FDS + Samba + IdealX

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Alan Ferrier wrote:
> Good point ;)
>
> [09/Aug/2006:11:12:56 +0000] conn=1284 fd=64 slot=64 connection from 
> 127.0.0.1 to 127.0.0.1
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=0 BIND 
> dn="uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot" 
> method=128 version=3
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=0 RESULT err=0 tag=97 
> nentries=0 etime=0 
> dn="uid=admin,ou=administrators,ou=topologymanagement,o=netscaperoot"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=1 SRCH base="" scope=0 
> filter="(objectClass=*)" attrs="supportedControl"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=2 SRCH 
> base="dc=digitalbridges,dc=sys" scope=2 
> filter="(&(uid=alan.ferrier)(objectClass=sambaSamAccount))" attrs="u
> id uidNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange 
> sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn 
> displayName samb
> aHomeDrive sambaHomePath sambaLogonScript sambaProfilePath description 
> sambaUserWorkstations sambaSID sambaPrimaryGroupSID sambaLMPassword 
> sambaNTPassword sa
> mbaDomainName objectClass sambaAcctFlags sambaMungedDial 
> sambaBadPasswordCount sambaBadPasswordTime sambaPasswordHistory 
> modifyTimestamp sambaLogonHours modi
> fyTimestamp"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=2 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 fd=65 slot=65 connection from 
> 127.0.0.1 to 127.0.0.1
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=0 BIND 
> dn="uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot" 
> method=128 version=3
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=0 RESULT err=0 tag=97 
> nentries=0 etime=0 
> dn="uid=admin,ou=administrators,ou=topologymanagement,o=netscaperoot"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=1 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=alan.ferrier))" a
> ttrs="uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=2 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=alan.ferrier))" a
> ttrs=ALL
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=2 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=3 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixGroup)(|(memberUid=alan.ferrie
> r)(uniqueMember=uid=alan.ferrier,ou=People,dc=DIGITALBRIDGES,dc=SYS)))" 
> attrs="gidNumber"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=3 RESULT err=0 tag=101 
> nentries=3 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=4 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixGroup)(uniqueMember=cn=Schema
> Admins,ou=Groups,dc=DIGITALBRIDGES,dc=SYS))" attrs="gidNumber"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=4 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=5 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixGroup)(uniqueMember=cn=Enterpr
> ise Admins,ou=Groups,dc=DIGITALBRIDGES,dc=SYS))" attrs="gidNumber"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=5 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=6 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixGroup)(uniqueMember=cn=operati
> ons,ou=Groups,dc=DIGITALBRIDGES,dc=SYS))" attrs="gidNumber"
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=6 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=3 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=sambaGroupMapping)(gidNumber=513))"
> attrs="gidNumber sambaSID sambaGroupType sambaSIDList description 
> displayName cn objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=3 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=4 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=sambaGroupMapping)(gidNumber=1002))
> " attrs="gidNumber sambaSID sambaGroupType sambaSIDList description 
> displayName cn objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=4 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=5 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=sambaGroupMapping)(gidNumber=1003))
> " attrs="gidNumber sambaSID sambaGroupType sambaSIDList description 
> displayName cn objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=5 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=6 SRCH 
> base="ou=Groups,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=sambaGroupMapping)(gidNumber=1025))
> " attrs="gidNumber sambaSID sambaGroupType sambaSIDList description 
> displayName cn objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=6 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=7 SRCH 
> base="dc=digitalbridges,dc=sys" scope=2 
> filter="(&(uid=marisa$)(objectClass=sambaSamAccount))" attrs="uid ui
> dNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange 
> sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn 
> displayName sambaHome
> Drive sambaHomePath sambaLogonScript sambaProfilePath description 
> sambaUserWorkstations sambaSID sambaPrimaryGroupSID sambaLMPassword 
> sambaNTPassword sambaDo
> mainName objectClass sambaAcctFlags sambaMungedDial 
> sambaBadPasswordCount sambaBadPasswordTime sambaPasswordHistory 
> modifyTimestamp sambaLogonHours modifyTim
> estamp"
> [09/Aug/2006:11:12:56 +0000] conn=1284 op=7 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1286 fd=66 slot=66 connection from 
> 127.0.0.1 to 127.0.0.1
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=7 UNBIND
> [09/Aug/2006:11:12:56 +0000] conn=1285 op=7 fd=65 closed - U1
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=0 BIND dn="" method=128 
> version=3
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=0 RESULT err=0 tag=97 
> nentries=0 etime=0 dn=""
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=1 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=marisa$))" attrs=
> "uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=1 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=2 SRCH 
> base="ou=Computers,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=marisa$))" att
> rs="uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=2 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=3 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=MARISA$))" attrs=
> "uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=3 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=4 SRCH 
> base="ou=Computers,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=MARISA$))" att
> rs="uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:56 +0000] conn=1286 op=4 RESULT err=0 tag=101 
> nentries=0 etime=0

