Changeset 272 for branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample
- Timestamp:
- Jun 16, 2009, 5:52:30 PM (16 years ago)
- Location:
- branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample
- Files:
-
- 11 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/DomApps.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 12. Integrating Additional Services</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="kerberos.html" title="Chapter 11. Active Directory, Kerberos, and Security"><link rel="next" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 12. Integrating Additional Services</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="kerberos.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="HA.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="DomApps"></a>Chapter 12. Integrating Additional Services</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="DomApps.html#id26161 62">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></div><p>2 <a class="indexterm" name="id26161 13"></a>3 <a class="indexterm" name="id26161 19"></a>4 <a class="indexterm" name="id26161 26"></a>5 <a class="indexterm" name="id26161 33"></a>6 <a class="indexterm" name="id261614 0"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 12. Integrating Additional Services</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="kerberos.html" title="Chapter 11. Active Directory, Kerberos, and Security"><link rel="next" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 12. Integrating Additional Services</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="kerberos.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="HA.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="DomApps"></a>Chapter 12. Integrating Additional Services</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></div><p> 2 <a class="indexterm" name="id2616122"></a> 3 <a class="indexterm" name="id2616129"></a> 4 <a class="indexterm" name="id2616136"></a> 5 <a class="indexterm" name="id2616142"></a> 6 <a class="indexterm" name="id2616149"></a> 7 7 You've come a long way now. You have pretty much mastered Samba-3 for 8 8 most uses it can be put to. Up until now, you have cast Samba-3 in the leading … … 15 15 the latest Windows authentication technologies. Let's get started this is 16 16 leading edge. 17 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26161 62"></a>Introduction</h2></div></div></div><p>17 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616172"></a>Introduction</h2></div></div></div><p> 18 18 Abmas has continued its miraculous growth; indeed, nothing seems to be able 19 19 to stop its diversification into multiple (and seemingly unrelated) fields. … … 31 31 gradually, taking over key services and easing the way to a full migration and, 32 32 therefore, integration into Abmas's existing business later. 33 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616193"></a>Assignment Tasks</h3></div></div></div><p> 34 <a class="indexterm" name="id2616201"></a> 33 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616202"></a>Assignment Tasks</h3></div></div></div><p> 35 34 <a class="indexterm" name="id2616210"></a> 35 <a class="indexterm" name="id2616219"></a> 36 36 You've promised the skeptical Abmas Snack Foods management team 37 37 that you can show them how Samba can ease itself and other Open Source … … 40 40 acquisition). You have chosen Web proxying and caching as your proving ground. 41 41 </p><p> 42 <a class="indexterm" name="id26162 28"></a>43 <a class="indexterm" name="id26162 35"></a>42 <a class="indexterm" name="id2616238"></a> 43 <a class="indexterm" name="id2616245"></a> 44 44 Abmas Snack Foods has several thousand users housed at its head office 45 45 and multiple regional offices, plants, and warehouses. A high proportion of … … 51 51 the earliest commercial users of Microsoft ISA. 52 52 </p><p> 53 <a class="indexterm" name="id26162 56"></a>54 <a class="indexterm" name="id26162 63"></a>55 <a class="indexterm" name="id26162 70"></a>53 <a class="indexterm" name="id2616275"></a> 54 <a class="indexterm" name="id2616282"></a> 55 <a class="indexterm" name="id2616289"></a> 56 56 The team is not happy with ISA. Because it never lived up to its marketing promises, 57 57 it underperformed and had reliability problems. You have pounced on the opportunity … … 64 64 This is a hands-on exercise. You build software applications so 65 65 that you obtain the functionality Abmas needs. 66 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616 294"></a>Dissection and Discussion</h2></div></div></div><p>66 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616313"></a>Dissection and Discussion</h2></div></div></div><p> 67 67 The key requirements in this business example are straightforward. You are not required 68 68 to do anything new, just to replicate an existing system, not lose any existing features, … … 74 74 </p></li><li><p> 75 75 Seamless and transparent interoperability with the existing Active Directory domain 76 </p></li></ul></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26163 27"></a>Technical Issues</h3></div></div></div><p>77 <a class="indexterm" name="id26163 34"></a>78 <a class="indexterm" name="id26163 41"></a>79 <a class="indexterm" name="id26163 48"></a>80 <a class="indexterm" name="id26163 55"></a>81 <a class="indexterm" name="id26163 62"></a>82 <a class="indexterm" name="id26163 69"></a>83 <a class="indexterm" name="id26163 76"></a>84 <a class="indexterm" name="id2616 382"></a>85 <a class="indexterm" name="id2616 389"></a>86 <a class="indexterm" name="id2616 396"></a>87 <a class="indexterm" name="id26164 03"></a>88 <a class="indexterm" name="id26164 10"></a>89 <a class="indexterm" name="id26164 19"></a><a class="indexterm" name="id2616425"></a>76 </p></li></ul></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616346"></a>Technical Issues</h3></div></div></div><p> 77 <a class="indexterm" name="id2616354"></a> 78 <a class="indexterm" name="id2616361"></a> 79 <a class="indexterm" name="id2616368"></a> 80 <a class="indexterm" name="id2616374"></a> 81 <a class="indexterm" name="id2616381"></a> 82 <a class="indexterm" name="id2616388"></a> 83 <a class="indexterm" name="id2616395"></a> 84 <a class="indexterm" name="id2616402"></a> 85 <a class="indexterm" name="id2616409"></a> 86 <a class="indexterm" name="id2616416"></a> 87 <a class="indexterm" name="id2616423"></a> 88 <a class="indexterm" name="id2616430"></a> 89 <a class="indexterm" name="id2616439"></a><a class="indexterm" name="id2616445"></a> 90 90 Functionally, the user's Internet Explorer requests a browsing session with the 91 91 Squid proxy, for which it offers its AD authentication token. Squid hands off … … 108 108 </p></li><li><p> 109 109 Tying it all together 110 </p></li></ul></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616 483"></a>Political Issues</h3></div></div></div><p>110 </p></li></ul></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616502"></a>Political Issues</h3></div></div></div><p> 111 111 You are a stranger in a strange land, and all eyes are upon you. Some would even like to see 112 112 you fail. For you to gain the trust of your newly acquired IT people, it is essential that your … … 114 114 will the entrenched positions consider taking up your new way of doing things on a 115 115 wider scale. 116 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26165 00"></a>Implementation</h2></div></div></div><p>117 <a class="indexterm" name="id26165 08"></a>116 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616520"></a>Implementation</h2></div></div></div><p> 117 <a class="indexterm" name="id2616528"></a> 118 118 First, your system needs to be prepared and in a known good state to proceed. This consists 119 119 of making sure that everything the system depends on is present and that everything that could … … 122 122 they must be removed. 123 123 </p><p> 124 <a class="indexterm" name="id26165 25"></a>124 <a class="indexterm" name="id2616545"></a> 125 125 The following packages should be available on your Red Hat Linux system: 126 126 </p><div class="itemizedlist"><ul type="disc"><li><p> 127 <a class="indexterm" name="id26165 40"></a>128 <a class="indexterm" name="id26165 47"></a>127 <a class="indexterm" name="id2616560"></a> 128 <a class="indexterm" name="id2616566"></a> 129 129 krb5-libs 130 130 </p></li><li><p> … … 137 137 pam_krb5 138 138 </p></li></ul></div><p> 139 <a class="indexterm" name="id26165 77"></a>139 <a class="indexterm" name="id2616597"></a> 140 140 In the case of SUSE Linux, these packages are called: 141 141 </p><div class="itemizedlist"><ul type="disc"><li><p> … … 144 144 heimdal-devel 145 145 </p></li><li><p> 146 <a class="indexterm" name="id26166 02"></a>146 <a class="indexterm" name="id2616621"></a> 147 147 heimdal 148 148 </p></li><li><p> … … 153 153 for your Linux system to ensure that the packages are correctly updated. 154 154 </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 155 <a class="indexterm" name="id26166 27"></a>156 <a class="indexterm" name="id26166 34"></a>157 <a class="indexterm" name="id26166 41"></a>155 <a class="indexterm" name="id2616646"></a> 156 <a class="indexterm" name="id2616653"></a> 157 <a class="indexterm" name="id2616660"></a> 158 158 If the requirement is for interoperation with MS Windows Server 2003, it 159 159 will be necessary to ensure that you are using MIT Kerberos version 1.3.1 … … 161 161 updating. 162 162 </p><p> 163 <a class="indexterm" name="id26166 54"></a>164 <a class="indexterm" name="id26166 61"></a>163 <a class="indexterm" name="id2616674"></a> 164 <a class="indexterm" name="id2616681"></a> 165 165 Heimdal 0.6 or later is required in the case of SUSE Linux. SUSE Enterprise 166 166 Linux Server 8 ships with Heimdal 0.4. SUSE 9 ships with the necessary version. 167 167 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="ch10-one"></a>Removal of Pre-Existing Conflicting RPMs</h3></div></div></div><p> 168 <a class="indexterm" name="id2616 684"></a>168 <a class="indexterm" name="id2616704"></a> 169 169 If Samba and/or Squid RPMs are installed, they should be updated. You can 170 170 build both from source. 171 171 </p><p> 172 <a class="indexterm" name="id2616 696"></a>173 <a class="indexterm" name="id26167 02"></a>174 <a class="indexterm" name="id26167 09"></a>172 <a class="indexterm" name="id2616716"></a> 173 <a class="indexterm" name="id2616722"></a> 174 <a class="indexterm" name="id2616729"></a> 175 175 Locating the packages to be un-installed can be achieved by running: 176 176 </p><pre class="screen"> … … 182 182 <code class="prompt">root# </code> rpm -e samba-common 183 183 </pre><p> 184 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26167 49"></a>Kerberos Configuration</h3></div></div></div><p>185 <a class="indexterm" name="id26167 57"></a>186 <a class="indexterm" name="id26167 64"></a>187 <a class="indexterm" name="id26167 74"></a>188 <a class="indexterm" name="id2616 780"></a>184 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616769"></a>Kerberos Configuration</h3></div></div></div><p> 185 <a class="indexterm" name="id2616777"></a> 186 <a class="indexterm" name="id2616784"></a> 187 <a class="indexterm" name="id2616793"></a> 188 <a class="indexterm" name="id2616800"></a> 189 189 The systems Kerberos installation must be configured to communicate with 190 190 your primary Active Directory server (ADS KDC). … … 194 194 unless you are using Windows 2003 servers. 195 195 </p><p> 196 <a class="indexterm" name="id2616799"></a>197 <a class="indexterm" name="id2616806"></a>198 <a class="indexterm" name="id2616813"></a>199 196 <a class="indexterm" name="id2616819"></a> 200 <a class="indexterm" name="id2616826"></a> 201 <a class="indexterm" name="id2616835"></a> 202 <a class="indexterm" name="id2616842"></a> 197 <a class="indexterm" name="id2616825"></a> 198 <a class="indexterm" name="id2616832"></a> 199 <a class="indexterm" name="id2616839"></a> 200 <a class="indexterm" name="id2616846"></a> 201 <a class="indexterm" name="id2616855"></a> 202 <a class="indexterm" name="id2616861"></a> 203 203 Officially, neither MIT (1.3.4) nor Heimdal (0.63) Kerberos needs an <code class="filename">/etc/krb5.conf</code> 204 204 file in order to work correctly. All ADS domains automatically create SRV records in the … … 208 208 specifying only a single KDC, even if there is more than one. Using the DNS lookup 209 209 allows the KRB5 libraries to use whichever KDCs are available. 210 </p><div class="procedure"><a name="id26168 76"></a><p class="title"><b>Procedure 12.1. Kerberos Configuration Steps</b></p><ol type="1"><li><p>211 <a class="indexterm" name="id2616 887"></a>210 </p><div class="procedure"><a name="id2616896"></a><p class="title"><b>Procedure 12.1. Kerberos Configuration Steps</b></p><ol type="1"><li><p> 211 <a class="indexterm" name="id2616907"></a> 212 212 If you find the need to manually configure the <code class="filename">krb5.conf</code>, you should edit it 213 213 to have the contents shown in <a class="link" href="DomApps.html#ch10-krb5conf" title="Example 12.1. Kerberos Configuration File: /etc/krb5.conf">“Kerberos Configuration File: /etc/krb5.conf”</a>. The final fully qualified path for this file 214 214 should be <code class="filename">/etc/krb5.conf</code>. 215 215 </p></li><li><p> 216 <a class="indexterm" name="id2616922"></a> 217 <a class="indexterm" name="id2616929"></a> 218 <a class="indexterm" name="id2616936"></a> 219 <a class="indexterm" name="id2616943"></a> 216 <a class="indexterm" name="id2616942"></a> 220 217 <a class="indexterm" name="id2616949"></a> 221 218 <a class="indexterm" name="id2616956"></a> 222 <a class="indexterm" name="id261696 3"></a>223 <a class="indexterm" name="id26169 70"></a>224 <a class="indexterm" name="id261697 7"></a>225 <a class="indexterm" name="id261698 6"></a>226 <a class="indexterm" name="id261699 3"></a>227 <a class="indexterm" name="id261 7000"></a>219 <a class="indexterm" name="id2616962"></a> 220 <a class="indexterm" name="id2616969"></a> 221 <a class="indexterm" name="id2616976"></a> 222 <a class="indexterm" name="id2616983"></a> 223 <a class="indexterm" name="id2616990"></a> 224 <a class="indexterm" name="id2616997"></a> 228 225 <a class="indexterm" name="id2617006"></a> 226 <a class="indexterm" name="id2617012"></a> 227 <a class="indexterm" name="id2617019"></a> 228 <a class="indexterm" name="id2617026"></a> 229 229 The following gotchas often catch people out. Kerberos is case sensitive. Your realm must 230 230 be in UPPERCASE, or you will get an error: “<span class="quote">Cannot find KDC for requested realm while getting … … 242 242 when you try to join the realm. 243 243 </p></li><li><p> 244 <a class="indexterm" name="id26170 51"></a>244 <a class="indexterm" name="id2617070"></a> 245 245 You are now ready to test your installation by issuing the command: 246 246 </p><pre class="screen"> … … 262 262 kdc = w2k3s.london.abmas.biz 263 263 } 264 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id26171 16"></a>264 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id2617135"></a> 265 265 The command 266 266 </p><pre class="screen"> … … 268 268 </pre><p> 269 269 shows the Kerberos tickets cached by the system. 270 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26171 39"></a>Samba Configuration</h4></div></div></div><p>271 <a class="indexterm" name="id26171 46"></a>270 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617158"></a>Samba Configuration</h4></div></div></div><p> 271 <a class="indexterm" name="id2617166"></a> 272 272 Samba must be configured to correctly use Active Directory. Samba-3 must be used, since it 273 273 has the necessary components to interface with Active Directory. 274 </p><div class="procedure"><a name="id26171 57"></a><p class="title"><b>Procedure 12.2. Securing Samba-3 With ADS Support Steps</b></p><ol type="1"><li><p>275 <a class="indexterm" name="id26171 69"></a>276 <a class="indexterm" name="id26171 76"></a>277 <a class="indexterm" name="id2617 183"></a>278 <a class="indexterm" name="id2617 190"></a>279 <a class="indexterm" name="id2617 196"></a>274 </p><div class="procedure"><a name="id2617177"></a><p class="title"><b>Procedure 12.2. Securing Samba-3 With ADS Support Steps</b></p><ol type="1"><li><p> 275 <a class="indexterm" name="id2617188"></a> 276 <a class="indexterm" name="id2617195"></a> 277 <a class="indexterm" name="id2617202"></a> 278 <a class="indexterm" name="id2617209"></a> 279 <a class="indexterm" name="id2617216"></a> 280 280 Download the latest stable Samba-3 for Red Hat Linux from the official Samba Team 281 281 <a class="ulink" href="http://ftp.samba.org" target="_top">FTP site.