;br&gt;&lt;br&gt;Jeremy.
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-Release-Planning-3.5--Samba-3.5.0pre1-on-October-29--tp25817874p26482343.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26482114</id>
	<title>Re: Structure of prefixMap over LDAP</title>
	<published>2009-11-23T09:06:56Z</published>
	<updated>2009-11-23T09:06:56Z</updated>
	<author>
		<name>Obaid Farooqi</name>
	</author>
	<content type="html">Hi Andrew:
&lt;br&gt;We're still working on this issue and I'll be in touch as soon as I have something concrete.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Obaid Farooqi
&lt;br&gt;Sr. Support Escalation Engineer | Microsoft
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Obaid Farooqi 
&lt;br&gt;Sent: Wednesday, November 11, 2009 2:38 PM
&lt;br&gt;To: 'Andrew Bartlett'
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: RE: Structure of prefixMap over LDAP
&lt;br&gt;&lt;br&gt;Hi Andrew:
&lt;br&gt;I'll be helping you with your question regarding perfMap over LDAP. If you have any question/clarification about this issue, please feel free to contact me.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Obaid Farooqi
&lt;br&gt;Sr. Support Escalation Engineer | Microsoft
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Andrew Bartlett [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;] 
&lt;br&gt;Sent: Tuesday, November 10, 2009 6:39 PM
&lt;br&gt;To: Interoperability Documentation Help
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pfif@...&lt;/a&gt;
&lt;br&gt;Subject: Structure of prefixMap over LDAP
&lt;br&gt;&lt;br&gt;MS-ADA3 2.115 describes the prefixmap:
&lt;br&gt;&lt;br&gt;&amp;nbsp; Attribute prefixMap
&lt;br&gt;&amp;nbsp; The prefixMap attribute is for internal use only.
&lt;br&gt;&lt;br&gt;However, it is exposed over LDAP, and I don't see a description of it's format in MS-ADTS. &amp;nbsp;With ldp I see only: 'binary blob'. &amp;nbsp;With ldbsearch, I see:
&lt;br&gt;&lt;br&gt;bin/ldbsearch -H ldap://win2k3-2.ad.naomi.abartlet.net -s base -b CN=Schema,CN=Configuration,DC=ad,DC=naomi,DC=abartlet,DC=net
&lt;br&gt;-Uadministrator prefixMap
&lt;br&gt;&lt;br&gt;# record 1
&lt;br&gt;dn: CN=Schema,CN=Configuration,DC=ad,DC=naomi,DC=abartlet,DC=net
&lt;br&gt;prefixMap::
&lt;br&gt;BwAAAFkAAADUEQcAKoZIikEBBcsTCAAqhkiB/xcBBbZuCAAqhkiBzBEBBVBvCAAqhk
&lt;br&gt;&amp;nbsp;iCugUBBesFCAAqhkiB8xcBBZQGBwAqhkiJHQEFzwYHACqGSNMFAQU=
&lt;br&gt;&lt;br&gt;(and our --show-binary option does not know how to parse this). 
&lt;br&gt;&lt;br&gt;It was in the past assumed that this attribute was not available over LDAP, but as it is, could you please describe the format?
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Andrew Bartlett
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrew Bartlett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://samba.org/~abartlet/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org/~abartlet/&lt;/a&gt;&lt;br&gt;Authentication Developer, Samba Team &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://samba.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://samba.org&lt;/a&gt;&lt;br&gt;Samba Developer, Cisco Inc.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;cifs-protocol mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26482114&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cifs-protocol@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.samba.org/mailman/listinfo/cifs-protocol&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/listinfo/cifs-protocol&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---cifs-protocol-f13152.html&quot; embed=&quot;fixTarget[13152]&quot; target=&quot;_top&quot; &gt;Samba - cifs-protocol&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Structure-of-prefixMap-over-LDAP-tp26294095p26482114.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26479955</id>
	<title>Re: a few SD questions</title>
	<published>2009-11-23T07:19:42Z</published>
	<updated>2009-11-23T07:19:42Z</updated>
	<author>
		<name>Matthias Dieter Wallnöfer-3</name>
	</author>
	<content type="html">Nadya,
&lt;br&gt;&lt;br&gt;Ah, okay.
&lt;br&gt;&lt;br&gt;Regarding security descriptors: this still fails in ldap.py &amp;nbsp;(at least 
&lt;br&gt;on my box). Do you plan investigations?
&lt;br&gt;&lt;br&gt;&amp;gt; test: Test add_ldif() with BASE64 security descriptor input using 
&lt;br&gt;&amp;gt; WRONG domain SID
&lt;br&gt;...
&lt;br&gt;&amp;gt; failure: Test add_ldif() with BASE64 security descriptor input using 
&lt;br&gt;&amp;gt; WRONG domain SID [
&lt;br&gt;&amp;gt; Traceback (most recent call last):
&lt;br&gt;&amp;gt; &amp;nbsp; File &amp;quot;./lib/ldb/tests/python/ldap.py&amp;quot;, line 1730, in 
&lt;br&gt;&amp;gt; test_security_descriptor_add_neg
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; self.assertRaises(KeyError, lambda: res[0][&amp;quot;nTSecurityDescriptor&amp;quot;])
&lt;br&gt;&amp;gt; AssertionError: KeyError not raised
&lt;br&gt;&amp;gt; ]
&lt;br&gt;Greets,
&lt;br&gt;Matthias
&lt;br&gt;&lt;br&gt;Nadezhda Ivanova wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Matthias,
&lt;br&gt;&amp;gt; I have some more work to do on access checks for the search request - as you can see, acl.c does not yet handle them. I expect this will be done by the end of the week. After that, kludge will stay in the codebase for a little while, and will be optionally enabled by a configuration parameter. This will allow testers (read ekacnet) to fall back to it if some very serious bug is found. I suppose eventually we will remove it altogether.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Nadya
&lt;br&gt;&amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; From: Matthias Dieter Wallnöfer&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdw@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; To: Nadezhda Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Andrew Bartlett&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sent: Monday, November 23, 2009 4:00:21 PM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: a few SD questions
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hi Nadya,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (maybe a bit out of topic - but I think it's worth to ask) do you plan
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; to remove the &amp;quot;kludge_acl&amp;quot; module? I think with your recent work it's
&lt;br&gt;&amp;gt;&amp;gt; nearly obsolete and I personally don't see it useful anymore (to be
&lt;br&gt;&amp;gt;&amp;gt; honest I would like to see it dropped soon). I think with some minor
&lt;br&gt;&amp;gt;&amp;gt; work and suggestions by abartlet it should be feasible.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Matthias
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Nadezhda Ivanova wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hi Mattieu,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thanks for the research. I do not understand however why you expect
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; to have an ID (I assume that is what you mean by DI) flag in the DACL
&lt;br&gt;&amp;gt;&amp;gt; ace. The DACL has the P flag, which means break inheritance - we are
&lt;br&gt;&amp;gt;&amp;gt; not supposed to inherit anything from the parent in the DACL. This is
&lt;br&gt;&amp;gt;&amp;gt; also the case in the win2k3 descriptor that you have pasted. In that
&lt;br&gt;&amp;gt;&amp;gt; descriptor you seem to have nothing inherited in the DACL as well.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The sacl seems to me missing an inherit only flag, will have to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; debug what is causing this...
