Search posterous

Search all posts and users. Type a name, type a favorite song title, whatever! See what comes up.
  

More posterous blogs











More recommended blogs »

Here are posterous posts filed under samba...

I am posting this as a note for myself and anyone who ever has to get Samba and Win7 to play together nicely. Also, this is a work in progress and I will appreciate any thoughts, though posting to the samba list could be more productive...

This is our set up at work:
server running Samba on debian - domain controller
Various machines either single booting XP or dual booting XP and debian - domain members
New machines with Windows 7 Professional - trying to join domain as members

Roaming profiles are in use both on XP and debian
Samba shares - each person in the research group has their own filespace, profile, and a common shared area which is read/write/accessible

Previously, we were using the stable lenny package of samba, which is version 3.2.5
http://packages.debian.org/lenny/samba

Viewing the samba shares seem to work fine after some changes to the local security policy.
http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
Can even print from the shared printers, which is pretty good, I thought. This is all before I join Win 7 to the domain, it's just a normal computer sitting in the department private network.

Out of the box, Win 7 will not join a samba domain. As stated on the samba wiki, a version of samba 3.3 or higher is required, and some registry keys need to be changed.
http://wiki.samba.org/index.php/Windows7
I first tried changing the registry keys and joining the domain on the Win7 machine while keeping samba at 3.2.5 Although the join is now successful (with the DNS error message ignored), attempts to log in fail with "the trusted relationship between this workstation and the primary domain failed".

So I proceeded to update samba using lenny-backports, which has samba version 3.4.2
http://packages.debian.org/lenny-backports/samba
I forgot to look at dependencies first time round (yes I'm a noob), but after using some commands like
dpkg -l | grep samba
dpkg --configure --pending
dependencies can be sorted out.

(I could have avoided it by using apt, but I had some problems doing aptitude update, possibly a missing public key somewhere =S)

After the update is completed, log in on the Win 7 now works, but with only a temporary profile instead of a properly persistent roaming profile. It appears that this is because they made a new version of the profiles protocol in Vista and Windows 7.
http://bugs.contribs.org/show_bug.cgi?id=3666

Attempted to add some kind of profiles.v2 reference in samba's configuration file does not work. So, in the samba "profile" share, I added $username.v2 in addition to the existing $username folder. This fixed the roaming profile issue.

The home/filespace area was not successfully mounted initially because Win7 decided to reserve the drive letter for some usb thing. Again, some regedit-ing sorted it out - the relevant DosDevices key in HKLM/System/MountedDevices need to be free.

So, now, the Win 7 is finally a member of the domain, allows log in, has a functional (I think) roaming profile, and has the right home filespace mounted. The shared drive is mounted, however, it now insists that "Access is denied" (even though it worked before I joined the domain or updated samba, and it still works on pre Win7 machines and everywhere when booted into debian). Printing is not yet tested-- will need to do that tomorrow.

This has taken 2 work days and most of this weekend (and I started the weekend ago). Gaaaah.

Filed under: samba

philwbass says...

Highly recommend this DVD!

Seu Jorge is a treasure ( I adore his album of acoustic Bowie covers in Portuguese for The Life Aquatic sessions.

Here his band plays beautifully!

Here's one from The Life Aquatic

And another from the DVD 

Filed under: samba

Caio Call says...

O ultimo adidas Samba lançado vem em camurça verde com sola e detalhes internos em branco e faixinhas pretas, além disso vem com um cadarço extra na cor branca. O Samba foi um dos primeiros e mais vendidos modelos da adidas até hoje e estará em breve fazendo 60 anos! Confira as fotos desse modelo.


     
Click here to download:
Adidas_Samba_GreenBlack_Quick_.zip (100 KB)

Filed under: samba

rota021 says...

CCBB%20Rio-%20rotunda_new.jpg

Na antiga Rua da Direita, hoje 1º de Março, funciona há 20 anos o Centro Cultural Banco do Brasil. Sede da primeira Associação Comercial, da Bolsa de Fundos Públicos e ao lado do Casa França-Brasil, o CCBB tem espaço cativo na vida do carioca. Por ali, já passaram exposições muito importantes como 'China Hoje', além de ser o ponto central de festivais como 'Anima Mundi' e 'É Tudo Verdade'.