</a> The official Samba Team … … 283 283 needed, and are linked against MIT KRB5 version 1.3.1 and therefore are ready for use. 284 284 </p><p> 285 <a class="indexterm" name="id26172 23"></a>286 <a class="indexterm" name="id26172 30"></a>285 <a class="indexterm" name="id2617242"></a> 286 <a class="indexterm" name="id2617249"></a> 287 287 The necessary, validated RPM packages for SUSE Linux may be obtained from 288 288 the <a class="ulink" href="ftp://ftp.sernet.de/pub/samba" target="_top">SerNet</a> FTP site that … … 294 294 file so it has contents similar to the example shown in <a class="link" href="DomApps.html#ch10-smbconf" title="Example 12.2. Samba Configuration File: /etc/samba/smb.conf">“Samba Configuration File: /etc/samba/smb.conf”</a>. 295 295 </p></li><li><p> 296 <a class="indexterm" name="id2617 281"></a>297 <a class="indexterm" name="id2617 288"></a>298 <a class="indexterm" name="id2617 295"></a>i299 <a class="indexterm" name="id26173 06"></a>300 <a class="indexterm" name="id26173 13"></a>296 <a class="indexterm" name="id2617301"></a> 297 <a class="indexterm" name="id2617307"></a> 298 <a class="indexterm" name="id2617314"></a>i 299 <a class="indexterm" name="id2617326"></a> 300 <a class="indexterm" name="id2617332"></a> 301 301 Next you need to create a computer account in the Active Directory. 302 302 This sets up the trust relationship needed for other clients to … … 308 308 </pre><p> 309 309 </p></li><li><p> 310 <a class="indexterm" name="id2617347"></a>311 <a class="indexterm" name="id2617354"></a>312 <a class="indexterm" name="id2617361"></a>313 310 <a class="indexterm" name="id2617367"></a> 314 <a class="indexterm" name="id2617374"></a> 311 <a class="indexterm" name="id2617373"></a> 312 <a class="indexterm" name="id2617380"></a> 313 <a class="indexterm" name="id2617387"></a> 314 <a class="indexterm" name="id2617394"></a> 315 315 Your new Samba binaries must be started in the standard manner as is applicable 316 316 to the platform you are running on. Alternatively, start your Active Directory-enabled Samba with the following commands: … … 321 321 </pre><p> 322 322 </p></li><li><p> 323 <a class="indexterm" name="id26174 15"></a>324 <a class="indexterm" name="id26174 22"></a>325 <a class="indexterm" name="id26174 31"></a>326 <a class="indexterm" name="id26174 38"></a>327 <a class="indexterm" name="id26174 45"></a>323 <a class="indexterm" name="id2617435"></a> 324 <a class="indexterm" name="id2617441"></a> 325 <a class="indexterm" name="id2617451"></a> 326 <a class="indexterm" name="id2617458"></a> 327 <a class="indexterm" name="id2617464"></a> 328 328 We now need to test that Samba is communicating with the Active 329 329 Directory domain; most specifically, we want to see whether winbind … … 358 358 This enumerates all the groups in your Active Directory tree. 359 359 </p></li><li><p> 360 <a class="indexterm" name="id26175 09"></a>361 <a class="indexterm" name="id26175 16"></a>360 <a class="indexterm" name="id2617528"></a> 361 <a class="indexterm" name="id2617535"></a> 362 362 Squid uses the <code class="literal">ntlm_auth</code> helper build with Samba-3. 363 363 You may test <code class="literal">ntlm_auth</code> with the command: … … 371 371 </pre><p> 372 372 </p></li><li><p> 373 <a class="indexterm" name="id2617568"></a>374 <a class="indexterm" name="id2617575"></a>375 <a class="indexterm" name="id2617582"></a>376 373 <a class="indexterm" name="id2617588"></a> 377 <a class="indexterm" name="id2617595"></a> 378 <a class="indexterm" name="id2617602"></a> 379 <a class="indexterm" name="id2617609"></a> 380 <a class="indexterm" name="id2617616"></a> 374 <a class="indexterm" name="id2617594"></a> 375 <a class="indexterm" name="id2617601"></a> 376 <a class="indexterm" name="id2617608"></a> 377 <a class="indexterm" name="id2617615"></a> 378 <a class="indexterm" name="id2617622"></a> 379 <a class="indexterm" name="id2617629"></a> 380 <a class="indexterm" name="id2617635"></a> 381 381 The <code class="literal">ntlm_auth</code> helper, when run from a command line as the user 382 382 “<span class="quote">root</span>”, authenticates against your Active Directory domain (with … … 396 396 <code class="prompt">root# </code> chmod 750 /var/lib/samba/winbindd_privileged 397 397 </pre><p> 398 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617 691"></a>NSS Configuration</h4></div></div></div><p>399 <a class="indexterm" name="id2617 699"></a>400 <a class="indexterm" name="id26177 05"></a>401 <a class="indexterm" name="id26177 12"></a>398 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617710"></a>NSS Configuration</h4></div></div></div><p> 399 <a class="indexterm" name="id2617718"></a> 400 <a class="indexterm" name="id2617725"></a> 401 <a class="indexterm" name="id2617732"></a> 402 402 For Squid to benefit from Samba-3, NSS must be updated to allow winbind as a valid route to user authentication. 403 403 </p><p> 404 404 Edit your <code class="filename">/etc/nsswitch.conf</code> file so it has the parameters shown 405 405 in <a class="link" href="DomApps.html#ch10-etcnsscfg" title="Example 12.3. NSS Configuration File Extract File: /etc/nsswitch.conf">“NSS Configuration File Extract File: /etc/nsswitch.conf”</a>. 406 </p><div class="example"><a name="ch10-smbconf"></a><p class="title"><b>Example 12.2. Samba Configuration File: <code class="filename">/etc/samba/smb.conf</code></b></p><div class="example-contents"><table class="simplelist" border="0" summary="Simple list"><tr><td> </td></tr><tr><td><em class="parameter"><code>[global]</code></em></td></tr><tr><td><a class="indexterm" name="id26177 70"></a><em class="parameter"><code>workgroup = LONDON</code></em></td></tr><tr><td><a class="indexterm" name="id2617782"></a><em class="parameter"><code>netbios name = W2K3S</code></em></td></tr><tr><td><a class="indexterm" name="id2617794"></a><em class="parameter"><code>realm = LONDON.ABMAS.BIZ</code></em></td></tr><tr><td><a class="indexterm" name="id2617806"></a><em class="parameter"><code>security = ads</code></em></td></tr><tr><td><a class="indexterm" name="id2617817"></a><em class="parameter"><code>encrypt passwords = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617829"></a><em class="parameter"><code>password server = w2k3s.london.abmas.biz</code></em></td></tr><tr><td># separate domain and username with '/', like DOMAIN/username</td></tr><tr><td><a class="indexterm" name="id2617846"></a><em class="parameter"><code>winbind separator = /</code></em></td></tr><tr><td># use UIDs from 10000 to 20000 for domain users</td></tr><tr><td><a class="indexterm" name="id2617862"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td># use GIDs from 10000 to 20000 for domain groups</td></tr><tr><td><a class="indexterm" name="id2617877"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr><tr><td># allow enumeration of winbind users and groups</td></tr><tr><td><a class="indexterm" name="id2617893"></a><em class="parameter"><code>winbind enum users = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617905"></a><em class="parameter"><code>winbind enum groups = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617917"></a><em class="parameter"><code>winbind user default domain = yes</code></em></td></tr></table></div></div><br class="example-break"><div class="example"><a name="ch10-etcnsscfg"></a><p class="title"><b>Example 12.3. NSS Configuration File Extract File: <code class="filename">/etc/nsswitch.conf</code></b></p><div class="example-contents"><pre class="screen">406 </p><div class="example"><a name="ch10-smbconf"></a><p class="title"><b>Example 12.2. Samba Configuration File: <code class="filename">/etc/samba/smb.conf</code></b></p><div class="example-contents"><table class="simplelist" border="0" summary="Simple list"><tr><td> </td></tr><tr><td><em class="parameter"><code>[global]</code></em></td></tr><tr><td><a class="indexterm" name="id2617790"></a><em class="parameter"><code>workgroup = LONDON</code></em></td></tr><tr><td><a class="indexterm" name="id2617802"></a><em class="parameter"><code>netbios name = W2K3S</code></em></td></tr><tr><td><a class="indexterm" name="id2617813"></a><em class="parameter"><code>realm = LONDON.ABMAS.BIZ</code></em></td></tr><tr><td><a class="indexterm" name="id2617825"></a><em class="parameter"><code>security = ads</code></em></td></tr><tr><td><a class="indexterm" name="id2617837"></a><em class="parameter"><code>encrypt passwords = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617849"></a><em class="parameter"><code>password server = w2k3s.london.abmas.biz</code></em></td></tr><tr><td># separate domain and username with '/', like DOMAIN/username</td></tr><tr><td><a class="indexterm" name="id2617865"></a><em class="parameter"><code>winbind separator = /</code></em></td></tr><tr><td># use UIDs from 10000 to 20000 for domain users</td></tr><tr><td><a class="indexterm" name="id2617881"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td># use GIDs from 10000 to 20000 for domain groups</td></tr><tr><td><a class="indexterm" name="id2617897"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr><tr><td># allow enumeration of winbind users and groups</td></tr><tr><td><a class="indexterm" name="id2617913"></a><em class="parameter"><code>winbind enum users = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617925"></a><em class="parameter"><code>winbind enum groups = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617937"></a><em class="parameter"><code>winbind user default domain = yes</code></em></td></tr></table></div></div><br class="example-break"><div class="example"><a name="ch10-etcnsscfg"></a><p class="title"><b>Example 12.3. NSS Configuration File Extract File: <code class="filename">/etc/nsswitch.conf</code></b></p><div class="example-contents"><pre class="screen"> 407 407 passwd: files winbind 408 408 shadow: files 409 409 group: files winbind 410 </pre></div></div><br class="example-break"></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26179 56"></a>Squid Configuration</h4></div></div></div><p>411 <a class="indexterm" name="id26179 64"></a>412 <a class="indexterm" name="id26179 71"></a>410 </pre></div></div><br class="example-break"></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617976"></a>Squid Configuration</h4></div></div></div><p> 411 <a class="indexterm" name="id2617983"></a> 412 <a class="indexterm" name="id2617990"></a> 413 413 Squid must be configured correctly to interact with the Samba-3 414 414 components that handle Active Directory authentication. 415 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id261 7986"></a>Configuration</h3></div></div></div></div><div class="procedure"><a name="id2617991"></a><p class="title"><b>Procedure 12.3. Squid Configuration Steps</b></p><ol type="1"><li><p>416 <a class="indexterm" name="id26180 03"></a>417 <a class="indexterm" name="id26180 09"></a>418 <a class="indexterm" name="id26180 17"></a>415 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2618005"></a>Configuration</h3></div></div></div></div><div class="procedure"><a name="id2618011"></a><p class="title"><b>Procedure 12.3. Squid Configuration Steps</b></p><ol type="1"><li><p> 416 <a class="indexterm" name="id2618022"></a> 417 <a class="indexterm" name="id2618029"></a> 418 <a class="indexterm" name="id2618037"></a> 419 419 If your Linux distribution is SUSE Linux 9, the version of Squid 420 420 supplied is already enabled to use the winbind helper agent. You … … 422 422 programs. 423 423 </p></li><li><p> 424 <a class="indexterm" name="id26180 34"></a>425 <a class="indexterm" name="id26180 41"></a>426 <a class="indexterm" name="id26180 48"></a>427 <a class="indexterm" name="id26180 55"></a>428 <a class="indexterm" name="id26180 62"></a>424 <a class="indexterm" name="id2618054"></a> 425 <a class="indexterm" name="id2618061"></a> 426 <a class="indexterm" name="id2618068"></a> 427 <a class="indexterm" name="id2618074"></a> 428 <a class="indexterm" name="id2618081"></a> 429 429 Squid, by default, runs as the user <code class="constant">nobody</code>. You need to 430 430 add a system user <code class="constant">squid</code> and a system group … … 434 434 and a <code class="constant">squid</code> group in <code class="filename">/etc/group</code> if these aren't there already. 435 435 </p></li><li><p> 436 <a class="indexterm" name="id26181 09"></a>437 <a class="indexterm" name="id26181 16"></a>436 <a class="indexterm" name="id2618129"></a> 437 <a class="indexterm" name="id2618136"></a> 438 438 You now need to change the permissions on Squid's <code class="constant">var</code> 439 439 directory. Enter the following command: … … 442 442 </pre><p> 443 443 </p></li><li><p> 444 <a class="indexterm" name="id26181 47"></a>445 <a class="indexterm" name="id26181 54"></a>444 <a class="indexterm" name="id2618167"></a> 445 <a class="indexterm" name="id2618173"></a> 446 446 Squid must also have control over its logging. Enter the following commands: 447 447 </p><pre class="screen"> … … 457 457 </pre><p> 458 458 </p></li><li><p> 459 <a class="indexterm" name="id26182 14"></a>459 <a class="indexterm" name="id2618233"></a> 460 460 The <code class="filename">/etc/squid/squid.conf</code> file must be edited to include the lines from 461 461 <a class="link" href="DomApps.html#etcsquidcfg" title="Example 12.4. Squid Configuration File Extract /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]">“Squid Configuration File Extract /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]”</a> and <a class="link" href="DomApps.html#etcsquid2" title="Example 12.5. Squid Configuration File extract File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]">“Squid Configuration File extract File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]”</a>. 462 462 </p></li><li><p> 463 <a class="indexterm" name="id26182 48"></a>463 <a class="indexterm" name="id2618267"></a> 464 464 You must create Squid's cache directories before it may be run. Enter the following command: 465 465 </p><pre class="screen"> … … 488 488 acl AuthorizedUsers proxy_auth REQUIRED 489 489 http_access allow all AuthorizedUsers 490 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26183 52"></a>Key Points Learned</h3></div></div></div><p>491 <a class="indexterm" name="id26183 60"></a>492 <a class="indexterm" name="id26183 67"></a>493 <a class="indexterm" name="id26183 74"></a>494 <a class="indexterm" name="id2618 381"></a>495 <a class="indexterm" name="id2618 393"></a>490 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2618372"></a>Key Points Learned</h3></div></div></div><p> 491 <a class="indexterm" name="id2618380"></a> 492 <a class="indexterm" name="id2618387"></a> 493 <a class="indexterm" name="id2618394"></a> 494 <a class="indexterm" name="id2618401"></a> 495 <a class="indexterm" name="id2618412"></a> 496 496 Microsoft Windows networking protocols permeate the spectrum of technologies that Microsoft 497 497 Windows clients use, even when accessing traditional services such as Web browsers. Depending … … 500 500 the cookie-based authentication regime used by all competing browsers. It is Samba's implementation 501 501 of NTLMSSP that makes it attractive to implement the solution that has been demonstrated in this chapter. 502 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26184 13"></a>Questions and Answers</h2></div></div></div><p>503 <a class="indexterm" name="id26184 21"></a>504 <a class="indexterm" name="id26184 28"></a>505 <a class="indexterm" name="id26184 35"></a>506 <a class="indexterm" name="id26184 41"></a>502 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618432"></a>Questions and Answers</h2></div></div></div><p> 503 <a class="indexterm" name="id2618440"></a> 504 <a class="indexterm" name="id2618447"></a> 505 <a class="indexterm" name="id2618454"></a> 506 <a class="indexterm" name="id2618461"></a> 507 507 The development of the <code class="literal">ntlm_auth</code> module was first discussed in many Open Source circles 508 508 in 2002. At the SambaXP conference in Goettingen, Germany, Mr. Francesco Chemolli demonstrated the use of … … 523 523 Make certain that your Squid proxy server is equipped with sufficient memory to permit all proxy operations to run 524 524 out of memory without invoking the overheads involved in the use of memory that has to be swapped to disk. 525 </p><div class="qandaset"><dl><dt> <a href="DomApps.html#id26185 19">525 </p><div class="qandaset"><dl><dt> <a href="DomApps.html#id2618546"> 526 526 What does Samba have to do with Web proxy serving? 527 </a></dt><dt> <a href="DomApps.html#id2618 685">527 </a></dt><dt> <a href="DomApps.html#id2618712"> 528 528 What other services does Samba provide? 529 </a></dt><dt> <a href="DomApps.html#id26188 28">529 </a></dt><dt> <a href="DomApps.html#id2618855"> 530 530 Does use of Samba (ntlm_auth) improve the performance of Squid? 531 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id26185 19"></a><a name="id2618521"></a></td><td align="left" valign="top"><p>531 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2618546"></a><a name="id2618548"></a></td><td align="left" valign="top"><p> 532 532 What does Samba have to do with Web proxy serving? 533 533 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 534 <a class="indexterm" name="id26185 33"></a>535 <a class="indexterm" name="id26185 40"></a>536 <a class="indexterm" name="id26185 47"></a>537 <a class="indexterm" name="id26185 56"></a>538 <a class="indexterm" name="id26185 63"></a>534 <a class="indexterm" name="id2618560"></a> 535 <a class="indexterm" name="id2618567"></a> 536 <a class="indexterm" name="id2618574"></a> 537 <a class="indexterm" name="id2618583"></a> 538 <a class="indexterm" name="id2618590"></a> 539 539 To provide transparent interoperability between Windows clients and the network services 540 540 that are used from them, Samba had to develop tools and facilities that deliver that feature. The benefit … … 542 542 module is basically a wrapper around authentication code from the core of the Samba project. 543 543 </p><p> 544 <a class="indexterm" name="id2618585"></a> 545 <a class="indexterm" name="id2618592"></a> 546 <a class="indexterm" name="id2618601"></a> 547 <a class="indexterm" name="id2618610"></a> 544 <a class="indexterm" name="id2618612"></a> 548 545 <a class="indexterm" name="id2618619"></a> 549 <a class="indexterm" name="id2618626"></a> 550 <a class="indexterm" name="id2618633"></a> 551 <a class="indexterm" name="id2618640"></a> 552 <a class="indexterm" name="id2618647"></a> 546 <a class="indexterm" name="id2618629"></a> 547 <a class="indexterm" name="id2618638"></a> 548 <a class="indexterm" name="id2618646"></a> 549 <a class="indexterm" name="id2618653"></a> 550 <a class="indexterm" name="id2618660"></a> 551 <a class="indexterm" name="id2618667"></a> 552 <a class="indexterm" name="id2618674"></a> 553 553 The <code class="literal">ntlm_auth</code> module supports basic plain-text authentication and NTLMSSP 554 554 protocols. This module makes it possible for Web and FTP proxy requests to be authenticated without … … 558 558 also. 559 559 </p><p> 560 <a class="indexterm" name="id26186 71"></a>560 <a class="indexterm" name="id2618699"></a> 561 561 The short answer is that by adding a wrapper around key authentication components of Samba, other 562 562 projects (like Squid) can benefit from the labors expended in meeting user interoperability needs. 563 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618 685"></a><a name="id2618687"></a></td><td align="left" valign="top"><p>563 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618712"></a><a name="id2618714"></a></td><td align="left" valign="top"><p> 564 564 What other services does Samba provide? 565 565 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 566 <a class="indexterm" name="id2618699"></a>567 <a class="indexterm" name="id2618706"></a>568 <a class="indexterm" name="id2618712"></a>569 <a class="indexterm" name="id2618719"></a>570 566 <a class="indexterm" name="id2618726"></a> 567 <a class="indexterm" name="id2618733"></a> 568 <a class="indexterm" name="id2618740"></a> 569 <a class="indexterm" name="id2618746"></a> 570 <a class="indexterm" name="id2618753"></a> 571 571 Samba-3 is a file and print server. The core components that provide this functionality are <code class="literal">smbd</code>, 572 572 <code class="literal">nmbd</code>, and the identity resolver daemon, <code class="literal">winbindd</code>. 573 573 </p><p> 574 <a class="indexterm" name="id26187 57"></a>575 <a class="indexterm" name="id26187 63"></a>574 <a class="indexterm" name="id2618784"></a> 575 <a class="indexterm" name="id2618791"></a> 576 576 Samba-3 is an SMB/CIFS client. The core component that provides this is called <code class="literal">smbclient</code>. 577 577 </p><p> 578 <a class="indexterm" name="id2618781"></a>579 <a class="indexterm" name="id2618788"></a>580 <a class="indexterm" name="id2618794"></a>581 <a class="indexterm" name="id2618801"></a>582 578 <a class="indexterm" name="id2618808"></a> 579 <a class="indexterm" name="id2618815"></a> 580 <a class="indexterm" name="id2618822"></a> 581 <a class="indexterm" name="id2618828"></a> 582 <a class="indexterm" name="id2618835"></a> 583 583 Samba-3 includes a number of helper tools, plug-in modules, utilities, and test and validation facilities. 584 584 Samba-3 includes glue modules that help provide interoperability between MS Windows clients and UNIX/Linux … … 587 587 to permit identity resolution via SMB/CIFS servers (Windows NT4/200x, Samba, and a host of other commercial 588 588 server products). 589 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26188 28"></a><a name="id2618830"></a></td><td align="left" valign="top"><p>589 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618855"></a><a name="id2618858"></a></td><td align="left" valign="top"><p> 590 590 Does use of Samba (<code class="literal">ntlm_auth</code>) improve the performance of Squid? 591 591 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/HA.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 13. Performance, Reliability, and Availability</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="DomApps.html" title="Chapter 12. Integrating Additional Services"><link rel="next" href="ch14.html" title="Chapter 14. Samba Support"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 13. Performance, Reliability, and Availability</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="DomApps.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="ch14.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="HA"></a>Chapter 13. Performance, Reliability, and Availability</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="HA.html#id26189 32">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></div><p>2 <a class="indexterm" name="id2618 894"></a>3 <a class="indexterm" name="id26189 01"></a>4 <a class="indexterm" name="id26189 07"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 13. Performance, Reliability, and Availability</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="DomApps.html" title="Chapter 12. Integrating Additional Services"><link rel="next" href="ch14.html" title="Chapter 14. Samba Support"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 13. Performance, Reliability, and Availability</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="DomApps.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="ch14.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="HA"></a>Chapter 13. Performance, Reliability, and Availability</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></div><p> 2 <a class="indexterm" name="id2618921"></a> 3 <a class="indexterm" name="id2618928"></a> 4 <a class="indexterm" name="id2618935"></a> 5 5 Well, you have reached one of the last chapters of this book. It is customary to attempt 6 6 to wrap up the theme and contents of a book in what is generally regarded as the … … 11 11 </p><div class="blockquote"><table border="0" width="100%" cellspacing="0" cellpadding="0" class="blockquote" summary="Block quote"><tr><td width="10%" valign="top"> </td><td width="80%" valign="top"><p> 12 12 In a world so full of noise, how can the sparrow be heard? 13 </p></td><td width="10%" valign="top"> </td></tr><tr><td width="10%" valign="top"> </td><td colspan="2" align="right" valign="top">--<span class="attribution">Anonymous</span></td></tr></table></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26189 32"></a>Introduction</h2></div></div></div><p>14 <a class="indexterm" name="id26189 40"></a>13 </p></td><td width="10%" valign="top"> </td></tr><tr><td width="10%" valign="top"> </td><td colspan="2" align="right" valign="top">--<span class="attribution">Anonymous</span></td></tr></table></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618959"></a>Introduction</h2></div></div></div><p> 14 <a class="indexterm" name="id2618967"></a> 15 15 The sparrow is a small bird whose sounds are drowned out by the noise of the busy 16 16 world it lives in. Likewise, the simple steps that can be taken to improve the … … 21 21 custom tools and methods. Only passing comments are offered concerning these methods. 22 22 </p><p> 23 <a class="indexterm" name="id26189 60"></a>24 <a class="indexterm" name="id261 8967"></a>25 <a class="indexterm" name="id261 8974"></a>23 <a class="indexterm" name="id2618997"></a> 24 <a class="indexterm" name="id2619004"></a> 25 <a class="indexterm" name="id2619011"></a> 26 26 <a class="ulink" href="http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&q=samba+cluster&btnG=Google+Search" target="_top">A search</a> 27 27 for “<span class="quote">samba cluster</span>” produced 71,600 hits. And a search for “<span class="quote">highly available samba</span>” … … 30 30 availability, reliability, and scalability are of vital interest to corporate network users. 31 31 </p><p> 32 <a class="indexterm" name="id26190 07"></a>32 <a class="indexterm" name="id2619044"></a> 33 33 So without further background, you can review a checklist of simple steps that 34 34 can be taken to ensure acceptable network performance while keeping costs of ownership 35 35 well under control. 36 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26190 19"></a>Dissection and Discussion</h2></div></div></div><p>37 <a class="indexterm" name="id26190 27"></a>38 <a class="indexterm" name="id26190 34"></a>36 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619057"></a>Dissection and Discussion</h2></div></div></div><p> 37 <a class="indexterm" name="id2619065"></a> 38 <a class="indexterm" name="id2619071"></a> 39 39 If it is your purpose to get the best mileage out of your Samba servers, there is one rule that 40 40 must be obeyed. If you want the best, keep your implementation as simple as possible. You may … … 45 45 complex ones. 46 46 </p><p> 47 <a class="indexterm" name="id26190 56"></a>48 <a class="indexterm" name="id2619 063"></a>47 <a class="indexterm" name="id2619093"></a> 48 <a class="indexterm" name="id2619100"></a> 49 49 Problems reported by users fall into three categories: configurations that do not work, those 50 50 that have broken behavior, and poor performance. The term <span class="emphasis"><em>broken behavior</em></span> … … 55 55 and at other times not listing them even though the machines are in use on the network. 56 56 </p><p> 57 <a class="indexterm" name="id2619 090"></a>58 <a class="indexterm" name="id2619 097"></a>59 <a class="indexterm" name="id26191 04"></a>60 <a class="indexterm" name="id26191 11"></a>61 <a class="indexterm" name="id26191 18"></a>62 <a class="indexterm" name="id26191 24"></a>57 <a class="indexterm" name="id2619128"></a> 58 <a class="indexterm" name="id2619134"></a> 59 <a class="indexterm" name="id2619141"></a> 60 <a class="indexterm" name="id2619148"></a> 61 <a class="indexterm" name="id2619155"></a> 62 <a class="indexterm" name="id2619162"></a> 63 63 A significant number of reports concern problems with the <code class="literal">smbfs</code> file system 64 64 driver that is part of the Linux kernel, not part of Samba. Users continue to interpret that … … 71 71 Samba and are really foreign to it. 72 72 </p><p> 73 <a class="indexterm" name="id2619 185"></a>73 <a class="indexterm" name="id2619222"></a> 74 74 The new project, <code class="literal">cifsfs</code>, is destined to replace <code class="literal">smbfs</code>. 75 75 It, too, is not part of Samba, even though one of the Samba Team members is a prime mover in … … 78 78 Table 13.1 lists typical causes of: 79 79 </p><div class="itemizedlist"><ul type="disc"><li><p>Not Working (NW)</p></li><li><p>Broken Behavior (BB)</p></li><li><p>Poor Performance (PP)</p></li></ul></div><div class="table"><a name="ProbList"></a><p class="title"><b>Table 13.1. Effect of Common Problems</b></p><div class="table-contents"><table summary="Effect of Common Problems" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="center"></colgroup><thead><tr><th align="left"><p>Problem</p></th><th align="center"><p>NW</p></th><th align="center"><p>BB</p></th><th align="center"><p>PP</p></th></tr></thead><tbody><tr><td align="left"><p>File locking</p></td><td align="center"><p>-</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Hardware problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Incorrect authentication</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Incorrect configuration</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>LDAP problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Name resolution</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Printing problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Slow file transfer</p></td><td align="center"><p>-</p></td><td align="center"><p>-</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Winbind problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr></tbody></table></div></div><br class="table-break"><p> 80 <a class="indexterm" name="id2619 479"></a>80 <a class="indexterm" name="id2619516"></a> 81 81 It is obvious to all that the first requirement (as a matter of network hygiene) is to eliminate 82 82 problems that affect basic network operation. This book has provided sufficient working examples 83 83 to help you to avoid all these problems. 84 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619 492"></a>Guidelines for Reliable Samba Operation</h2></div></div></div><p>85 <a class="indexterm" name="id26195 01"></a>86 <a class="indexterm" name="id26195 08"></a>84 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619530"></a>Guidelines for Reliable Samba Operation</h2></div></div></div><p> 85 <a class="indexterm" name="id2619538"></a> 86 <a class="indexterm" name="id2619545"></a> 87 87 Your objective is to provide a network that works correctly, can grow at all times, is resilient 88 88 at times of extreme demand, and can scale to meet future needs. The following subject areas provide 89 89 pointers that can help you today. 90 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26195 20"></a>Name Resolution</h3></div></div></div><p>90 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2619557"></a>Name Resolution</h3></div></div></div><p> 91 91 There are three basic current problem areas: bad hostnames, routed networks, and network collisions. 92 92 These are covered in the following discussion. 93 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26195 31"></a>Bad Hostnames</h4></div></div></div><p>94 <a class="indexterm" name="id26195 39"></a>95 <a class="indexterm" name="id26195 48"></a>96 <a class="indexterm" name="id26195 55"></a>97 <a class="indexterm" name="id26195 62"></a>98 <a class="indexterm" name="id2619 569"></a>93 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619568"></a>Bad Hostnames</h4></div></div></div><p> 94 <a class="indexterm" name="id2619576"></a> 95 <a class="indexterm" name="id2619586"></a> 96 <a class="indexterm" name="id2619592"></a> 97 <a class="indexterm" name="id2619599"></a> 98 <a class="indexterm" name="id2619606"></a> 99 99 When configured as a DHCP client, a number of Linux distributions set the system hostname 100 100 to <code class="constant">localhost</code>. If the parameter <em class="parameter"><code>netbios name</code></em> is not … … 108 108 correctly. 