Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #21 (permalink)  
Old 10-15-2008, 06:51 AM
Intermediate Member
 
Posts: 16
Default

all users have the same schemas.

The only difference between root and the rest, is that it got added through the smbpasswd command and not from the admin GUI.

After I checked the LDAP-tree with a browser I found a entry for root, but with minimum of objects:

uid root
displayName root
objectClass sambaSamAccount
objectClass account

Tried a smbpasswd -x root without luck.. Apparantly i need to remove this entry from my ldap, but how?
Reply With Quote
  #22 (permalink)  
Old 10-15-2008, 06:58 AM
Senior Member
 
Posts: 72
Default

Quote:
Originally Posted by trakkert View Post
all users have the same schemas.

The only difference between root and the rest, is that it got added through the smbpasswd command and not from the admin GUI.

After I checked the LDAP-tree with a browser I found a entry for root, but with minimum of objects:

uid root
displayName root
objectClass sambaSamAccount
objectClass account

Tried a smbpasswd -x root without luck.. Apparantly i need to remove this entry from my ldap, but how?
I can recommend using Apache Directory Studio
Reply With Quote
  #23 (permalink)  
Old 10-16-2008, 01:41 AM
Intermediate Member
 
Posts: 16
Default

Error while deleting entry
[LDAP: error code 50 - no write access to parent]
[LDAP: error code 50 - no write access to parent]

This is with my admin user.
Reply With Quote
  #24 (permalink)  
Old 10-16-2008, 02:05 AM
Senior Member
 
Posts: 72
Default

Quote:
Originally Posted by trakkert View Post
Error while deleting entry
[LDAP: error code 50 - no write access to parent]
[LDAP: error code 50 - no write access to parent]

This is with my admin user.
The ldap root user (zimbra) and not just the "admin" account?
Reply With Quote
  #25 (permalink)  
Old 10-16-2008, 06:07 AM
Intermediate Member
 
Posts: 16
Default

admin is the name of my ldap administrator, so i believe yes to your question.

Also in the admin GUI, when i go to edit account -> General Information -> Account Setup: he is set as administrator.

But is there another user, that is associated to the LDAP password? Atleast I cant see anyone in my ldap tree.
Reply With Quote
  #26 (permalink)  
Old 10-16-2008, 06:13 AM
Senior Member
 
Posts: 72
Default

Quote:
Originally Posted by trakkert View Post
admin is the name of my ldap administrator, so i believe yes to your question.

Also in the admin GUI, when i go to edit account -> General Information -> Account Setup: he is set as administrator.

But is there another user, that is associated to the LDAP password? Atleast I cant see anyone in my ldap tree.
You cannot control the ldap admin account in zimbra account manager. The ldap admin/root account is specifically called 'zimbra'.
The bind string is like this :
"uid=zimbra,cn=admins,cn=zimbra"
you can get the ldap root account password with the following commands :
Quote:
su zimbra
zmlocalconfig -s ldap_root_password
Reply With Quote
  #27 (permalink)  
Old 10-16-2008, 06:35 AM
Intermediate Member
 
Posts: 16
Default

Quote:
Originally Posted by lithorus View Post
You cannot control the ldap admin account in zimbra account manager. The ldap admin/root account is specifically called 'zimbra'.
The bind string is like this :
"uid=zimbra,cn=admins,cn=zimbra"
you can get the ldap root account password with the following commands :
Aha, there I got it. root is gone and readded as an alias.
And now i finally understand why there were so few objects on my users in ldap

You have been great assistance, thank you for your help!
Reply With Quote
  #28 (permalink)  
Old 01-20-2009, 01:12 PM
New Member
 
Posts: 3
Default

i administer a zimbra server for both my company, and our parent company. All of the user accounts are in two different domains, and I was wondering if anyone had any input on making a single samba instance authenticate against both domains.

If this is not possible, would it be possible at this point to setup an external ldap server, and have both domains authenticate against this ldap server with minimum reconfiguration on the zimbra side of things? I realize this may not be the appropiate place to ask the second question, but these things go hand in hand for me. Thanks in advance for any help.
Reply With Quote
  #29 (permalink)  
Old 01-21-2009, 07:22 AM
Special Member
 
Posts: 113
Default

hi devnul,

how do you currently authenticate the two samba-server's.

what we have done in a similar situation (two samba-server on two location's)

i am running on both side's a ldap-server (on ubuntu 8.04.1) replicate this two and authenticate samba against this openldap.

the user's get managed by gosa (http://www.gosa-project.org), when a user get created in gosa with mail-attribute's gosa execute's a script (running with ssh on the zimbra-server, which is only on one location) and create's with zmprov the account with the attribute's out the ldap-server.

authentication within Zimbra is done against the openldap-Server, so zimbra, samba and unix-logon's are in one database.
it is necesarry the account-name's are the same in both part's (ldap, samba and zimbra, the domain-part cat get cuted off, when auth to ldap from zimbra)

this would be some work on the system, but pretty less on zimbra's side.

disadvantage: password modify cant be done in zimbra.

greetings
thomas
Reply With Quote
  #30 (permalink)  
Old 01-28-2009, 02:29 AM
Junior Member
 
Posts: 9
Default

Quote:
Originally Posted by msghaleb View Post
for me it seams to be domain issue, in the Howto, zimbra is the server name and tm.local is the domain name.

FQDN = zimbra.tm.local

make sure to follow in the same way in regards with your setup, its kinda commen problem by the way.

If you are sure let us know

Thank you.

M. Ghaleb
Hi Everybody,

I'm new to Zimbra and Ubuntu and i installed with the tutorial given in this forum. I got the same issue that i do not get samba group tap while creating Posix Group. Please can i get detailed information to understand this and help me in resolving this issue.

Thanks
Jram
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.