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I am also not sure about the differences in the group. Are you sure
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; the policy in win2k3 has been created without providing an owner or a
&lt;br&gt;&amp;gt;&amp;gt; group?
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Nadya
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; From: Matthieu Patou&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; To: samba-technical&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Nadezhda
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479955&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Sent: Monday, November 23, 2009 8:42:09 AM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: a few SD questions
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello nadya,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I made some tests today with GPO and it seems that things are
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; getting
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; lot more better
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Below it's the SD for a newly created policy, it quite OK just we
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; have
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the duplicate ACL for Domain Admins due to the fact that the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; creator
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; owner is Domain Admin. Also I think that we should have the AI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; control
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; flag as the SD is DACL_PROTECTED and that it has some (all?) ACL
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; from
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the parent SD. Also those inherited ACE should have the flag DI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (although it isn't very clear what is the effect of this flag,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; seems
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; more cosmetic than something else to me).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-487418869-183637953-2310109715-512G:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S-1-5-21-487418869-183637953-2310109715-513D:P
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-487418869-183637953-231010971
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 5-512)(A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-2
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 1-487418869-183637953-2310109715-519)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; 487418869-183637953-2310109715-512)(A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;C
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; O)(A;C
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; I;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)(OA;CI;CR;edacfd8f-ffb3-1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 1d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S:AI(OU;CIIDSA;WP;f30e3bbe-9ff0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; -11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CII
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; DSA;WP
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; ;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa00304
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 9e2;WD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; )
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In the same time here is the SD for a newly create gpo in w2k3:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; They are identical for the DACL part, there is still some
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; difference
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the sacl part. Also it's worth noting that the group is different
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; O:S-1-5-21-3208502064-746857408-2662927446-512G:S-1-5-21-3208502064-746
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 857408-2662927446-512
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; D:PAI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 46-512)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 46-519)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-2662927446
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -512)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;CO)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; S:AI
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/a-few-SD-questions-tp26473433p26479955.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26480038</id>
	<title>Re: a few SD questions</title>
	<published>2009-11-23T07:19:24Z</published>
	<updated>2009-11-23T07:19:24Z</updated>
	<author>
		<name>Nadezhda Ivanova-2</name>
	</author>
	<content type="html">Eventually yes. Got to ask Zahari what is the purpose of this test...
&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;&amp;gt; From: Matthias Dieter Wallnöfer &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdw@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Nadezhda Ivanova &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sent: Monday, November 23, 2009 5:15:00 PM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; Subject: Re: a few SD questions
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; Nadya,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Ah, okay.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Regarding security descriptors: this still fails in ldap.py &amp;nbsp;(at least 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; on my box). Do you plan investigations?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; test: Test add_ldif() with BASE64 security descriptor input using 
&lt;br&gt;&amp;gt; &amp;gt; WRONG domain SID
&lt;br&gt;&amp;gt; ...
&lt;br&gt;&amp;gt; &amp;gt; failure: Test add_ldif() with BASE64 security descriptor input using 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; WRONG domain SID [
&lt;br&gt;&amp;gt; &amp;gt; Traceback (most recent call last):
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; File &amp;quot;./lib/ldb/tests/python/ldap.py&amp;quot;, line 1730, in 
&lt;br&gt;&amp;gt; &amp;gt; test_security_descriptor_add_neg
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; self.assertRaises(KeyError, lambda: 
&lt;br&gt;&amp;gt; res[0][&amp;quot;nTSecurityDescriptor&amp;quot;])
&lt;br&gt;&amp;gt; &amp;gt; AssertionError: KeyError not raised
&lt;br&gt;&amp;gt; &amp;gt; ]
&lt;br&gt;&amp;gt; Greets,
&lt;br&gt;&amp;gt; Matthias
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Nadezhda Ivanova wrote:
&lt;br&gt;&amp;gt; &amp;gt; Hi Matthias,
&lt;br&gt;&amp;gt; &amp;gt; I have some more work to do on access checks for the search request 
&lt;br&gt;&amp;gt; - as you can see, acl.c does not yet handle them. I expect this will 
&lt;br&gt;&amp;gt; be done by the end of the week. After that, kludge will stay in the 
&lt;br&gt;&amp;gt; codebase for a little while, and will be optionally enabled by a 
&lt;br&gt;&amp;gt; configuration parameter. This will allow testers (read ekacnet) to 
&lt;br&gt;&amp;gt; fall back to it if some very serious bug is found. I suppose 
&lt;br&gt;&amp;gt; eventually we will remove it altogether.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Regards,
&lt;br&gt;&amp;gt; &amp;gt; Nadya
&lt;br&gt;&amp;gt; &amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; From: Matthias Dieter Wallnöfer&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdw@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; To: Nadezhda Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;, 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, 
&lt;br&gt;&amp;gt; Andrew Bartlett&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Sent: Monday, November 23, 2009 4:00:21 PM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Subject: Re: a few SD questions
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Hi Nadya,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (maybe a bit out of topic - but I think it's worth to ask) do you 
&lt;br&gt;&amp;gt; plan
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; to remove the &amp;quot;kludge_acl&amp;quot; module? I think with your recent work 
&lt;br&gt;&amp;gt; it's
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; nearly obsolete and I personally don't see it useful anymore (to be
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; honest I would like to see it dropped soon). I think with some 
&lt;br&gt;&amp;gt; minor
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; work and suggestions by abartlet it should be feasible.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Matthias
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Nadezhda Ivanova wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Hi Mattieu,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Thanks for the research. I do not understand however why you 
&lt;br&gt;&amp;gt; expect
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; to have an ID (I assume that is what you mean by DI) flag in the 
&lt;br&gt;&amp;gt; DACL
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; ace. The DACL has the P flag, which means break inheritance - we 
&lt;br&gt;&amp;gt; are
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; not supposed to inherit anything from the parent in the DACL. This 
&lt;br&gt;&amp;gt; is
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; also the case in the win2k3 descriptor that you have pasted. In 
&lt;br&gt;&amp;gt; that
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; descriptor you seem to have nothing inherited in the DACL as well.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; The sacl seems to me missing an inherit only flag, will have to
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; debug what is causing this...