109 109 </p><p> 110 <a class="indexterm" name="id26196 24"></a>110 <a class="indexterm" name="id2619661"></a> 111 111 A few sites have tried to name Windows clients and Samba servers with a name that begins 112 112 with the digits 1-9. This does not work either because it may result in the client or 113 113 server attempting to use that name as an IP address. 114 114 </p><p> 115 <a class="indexterm" name="id26196 38"></a>116 <a class="indexterm" name="id26196 47"></a>115 <a class="indexterm" name="id2619675"></a> 116 <a class="indexterm" name="id2619684"></a> 117 117 A Samba server called <code class="constant">FRED</code> in a NetBIOS domain called <code class="constant">COLLISION</code> 118 118 in a network environment that is part of the fully-qualified Internet domain namespace known … … 123 123 fails given that you probably do not have this in your DNS namespace. 124 124 </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 125 <a class="indexterm" name="id2619 691"></a>126 <a class="indexterm" name="id26197 00"></a>127 <a class="indexterm" name="id26197 07"></a>125 <a class="indexterm" name="id2619728"></a> 126 <a class="indexterm" name="id2619738"></a> 127 <a class="indexterm" name="id2619744"></a> 128 128 An Active Directory realm called <code class="constant">collision.parrots.com</code> is perfectly okay, 129 129 although it too must be capable of being resolved via DNS, something that functions correctly 130 130 if Windows 200x ADS has been properly installed and configured. 131 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26197 23"></a>Routed Networks</h4></div></div></div><p>132 <a class="indexterm" name="id26197 31"></a>133 <a class="indexterm" name="id26197 38"></a>134 <a class="indexterm" name="id26197 47"></a>131 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619760"></a>Routed Networks</h4></div></div></div><p> 132 <a class="indexterm" name="id2619768"></a> 133 <a class="indexterm" name="id2619775"></a> 134 <a class="indexterm" name="id2619784"></a> 135 135 NetBIOS networks (Windows networking with NetBIOS over TCP/IP enabled) makes extensive use 136 136 of UDP-based broadcast traffic, as you saw during the exercises in <a class="link" href="primer.html" title="Chapter 16. Networking Primer">“Networking Primer”</a>. 137 137 </p><p> 138 <a class="indexterm" name="id2619 767"></a>139 <a class="indexterm" name="id2619 774"></a>140 <a class="indexterm" name="id2619 780"></a>138 <a class="indexterm" name="id2619804"></a> 139 <a class="indexterm" name="id2619811"></a> 140 <a class="indexterm" name="id2619818"></a> 141 141 UDP broadcast traffic is not forwarded by routers. This means that NetBIOS broadcast-based 142 142 networking cannot function across routed networks (i.e., multi-subnet networks) unless 143 143 special provisions are made: 144 144 </p><div class="itemizedlist"><ul type="disc"><li><p> 145 <a class="indexterm" name="id2619 797"></a>146 <a class="indexterm" name="id26198 04"></a>147 <a class="indexterm" name="id26198 11"></a>145 <a class="indexterm" name="id2619835"></a> 146 <a class="indexterm" name="id2619841"></a> 147 <a class="indexterm" name="id2619848"></a> 148 148 Either install on every Windows client an LMHOSTS file (located in the directory 149 149 <code class="filename">C:\windows\system32\drivers\etc</code>). It is also necessary to … … 152 152 manual page for the <code class="filename">smb.conf</code> file. 153 153 </p></li><li><p> 154 <a class="indexterm" name="id26198 57"></a>154 <a class="indexterm" name="id2619894"></a> 155 155 Or configure Samba as a WINS server, and configure all network clients to use that 156 156 WINS server in their TCP/IP configuration. 157 157 </p></li></ul></div><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 158 <a class="indexterm" name="id2619 874"></a>159 <a class="indexterm" name="id2619 883"></a>158 <a class="indexterm" name="id2619911"></a> 159 <a class="indexterm" name="id2619920"></a> 160 160 The use of DNS is not an acceptable substitute for WINS. DNS does not store specific 161 161 information regarding NetBIOS networking particulars that get stored in the WINS 162 162 name resolution database and that Windows clients require and depend on. 163 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619 896"></a>Network Collisions</h4></div></div></div><p>164 <a class="indexterm" name="id26199 04"></a>165 <a class="indexterm" name="id26199 13"></a>166 <a class="indexterm" name="id26199 22"></a>167 <a class="indexterm" name="id26199 29"></a>163 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619933"></a>Network Collisions</h4></div></div></div><p> 164 <a class="indexterm" name="id2619941"></a> 165 <a class="indexterm" name="id2619950"></a> 166 <a class="indexterm" name="id2619959"></a> 167 <a class="indexterm" name="id2619966"></a> 168 168 Excessive network activity causes NetBIOS network timeouts. Timeouts may result in 169 169 blue screen of death (BSOD) experiences. High collision rates may be caused by excessive … … 174 174 in <a class="link" href="primer.html" title="Chapter 16. Networking Primer">“Networking Primer”</a>. 175 175 </p><p> 176 <a class="indexterm" name="id26199 58"></a>177 <a class="indexterm" name="id26 19965"></a>178 <a class="indexterm" name="id26 19972"></a>176 <a class="indexterm" name="id2619995"></a> 177 <a class="indexterm" name="id2620002"></a> 178 <a class="indexterm" name="id2620009"></a> 179 179 Under no circumstances should the facility be supported by many routers, known as <code class="constant">NetBIOS 180 180 forwarding</code>, unless you know exactly what you are doing. Inappropriate use of this … … 184 184 less than 15 KB/sec. After the NetBIOS forwarding was turned off, file transfer performance 185 185 immediately returned to 11 MB/sec. 186 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26 19995"></a>Samba Configuration</h3></div></div></div><p>186 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620033"></a>Samba Configuration</h3></div></div></div><p> 187 187 As a general rule, the contents of the <code class="filename">smb.conf</code> file should be kept as simple as possible. 188 188 No parameter should be specified unless you know it is essential to operation. 189 189 </p><p> 190 <a class="indexterm" name="id26200 15"></a>191 <a class="indexterm" name="id26200 22"></a>192 <a class="indexterm" name="id26200 29"></a>190 <a class="indexterm" name="id2620052"></a> 191 <a class="indexterm" name="id2620060"></a> 192 <a class="indexterm" name="id2620066"></a> 193 193 Many UNIX administrators like to fully document the settings in the <code class="filename">smb.conf</code> file. This is a 194 194 bad idea because it adds content to the file. The <code class="filename">smb.conf</code> file is re-read by every <code class="literal">smbd</code> … … 198 198 It is recommended to keep a fully documented <code class="filename">smb.conf</code> file on hand, and then to operate Samba only 199 199 with an optimized file. 200 </p><p><a class="indexterm" name="id2620 079"></a>200 </p><p><a class="indexterm" name="id2620116"></a> 201 201 The preferred way to maintain a documented file is to call it something like <code class="filename">smb.conf.master</code>. 202 202 You can generate the optimized file by executing: … … 224 224 Press enter to see a dump of your service definitions 225 225 </pre><p> 226 <a class="indexterm" name="id26201 38"></a>226 <a class="indexterm" name="id2620176"></a> 227 227 You now, of course, press the enter key to complete the command, or else abort it by pressing Ctrl-C. 228 228 The important thing to note is the noted Server role, as well as warning messages. Noted configuration … … 234 234 </pre><p> 235 235 </p><p> 236 <a class="indexterm" name="id2620 166"></a>237 <a class="indexterm" name="id2620 173"></a>238 <a class="indexterm" name="id2620 180"></a>236 <a class="indexterm" name="id2620203"></a> 237 <a class="indexterm" name="id2620210"></a> 238 <a class="indexterm" name="id2620217"></a> 239 239 There are two parameters that can cause severe network performance degradation: <em class="parameter"><code>socket options</code></em> 240 240 and <em class="parameter"><code>socket address</code></em>. The <em class="parameter"><code>socket options</code></em> parameter was often necessary … … 242 242 this parameter being set. Do not use either parameter unless it has been proven necessary to use them. 243 243 </p><p> 244 <a class="indexterm" name="id26202 14"></a>245 <a class="indexterm" name="id26202 21"></a>246 <a class="indexterm" name="id26202 28"></a>247 <a class="indexterm" name="id26202 35"></a>244 <a class="indexterm" name="id2620251"></a> 245 <a class="indexterm" name="id2620258"></a> 246 <a class="indexterm" name="id2620265"></a> 247 <a class="indexterm" name="id2620272"></a> 248 248 Another <code class="filename">smb.conf</code> parameter that may cause severe network performance degradation is the 249 249 <em class="parameter"><code>strict sync</code></em> parameter. Do not use this at all. There is no good reason … … 252 252 degrade network performance, so do not set it; if you must, do so with caution. 253 253 </p><p> 254 <a class="indexterm" name="id2620 276"></a>255 <a class="indexterm" name="id2620 283"></a>256 <a class="indexterm" name="id2620 290"></a>257 <a class="indexterm" name="id2620 297"></a>254 <a class="indexterm" name="id2620313"></a> 255 <a class="indexterm" name="id2620320"></a> 256 <a class="indexterm" name="id2620327"></a> 257 <a class="indexterm" name="id2620334"></a> 258 258 Finally, many network administrators deliberately disable opportunistic locking support. While this 259 259 does not degrade Samba performance, it significantly degrades Windows client performance because … … 263 263 oplock support for operations that are tolerant of it. See <a class="link" href="appendix.html#ch12dblck" title="Shared Data Integrity">“Shared Data Integrity”</a> for more 264 264 information. 265 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26203 23"></a>Use and Location of BDCs</h3></div></div></div><p>266 <a class="indexterm" name="id26203 31"></a>267 <a class="indexterm" name="id26203 37"></a>268 <a class="indexterm" name="id26203 44"></a>269 <a class="indexterm" name="id26203 51"></a>270 <a class="indexterm" name="id26203 58"></a>265 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620360"></a>Use and Location of BDCs</h3></div></div></div><p> 266 <a class="indexterm" name="id2620368"></a> 267 <a class="indexterm" name="id2620374"></a> 268 <a class="indexterm" name="id2620381"></a> 269 <a class="indexterm" name="id2620388"></a> 270 <a class="indexterm" name="id2620395"></a> 271 271 On a network segment where there is a PDC and a BDC, the BDC carries the bulk of the network logon 272 272 processing. If the BDC is a heavily loaded server, the PDC carries a greater proportion of … … 276 276 and is undesirable. 277 277 </p><p> 278 <a class="indexterm" name="id2620 376"></a>279 <a class="indexterm" name="id2620 383"></a>278 <a class="indexterm" name="id2620413"></a> 279 <a class="indexterm" name="id2620420"></a> 280 280 As a general guide, instead of adding domain member servers to a network, you would be better advised 281 281 to add BDCs until there are fewer than 30 Windows clients per BDC. Beyond that ratio, you should add 282 282 domain member servers. This practice ensures that there are always sufficient domain controllers 283 283 to handle logon requests and authentication traffic. 284 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 398"></a>Use One Consistent Version of MS Windows Client</h3></div></div></div><p>284 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620435"></a>Use One Consistent Version of MS Windows Client</h3></div></div></div><p> 285 285 Every network client has its own peculiarities. From a management perspective, it is easier to deal 286 286 with one version of MS Windows that is maintained to a consistent update level than it is to deal … … 290 290 have necessitated special handling from the Samba server end. If you want to remain sane, keep you 291 291 client workstation configurations consistent. 292 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26204 20"></a>For Scalability, Use SAN-Based Storage on Samba Servers</h3></div></div></div><p>293 <a class="indexterm" name="id26204 29"></a>294 <a class="indexterm" name="id26204 36"></a>292 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620457"></a>For Scalability, Use SAN-Based Storage on Samba Servers</h3></div></div></div><p> 293 <a class="indexterm" name="id2620466"></a> 294 <a class="indexterm" name="id2620473"></a> 295 295 Many SAN-based storage systems permit more than one server to share a common data store. 296 296 Use of a shared SAN data store means that you do not need to use time- and resource-hungry data 297 297 synchronization techniques. 298 298 </p><p> 299 <a class="indexterm" name="id26204 50"></a>300 <a class="indexterm" name="id26204 56"></a>299 <a class="indexterm" name="id2620487"></a> 300 <a class="indexterm" name="id2620494"></a> 301 301 The use of a collection of relatively low-cost front-end Samba servers that are coupled to 302 302 a shared backend SAN data store permits load distribution while containing costs below that 303 303 of installing and managing a complex clustering facility. 304 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 470"></a>Distribute Network Load with MSDFS</h3></div></div></div><p>305 <a class="indexterm" name="id2620 478"></a>306 <a class="indexterm" name="id2620 485"></a>304 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620507"></a>Distribute Network Load with MSDFS</h3></div></div></div><p> 305 <a class="indexterm" name="id2620515"></a> 306 <a class="indexterm" name="id2620522"></a> 307 307 Microsoft DFS (distributed file system) technology has been implemented in Samba. MSDFS permits 308 308 data to be accessed from a single share and yet to actually be distributed across multiple actual … … 310 310 implementation of an MSDFS installation. 311 311 </p><p> 312 <a class="indexterm" name="id26205 03"></a>313 <a class="indexterm" name="id26205 12"></a>312 <a class="indexterm" name="id2620540"></a> 313 <a class="indexterm" name="id2620550"></a> 314 314 The combination of multiple backend servers together with a front-end server and use of MSDFS 315 315 can achieve almost the same as you would obtain with a clustered Samba server. 316 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26205 24"></a>Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</h3></div></div></div><p>317 <a class="indexterm" name="id26205 33"></a>318 <a class="indexterm" name="id26205 40"></a>319 <a class="indexterm" name="id26205 47"></a>316 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620562"></a>Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</h3></div></div></div><p> 317 <a class="indexterm" name="id2620570"></a> 318 <a class="indexterm" name="id2620577"></a> 319 <a class="indexterm" name="id2620584"></a> 320 320 Consider using <code class="literal">rsync</code> to replicate data across the WAN during times 321 321 of low utilization. Users can then access the replicated data store rather than needing to do so … … 324 324 implementation if you choose to permit modification and return replication of the modified file; 325 325 otherwise, you may inadvertently overwrite important data. 326 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620 570"></a>Hardware Problems</h3></div></div></div><p>327 <a class="indexterm" name="id2620 578"></a>328 <a class="indexterm" name="id2620 585"></a>329 <a class="indexterm" name="id2620 592"></a>330 <a class="indexterm" name="id2620 599"></a>331 <a class="indexterm" name="id26206 08"></a>332 <a class="indexterm" name="id26206 17"></a>326 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620607"></a>Hardware Problems</h3></div></div></div><p> 327 <a class="indexterm" name="id2620615"></a> 328 <a class="indexterm" name="id2620622"></a> 329 <a class="indexterm" name="id2620629"></a> 330 <a class="indexterm" name="id2620636"></a> 331 <a class="indexterm" name="id2620645"></a> 332 <a class="indexterm" name="id2620654"></a> 333 333 Networking hardware prices have fallen sharply over the past 5 years. A surprising number 334 334 of Samba networking problems over this time have been traced to defective network interface 335 335 cards (NICs) or defective HUBs, switches, and cables. 336 336 </p><p> 337 <a class="indexterm" name="id26206 34"></a>337 <a class="indexterm" name="id2620671"></a> 338 338 Not surprising is the fact that network administrators do not like to be shown to have made 339 339 a bad decision. Money saved in buying low-cost hardware may result in high costs incurred 340 340 in corrective action. 341 341 </p><p> 342 <a class="indexterm" name="id26206 47"></a>343 <a class="indexterm" name="id26206 54"></a>344 <a class="indexterm" name="id26206 61"></a>345 <a class="indexterm" name="id2620 668"></a>346 <a class="indexterm" name="id2620 675"></a>342 <a class="indexterm" name="id2620684"></a> 343 <a class="indexterm" name="id2620691"></a> 344 <a class="indexterm" name="id2620698"></a> 345 <a class="indexterm" name="id2620705"></a> 346 <a class="indexterm" name="id2620712"></a> 347 347 Defective NICs, HUBs, and switches may appear as intermittent network access problems, intermittent 348 348 or persistent data corruption, slow network throughput, low performance, or even as BSOD … … 353 353 Defective hardware problems may take patience and persistence before the real cause can be discovered. 354 354 </p><p> 355 <a class="indexterm" name="id2620 698"></a>355 <a class="indexterm" name="id2620736"></a> 356 356 Networking hardware defects can significantly impact perceived Samba performance, but defective 357 357 RAID controllers as well as SCSI and IDE hard disk controllers have also been known to impair Samba server … … 360 360 administrator until the entire server was replaced. While you may well think that this would never 361 361 happen to you, experience shows that given the right (unfortunate) circumstances, this can happen to anyone. 362 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26207 28"></a>Large Directories</h3></div></div></div><p>362 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620755"></a>Large Directories</h3></div></div></div><p> 363 363 There exist applications that create or manage directories containing many thousands of files. Such 364 364 applications typically generate many small files (less than 100 KB). At the best of times, under UNIX, … … 400 400 as specified in the <code class="filename">smb.conf</code> stanza. This means that smbd will not be able to find lower case 401 401 filenames with these settings. Note, this is done on a per-share basis. 402 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26208 32"></a>Key Points Learned</h2></div></div></div><p>402 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620859"></a>Key Points Learned</h2></div></div></div><p> 403 403 This chapter has touched in broad sweeps on a number of simple steps that can be taken 404 404 to ensure that your Samba network is resilient, scalable, and reliable, and that it … … 409 409 her an even break. 410 410 </p><p> 411 <a class="indexterm" name="id26208 53"></a>411 <a class="indexterm" name="id2620880"></a> 412 412 Last, but not least, you should not only keep the network design simple, but also be sure it is 413 413 well documented. This book may serve as your pattern for documenting every -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/RefSection.html
r231 r272 4 4 published regarding Samba, or just to gain a more broad understanding of how Samba can 5 5 play in a Windows networking world. 6 </p><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id26146 72">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616162">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618932">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621928">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625407">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.6 </p><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A. 7 7 GNU General Public License version 3 8 </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id26288 70">A.8 </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A. 9 9 Preamble 10 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 15">A.10 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A. 11 11 TERMS AND CONDITIONS 12 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 19">A.12 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A. 13 13 0. Definitions. 14 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26291 11">A.14 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A. 15 15 1. Source Code. 16 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 10">A.16 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A. 17 17 2. Basic Permissions. 18 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 49">A.18 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A. 19 19 3. Protecting Users’ Legal Rights From Anti-Circumvention Law. 20 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 290">A.20 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A. 21 21 4. Conveying Verbatim Copies. 22 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26293 17">A.22 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A. 23 23 5. Conveying Modified Source Versions. 24 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26294 12">A.24 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A. 25 25 6. Conveying Non-Source Forms. 26 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26296 02">A.26 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A. 27 27 7. Additional Terms. 28 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26297 38">A.28 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A. 29 29 8. Termination. 30 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 781">A.30 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A. 31 31 9. Acceptance Not Required for Having Copies. 32 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 01">A.32 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A. 33 33 10. Automatic Licensing of Downstream Recipients. 34 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 53">A.34 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A. 35 35 11. Patents. 36 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26 29988">A.36 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A. 37 37 12. No Surrender of Others’ Freedom. 38 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 10">A.38 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A. 39 39 13. Use with the ???TITLE??? Affero General Public License. 40 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 39">A.40 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A. 41 41 14. Revised Versions of this License. 42 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 01">A.42 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A. 43 43 15. Disclaimer of Warranty. 44 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 28">A.44 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A. 45 45 16. Limitation of Liability. 46 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 48">A.46 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A. 47 47 17. Interpretation of Sections 15 and 16. 48 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 64">A.48 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A. 49 49 END OF TERMS AND CONDITIONS 50 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 68">A.50 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A. 51 51 How to Apply These Terms to Your New Programs 52 52 </a></span></dt></dl></dd></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="nw4migration.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> <a accesskey="n" href="kerberos.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 10. Migrating NetWare Server to Samba-3 </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Chapter 11. Active Directory, Kerberos, and Security</td></tr></table></div></body></html> -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/apa.html
r231 r272 1 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Appendix A. GNU General Public License version 3</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="primer.html" title="Chapter 16. Networking Primer"><link rel="next" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Appendix A. 2 2 GNU General Public License version 3 3 </th></tr><tr><td width="20%" align="left"><a accesskey="p" href="primer.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="go01.html">Next</a></td></tr></table><hr></div><div class="appendix" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="id26288 40"></a>Appendix A.3 </th></tr><tr><td width="20%" align="left"><a accesskey="p" href="primer.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="go01.html">Next</a></td></tr></table><hr></div><div class="appendix" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="id2628864"></a>Appendix A. 4 4 <acronym class="acronym">GNU</acronym> General Public License version 3 5 </h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="bridgehead"><a href="apa.html#id26288 70">A.5 </h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A. 6 6 Preamble 7 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 15">A.7 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A. 8 8 TERMS AND CONDITIONS 9 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 19">A.9 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A. 10 10 0. Definitions. 11 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26291 11">A.11 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A. 12 12 1. Source Code. 13 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 10">A.13 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A. 14 14 2. Basic Permissions. 15 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 49">A.15 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A. 16 16 3. Protecting Users’ Legal Rights From Anti-Circumvention Law. 17 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 290">A.17 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A. 18 18 4. Conveying Verbatim Copies. 19 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26293 17">A.19 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A. 20 20 5. Conveying Modified Source Versions. 21 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26294 12">A.21 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A. 22 22 6. Conveying Non-Source Forms. 23 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26296 02">A.23 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A. 24 24 7. Additional Terms. 25 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26297 38">A.25 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A. 26 26 8. Termination. 27 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 781">A.27 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A. 28 28 9. Acceptance Not Required for Having Copies. 29 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 01">A.29 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A. 30 30 10. Automatic Licensing of Downstream Recipients. 31 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 53">A.31 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A. 32 32 11. Patents. 33 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26 29988">A.33 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A. 34 34 12. No Surrender of Others’ Freedom. 35 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 10">A.35 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A. 36 36 13. Use with the ???TITLE??? Affero General Public License. 37 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 39">A.37 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A. 38 38 14. Revised Versions of this License. 39 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 01">A.39 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A. 40 40 15. Disclaimer of Warranty. 41 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 28">A.41 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A. 42 42 16. Limitation of Liability. 43 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 48">A.43 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A. 44 44 17. Interpretation of Sections 15 and 16. 45 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 64">A.45 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A. 46 46 END OF TERMS AND CONDITIONS 47 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 68">A.47 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A. 48 48 How to Apply These Terms to Your New Programs 49 49 </a></span></dt></dl></div><p> … … 55 55 Everyone is permitted to copy and distribute verbatim copies of this license 56 56 document, but changing it is not allowed. 57 </p><h2><a name="id26288 70"></a>57 </p><h2><a name="id2628893"></a> 58 58 Preamble 59 59 </h2><p> … … 119 119 The precise terms and conditions for copying, distribution and modification 120 120 follow. 121 </p><h2><a name="id26290 15"></a>121 </p><h2><a name="id2629038"></a> 122 122 TERMS AND CONDITIONS 123 </h2><h2><a name="id26290 19"></a>123 </h2><h2><a name="id2629042"></a> 124 124 0. Definitions. 125 125 </h2><p> … … 163 163 a list of user commands or options, such as a menu, a prominent item in the 164 164 list meets this criterion. 165 </p><h2><a name="id26291 11"></a>165 </p><h2><a name="id2629134"></a> 166 166 1. Source Code. 167 167 </h2><p> … … 203 203 </p><p> 204 204 The Corresponding Source for a work in source code form is that same work. 205 </p><h2><a name="id26292 10"></a>205 </p><h2><a name="id2629233"></a> 206 206 2. Basic Permissions. 207 207 </h2><p> … … 228 228 conditions stated below. Sublicensing is not allowed; section 10 makes it 229 229 unnecessary. 230 </p><h2><a name="id26292 49"></a>230 </p><h2><a name="id2629272"></a> 231 231 3. Protecting Users’ Legal Rights From Anti-Circumvention Law. 232 232 </h2><p> … … 243 243 third parties’ legal rights to forbid circumvention of technological 244 244 measures. 245 </p><h2><a name="id2629 290"></a>245 </p><h2><a name="id2629308"></a> 246 246 4. Conveying Verbatim Copies. 247 247 </h2><p> … … 256 256 You may charge any price or no price for each copy that you convey, and you 257 257 may offer support or warranty protection for a fee. 258 </p><h2><a name="id26293 17"></a>258 </p><h2><a name="id2629335"></a> 259 259 5. Conveying Modified Source Versions. 260 260 </h2><p> … … 292 292 permit. Inclusion of a covered work in an aggregate does not cause 293 293 this License to apply to the other parts of the aggregate. 294 </p><h2><a name="id26294 12"></a>294 </p><h2><a name="id2629431"></a> 295 295 6. Conveying Non-Source Forms. 296 296 </h2><p> … … 387 387 and must require no special password or key for unpacking, reading or 388 388 copying. 389 </p><h2><a name="id26296 02"></a>389 </p><h2><a name="id2629620"></a> 390 390 7. Additional Terms. 391 391 </h2><p> … … 451 451 of a separately written license, or stated as exceptions; the above 452 452 requirements apply either way. 453 </p><h2><a name="id26297 38"></a>453 </p><h2><a name="id2629756"></a> 454 454 8. Termination. 455 455 </h2><p> … … 477 477 reinstated, you do not qualify to receive new licenses for the same 478 478 material under section 10. 479 </p><h2><a name="id2629 781"></a>479 </p><h2><a name="id2629800"></a> 480 480 9. Acceptance Not Required for Having Copies. 481 481 </h2><p> … … 488 488 Therefore, by modifying or propagating a covered work, you indicate your 489 489 acceptance of this License to do so. 490 </p><h2><a name="id26298 01"></a>490 </p><h2><a name="id2629819"></a> 491 491 10. Automatic Licensing of Downstream Recipients. 492 492 </h2><p> … … 513 513 by making, using, selling, offering for sale, or importing the Program or 514 514 any portion of it. 515 </p><h2><a name="id26298 53"></a>515 </p><h2><a name="id2629871"></a> 516 516 11. Patents. 517 517 </h2><p> … … 580 580 implied license or other defenses to infringement that may otherwise be 581 581 available to you under applicable patent law. 582 </p><h2><a name="id26 29988"></a>582 </p><h2><a name="id2630017"></a> 583 583 12. No Surrender of Others’ Freedom. 