Samba 2.2 alpha3 released

William R. Knox wknox at mitre.org
Mon Mar 26 16:51:40 GMT 2001


Whoever runs the binary has an EUID of root, but their UID is still that
of the original user. This is checked by LPRng, which will only allow the
-U flag to be used if the UID is root or listed in the allow_user_setting
in the config file. The setuid is so that LPRng can bind to ports in the
range 721-731, which Berkeley based LPD daemons sometimes require. Just
try the allow_user_setting in the lpd.conf and send a HUP to the LPD
daemon - I bet your problems will be solved.

			Bill Knox
			Senior Operating Systems Programmer/Analyst
			The MITRE Corporation

On Mon, 26 Mar 2001, Fouquet, Errol wrote:

> Date: Mon, 26 Mar 2001 08:51:13 -0700
> From: "Fouquet, Errol" <Errol.Fouquet at mms.gov>
> To: 'William R. Knox' <wknox at mitre.org>
> Cc: samba at samba.org
> Subject: RE: Samba 2.2 alpha3 released
>
> Bill,
> The problem is not related to LPRng.
> I agree that the "-U" flag is only available to root. However my lpr binary
> is "setuid root". This means that whomever runs the binary, does in fact run
> as the root user. It worked before, I would guess, because 2.0.x versions of
> Samba allowed the execution of setuid programs. It appears to me that 2.2a2
> does not.
>
>
> -----Original Message-----
> From: William R. Knox [mailto:wknox at mitre.org]
> Sent: Monday, March 26, 2001 9:08 AM
> To: Fouquet, Errol
> Cc: samba at samba.org
> Subject: RE: Samba 2.2 alpha3 released
>
>
> Pardon the somewhat off-topic reply. LPRng will not allow a non-root user
> to use the -U flag by default. I couldn't tell you why it worked before.
> However, you can edit your lpd.conf file and add the line
> "allow_user_setting=name_of_smb_user" to allow the user as which the samba
> processes run (in our case nobody) to use this flag. This works like a
> charm for us here. Good luck!
>
> 			Bill Knox
> 			Senior Operating Systems Programmer/Analyst
> 			The MITRE Corporation
>
[original message deleted to save electrons, a precious natural resource]





More information about the samba mailing list