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; I am also not sure about the differences in the group. Are you 
&lt;br&gt;&amp;gt; sure
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; the policy in win2k3 has been created without providing an owner or 
&lt;br&gt;&amp;gt; a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; group?
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Nadya
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; From: Matthieu Patou&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; To: samba-technical&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=16&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Nadezhda
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26480038&amp;i=17&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Sent: Monday, November 23, 2009 8:42:09 AM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: a few SD questions
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello nadya,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; I made some tests today with GPO and it seems that things are
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; getting
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; lot more better
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Below it's the SD for a newly created policy, it quite OK just we
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; have
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; the duplicate ACL for Domain Admins due to the fact that the
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; creator
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; owner is Domain Admin. Also I think that we should have the AI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; control
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; flag as the SD is DACL_PROTECTED and that it has some (all?) ACL
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; from
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; the parent SD. Also those inherited ACE should have the flag DI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (although it isn't very clear what is the effect of this flag,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; seems
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; more cosmetic than something else to me).
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; O:S-1-5-21-487418869-183637953-2310109715-512G:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; S-1-5-21-487418869-183637953-2310109715-513D:P
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-487418869-183637953-231010971
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; 5-512)(A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-2
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 1-487418869-183637953-2310109715-519)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; 487418869-183637953-2310109715-512)(A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;C
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; O)(A;C
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; I;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)(OA;CI;CR;edacfd8f-ffb3-1
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 1d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; S:AI(OU;CIIDSA;WP;f30e3bbe-9ff0
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; -11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CII
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; DSA;WP
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; ;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa00304
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; 9e2;WD
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; )
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; In the same time here is the SD for a newly create gpo in w2k3:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; They are identical for the DACL part, there is still some
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; difference
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; the sacl part. Also it's worth noting that the group is different
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; O:S-1-5-21-3208502064-746857408-2662927446-512G:S-1-5-21-3208502064-746
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; 857408-2662927446-512
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; D:PAI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; 46-512)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; 46-519)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-2662927446
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; -512)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;CO)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; S:AI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; (OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/a-few-SD-questions-tp26473433p26480038.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26479634</id>
	<title>Vista laptop in Samba 3.3.4 domain suddenly trying to use roaming profiles?</title>
	<published>2009-11-23T07:03:20Z</published>
	<updated>2009-11-23T07:03:20Z</updated>
	<author>
		<name>David Whitney-3</name>
	</author>
	<content type="html">Grettings, all
&lt;br&gt;&lt;br&gt;I have a bizarre problem on a laptop in my Samba 3.3.4 domain. This domain
&lt;br&gt;includes a mixture of XP Pro and Vista Ultimate clients.
&lt;br&gt;&lt;br&gt;I had just completed a migration to this new domain (from a Samba 2.2.8a
&lt;br&gt;domain), and all seemed happy and well - machines had rebooted and were
&lt;br&gt;still active in the domain, users were logging in with no problem, shares
&lt;br&gt;were working perfectly - all over the span of a week or so - until last
&lt;br&gt;night.
&lt;br&gt;&lt;br&gt;Trying to log into my wife's laptop (Vista Ultimate) under her account, I
&lt;br&gt;got an odd message that said &amp;quot;Your roaming profile was not completely
&lt;br&gt;synchronized. Please contact your administrator.&amp;quot; The only problem is I am
&lt;br&gt;*not* using roaming profiles in my Samba domain! And this account had logged
&lt;br&gt;into the domain several times on this laptop with no problem after the
&lt;br&gt;migration.
&lt;br&gt;&lt;br&gt;I looked on the home shares for the particular account, and surely enough
&lt;br&gt;there is the &amp;quot;profile.V2&amp;quot; folder indicating what I understand is the attempt
&lt;br&gt;by a Vista box to build a first-time Vista-style roaming profile on my
&lt;br&gt;Samba-defined user share. I logged in under a different account that has
&lt;br&gt;admin privs, and sure enough, it tried to load a roaming profile there, too.
&lt;br&gt;That told me, additionally, that Vista thought this was the first time this
&lt;br&gt;user had logged into that box/domain, which was obviously incorrect. The
&lt;br&gt;profiles for each user that had used until that point were on the machine,
&lt;br&gt;intact.
&lt;br&gt;&lt;br&gt;I've changed the local policy on that box to disallow roaming profiles
&lt;br&gt;expressly, but now the local profiles that had been working just fine are no
&lt;br&gt;longer associated with their proper users, and I'm not sure how to restore
&lt;br&gt;the association (or even if I can). I can browse the machine remotely and
&lt;br&gt;copy the files from that local profile if I have to, but I'd like to avoid
&lt;br&gt;it.