584 584 </h2><p> … … 592 592 Program, the only way you could satisfy both those terms and this License 593 593 would be to refrain entirely from conveying the Program. 594 </p><h2><a name="id26300 10"></a>594 </p><h2><a name="id2630039"></a> 595 595 13. Use with the <acronym class="acronym">GNU</acronym> Affero General Public License. 596 596 </h2><p> … … 603 603 section 13, concerning interaction through a network will apply to the 604 604 combination as such. 605 </p><h2><a name="id26300 39"></a>605 </p><h2><a name="id2630067"></a> 606 606 14. Revised Versions of this License. 607 607 </h2><p> … … 628 628 However, no additional obligations are imposed on any author or copyright 629 629 holder as a result of your choosing to follow a later version. 630 </p><h2><a name="id26301 01"></a>630 </p><h2><a name="id2630130"></a> 631 631 15. Disclaimer of Warranty. 632 632 </h2><p> … … 639 639 YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL 640 640 NECESSARY SERVICING, REPAIR OR CORRECTION. 641 </p><h2><a name="id26301 28"></a>641 </p><h2><a name="id2630156"></a> 642 642 16. Limitation of Liability. 643 643 </h2><p> … … 651 651 EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF 652 652 SUCH DAMAGES. 653 </p><h2><a name="id26301 48"></a>653 </p><h2><a name="id2630176"></a> 654 654 17. Interpretation of Sections 15 and 16. 655 655 </h2><p> … … 660 660 warranty or assumption of liability accompanies a copy of the Program in 661 661 return for a fee. 662 </p><h2><a name="id26301 64"></a>662 </p><h2><a name="id2630193"></a> 663 663 END OF TERMS AND CONDITIONS 664 </h2><h2><a name="id26301 68"></a>664 </h2><h2><a name="id2630197"></a> 665 665 How to Apply These Terms to Your New Programs 666 666 </h2><p> -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/appendix.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 15. A Collection of Useful Tidbits</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="ch14.html" title="Chapter 14. Samba Support"><link rel="next" href="primer.html" title="Chapter 16. Networking Primer"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 15. A Collection of Useful Tidbits</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="ch14.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="primer.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="appendix"></a>Chapter 15. A Collection of Useful Tidbits</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id26219 28">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></div><p>2 <a class="indexterm" name="id26213 49"></a>3 <a class="indexterm" name="id26213 55"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 15. A Collection of Useful Tidbits</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="ch14.html" title="Chapter 14. Samba Support"><link rel="next" href="primer.html" title="Chapter 16. Networking Primer"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 15. A Collection of Useful Tidbits</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="ch14.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="primer.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="appendix"></a>Chapter 15. A Collection of Useful Tidbits</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></div><p> 2 <a class="indexterm" name="id2621376"></a> 3 <a class="indexterm" name="id2621382"></a> 4 4 Information presented here is considered to be either basic or well-known material that is informative 5 5 yet helpful. Over the years, I have observed an interesting behavior. There is an expectation that … … 8 8 as shown in the example given below. 9 9 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="domjoin"></a>Joining a Domain: Windows 200x/XP Professional</h2></div></div></div><p> 10 <a class="indexterm" name="id2621 386"></a>10 <a class="indexterm" name="id2621412"></a> 11 11 Microsoft Windows NT/200x/XP Professional platforms can participate in Domain Security. 12 12 This section steps through the process for making a Windows 200x/XP Professional machine a 13 13 member of a Domain Security environment. It should be noted that this process is identical 14 14 when joining a domain that is controlled by Windows NT4/200x as well as a Samba PDC. 15 </p><div class="procedure"><a name="id26214 00"></a><p class="title"><b>Procedure 15.1. Steps to Join a Domain</b></p><ol type="1"><li><p>15 </p><div class="procedure"><a name="id2621426"></a><p class="title"><b>Procedure 15.1. Steps to Join a Domain</b></p><ol type="1"><li><p> 16 16 Click <span class="guimenu">Start</span>. 17 17 </p></li><li><p> … … 51 51 Joining the domain is now complete. 52 52 </p></li></ol></div><p> 53 <a class="indexterm" name="id26218 18"></a>54 <a class="indexterm" name="id26218 25"></a>53 <a class="indexterm" name="id2621845"></a> 54 <a class="indexterm" name="id2621852"></a> 55 55 The screen capture shown in <a class="link" href="appendix.html#swxpp007" title="Figure 15.4. The Computer Name Changes Panel Domain MIDEARTH">“The Computer Name Changes Panel Domain MIDEARTH”</a> has a button labeled <span class="guimenu">More...</span>. This button opens a 56 56 panel in which you can set (or change) the Primary DNS suffix of the computer. This is a parameter that mainly affects members 57 57 of Microsoft Active Directory. Active Directory is heavily oriented around the DNS namespace. 58 58 </p><p> 59 <a class="indexterm" name="id26218 51"></a>60 <a class="indexterm" name="id26218 58"></a>59 <a class="indexterm" name="id2621878"></a> 60 <a class="indexterm" name="id2621885"></a> 61 61 Where NetBIOS technology uses WINS as well as UDP broadcast as key mechanisms for name resolution, Active Directory servers 62 62 register their services with the Microsoft Dynamic DNS server. Windows clients must be able to query the correct DNS server 63 63 to find the services (like which machines are domain controllers or which machines have the Netlogon service running). 64 64 </p><p> 65 <a class="indexterm" name="id2621 876"></a>65 <a class="indexterm" name="id2621903"></a> 66 66 The default setting of the Primary DNS suffix is the Active Directory domain name. When you change the Primary DNS suffix, 67 67 this does not affect domain membership, but it can break network browsing and the ability to resolve your computer name to … … 71 71 Where the client is a member of a Samba domain, it is preferable to leave this field blank. 72 72 </p><p> 73 <a class="indexterm" name="id26219 00"></a>73 <a class="indexterm" name="id2621927"></a> 74 74 According to Microsoft documentation, “<span class="quote">If this computer belongs to a group with <code class="constant">Group Policy</code> 75 75 enabled on <code class="literal">Primary DNS suffice of this computer</code>, the string specified in the Group Policy is used 76 76 as the primary DNS suffix and you might need to restart your computer to view the correct setting. The local setting is 77 77 used only if Group Policy is disabled or unspecified.</span>” 78 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26219 28"></a>Samba System File Location</h2></div></div></div><p><a class="indexterm" name="id2621935"></a><a class="indexterm" name="id2621943"></a><a class="indexterm" name="id2621951"></a>78 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621955"></a>Samba System File Location</h2></div></div></div><p><a class="indexterm" name="id2621962"></a><a class="indexterm" name="id2621970"></a><a class="indexterm" name="id2621978"></a> 79 79 One of the frustrations expressed by subscribers to the Samba mailing lists revolves around the choice of where the default Samba Team 80 80 build and installation process locates its Samba files. The location, chosen in the early 1990s, for the default installation is … … 84 84 Several UNIX vendors, and Linux vendors in particular, elected to locate the Samba files in a location other than the Samba Team 85 85 default. 86 </p><p><a class="indexterm" name="id262 1987"></a><a class="indexterm" name="id2621999"></a><a class="indexterm" name="id2622006"></a><a class="indexterm" name="id2622018"></a><a class="indexterm" name="id2622026"></a><a class="indexterm" name="id2622037"></a><a class="indexterm" name="id2622045"></a><a class="indexterm" name="id2622053"></a><a class="indexterm" name="id2622061"></a><a class="indexterm" name="id2622069"></a><a class="indexterm" name="id2622076"></a><a class="indexterm" name="id2622084"></a><a class="indexterm" name="id2622092"></a><a class="indexterm" name="id2622100"></a><a class="indexterm" name="id2622108"></a><a class="indexterm" name="id2622116"></a>86 </p><p><a class="indexterm" name="id2622014"></a><a class="indexterm" name="id2622025"></a><a class="indexterm" name="id2622033"></a><a class="indexterm" name="id2622045"></a><a class="indexterm" name="id2622052"></a><a class="indexterm" name="id2622064"></a><a class="indexterm" name="id2622072"></a><a class="indexterm" name="id2622080"></a><a class="indexterm" name="id2622088"></a><a class="indexterm" name="id2622095"></a><a class="indexterm" name="id2622103"></a><a class="indexterm" name="id2622111"></a><a class="indexterm" name="id2622119"></a><a class="indexterm" name="id2622127"></a><a class="indexterm" name="id2622135"></a><a class="indexterm" name="id2622143"></a> 87 87 Linux vendors, working in conjunction with the Free Standards Group (FSG), Linux Standards Base (LSB), and File Hierarchy 88 88 System (FHS), have elected to locate the configuration files under the <code class="filename">/etc/samba</code> directory, common binary … … 93 93 <code class="filename">/usr/lib/samba</code> directory tree. The files located there include the dynamically loadable modules for the 94 94 passdb backend as well as for the VFS modules. 95 </p><p><a class="indexterm" name="id2622 185"></a><a class="indexterm" name="id2622193"></a><a class="indexterm" name="id2622201"></a>95 </p><p><a class="indexterm" name="id2622212"></a><a class="indexterm" name="id2622220"></a><a class="indexterm" name="id2622228"></a> 96 96 Samba creates runtime control files and generates log files. The runtime control files (tdb and dat files) are stored in 97 97 the <code class="filename">/var/lib/samba</code> directory. Log files are created in <code class="filename">/var/log/samba.</code> … … 99 99 When Samba is built and installed using the default Samba Team process, all files are located under the 100 100 <code class="filename">/usr/local/samba</code> directory tree. This makes it simple to find the files that Samba owns. 101 </p><p><a class="indexterm" name="id26222 40"></a>101 </p><p><a class="indexterm" name="id2622267"></a> 102 102 One way to find the Samba files that are installed on your UNIX/Linux system is to search for the location 103 103 of all files called <code class="literal">smbd</code>. Here is an example: … … 132 132 Many people have been caught by installation of Samba using the default Samba Team process when it was already installed 133 133 by the platform vendor's method. If your platform uses RPM format packages, you can check to see if Samba is installed by 134 executing:<a class="indexterm" name="id26223 13"></a>134 executing:<a class="indexterm" name="id2622340"></a> 135 135 </p><pre class="screen"> 136 136 <code class="prompt">root# </code> rpm -qa | grep samba … … 144 144 samba3-client-3.0.20-1 145 145 samba3-cifsmount-3.0.20-1 146 </pre><p><a class="indexterm" name="id26223 36"></a>146 </pre><p><a class="indexterm" name="id2622362"></a> 147 147 The package names, of course, vary according to how the vendor, or the binary package builder, prepared them. 148 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26223 49"></a>Starting Samba</h2></div></div></div><p><a class="indexterm" name="id2622356"></a>148 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622376"></a>Starting Samba</h2></div></div></div><p><a class="indexterm" name="id2622382"></a> 149 149 Samba essentially consists of two or three daemons. A daemon is a UNIX application that runs in the background and provides services. 150 150 An example of a service is the Apache Web server for which the daemon is called <code class="literal">httpd</code>. In the case of Samba, there … … 187 187 exit 0 188 188 </pre></div></div><br class="example-break"><div class="variablelist"><dl><dt><span class="term">nmbd</span></dt><dd><p> 189 <a class="indexterm" name="id26224 18"></a>190 <a class="indexterm" name="id26224 25"></a>189 <a class="indexterm" name="id2622445"></a> 190 <a class="indexterm" name="id2622452"></a> 191 191 This daemon handles all name registration and resolution requests. It is the primary vehicle involved 192 192 in network browsing. It handles all UDP-based protocols. The <code class="literal">nmbd</code> daemon should 193 193 be the first command started as part of the Samba startup process. 194 194 </p></dd><dt><span class="term">smbd</span></dt><dd><p> 195 <a class="indexterm" name="id26224 55"></a>196 <a class="indexterm" name="id26224 62"></a>195 <a class="indexterm" name="id2622482"></a> 196 <a class="indexterm" name="id2622488"></a> 197 197 This daemon handles all TCP/IP-based connection services for file- and print-based operations. It also 198 198 manages local authentication. It should be started immediately following the startup of <code class="literal">nmbd</code>. 199 199 </p></dd><dt><span class="term">winbindd</span></dt><dd><p> 200 <a class="indexterm" name="id2622 490"></a>201 <a class="indexterm" name="id2622 497"></a>200 <a class="indexterm" name="id2622517"></a> 201 <a class="indexterm" name="id2622524"></a> 202 202 This daemon should be started when Samba is a member of a Windows NT4 or ADS domain. It is also needed when 203 203 Samba has trust relationships with another domain. The <code class="literal">winbindd</code> daemon will check the … … 253 253 exit 1 254 254 esac 255 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id26226 16"></a>255 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id2622637"></a> 256 256 SUSE Linux implements individual control over each Samba daemon. A Samba control script that can be conveniently 257 257 executed from the command line is shown in <a class="link" href="appendix.html#ch12SL" title="Example 15.1. A Useful Samba Control Script for SUSE Linux">“A Useful Samba Control Script for SUSE Linux”</a>. This can be located in the directory 258 258 <code class="filename">/sbin</code> in a file called <code class="filename">samba</code>. This type of control script should be 259 259 owned by user root and group root, and set so that only root can execute it. 260 </p><p><a class="indexterm" name="id26226 52"></a>260 </p><p><a class="indexterm" name="id2622672"></a> 261 261 A sample startup script for a Red Hat Linux system is shown in <a class="link" href="appendix.html#ch12RHscript" title="Example 15.2. A Sample Samba Control Script for Red Hat Linux">“A Sample Samba Control Script for Red Hat Linux”</a>. 262 262 This file could be located in the directory <code class="filename">/etc/rc.d</code> and can be called … … 265 265 the Samba source code distribution tarball. The packaging files for each platform include a 266 266 startup control file. 267 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622 695"></a>DNS Configuration Files</h2></div></div></div><p>267 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622715"></a>DNS Configuration Files</h2></div></div></div><p> 268 268 The following files are common to all DNS server configurations. Rather than repeat them multiple times, they 269 269 are presented here for general reference. 