Start here

> [09/Aug/2006:11:12:57 +0000] conn=1287 fd=65 slot=65 connection from 
> 127.0.0.1 to 127.0.0.1
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=0 SRCH 
> base="dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=marisa$))" attrs=ALL
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=0 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=1 SRCH 
> base="sambaDomainName=BRIDGES,dc=digitalbridges,dc=sys" scope=0 
> filter="(objectClass=sambaUnixIdPool)" attrs
> =ALL
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=2 MOD 
> dn="sambaDomainName=BRIDGES,dc=digitalbridges,dc=sys"
> [09/Aug/2006:11:12:57 +0000] conn=1287 op=2 RESULT err=50 tag=103 
> nentries=0 etime=0

The client does not BIND (that is, it does not authenticate as an 
identity) so all operations are done as anonymous.  By default (and for 
good reason!) no write operations are allowed by anonymous.  You must 
somehow configure your client to use a BIND identity so that you can set 
an appropriate ACI to allow that identity to update the directory server.

> [09/Aug/2006:11:12:57 +0000] conn=1287 op=-1 fd=65 closed - B1
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=5 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=marisa$))" attrs=
> "uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=5 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=6 SRCH 
> base="ou=Computers,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=marisa$))" att
> rs="uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=6 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=7 SRCH 
> base="ou=People,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=MARISA$))" attrs=
> "uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=7 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=8 SRCH 
> base="ou=Computers,dc=digitalbridges,dc=sys" scope=2 
> filter="(&(objectClass=posixAccount)(uid=MARISA$))" att
> rs="uid userPassword uidNumber gidNumber cn homeDirectory loginShell 
> gecos description objectClass"
> [09/Aug/2006:11:12:57 +0000] conn=1286 op=8 RESULT err=0 tag=101 
> nentries=0 etime=0
> [09/Aug/2006:11:12:58 +0000] conn=1286 op=-1 fd=66 closed - B1
> [09/Aug/2006:11:12:58 +0000] conn=1284 op=-1 fd=64 closed - B1
>
>
> mj at sci.fi wrote:
>> Alan Ferrier <alan.ferrier at iplay.com> kirjoitti:
>>> Hi guys,
>>>
>>> I'm attempting to integrate FDS + the IdealX scripts to handle User, 
>>> Group and Computer Management. It's all going reasonably well - I 
>>> can authenticate against the Samba Domain and do most admin type 
>>> tasks. I'm having an issue when attempting to add a Computer to the 
>>> Domain, however. It's blowing chunks with an "Insufficient 'write' 
>>> privilege" error. Log snippet below.
>>>
>>> Running "/usr/sbin/smbldap-useradd -w marisa$" from the command line 
>>> works fine.
>>>
>>> I've tried adding an ACI for the admin user for 
>>> "sambadomainname=bridges,dc=digitalbridges,dc=sys" but this doesn't 
>>> appear to change anything.
>>>
>>> Any hints greatly appreciated!
>>
>>
>> Hint: Submit FDS access logfile snippets containing your failed 
>> operations.
>>
>> BR,
>> Mike
>>
>> -- 
>> Fedora-directory-users mailing list
>> Fedora-directory-users at redhat.com
>> https://www.redhat.com/mailman/listinfo/fedora-directory-users
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3178 bytes
Desc: S/MIME Cryptographic Signature
Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20060809/ae09253d/attachment.bin 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux