[Samba] Error with samba update in debian.

Rowland Penny rpenny at samba.org
Wed Dec 28 14:16:54 UTC 2016


On Wed, 28 Dec 2016 08:45:17 -0500 (CST)
Luis Felipe Dominguez Vega <luis.dominguez at mtz.desoft.cu> wrote:

> I comment the idmap line and "systemctl restart samba-ad-dc" but the
> squid not authenticate, same error...
> 
> --------------------------------------- 
> Al tanto 
> Ing. Luis Felipe Domínguez Vega 
> Administrador de la Red de Desoft Matanzas 
> GNU/Linux Kernel Developer - rtlwifi kernel module 
> 
> "No es grande aquel que nunca falla, es grande el que nunca se da por
> vencido… " 
> 
> ----- Original Message -----
> From: "Rowland Penny via samba" <samba at lists.samba.org>
> To: samba at lists.samba.org
> Sent: Wednesday, December 28, 2016 8:12:30 AM
> Subject: Re: [Samba] Error with samba update in debian.
> 
> On Wed, 28 Dec 2016 13:57:58 +0100
> "L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:
> 
> > Hai, 
> > Can you post your smb.conf that helps. 
> > 
> > But you probly forgot to set: 
> > ntlm auth = yes
> > 
> > and maybe more, a summup: 
> > 
> > This is the full list: 
> > https://wiki.samba.org/index.php/Samba_Features_added/changed_(by_release)
> > 
> > 
> > The complete history, have a look at the X.x.0 release notes.
> > https://www.samba.org/samba/history/
> > 
> > For the major differences (new features, etc.)
> > 
> > Upgrade samba from a : 4.4.x => 4.5.x 
> > ! remove all idmap config lines from your smb.conf of the DC's.
> > ! run: net cache flush
> > ! Restart samba or reboot the DC
> > 
> 
> Nearly correct ;-)
> 
> It should be:
> 
> If you have 'idmap config' lines in a smb.conf on a DC, remove them.
> They had absolutely no affect and did nothing before Samba version
> 4.5.0, from Samba 4.5.0 they lead to errors.
> 
> Rowland
> 

If you mean:

idmap_ldb:use rfc2307 = yes

Then uncomment it, you need this line on a Samba AD DC.

I referred to the 'idmap config' lines you find on a Samba domain
member, i.e. 'idmap config SAMDOM : range = 10000-999999'

These lines do not have and never have had a place on a Samba AD DC.

Rowland



More information about the samba mailing list