270 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26227 07"></a>The Forward Zone File for the Loopback Adaptor</h3></div></div></div><p>270 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622727"></a>The Forward Zone File for the Loopback Adaptor</h3></div></div></div><p> 271 271 The forward zone file for the loopback address never changes. An example file is shown 272 272 in <a class="link" href="appendix.html#loopback" title="Example 15.3. DNS Localhost Forward Zone File: /var/lib/named/localhost.zone">“DNS Localhost Forward Zone File: /var/lib/named/localhost.zone”</a>. All traffic destined for an IP address that is hosted on a … … 285 285 IN NS @ 286 286 IN A 127.0.0.1 287 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26227 55"></a>The Reverse Zone File for the Loopback Adaptor</h3></div></div></div><p>287 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622776"></a>The Reverse Zone File for the Loopback Adaptor</h3></div></div></div><p> 288 288 The reverse zone file for the loopback address as shown in <a class="link" href="appendix.html#dnsloopy" title="Example 15.4. DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone">“DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone”</a> 289 289 is necessary so that references to the address <code class="constant">127.0.0.1</code> can be … … 345 345 M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33 346 346 ; End of File 347 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622 895"></a>DNS Root Server Hint File</h3></div></div></div><p>347 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622916"></a>DNS Root Server Hint File</h3></div></div></div><p> 348 348 The content of the root hints file as shown in <a class="link" href="appendix.html#roothint" title="Example 15.5. DNS Root Name Server Hint File: /var/lib/named/root.hint">“DNS Root Name Server Hint File: /var/lib/named/root.hint”</a> changes slowly over time. 349 349 Periodically this file should be updated from the source shown. Because 350 350 of its size, this file is located at the end of this chapter. 351 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="altldapcfg"></a>Alternative LDAP Database Initialization</h2></div></div></div><p><a class="indexterm" name="id26229 26"></a><a class="indexterm" name="id2622937"></a>351 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="altldapcfg"></a>Alternative LDAP Database Initialization</h2></div></div></div><p><a class="indexterm" name="id2622947"></a><a class="indexterm" name="id2622958"></a> 352 352 The following procedure may be used as an alternative means of configuring 353 353 the initial LDAP database. Many administrators prefer to have greater control 354 354 over how system files get configured. 355 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26229 54"></a>Initialization of the LDAP Database</h3></div></div></div><p><a class="indexterm" name="id2622961"></a><a class="indexterm" name="id2622969"></a><a class="indexterm" name="id2622981"></a>355 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622975"></a>Initialization of the LDAP Database</h3></div></div></div><p><a class="indexterm" name="id2622982"></a><a class="indexterm" name="id2622990"></a><a class="indexterm" name="id2623001"></a> 356 356 The first step to get the LDAP server ready for action is to create the LDIF file from 357 357 which the LDAP database will be preloaded. This is necessary to create the containers … … 706 706 displayName: Domain Users 707 707 description: Domain Users 708 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26235 32"></a>The LDAP Account Manager</h2></div></div></div><p>709 <a class="indexterm" name="id26235 40"></a>710 <a class="indexterm" name="id26235 47"></a>711 <a class="indexterm" name="id26235 56"></a>712 <a class="indexterm" name="id26235 63"></a>713 <a class="indexterm" name="id26235 70"></a>714 <a class="indexterm" name="id2623 576"></a>715 <a class="indexterm" name="id2623 583"></a>708 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2623561"></a>The LDAP Account Manager</h2></div></div></div><p> 709 <a class="indexterm" name="id2623569"></a> 710 <a class="indexterm" name="id2623575"></a> 711 <a class="indexterm" name="id2623585"></a> 712 <a class="indexterm" name="id2623591"></a> 713 <a class="indexterm" name="id2623598"></a> 714 <a class="indexterm" name="id2623605"></a> 715 <a class="indexterm" name="id2623612"></a> 716 716 The LDAP Account Manager (LAM) is an application suite that has been written in PHP. 717 717 LAM can be used with any Web server that has PHP4 support. It connects to the LDAP … … 725 725 of 2005. 726 726 </p><p> 727 <a class="indexterm" name="id26236 15"></a>728 <a class="indexterm" name="id26236 21"></a>729 <a class="indexterm" name="id26236 28"></a>727 <a class="indexterm" name="id2623643"></a> 728 <a class="indexterm" name="id2623650"></a> 729 <a class="indexterm" name="id2623657"></a> 730 730 Requirements: 731 731 </p><div class="itemizedlist"><ul type="disc"><li><p>A web server that will work with PHP4.</p></li><li><p>PHP4 (available from the <a class="ulink" href="http://www.php.net/" target="_top">PHP</a> home page.)</p></li><li><p>OpenLDAP 2.0 or later.</p></li><li><p>A Web browser that supports CSS.</p></li><li><p>Perl.</p></li><li><p>The gettext package.</p></li><li><p>mcrypt + mhash (optional).</p></li><li><p>It is also a good idea to install SSL support.</p></li></ul></div><p> 732 732 LAM is a useful tool that provides a simple Web-based device that can be used to 733 733 manage the contents of the LDAP directory to: 734 <a class="indexterm" name="id2623 689"></a>735 <a class="indexterm" name="id2623 696"></a>736 <a class="indexterm" name="id26237 03"></a>734 <a class="indexterm" name="id2623717"></a> 735 <a class="indexterm" name="id2623724"></a> 736 <a class="indexterm" name="id2623731"></a> 737 737 </p><div class="itemizedlist"><ul type="disc"><li><p>Display user/group/host and Domain entries.</p></li><li><p>Manage entries (Add/Delete/Edit).</p></li><li><p>Filter and sort entries.</p></li><li><p>Store and use multiple operating profiles.</p></li><li><p>Edit organizational units (OUs).</p></li><li><p>Upload accounts from a file.</p></li><li><p>Is compatible with Samba-2.2.x and Samba-3.</p></li></ul></div><p> 738 738 When correctly configured, LAM allows convenient management of UNIX (Posix) and Samba 739 739 user, group, and windows domain member machine accounts. 740 740 </p><p> 741 <a class="indexterm" name="id26237 57"></a>742 <a class="indexterm" name="id26237 64"></a>743 <a class="indexterm" name="id26237 71"></a>744 <a class="indexterm" name="id2623 777"></a>741 <a class="indexterm" name="id2623785"></a> 742 <a class="indexterm" name="id2623792"></a> 743 <a class="indexterm" name="id2623799"></a> 744 <a class="indexterm" name="id2623806"></a> 745 745 The default password is “<span class="quote">lam.</span>” It is highly recommended that you use only 746 746 an SSL connection to your Web server for all remote operations involving LAM. If you … … 761 761 <code class="filename">/srv/www/htdocs</code> directory. 762 762 </p></li><li><p> 763 <a class="indexterm" name="id26238 57"></a>763 <a class="indexterm" name="id2623886"></a> 764 764 Set file permissions using the following commands: 765 765 </p><pre class="screen"> … … 771 771 </pre><p> 772 772 </p></li><li><p> 773 <a class="indexterm" name="id26239 10"></a>773 <a class="indexterm" name="id2623938"></a> 774 774 Using your favorite editor create the following <code class="filename">config.cfg</code> 775 775 LAM configuration file: … … 779 779 <code class="prompt">root# </code> vi config.cfg 780 780 </pre><p> 781 <a class="indexterm" name="id26239 51"></a>782 <a class="indexterm" name="id26239 60"></a>781 <a class="indexterm" name="id2623979"></a> 782 <a class="indexterm" name="id2623988"></a> 783 783 An example file is shown in <a class="link" href="appendix.html#lamcfg" title="Example 15.11. Example LAM Configuration File config.cfg">“Example LAM Configuration File config.cfg”</a>. 784 784 This is the minimum configuration that must be completed. The LAM profile … … 795 795 change the settings to match local site needs. 796 796 </p></li></ol></div><p> 797 <a class="indexterm" name="id26240 19"></a>797 <a class="indexterm" name="id2624048"></a> 798 798 An example of a working file is shown here in <a class="link" href="appendix.html#lamconf" title="Example 15.12. LAM Profile Control File lam.conf">“LAM Profile Control File lam.conf”</a>. 799 799 This file has been stripped of comments to keep the size small. The comments … … 803 803 are preferred at your site. 804 804 </p><p> 805 <a class="indexterm" name="id26240 43"></a>805 <a class="indexterm" name="id2624071"></a> 806 806 It is important that your LDAP server is running at the time that LAM is 807 807 being configured. This permits you to validate correct operation. 808 808 An example of the LAM login screen is provided in <a class="link" href="appendix.html#lam-login" title="Figure 15.6. The LDAP Account Manager Login Screen">“The LDAP Account Manager Login Screen”</a>. 809 809 </p><div class="figure"><a name="lam-login"></a><p class="title"><b>Figure 15.6. The LDAP Account Manager Login Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-login.png" width="270" alt="The LDAP Account Manager Login Screen"></div></div></div><br class="figure-break"><p> 810 <a class="indexterm" name="id26241 05"></a>810 <a class="indexterm" name="id2624134"></a> 811 811 The LAM configuration editor has a number of options that must be managed correctly. 812 812 An example of use of the LAM configuration editor is shown in <a class="link" href="appendix.html#lam-config" title="Figure 15.7. The LDAP Account Manager Configuration Screen">“The LDAP Account Manager Configuration Screen”</a>. … … 818 818 using LAM to add additional users and groups. 819 819 </p><div class="figure"><a name="lam-config"></a><p class="title"><b>Figure 15.7. The LDAP Account Manager Configuration Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-config.png" width="270" alt="The LDAP Account Manager Configuration Screen"></div></div></div><br class="figure-break"><p> 820 <a class="indexterm" name="id2624 177"></a>820 <a class="indexterm" name="id2624205"></a> 821 821 LAM has some nice, but unusual features. For example, one unexpected feature in most application 822 822 screens permits the generation of a PDF file that lists configuration information. This is a well … … 824 824 space. 825 825 </p><p> 826 <a class="indexterm" name="id2624 192"></a>826 <a class="indexterm" name="id2624220"></a> 827 827 When you log onto LAM the opening screen drops you right into the user manager as shown in 828 828 <a class="link" href="appendix.html#lam-user" title="Figure 15.8. The LDAP Account Manager User Edit Screen">“The LDAP Account Manager User Edit Screen”</a>. This is a logical action as it permits the most-needed facility … … 838 838 memberships. 839 839 </p><div class="figure"><a name="lam-group"></a><p class="title"><b>Figure 15.9. The LDAP Account Manager Group Edit Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-groups.png" width="270" alt="The LDAP Account Manager Group Edit Screen"></div></div></div><br class="figure-break"><div class="figure"><a name="lam-group-mem"></a><p class="title"><b>Figure 15.10. The LDAP Account Manager Group Membership Edit Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-group-members.png" width="270" alt="The LDAP Account Manager Group Membership Edit Screen"></div></div></div><br class="figure-break"><p> 840 <a class="indexterm" name="id2624 372"></a><a class="indexterm" name="id2624377"></a>840 <a class="indexterm" name="id2624400"></a><a class="indexterm" name="id2624406"></a> 841 841 The final screen presented here is one that you should not normally need to use. Host accounts will 842 842 be automatically managed using the smbldap-tools scripts. This means that the screen <a class="link" href="appendix.html#lam-host" title="Figure 15.11. The LDAP Account Manager Host Edit Screen">“The LDAP Account Manager Host Edit Screen”</a> … … 884 884 cachetimeout: 5 885 885 pwdhash: SSHA 886 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26245 29"></a>IDEALX Management Console</h2></div></div></div><p>886 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2624558"></a>IDEALX Management Console</h2></div></div></div><p> 887 887 IMC (the IDEALX Mamagement Console) is a tool that can be used as the basis for a comprehensive 888 888 web-based management interface for UNIX and Linux systems. … … 898 898 For further information regarding IMC refer to the web <a class="ulink" href="http://imc.sourceforge.net/" target="_top">site.</a> 899 899 Prebuilt RPM packages are also <a class="ulink" href="http://imc.sourceforge.net/download.html" target="_top">available.</a> 900 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12-SUIDSGID"></a>Effect of Setting File and Directory SUID/SGID Permissions Explained</h2></div></div></div><a class="indexterm" name="id26246 35"></a><a class="indexterm" name="id2624642"></a><p>900 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12-SUIDSGID"></a>Effect of Setting File and Directory SUID/SGID Permissions Explained</h2></div></div></div><a class="indexterm" name="id2624663"></a><a class="indexterm" name="id2624670"></a><p> 901 901 The setting of the SUID/SGID bits on the file or directory permissions flag has particular 902 902 consequences. If the file is executable and the SUID bit is set, it executes with the privilege … … 968 968 drw-rw-r-- 2 bobj Domain Users 12346 Dec 18 18:11 maryvfile.txt 969 969 </pre><p> 970 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12dblck"></a>Shared Data Integrity</h2></div></div></div><p><a class="indexterm" name="id2624 873"></a><a class="indexterm" name="id2624880"></a>970 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12dblck"></a>Shared Data Integrity</h2></div></div></div><p><a class="indexterm" name="id2624901"></a><a class="indexterm" name="id2624909"></a> 971 971 The integrity of shared data is often viewed as a particularly emotional issue, especially where 972 972 there are concurrent problems with multiuser data access. Contrary to the assertions of some who have … … 974 974 </p><p> 975 975 The solution to concurrent multiuser data access problems must consider three separate areas 976 from which the problem may stem:<a class="indexterm" name="id26249 09"></a><a class="indexterm" name="id2624920"></a><a class="indexterm" name="id2624932"></a>977 </p><div class="itemizedlist"><ul type="disc"><li><p>application-level locking controls</p></li><li><p>client-side locking controls</p></li><li><p>server-side locking controls</p></li></ul></div><p><a class="indexterm" name="id26249 64"></a><a class="indexterm" name="id2624972"></a>976 from which the problem may stem:<a class="indexterm" name="id2624932"></a><a class="indexterm" name="id2624943"></a><a class="indexterm" name="id2624955"></a> 977 </p><div class="itemizedlist"><ul type="disc"><li><p>application-level locking controls</p></li><li><p>client-side locking controls</p></li><li><p>server-side locking controls</p></li></ul></div><p><a class="indexterm" name="id2624987"></a><a class="indexterm" name="id2624995"></a> 978 978 Many database applications use some form of application-level access control. An example of one 979 979 well-known application that uses application-level locking is Microsoft Access. Detailed guidance 980 980 is provided here because this is the most common application for which problems have been reported. 981 </p><p><a class="indexterm" name="id262 4988"></a><a class="indexterm" name="id2624996"></a>981 </p><p><a class="indexterm" name="id2625012"></a><a class="indexterm" name="id2625020"></a> 982 982 Common applications that are affected by client- and server-side locking controls include MS 983 983 Excel and Act!. Important locking guidance is provided here. 984 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26250 09"></a>Microsoft Access</h3></div></div></div><p>984 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625032"></a>Microsoft Access</h3></div></div></div><p> 985 985 The best advice that can be given is to carefully read the Microsoft knowledgebase articles that 986 986 cover this area. Examples of relevant documents include: 987 </p><div class="itemizedlist"><ul type="disc"><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;208778</p></li><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;299373</p></li></ul></div><p><a class="indexterm" name="id26250 36"></a><a class="indexterm" name="id2625048"></a>987 </p><div class="itemizedlist"><ul type="disc"><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;208778</p></li><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;299373</p></li></ul></div><p><a class="indexterm" name="id2625059"></a><a class="indexterm" name="id2625071"></a> 988 988 Make sure that your MS Access database file is configured for multiuser access (not set for 989 989 exclusive open). Open MS Access on each client workstation, then set the following: <span class="guimenu">(Menu bar) Tools</span>+<span class="guimenu">Options</span>+<span class="guimenu">[tab] General</span>. Set network path to Default database folder: <code class="filename">\\server\share\folder</code>. 