&lt;br&gt;Could the learned folks here offer any suggestions on why this laptop would
&lt;br&gt;suddenly think it was supposed to use roaming profiles on my
&lt;br&gt;non-roaming-profile Samba domain? Is there some mystery setting in smb.conf
&lt;br&gt;I might possibly have set (or perhaps deleted??) that would leave Samba
&lt;br&gt;thinking was trying to use roaming profiles? Based on late-night research, I
&lt;br&gt;expressly set &amp;quot;logon path&amp;quot; to be blank in smb.conf, which is supposed to
&lt;br&gt;disable Samba roaming profiles. It had not been expressly set before. I have
&lt;br&gt;logged into a desktop box and it worked normally.
&lt;br&gt;&lt;br&gt;Appreciate any thoughts or suggestions. The desktop boxes, so far, seem
&lt;br&gt;unaffected and are working normally. I'm thinking my next step is to copy
&lt;br&gt;the files from the particular profile in question, remove the machine from
&lt;br&gt;the domain, and then rejoin it, but I'm not sure I still won't have the same
&lt;br&gt;problem.
&lt;br&gt;&lt;br&gt;The only other problem I've had in this migration was in getting logon
&lt;br&gt;scripts to work (which I never did), but I don't think this is related to
&lt;br&gt;that issue....and the fact that other than scripts the domain was working
&lt;br&gt;fine is what really has me puzzled.
&lt;br&gt;&lt;br&gt;Any thoughts or suggestions appreciated.
&lt;br&gt;-David
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vista-laptop-in-Samba-3.3.4-domain-suddenly-trying-to-use-roaming-profiles--tp26479634p26479634.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26479059</id>
	<title>Re: [s4] My recent work</title>
	<published>2009-11-23T06:24:35Z</published>
	<updated>2009-11-23T06:24:35Z</updated>
	<author>
		<name>Nadezhda Ivanova-2</name>
	</author>
	<content type="html">I noticed that you fixed some warnings. Way to go, they were annoying :). I really think we should avoid warnings like &amp;quot;incompatible pointer type&amp;quot; and &amp;quot;not handled in switch&amp;quot;, these are all potential bugs...
&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479059&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical-bounces@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479059&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical-bounces@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Andrew Bartlett &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479059&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt;, Matthias Dieter Wallnöfer &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479059&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdw@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: samba-technical &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479059&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sent: Monday, November 23, 2009 4:15:53 PM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; Subject: [s4] My recent work
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; Hi abartlet and other s4 developers,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I would like to bring to attention my recent work:
&lt;br&gt;&amp;gt; - &amp;quot;const&amp;quot; patches: I did improvements over the last weekend and some 
&lt;br&gt;&amp;gt; (those in common with s3) where merged - the s4 ones are outstanding: 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&lt;/a&gt;&lt;br&gt;&amp;gt; - &amp;quot;operational&amp;quot; work: I changed the operational attributes to be 
&lt;br&gt;&amp;gt; read-only through a indeed very simple patch - I hope that's enough: 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&lt;/a&gt;&lt;br&gt;&amp;gt; - &amp;quot;index counters&amp;quot;: I corrected the patch for LDB 
&lt;br&gt;&amp;gt; (&lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad4&lt;/a&gt;&lt;br&gt;&amp;gt; 5440a612c23cd15) 
&lt;br&gt;&amp;gt; - hope to have fixed it according to your suggestions
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Matthias
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-s4--My-recent-work-tp26478915p26479059.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26478915</id>
	<title>[s4] My recent work</title>
	<published>2009-11-23T06:20:35Z</published>
	<updated>2009-11-23T06:20:35Z</updated>
	<author>
		<name>Matthias Dieter Wallnöfer-3</name>
	</author>
	<content type="html">Hi abartlet and other s4 developers,
&lt;br&gt;&lt;br&gt;I would like to bring to attention my recent work:
&lt;br&gt;- &amp;quot;const&amp;quot; patches: I did improvements over the last weekend and some 
&lt;br&gt;(those in common with s3) where merged - the s4 ones are outstanding: 
&lt;br&gt;&lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/const&lt;/a&gt;&lt;br&gt;- &amp;quot;operational&amp;quot; work: I changed the operational attributes to be 
&lt;br&gt;read-only through a indeed very simple patch - I hope that's enough: 
&lt;br&gt;&lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/shortlog/refs/heads/operational&lt;/a&gt;&lt;br&gt;- &amp;quot;index counters&amp;quot;: I corrected the patch for LDB 
&lt;br&gt;(&lt;a href=&quot;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad45440a612c23cd15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://repo.or.cz/w/Samba/mdw.git/commitdiff/8fec9b617e00dc577bdaebad45440a612c23cd15&lt;/a&gt;) 
&lt;br&gt;- hope to have fixed it according to your suggestions
&lt;br&gt;&lt;br&gt;Matthias
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-s4--My-recent-work-tp26478915p26478915.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26478906</id>
	<title>Re: a few SD questions</title>
	<published>2009-11-23T06:14:48Z</published>
	<updated>2009-11-23T06:14:48Z</updated>
	<author>
		<name>Nadezhda Ivanova-2</name>
	</author>
	<content type="html">Hi Matthias,
&lt;br&gt;I have some more work to do on access checks for the search request - as you can see, acl.c does not yet handle them. I expect this will be done by the end of the week. After that, kludge will stay in the codebase for a little while, and will be optionally enabled by a configuration parameter. This will allow testers (read ekacnet) to fall back to it if some very serious bug is found. I suppose eventually we will remove it altogether.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Nadya
&lt;br&gt;----- Original Message -----
&lt;br&gt;&amp;gt; From: Matthias Dieter Wallnöfer &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdw@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Nadezhda Ivanova &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Andrew Bartlett &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;abartlet@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sent: Monday, November 23, 2009 4:00:21 PM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; Subject: Re: a few SD questions
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; Hi Nadya,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; (maybe a bit out of topic - but I think it's worth to ask) do you plan 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; to remove the &amp;quot;kludge_acl&amp;quot; module? I think with your recent work it's 
&lt;br&gt;&amp;gt; nearly obsolete and I personally don't see it useful anymore (to be 
&lt;br&gt;&amp;gt; honest I would like to see it dropped soon). I think with some minor 
&lt;br&gt;&amp;gt; work and suggestions by abartlet it should be feasible.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Matthias
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Nadezhda Ivanova wrote:
&lt;br&gt;&amp;gt; &amp;gt; Hi Mattieu,
&lt;br&gt;&amp;gt; &amp;gt; Thanks for the research. I do not understand however why you expect 
&lt;br&gt;&amp;gt; to have an ID (I assume that is what you mean by DI) flag in the DACL 
&lt;br&gt;&amp;gt; ace. The DACL has the P flag, which means break inheritance - we are 
&lt;br&gt;&amp;gt; not supposed to inherit anything from the parent in the DACL. This is 
&lt;br&gt;&amp;gt; also the case in the win2k3 descriptor that you have pasted. In that 
&lt;br&gt;&amp;gt; descriptor you seem to have nothing inherited in the DACL as well.
&lt;br&gt;&amp;gt; &amp;gt; The sacl seems to me missing an inherit only flag, will have to 
&lt;br&gt;&amp;gt; debug what is causing this...
&lt;br&gt;&amp;gt; &amp;gt; I am also not sure about the differences in the group. Are you sure 
&lt;br&gt;&amp;gt; the policy in win2k3 has been created without providing an owner or a 
&lt;br&gt;&amp;gt; group?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Regards,
&lt;br&gt;&amp;gt; &amp;gt; Nadya
&lt;br&gt;&amp;gt; &amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; From: Matthieu Patou&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; To: samba-technical&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Nadezhda 
&lt;br&gt;&amp;gt; Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478906&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Sent: Monday, November 23, 2009 8:42:09 AM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Subject: a few SD questions
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Hello nadya,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; I made some tests today with GPO and it seems that things are 
&lt;br&gt;&amp;gt; getting
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; lot more better
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Below it's the SD for a newly created policy, it quite OK just we 
&lt;br&gt;&amp;gt; have
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; the duplicate ACL for Domain Admins due to the fact that the 
&lt;br&gt;&amp;gt; creator
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; owner is Domain Admin. Also I think that we should have the AI 
&lt;br&gt;&amp;gt; control
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; flag as the SD is DACL_PROTECTED and that it has some (all?) ACL 
&lt;br&gt;&amp;gt; from
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; the parent SD. Also those inherited ACE should have the flag DI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (although it isn't very clear what is the effect of this flag, 
&lt;br&gt;&amp;gt; seems
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; more cosmetic than something else to me).
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; O:S-1-5-21-487418869-183637953-2310109715-512G:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; S-1-5-21-487418869-183637953-2310109715-513D:P
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-487418869-183637953-231010971
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 5-512)(A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-2
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;1-487418869-183637953-2310109715-519)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; 487418869-183637953-2310109715-512)(A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;C
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; O)(A;C
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;I;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)(OA;CI;CR;edacfd8f-ffb3-1
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;1d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; S:AI(OU;CIIDSA;WP;f30e3bbe-9ff0
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; -11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CII
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; DSA;WP
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; ;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa00304
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 9e2;WD
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; In the same time here is the SD for a newly create gpo in w2k3:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; They are identical for the DACL part, there is still some 
&lt;br&gt;&amp;gt; difference
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; the sacl part. Also it's worth noting that the group is different
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; O:S-1-5-21-3208502064-746857408-2662927446-512G:S-1-5-21-3208502064-746
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 857408-2662927446-512
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; D:PAI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 46-512)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 46-519)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-2662927446
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; -512)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;CO)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; S:AI
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; (OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/a-few-SD-questions-tp26473433p26478906.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26478705</id>
	<title>Re: home directories ask user for password</title>
	<published>2009-11-23T06:09:03Z</published>
	<updated>2009-11-23T06:09:03Z</updated>
	<author>
		<name>Massimo-21</name>
	</author>
	<content type="html">&amp;gt;Perhaps removing the 'valid users' solves your problem. In theory it can
&lt;br&gt;&amp;gt;only display the homedir of the user connecting. The 'homes' share is
&lt;br&gt;&amp;gt;translated to the user name. Below if my current config that is working
&lt;br&gt;&amp;gt;for me. The preexec that I have is creating the homedir if it does not
&lt;br&gt;&amp;gt;exist (Perhaps that may be another possible cause of your error?).
&lt;br&gt;&amp;gt;Script is included. Make sure you change $path to your homedir location.
&lt;br&gt;&amp;gt;For quota uncomment and change the quota function for a given device.
&lt;br&gt;&lt;br&gt;Hi Ton, Thank you for the help.
&lt;br&gt;I tryed to set your configuration.
&lt;br&gt;It creates the home directories but I receive access denied, wathching into the log I found that it looking for username.dll file but I don't know the matter.
&lt;br&gt;Below the log ...
