LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 06-30-2015, 10:42 AM   #1
Sum1
Member
 
Registered: Jul 2007
Distribution: Fedora, CentOS, and would like to get back to Gentoo
Posts: 332

Rep: Reputation: 30
CentOS 7.1503 and Samba4 AD DC


Not a question.
Brief report that hopefully saves time for others.

CentOS ver. 7.1503
SerNet Samba ver. 4.1.16 > 4.1.17 > 4.1.18

Upon performing system updates including Samba 4, some windows domain users will randomly lose the ability to access file shares and receive an error message stating essentially --- cannot access host ABC. The affected domain users remain authenticated on the domain controller and dns continues to function normally, but file shares not accessible.

Restarting the affected domain users' computers does not always resolve the issue and is time-consuming. I have found sending a rapid succession of the following commands on the domain controller:

Code:
[root@ABC ~]#killall samba
[root@ABC ~]#samba
[root@ABC ~]#killall samba
[root@ABC ~]#samba
[root@ABC ~]#killall samba
[root@ABC ~]#samba
[root@ABC ~]#killall samba
[root@ABC ~]#samba
clears the block without disrupting access for other domain users.
I know it's very un-scientific but I have used it with success across two production upgrades without restarting the domain controller.

HTH
 
Old 07-01-2015, 12:52 AM   #2
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
I have also installed you meas serner-samba? but yet i have not problem like that.
 
Old 07-01-2015, 11:47 PM   #3
Sum1
Member
 
Registered: Jul 2007
Distribution: Fedora, CentOS, and would like to get back to Gentoo
Posts: 332

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by paul2015 View Post
I have also installed you meas serner-samba? but yet i have not problem like that.
you are fortunate :-)
 
Old 07-02-2015, 12:03 AM   #4
paul2015
Member
 
Registered: Apr 2015
Distribution: CentOS Fedora
Posts: 149

Rep: Reputation: 4
i had disscusions about samba ad security on this forum and people say that it is not secured, and if i have linux users in network that makes much more unsecure my samba ad
what you think about it?
 
Old 07-02-2015, 12:45 AM   #5
Sum1
Member
 
Registered: Jul 2007
Distribution: Fedora, CentOS, and would like to get back to Gentoo
Posts: 332

Original Poster
Rep: Reputation: 30
My Samba 4 AD knowledge is definitely NOT expert level.....I wish I were a network engineer, but honestly nowhere close.

I'm guessing the concerns were about linux users on the network authenticating to the AD server by unencrypted connection.
I think those situations are limited.
Now that Samba 4 has been a stable release for a while, the tools are available and tested to authenticate linux users on a Samba 4 AD domain with encrypted connection using kerberos and sssd.

It's discussed better here: https://wiki.samba.org/index.php/Loc...ntication/sssd

Method 1: Connecting to AD via Kerberos (recommended) --- this provides encrypted kerberos authentication.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CentOS 6.6 or CentOS 7 (1503)? intelarmamd Linux - Distributions 2 04-20-2015 08:33 PM
First Look: CentOS 7.1 1503 desertcat Linux - Distributions 7 04-13-2015 10:56 AM
LXer: CentOS 7.1-1503 Screenshot Tour LXer Syndicated Linux News 0 04-01-2015 01:50 PM
Samba4 on Centos 6.4 Thiagolgf Linux - Server 1 10-23-2013 12:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 12:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration