Project

General

Profile

Tâche #30304

Scénario #30256: Traitement express MEN (25-27)

Modifications smb.conf à vérifier sur ScribeAD

Added by Joël Cuissinat 4 months ago. Updated 3 months ago.

Status:
Fermé
Priority:
Normal
Assigned To:
Start date:
06/09/2020
Due date:
% Done:

100%

Remaining (hours):
0.0

Description

Ces modifications portent sur la partie membre, il faudrait vérifier également la configuration ScribeAD.


Related issues

Related to Distribution EOLE - Tâche #30279: Modifications smb.conf à rétro-porter en 2.7.1 Fermé 06/09/2020
Related to Distribution EOLE - Tâche #30385: Correction SAMBA-T01 - Déclaration de partages supplémentaires - (2.7.2-rc3) Fermé 04/10/2020

Associated revisions

Revision d4ac9f7a (diff)
Added by Joël Cuissinat 3 months ago

Remove useless "invalid users" smb parameter

Ref: #30304

Revision 6c98a952 (diff)
Added by Joël Cuissinat 3 months ago

Remove samba deprecated "guest" mode in config file

Ref: #30304

Revision 4a60ec3e (diff)
Added by Joël Cuissinat 3 months ago

Remove "guest" mode in eole-fichier

Ref: #30304

Revision b3c4816f (diff)
Added by Joël Cuissinat 3 months ago

Clean smb configuration

Ref: #30304

Revision b0e86560 (diff)
Added by Joël Cuissinat 3 months ago

Increase idmap config range

Ref: #30304

History

#1 Updated by Joël Cuissinat 4 months ago

  • Status changed from Nouveau to En cours

#2 Updated by Joël Cuissinat 4 months ago

  • sur Scribe 2.7.1, le range n'est pas "bon"
    root@scribe:~# rgrep 'range' /etc/samba/smb.conf 
            idmap config *:range = 2000-2999
            idmap config DOMSCRIBE:range = 10000-999999
    
  • sur Scribe 2.7.1, il y a aussi du "nobody" qui traîne
    root@scribe:~# rgrep nobody /etc/samba/smb.conf 
            guest account = nobody
            invalid users = nobody guest
    

On pourrait conserver map to guest = Bad User mais, c'est peut-être la valeur par défaut (à vérifier)

#3 Updated by Joël Cuissinat 4 months ago

  • Related to Tâche #30279: Modifications smb.conf à rétro-porter en 2.7.1 added

#4 Updated by Joël Cuissinat 4 months ago

  • Parent task changed from #30148 to #30256

#5 Updated by Joël Cuissinat 3 months ago

  • map to guest
                      ·   Never - Means user login requests with an invalid password are rejected. This is the default.
    
                      ·   Bad User - Means user logins with an invalid password are rejected, unless the username does not exist, in which case it is treated as a guest login and mapped into the guest account.
    
                      ·   Bad Password - Means user logins with an invalid password are treated as a guest login and mapped into the guest account. Note that this can cause problems as it means that any user
                          incorrectly typing their password will be silently logged on as "guest" - and will not know the reason they cannot access files they think they should - there will have been no
                          message given to them that they got their password wrong. Helpdesk services will hate you if you set the map to guest parameter this way :-).
    
                      ·   Bad Uid - Is only applicable when Samba is configured in some type of domain mode security (security = {domain|ads}) and means that user logins which are successfully authenticated
                          but which have no valid Unix user account (and smbd is unable to create one) should be mapped to the defined guest account. This was the default behavior of Samba 2.x releases. Note
                          that if a member server is running winbindd, this option should never be required because the nss_winbind library will export the Windows domain users and groups to the underlying OS
                          via the Name Service Switch interface.
    

#6 Updated by Joël Cuissinat 3 months ago

Je propose également de supprimer la variable présentée comme suit dans la doc

Activer le mode invité sur le partage

Certaines configurations ou logiciels (exemple : WPKG) nécessitent de paramétrer des partages en mode invité (guest ok = yes).

Cela n'est possible que si le mode invité a été activé à l'aide de l'option Activer le mode invité sur le partage.

#7 Updated by Joël Cuissinat 3 months ago

  • Status changed from En cours to Résolu

#8 Updated by Fabrice Barconnière 3 months ago

Les commits sont bien présents et la doc modifiée.

#9 Updated by Fabrice Barconnière 3 months ago

  • Status changed from Résolu to Fermé
  • Remaining (hours) set to 0.0

#10 Updated by Joël Cuissinat 3 months ago

  • Related to Tâche #30385: Correction SAMBA-T01 - Déclaration de partages supplémentaires - (2.7.2-rc3) added

Also available in: Atom PDF