&lt;br&gt;Bye 
&lt;br&gt;Massimo
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;[2009/11/23 14:43:05, 0] param/loadparm.c:process_usershare_file(4611)
&lt;br&gt;&amp;nbsp; process_usershare_file: stat of /var/lib/samba/usershares/massimo.dll failed. Permission denied
&lt;br&gt;[2009/11/23 14:43:07, 0] param/loadparm.c:process_usershare_file(4611)
&lt;br&gt;&amp;nbsp; process_usershare_file: stat of /var/lib/samba/usershares/massimo.dll failed. No such file or directory
&lt;br&gt;[2009/11/23 14:43:07, 0] smbd/service.c:make_connection(1200)
&lt;br&gt;&amp;nbsp; kdgp3fb (10.29.30.1) couldn't find service massimo.dll
&lt;br&gt;[2009/11/23 14:43:07, 0] smbd/service.c:set_current_service(184)
&lt;br&gt;&amp;nbsp; chdir (/home/massimo) failed
&lt;br&gt;[2009/11/23 14:43:07, 0] param/loadparm.c:process_usershare_file(4611)
&lt;br&gt;&amp;nbsp; process_usershare_file: stat of /var/lib/samba/usershares/massimo.dll failed. Permission denied
&lt;br&gt;[2009/11/23 14:43:09, 0] param/loadparm.c:process_usershare_file(4611)
&lt;br&gt;&amp;nbsp; process_usershare_file: stat of /var/lib/samba/usershares/massimo.dll failed. No such file or directory
&lt;br&gt;[2009/11/23 14:43:09, 0] smbd/service.c:make_connection(1200)
&lt;br&gt;&amp;nbsp; kdgp3fb (10.29.30.1) couldn't find service massimo.dll
&lt;br&gt;[2009/11/23 14:43:09, 0] smbd/service.c:set_current_service(184)
&lt;br&gt;&amp;nbsp; chdir (/home/massimo) failed
&lt;br&gt;[2009/11/23 14:43:09, 0] smbd/service.c:set_current_service(184)
&lt;br&gt;&amp;nbsp; chdir (/home/massimo) failed
&lt;br&gt;[2009/11/23 14:43:09, 0] smbd/service.c:set_current_service(184)
&lt;br&gt;&amp;nbsp; chdir (/home/massimo) failed
&lt;br&gt;[2009/11/23 14:43:09, 0] smbd/service.c:set_current_service(184)
&lt;br&gt;&amp;nbsp; chdir (/home/massimo) failed
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/home-directories-ask-user-for-password-tp26476610p26478705.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26478634</id>
	<title>Re: a few SD questions</title>
	<published>2009-11-23T06:05:09Z</published>
	<updated>2009-11-23T06:05:09Z</updated>
	<author>
		<name>Matthias Dieter Wallnöfer-3</name>
	</author>
	<content type="html">Hi Nadya,
&lt;br&gt;&lt;br&gt;(maybe a bit out of topic - but I think it's worth to ask) do you plan 
&lt;br&gt;to remove the &amp;quot;kludge_acl&amp;quot; module? I think with your recent work it's 
&lt;br&gt;nearly obsolete and I personally don't see it useful anymore (to be 
&lt;br&gt;honest I would like to see it dropped soon). I think with some minor 
&lt;br&gt;work and suggestions by abartlet it should be feasible.
&lt;br&gt;&lt;br&gt;Matthias
&lt;br&gt;&lt;br&gt;Nadezhda Ivanova wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Mattieu,
&lt;br&gt;&amp;gt; Thanks for the research. I do not understand however why you expect to have an ID (I assume that is what you mean by DI) flag in the DACL ace. The DACL has the P flag, which means break inheritance - we are not supposed to inherit anything from the parent in the DACL. This is also the case in the win2k3 descriptor that you have pasted. In that descriptor you seem to have nothing inherited in the DACL as well.
&lt;br&gt;&amp;gt; The sacl seems to me missing an inherit only flag, will have to debug what is causing this...
&lt;br&gt;&amp;gt; I am also not sure about the differences in the group. Are you sure the policy in win2k3 has been created without providing an owner or a group?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Nadya
&lt;br&gt;&amp;gt; ----- Original Message -----
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; From: Matthieu Patou&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478634&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mat@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; To: samba-technical&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478634&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;samba-technical@...&lt;/a&gt;&amp;gt;, Nadezhda Ivanova&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478634&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nadezhda.ivanova@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sent: Monday, November 23, 2009 8:42:09 AM GMT+0200 Europe;Athens
&lt;br&gt;&amp;gt;&amp;gt; Subject: a few SD questions
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hello nadya,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; I made some tests today with GPO and it seems that things are getting
&lt;br&gt;&amp;gt;&amp;gt; a
&lt;br&gt;&amp;gt;&amp;gt; lot more better
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Below it's the SD for a newly created policy, it quite OK just we have
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; the duplicate ACL for Domain Admins due to the fact that the creator
&lt;br&gt;&amp;gt;&amp;gt; owner is Domain Admin. Also I think that we should have the AI control
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; flag as the SD is DACL_PROTECTED and that it has some (all?) ACL from
&lt;br&gt;&amp;gt;&amp;gt; the parent SD. Also those inherited ACE should have the flag DI
&lt;br&gt;&amp;gt;&amp;gt; (although it isn't very clear what is the effect of this flag, seems
&lt;br&gt;&amp;gt;&amp;gt; more cosmetic than something else to me).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; O:S-1-5-21-487418869-183637953-2310109715-512G:
&lt;br&gt;&amp;gt;&amp;gt; S-1-5-21-487418869-183637953-2310109715-513D:P
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-487418869-183637953-231010971
&lt;br&gt;&amp;gt;&amp;gt; 5-512)(A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-2
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;1-487418869-183637953-2310109715-519)
&lt;br&gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; 487418869-183637953-2310109715-512)(A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;C
&lt;br&gt;&amp;gt;&amp;gt; O)(A;C
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;I;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)(OA;CI;CR;edacfd8f-ffb3-1
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;1d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt;&amp;gt; S:AI(OU;CIIDSA;WP;f30e3bbe-9ff0
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CII
&lt;br&gt;&amp;gt;&amp;gt; DSA;WP
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa00304
&lt;br&gt;&amp;gt;&amp;gt; 9e2;WD
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In the same time here is the SD for a newly create gpo in w2k3:
&lt;br&gt;&amp;gt;&amp;gt; They are identical for the DACL part, there is still some difference