Para comemorar 20 anos de atuação no cenário cultural do Rio de Janeiro, o CCBB organizou uma série de eventos que começaram ontem (10) e que terminam amanhã (12). Confira abaixo, a programação completa.

10 de outubro | sábado

Cinema e Vídeo

• Maratoninha Sessão Criança
12h - Horton e o Mundo dos Quem (88 min)

• Cinema Nacional Legendado e Audiodescrito
14h - Xuxa e o Tesouro da Cidade Perdida (84 min)

• FilmeFashion - Documentários
16h - Valentino:  O último imperador (Valentino: The Last Emperor, Dir: Matt Tyrnauer, EUA, 2008, DVD, cor, 96’, 13 anos)
18h - Abrindo  o  Zíper  (Unzipped, Dir: Douglas Keeve, EUA, 1995, DVD, cor/p&b, 73’, 18 anos)
20h - Ciao! Manhattan (idem, Dir: John Palmer e David Weisman, EUA, 1972, DVD, cor/p&b, 84’, 18 anos)


Teatro

• Nu de mim mesmo (Cia do Teatro Autônomo) | Biblioteca, às 20h
• Toda nudez será castigada | Teatro I, às 19h30
• CCBB no Teatro - 20 anos de Companhias | Till, a Saga de um Herói
Torto (Grupo Galpão), às 18h30 e 21h

Senhas distribuídas na bilheteria do CCBB a partir de uma hora da apresentação.


11 de outubro | domingo

Cinema e Vídeo

• Maratoninha Sessão Criança
12h - Horton e o Mundo dos Quem (88 min)

• Filme Fashion - Documentários
14h - Annie Leibovitz: A Vida Através das Lentes (Annie Leibovitz: Life
Through a Lens, Dir: Barbara Leibovitz, EUA, 2008, DVD, cor, 79min., 10 anos)
16h - Jardins  Cinza  (Grey Gardens, Dir: Ellen Hovde, Albert Maysles,
David Maysles e Muffie Meyer, EUA, 1975, DVD, cor, 100min., livre)
18h - Identidade de Nós Mesmos (Aufzeichnungen zu Kleidern und Städten/Notebook  on  Cities & Clothes, Dir: Wim Wenders,Alemanha, 1989, DVD, cor, 79min., livre)
20h - Top Models - Um Conto de Fadas Brasileiro (idem, Dir: Richard Luiz, Brasil, 2009, DVD, cor, 90min., 14 anos)


Teatro

• Nu de mim mesmo (Cia do Teatro Autônomo) | Biblioteca, às 20h
• Toda nudez será castigada | Teatro I, às 19h30


Música

• Pode Apostar! - Silvia Machete, às 22h    
• Vozes de Mestres - Paulinho da Viola, às 23h    
• DJ Nepal, às 00h30

Senhas  distribuidas  a partir das 20h, na bilheteria especial, montada na entrada de serviço do CCBB Rio, esquina da Rua Itaboraí e Travessa Tocantins.


12 de outbro | Segunda (feriado)

Exposições

• Abertura da exposição Regina Silveira - Linha de Sombra


Cinema e Vídeo

• Filme Fashion - Documentários
14h - Lagerfeld Confidencial (Lagerfeld  Confidential, Dir: Rodolphe
Marconi, França, 2007, DVD, cor, 89min., livre)
16h - Assinado Chanel (Signé Chanel, Dir: Loïc Prigent, França, 2005,
DVD, cor, 130min., livre)
18h10 - Nanook, o Esquimó (Nanook of the North, Dir: Robert Flaherty, EUA, 1922, DVD, p&b, 79min., 13 anos)
20h - O Dia Anterior Fendi by Karl Lagerfeld (The Day Before Fendi by
Karl Lagerfeld, Dir: Loïc Prigent, EUA, 2009, DVD, cor, 52min., 14 anos)

• Maratoninha Sessão Criança
10h30 - O Balão Vermelho + O Aprendiz de Feiticeiro (55 min)
12h - A Bela Adormecida (75 min)
14h - Alvin e os Esquilos (92 min)
16h - Tinker Bell - Uma Aventura no Mundo das Fadas (78 min)


Música Infantil

• Armatrux, A Banda - Música para Crianças | Praça dos Correios, às 16h


Ideias

• O Olho e o Lugar - Regina Silveira | Lançamento do livro infanto-juvenil sobre a obra de Regina Silveira | Foyer, às 16h


Teatro

• Nu de mim mesmo (Cia do Teatro Autônomo) | Biblioteca, às 20h
• Toda nudez será castigada | Teatro I, às 19h30.

Filed under: samba

Anadin says...

Slightly out of date now but some of you might still be using Tiger on your servers - I know we are :P

Our problem was that due to a slightly unstable OD Master server running 10.4 we wanted to rebuild it from scratch but have never really been completely convinced about the BDC in our setup. We were very happy with our replicas but didn't trust promoting the BDC to PDC and all of the PC's still staying connected to the domain (about 100 of them).

We created a cunning plan to clone the master box, then install Tiger server clean and set it all up again specifically copying over the old SID and see if we could swap it out on the PC's without them knowing. Standard OS X server install, set up DNS, create OD Master (with exactly the same IP numbers and names as before), got that all working peachy with Kerberos etc. imported the OD backup.

We found these articles (massively grateful to all of these people posting these)..

http://www.afp548.com/article.php?story=20080403185017651&query=pdc

http://jmlittle.blogspot.com/2008/04/opendirectory-upgrade-path-from-104-to.html

http://www.netmojo.ca/2007/11/13/tiger-to-leopard-server-migration-part-two/

http://www.radiotope.com/node/61

Following all of these sites were were pretty sure we had it worked out - export the SID, backup the /var/db/samba and /var/samba folders. Create a new version of the PDC, stop the services, change the SID and bobs your uncle :)

All of the PC's that were already connected to the domain were fine, you could log on etc. we rejoiced - our job was done. Until.. we tried to add new machines to the domain - whoops! - not working:

net getlocalsid - returned CORRECTSID

net getdomainsid DOMAIN - returned WRONGSID

net getdomainsid - returned SERVERNAME = CORRECTSID, DOMAINNAME = WRONGSID

wtf? - two SID's?

So any machine has a SID and the domain has a SID, we used 'net setlocalsid SID' to set the SID we thought for the domain but it only sets the 'local' SID, on 10.5+ we have the 'net setDOMAINsid SID' command to sort that out.

Using tdbdump on the old secrets.tdb showed the wrong machine name for the local SID so I did not want to use that in case it broke something, but in the end this archive pointed me in the right direction..

http://lists.samba.org/archive/samba/2008-April/139732.html

It is so simple it is embarrassing.. shut down windows services, mv secrets.tdb secrets.tdb.bak

With NO secrets.tdb file use the 'net setlocalsid SID' command which creates a new SID for the local machine which is correct - then start Windows services, we had to do it twice.. BUT the domain inherited the local SID!, it seems when you start windows services, Samba creates a domain SID based on the local machine SID if one isn't there. Before, as we had created the PDC after running Windows services, it was adding a new SID to the secrets.tdb <phew> :)

Filed under: SAMBA

jqr says...

Jorge Ben's backup group. Love the green-on-green of the cover

Filed under: Samba

jqr says...

There are a couple of these compils out there: "Soul of Brazil" and "Samba Soul 70" come to mind.

Filed under: Samba

hdknr says...

Vistaの設定を変更して対応する(Samba3.0/Samba2.0/NTLMv2認証非対応NAS)

「Windows 95/98/Me/NT」を使っているので、Sambaの設定を変えないで使いたい場合はVista側の設定を変更する。

Windows Vistaでは共有フォルダへログインするときの認証方法が変更されたので、 Sambaサーバーへのログインに失敗する。
LinkStationやTeraStationなどのNASも内部的にはSambaを使用しているので、同様にログインできなくなる。