&lt;br&gt;&amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt;&amp;gt; the sacl part. Also it's worth noting that the group is different
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; O:S-1-5-21-3208502064-746857408-2662927446-512G:S-1-5-21-3208502064-746
&lt;br&gt;&amp;gt;&amp;gt; 857408-2662927446-512
&lt;br&gt;&amp;gt;&amp;gt; D:PAI
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt;&amp;gt; 46-512)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-26629274
&lt;br&gt;&amp;gt;&amp;gt; 46-519)
&lt;br&gt;&amp;gt;&amp;gt; (A;;RPWPCCDCLCLORCWOWDSDDTSW;;;S-1-5-21-3208502064-746857408-2662927446
&lt;br&gt;&amp;gt;&amp;gt; -512)
&lt;br&gt;&amp;gt;&amp;gt; (A;CIIO;RPWPCCDCLCLORCWOWDSDDTSW;;;CO)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPWPCCDCLCLORCWOWDSDDTSW;;;SY)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;AU)
&lt;br&gt;&amp;gt;&amp;gt; (OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)
&lt;br&gt;&amp;gt;&amp;gt; (A;CI;RPLCLORC;;;ED)
&lt;br&gt;&amp;gt;&amp;gt; S:AI
&lt;br&gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt; (OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0
&lt;br&gt;&amp;gt;&amp;gt; -a285-00aa003049e2;WD)
&lt;br&gt;&amp;gt;&amp;gt; (OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Matthieu.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---samba-technical-f13164.html&quot; embed=&quot;fixTarget[13164]&quot; target=&quot;_top&quot; &gt;Samba - samba-technical&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/a-few-SD-questions-tp26473433p26478634.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26477641</id>
	<title>Re: home directories ask user for password</title>
	<published>2009-11-23T05:01:19Z</published>
	<updated>2009-11-23T05:01:19Z</updated>
	<author>
		<name>Hoogstraten, Ton</name>
	</author>
	<content type="html">Massimo,
&lt;br&gt;&lt;br&gt;Perhaps removing the 'valid users' solves your problem. In theory it can
&lt;br&gt;only display the homedir of the user connecting. The 'homes' share is
&lt;br&gt;translated to the user name. Below if my current config that is working
&lt;br&gt;for me. The preexec that I have is creating the homedir if it does not
&lt;br&gt;exist (Perhaps that may be another possible cause of your error?).
&lt;br&gt;Script is included. Make sure you change $path to your homedir location.
&lt;br&gt;For quota uncomment and change the quota function for a given device.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Ton
&lt;br&gt;&lt;br&gt;&lt;br&gt;[homes]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = Home Directories
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read only = No
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; browseable = No
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; root preexec = /etc/samba/homedir.pl %U
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; create mask = 0664
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; directory mask = 0775
&lt;br&gt;&lt;br&gt;&lt;br&gt;homedir.pl:
&lt;br&gt;&lt;br&gt;#!/usr/bin/perl -w
&lt;br&gt;use strict;
&lt;br&gt;&lt;br&gt;my $user = shift;
&lt;br&gt;my $path = &amp;quot;&amp;lt;path to your homedir locations&amp;gt;&amp;quot;;
&lt;br&gt;my $logfile = &amp;quot;/var/log/samba/homedir.log&amp;quot;;
&lt;br&gt;&lt;br&gt;if (! -d &amp;quot;$path/$user&amp;quot; &amp;&amp; $user) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (my $uid = getpwnam($user)) {
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if ((mkdir &amp;quot;$path/$user&amp;quot;,0750) &amp;&amp; (chown $uid, -1,
&lt;br&gt;&amp;quot;$path/$user&amp;quot;)) { 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; open(LOG, &amp;quot;&amp;gt;&amp;gt;$logfile&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; my $time = localtime;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print LOG &amp;quot;$time: Homedir $path/$user for
&lt;br&gt;uid:$uid created.\n&amp;quot;;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #Set default quota for mount points:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #quota($user,15000,&amp;quot;&amp;lt;/dev/sda&amp;gt;&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; close(LOG);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;sub quota {
&lt;br&gt;my $user = shift;
&lt;br&gt;my $quota = shift;
&lt;br&gt;my $mount = shift;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (system(&amp;quot;/usr/sbin/setquota -u $user 0 $quota 0 0 $mount&amp;quot;) ==
&lt;br&gt;0)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; my $time = localtime;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print LOG &amp;quot;$time: Updated quota settings for user $user on
&lt;br&gt;$mount\n&amp;quot;;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }
&lt;br&gt;&lt;br&gt;}
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/home-directories-ask-user-for-password-tp26476610p26477641.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26477434</id>
	<title>Re: Samba 3.0.33/3.2.15 AD joined slow initial connect with LDAP backend</title>
	<published>2009-11-23T04:45:53Z</published>
	<updated>2009-11-23T04:45:53Z</updated>
	<author>
		<name>Hoogstraten, Ton</name>
	</author>
	<content type="html">Diego,
&lt;br&gt;&lt;br&gt;Thank you for your reply. I'm testing with 3.0.33 since that's the latest version Redhat is using in RHEL5 (Redhat has the habbit of holding a version and do backport patching). The 3.2.x version was marked for production and what I saw in FAQ was that the 3.4.x was still to experiment with?
&lt;br&gt;&lt;br&gt;If you mean the 'winbind enum users/groups' setting that has been turned off as suggested in the man pages. If activated it could crash a certain role AD controller. That's not something I can risk. But would that in normal behaviour not fill somekind of cache? If I increase the caching in theory that would perhaps reduce the numer of queries required for a user at a given time. I don't know if it would be a problem setting this to 3 days so the cache could also pass over the weekend. Does not take away why it takes so long to query the AD.
&lt;br&gt;&lt;br&gt;What do you mean with:
&lt;br&gt;&lt;br&gt;Looking up group names is really slow (up to a couple of minutes when using &amp;quot;id user.name&amp;quot; or &amp;quot;groups user.name&amp;quot;).
&lt;br&gt;&lt;br&gt;Is it always slow to query the AD? Would the 3.0.23d server that I need to upgrade be using more caching then the later versions by default?
&lt;br&gt;&lt;br&gt;To answer your last question. Yes, the ldap is running on the local system for the idmaps. In production I have one samba server running a master ldap idmap backend and the other samba server configured as slave.