この場合、Vista側のセキュリティポリシーを変更すれば、Sambaサーバー(およびNAS)にもログインできるようになる。 次の手順で設定する。

  1. スタートメニューの検索ボックスに「secpol.msc」と入力してEnterキーを押す。 「ローカルセキュリティポリシー」が起動する。
  2. 左側のツリーで「ローカルポリシー」→「セキュリティオプション」の順に選択する。
  3. 右側のリストから「ネットワークセキュリティ:LAN Manager認証レベル」という項目を探し出し、ダブルクリック。
    VistaNTLMv2Setting1.jpg
  4. 「ネットワークセキュリティ:LAN Manager認証レベルのプロパティ」ウインドウが出るので、値を「NTLM応答のみ送信する」に変更する。
    VistaNTLMv2Setting2.jpg
  5. PCを再起動する。 Samba3.0であれば、この設定で大丈夫なはず(バージョン3.2.3-1のSambaで確認)。
  6. 以上の設定でダメだった場合(Samba2.0やNAS等、環境によって変わる?)は、認証の度合いを下げるため「LM と NTLM を送信する - ネゴシエーションの場合、NTLMv2 セッション セキュリティを使う」を設定し、PCを再起動する。
  7. さらにダメだった場合は「LM と NTLM 応答を送信する」に設定して再起動する。

もっと詳しく知りたいときはマイクロソフトのサポートサイトのこちらのページを参照。

以下マイクロソフトのサポートサイトの「10.ネットワーク セキュリティ: LAN Manager 認証レベル」の文書抜粋
Vistaのデフォルトは3の「NTLMv2 応答のみ送信」が設定されています。

設定説明
0Send LM & NTLM responsesクライアントは、LM および NTLM 認証を使用し、NTLMv2 セッション セキュリティを使用しません。ドメイン コントローラは LM、NTLM、および NTLMv2 認証を受け入れます。
1LM と NTLM を送信する - ネゴシエーションの場合、NTLMv2 セッション セキュリティを使うクライアントは NTLMv2 認証を使用し、サーバーでサポートされている場合は NTLMv2 セッション セキュリティを使用します。
2NTLM 応答のみ送信クライアントは NTLM 認証のみを使用し、サーバーでサポートされている場合は NTLMv2 セッション セキュリティを使用します。ドメイン コントローラは LM、NTLM、NTLMv2 認証を許可します。
3NTLMv2 応答のみ送信クライアントは、NTLMv2 認証のみを使用し、サーバーがサポートしている場合は NTLMv2 セッション セキュリティを使用します。ドメイン コントローラは LM、NTLM、および NTLMv2 認証を受け入れます。
4NTLMv2 応答のみ送信 (LM を拒否する)クライアントは、NTLMv2 認証のみを使用し、サーバーがサポートしている場合は NTLMv2 セッション セキュリティを使用します。ドメイン コントローラは LM を拒否します (NTLM および NTLMv2 認証のみを受け入れます)。
5NTLMv2 応答のみ送信 (LM を拒否する)クライアントは、NTLMv2 認証のみを使用し、サーバーがサポートしている場合は NTLMv2 セッション セキュリティを使用します。ドメイン コントローラは LM と NTLM を拒否します (NTLMv2 認証のみを受け入れます)。

Filed under: Samba

hdknr says...

Sambaの設定を変更して対応する(Samba3.0のみ)

Sambaの3.0からはNTLMv2認証に対応したが、デフォルトの設定で「No」になっている。 「Yes」にすると使えるようになるが、これを行うと「Windows 95/98/Me/NT」から入れなくなるので注意。

参考にしたWebページ、以下文書抜粋

smb.conf プロトコルオプション
client NTLMv2 authクライアントのNTLMv2認証を使用するか(規定値はNo)
クライアントにWin95/98/Me/NTがなければYesにできる
Yesにするのがセキュリティ的に推奨値

Filed under: Samba

gissmog says...

Was für eine beschissene Qualität ... naja ... vllt. kann ja der eine oder andere was erkennen. Meiner Meinung nach gibts es jedoch mit Samba und SL keine Probleme - sofern man sich an die Vorgaben von Apple hält.

Gegen Ende mache ich ein "/etc/init.d/apache2 reload" .. hätte eigentlich "/etc/init.d/samba reload" sein sollen. Geht aber auch so - ich wolle es nur nochmal ausführen weil es teilweise ein paar Sekunden dauert bis Änderungen an der Konfiguration übernommen werden.

Filed under: Samba