&lt;br&gt;&lt;br&gt;Kind regards,
&lt;br&gt;&lt;br&gt;Ton
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Diego Zuccato [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26477434&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;diego.zuccato@...&lt;/a&gt;] 
&lt;br&gt;Sent: maandag 23 november 2009 12:42
&lt;br&gt;To: Hoogstraten, Ton
&lt;br&gt;Subject: Re: [Samba] Samba 3.0.33/3.2.15 AD joined slow initial connect with LDAP backend
&lt;br&gt;&lt;br&gt;Hoogstraten, Ton wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; However on the test 3.0.33 system I'm experiencing a problem that I
&lt;br&gt;Why are you using such an ancient version? What about 3.4.x ?
&lt;br&gt;&lt;br&gt;&amp;gt; I think the explanation for the difference in slowness per user is based
&lt;br&gt;&amp;gt; on the group membership of that user. For example an user that is only a
&lt;br&gt;&amp;gt; member of Domain Users takes about 10 seconds to display the shares
&lt;br&gt;&amp;gt; (still to slow in my opinion). For testing purpose I've reduced the
&lt;br&gt;&amp;gt; cache for winbind and idmap so the server needs to keep looking up the
&lt;br&gt;&amp;gt; user and SID information.
&lt;br&gt;Looking up group names is really slow (up to a couple of minutes when 
&lt;br&gt;using &amp;quot;id user.name&amp;quot; or &amp;quot;groups user.name&amp;quot;).
&lt;br&gt;&lt;br&gt;Have you tried playing with enum users/groups ? If activated on large AD 
&lt;br&gt;trees, it could impact performances a lot!
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; idmap alloc config:ldap_url &amp;nbsp; &amp;nbsp; = ldap://127.0.0.1/
&lt;br&gt;Are you using a locally running (on localhost!) ldap server?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Diego Zuccato
&lt;br&gt;Servizi Informatici
&lt;br&gt;Dip. di Astronomia - Università di Bologna
&lt;br&gt;Via Ranzani, 1 - 40126 Bologna - Italy
&lt;br&gt;tel.: +39 051 20 95786
&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26477434&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;diego.zuccato@...&lt;/a&gt;
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Samba-3.0.33-3.2.15-AD-joined-slow-initial-connect-with-LDAP-backend-tp26476269p26477434.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26477064</id>
	<title>Re: FreeBSD 7.2 domain member problem - partially SOLVED</title>
	<published>2009-11-23T04:17:53Z</published>
	<updated>2009-11-23T04:17:53Z</updated>
	<author>
		<name>Daniel O'Connor-2</name>
	</author>
	<content type="html">On Mon, 23 Nov 2009, Ivo Karabojkov wrote:
&lt;br&gt;&amp;gt; I am sure it should work without these strange links I've made.
&lt;br&gt;&amp;gt; I don't know what is the problem. I use ports, just to keep my
&lt;br&gt;&amp;gt; installations more standard.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; May you point me a good manual how to set up nss/ldap with Samba?
&lt;br&gt;&lt;br&gt;I used the samba how to guide and googled, the net/smbldap-tools is 
&lt;br&gt;pretty helpful.
&lt;br&gt;&lt;br&gt;That said it wasn't especially simple to setup :(
&lt;br&gt;&lt;br&gt;However I don't use winbind on my FreeBSD machine, I use nss/pam_ldap 
&lt;br&gt;and Samba talks to the LDAP server as well.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Daniel O'Connor software and network engineer
&lt;br&gt;for Genesis Software - &lt;a href=&quot;http://www.gsoft.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gsoft.com.au&lt;/a&gt;&lt;br&gt;&amp;quot;The nice thing about standards is that there
&lt;br&gt;are so many of them to choose from.&amp;quot;
&lt;br&gt;&amp;nbsp; -- Andrew Tanenbaum
&lt;br&gt;GPG Fingerprint - 5596 B766 97C0 0E94 4347 295E E593 DC20 7B3F CE8C
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (195 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26477064/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-7.2-domain-member-problem-tp26204285p26477064.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26476610</id>
	<title>home directories ask user for password</title>
	<published>2009-11-23T03:47:24Z</published>
	<updated>2009-11-23T03:47:24Z</updated>
	<author>
		<name>Massimo-21</name>
	</author>
	<content type="html">Hi to all,
&lt;br&gt;I have Samba configured as domain member with winbind and kerberos, I can access all share but I have some problem with the home directories because it ask me for password.
&lt;br&gt;&lt;br&gt;This is my smb.conf
&lt;br&gt;[global]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; workgroup = domain
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbios name = Manufac
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; server string = Server di rete
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = server di rete
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; encrypt passwords = true
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; realm = DOMAIN..LOCAL
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; password server = pdc01.domain.local
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; security = ADS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; winbind enum users = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; winbind enum groups = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; winbind separator= +
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; idmap uid = 500-100000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; idmap gid = 500-100000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; template shell = /bin/true
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; syslog = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; log file = /var/log/samba/log.%m
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max log size = 1000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dns proxy = No
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ldap ssl = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; panic action = /usr/share/samba/panic-action %d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; invalid users = root
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; template homedir = /home/%U
&lt;br&gt;[homes] 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; comment = Home Directories
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; browseable = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; writable = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; public = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; valid users = DOMAIN/%U
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; create mode = 0777
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; directory mode = 0777
&lt;br&gt;&lt;br&gt;I have the home directory created in /home/ with domain user right
&lt;br&gt;&lt;br&gt;Thank you in advance.
&lt;br&gt;&lt;br&gt;Bye
&lt;br&gt;-- 
&lt;br&gt;To unsubscribe from this list go to the following URL and read the
&lt;br&gt;instructions: &amp;nbsp;&lt;a href=&quot;https://lists.samba.org/mailman/options/samba&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.samba.org/mailman/options/samba&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Samba---General-f62.html&quot; embed=&quot;fixTarget[62]&quot; target=&quot;_top&quot; &gt;Samba - General&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/home-directories-ask-user-for-password-tp26476610p26476610.html" />
</entry>

</feed>