990 990 </p><p> 991 991 You can configure MS Access file sharing behavior as follows: click <span class="guimenu">[tab] Advanced</span>. 992 Set:<a class="indexterm" name="id2625 098"></a>993 </p><div class="itemizedlist"><ul type="disc"><li><p>Default open mode: Shared</p></li><li><p>Default Record Locking: Edited Record</p></li><li><p>Open databases using record_level locking</p></li></ul></div><p><a class="indexterm" name="id26251 28"></a>992 Set:<a class="indexterm" name="id2625122"></a> 993 </p><div class="itemizedlist"><ul type="disc"><li><p>Default open mode: Shared</p></li><li><p>Default Record Locking: Edited Record</p></li><li><p>Open databases using record_level locking</p></li></ul></div><p><a class="indexterm" name="id2625151"></a> 994 994 You must now commit the changes so that they will take effect. To do so, click 995 995 <span class="guimenu">Apply</span><span class="guimenu">Ok</span>. At this point, you should exit MS Access, restart 996 996 it, and then validate that these settings have not changed. 997 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26251 56"></a>Act! Database Sharing</h3></div></div></div><p><a class="indexterm" name="id2625163"></a><a class="indexterm" name="id2625171"></a>997 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625180"></a>Act! Database Sharing</h3></div></div></div><p><a class="indexterm" name="id2625186"></a><a class="indexterm" name="id2625194"></a> 998 998 Where the server sharing the ACT! database(s) is running Samba,or Windows NT, 200x, or XP, you 999 999 must disable opportunistic locking on the server and all workstations. Failure to do so … … 1003 1003 as well as from article 1004 1004 <a class="ulink" href="http://itdomino.saleslogix.com/act.nsf/docid/200110485036" target="_top">200110485036</a>. 1005 </p><p><a class="indexterm" name="id26252 01"></a><a class="indexterm" name="id2625210"></a>1005 </p><p><a class="indexterm" name="id2625225"></a><a class="indexterm" name="id2625233"></a> 1006 1006 These documents clearly state that opportunistic locking must be disabled on both 1007 1007 the server (Samba in the case we are interested in here), as well as on every workstation … … 1011 1011 Registered Act! users may download this utility from the Act! Web 1012 1012 <a class="ulink" href="http://www.act.com/support/updates/index.cfm" target="_top">site.</a> 1013 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26252 41"></a>Opportunistic Locking Controls</h3></div></div></div><p><a class="indexterm" name="id2625248"></a>1013 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625264"></a>Opportunistic Locking Controls</h3></div></div></div><p><a class="indexterm" name="id2625271"></a> 1014 1014 Third-party Windows applications may not be compatible with the use of opportunistic file 1015 and record locking. For applications that are known not to be compatible,<sup>[<a name="id26252 60" href="#ftn.id2625260" class="footnote">14</a>]</sup> oplock1015 and record locking. For applications that are known not to be compatible,<sup>[<a name="id2625283" href="#ftn.id2625283" class="footnote">14</a>]</sup> oplock 1016 1016 support may need to be disabled both on the Samba server and on the Windows workstations. 1017 </p><p><a class="indexterm" name="id26252 74"></a><a class="indexterm" name="id2625282"></a><a class="indexterm" name="id2625290"></a>1017 </p><p><a class="indexterm" name="id2625297"></a><a class="indexterm" name="id2625305"></a><a class="indexterm" name="id2625313"></a> 1018 1018 Oplocks enable a Windows client to cache parts of a file that are being 1019 1019 edited. Another windows client may then request to open the file with the … … 1022 1022 doing so, that workstation must flush the file from cache memory to the 1023 1023 disk or network drive. 1024 </p><p><a class="indexterm" name="id26253 11"></a>1024 </p><p><a class="indexterm" name="id2625334"></a> 1025 1025 Disabling of Oplocks usage may require server and client changes. 1026 1026 Oplocks may be disabled by file, by file pattern, on the share, or on the -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/ch14.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 14. Samba Support</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"><link rel="next" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 14. Samba Support</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="HA.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="appendix.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en-US"><div class="titlepage"><div><div><h2 class="title"><a name="id26208 71"></a>Chapter 14. Samba Support</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></div><p>2 <a class="indexterm" name="id2620 880"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 14. Samba Support</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"><link rel="next" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 14. Samba Support</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="HA.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="appendix.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en-US"><div class="titlepage"><div><div><h2 class="title"><a name="id2620898"></a>Chapter 14. Samba Support</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></div><p> 2 <a class="indexterm" name="id2620907"></a> 3 3 One of the most difficult to answer questions in the information technology industry is, “<span class="quote">What is 4 4 support?</span>”. That question irritates some folks, as much as common answers may annoy others. 5 5 </p><p> 6 <a class="indexterm" name="id2620 897"></a>6 <a class="indexterm" name="id2620924"></a> 7 7 The most aggravating situation pertaining to support is typified when, as a Linux user, a call is made to 8 8 an Internet service provider who, instead of listening to the problem to find a solution, blandly replies: … … 16 16 inconvenience, loss of productivity, disorientation, uncertainty, and real or perceived risk. 17 17 </p><p> 18 <a class="indexterm" name="id26209 28"></a>19 <a class="indexterm" name="id26209 35"></a>20 <a class="indexterm" name="id26209 42"></a>18 <a class="indexterm" name="id2620954"></a> 19 <a class="indexterm" name="id2620961"></a> 20 <a class="indexterm" name="id2620968"></a> 21 21 One of the forces that has become a driving force for the adoption of open source software is the fact that 22 22 many IT businesses have provided services that have perhaps failed to deliver what the customer expected, or 23 23 that have been found wanting for other reasons. 24 24 </p><p> 25 <a class="indexterm" name="id26209 56"></a>26 <a class="indexterm" name="id26209 63"></a>25 <a class="indexterm" name="id2620983"></a> 26 <a class="indexterm" name="id2620990"></a> 27 27 In recognition of the need for needs satisfaction as the primary experience an information technology user or 28 28 consumer expects, the information provided in this chapter may help someone to avoid an unpleasant experience 29 29 in respect of problem resolution. 30 30 </p><p> 31 <a class="indexterm" name="id262 0978"></a>32 <a class="indexterm" name="id262 0985"></a>33 <a class="indexterm" name="id262 0992"></a>31 <a class="indexterm" name="id2621004"></a> 32 <a class="indexterm" name="id2621011"></a> 33 <a class="indexterm" name="id2621018"></a> 34 34 In the open source software arena there are two support options: free support and paid-for (commercial) 35 35 support. 36 </p><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26210 02"></a>Free Support</h2></div></div></div><p>37 <a class="indexterm" name="id26210 09"></a>38 <a class="indexterm" name="id26210 16"></a>39 <a class="indexterm" name="id26210 23"></a>40 <a class="indexterm" name="id26210 30"></a>41 <a class="indexterm" name="id26210 37"></a>42 <a class="indexterm" name="id26210 44"></a>36 </p><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621028"></a>Free Support</h2></div></div></div><p> 37 <a class="indexterm" name="id2621036"></a> 38 <a class="indexterm" name="id2621043"></a> 39 <a class="indexterm" name="id2621050"></a> 40 <a class="indexterm" name="id2621057"></a> 41 <a class="indexterm" name="id2621064"></a> 42 <a class="indexterm" name="id2621071"></a> 43 43 Free support may be obtained from friends, colleagues, user groups, mailing lists, and interactive help 44 44 facilities. An example of an interactive dacility is the Internet relay chat (IRC) channels that host user 45 45 supported mutual assistance. 46 46 </p><p> 47 <a class="indexterm" name="id26210 58"></a>48 <a class="indexterm" name="id26210 65"></a>49 <a class="indexterm" name="id26210 72"></a>50 <a class="indexterm" name="id2621 079"></a>51 <a class="indexterm" name="id2621 086"></a>47 <a class="indexterm" name="id2621085"></a> 48 <a class="indexterm" name="id2621092"></a> 49 <a class="indexterm" name="id2621099"></a> 50 <a class="indexterm" name="id2621106"></a> 51 <a class="indexterm" name="id2621112"></a> 52 52 The Samba project maintains a mailing list that is commonly used to discuss solutions to Samba deployments. 53 53 Information regarding subscription to the Samba mailing list can be found on the Samba <a class="ulink" href="https://lists.samba.org/mailman/" target="_top">web</a> site. The public mailing list that can be used to obtain … … 56 56 the Samba <a class="ulink" href="http://www.samba.org/samba.irc.html" target="_top">IRC</a> web page. 57 57 </p><p> 58 <a class="indexterm" name="id26211 27"></a>59 <a class="indexterm" name="id26211 34"></a>60 <a class="indexterm" name="id26211 41"></a>61 <a class="indexterm" name="id26211 48"></a>58 <a class="indexterm" name="id2621154"></a> 59 <a class="indexterm" name="id2621161"></a> 60 <a class="indexterm" name="id2621168"></a> 61 <a class="indexterm" name="id2621175"></a> 62 62 As a general rule, it is considered poor net behavior to contact a Samba Team member directly 63 63 for free support. Most active members of the Samba Team work exceptionally long hours to assist … … 67 67 to show appropriate discretion and reservation in all direct contact. 68 68 </p><p> 69 <a class="indexterm" name="id26211 68"></a>70 <a class="indexterm" name="id2621 174"></a>71 <a class="indexterm" name="id2621 181"></a>69 <a class="indexterm" name="id2621194"></a> 70 <a class="indexterm" name="id2621201"></a> 71 <a class="indexterm" name="id2621208"></a> 72 72 When you stumble across a Samba bug, often the quickest way to get it resolved is by posting 73 73 a bug <a class="ulink" href="https://bugzilla.samba.org/" target="_top">report</a>. All such reports are mailed to … … 77 77 that will permit the problem to be reproduced. 78 78 </p><p> 79 <a class="indexterm" name="id26212 06"></a>79 <a class="indexterm" name="id2621232"></a> 80 80 We all recognize that sometimes free support does not provide the answer that is sought within 81 81 the time-frame required. At other times the problem is elusive and you may lack the experience 82 82 necessary to isolate the problem and thus to resolve it. This is a situation where is may be 83 83 prudent to purchase paid-for support. 84 </p></div><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26212 20"></a>Commercial Support</h2></div></div></div><p>84 </p></div><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621247"></a>Commercial Support</h2></div></div></div><p> 85 85 There are six basic support oriented services that are most commonly sought by Samba sites: 86 86 </p><div class="itemizedlist"><ul type="disc"><li><p>Assistance with network design</p></li><li><p>Staff Training</p></li><li><p>Assistance with Samba network deployment and installation</p></li><li><p>Priority telephone or email Samba configuration assistance</p></li><li><p>Trouble-shooting and diagnostic assistance</p></li><li><p>Provision of quality assured ready-to-install Samba binary packages</p></li></ul></div><p> 87 <a class="indexterm" name="id26212 67"></a>88 <a class="indexterm" name="id2621 274"></a>87 <a class="indexterm" name="id2621294"></a> 88 <a class="indexterm" name="id2621301"></a> 89 89 Information regarding companies that provide professional Samba support can be obtained by performing a Google 90 90 search, as well as by reference to the Samba <a class="ulink" href="http://www.samba.org/samba/support.html" target="_top">Support</a> web page. Companies who notify the Samba Team … … 94 94 them. 95 95 </p><p> 96 <a class="indexterm" name="id26213 00"></a>96 <a class="indexterm" name="id2621326"></a> 97 97 The policy within the Samba Team is to treat all commercial support providers equally and to show no 98 98 preference. As a result, Samba Team members who provide commercial support are lumped in with everyone else. … … 100 100 is pro-community; so do what you can to help a local business to prosper. 101 101 </p><p> 102 <a class="indexterm" name="id26213 17"></a>102 <a class="indexterm" name="id2621343"></a> 103 103 Open source software support can be found in any quality, at any price and in any place you can 104 104 to obtain it. Over 180 companies around the world provide Samba support, there is no excuse for -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/go01.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Glossary</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="apa.html" title="Appendix A. GNU General Public License version 3"><link rel="next" href="ix01.html" title="Index"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Glossary</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="apa.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="ix01.html">Next</a></td></tr></table><hr></div><div class="glossary"><div class="titlepage"><div><div><h2 class="title"><a name="id26303 57"></a>Glossary</h2></div></div></div><dl><dt>Access Control List</dt><dd><p>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Glossary</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="apa.html" title="Appendix A. GNU General Public License version 3"><link rel="next" href="ix01.html" title="Index"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Glossary</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="apa.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="ix01.html">Next</a></td></tr></table><hr></div><div class="glossary"><div class="titlepage"><div><div><h2 class="title"><a name="id2630385"></a>Glossary</h2></div></div></div><dl><dt>Access Control List</dt><dd><p> 2 2 A detailed list of permissions granted to users or groups with respect to file and network 3 3 resource access. -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/index.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Samba-3 by Example</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="next" href="pr01.html" title="About the Cover Artwork"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Samba-3 by Example</th></tr><tr><td width="20%" align="left"> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr></table><hr></div><div class="book" lang="en"><div class="titlepage"><div><div><h1 class="title"><a name="S3bE"></a>Samba-3 by Example</h1></div><div><h2 class="subtitle">Practical Exercises in Successful Samba Deployment</h2></div><div><div class="authorgroup"><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div></div><div><p class="pubdate">July, 2006</p></div></div><hr></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="preface"><a href="pr01.html">About the Cover Artwork</a></span></dt><dt><span class="preface"><a href="pr02.html">Acknowledgments</a></span></dt><dt><span class="preface"><a href="pr03.html">Foreword</a></span></dt><dd><dl><dt><span class="sect1"><a href="pr03.html#id2501076">By John M. Weathersby, Executive Director, OSSI</a></span></dt></dl></dd><dt><span class="preface"><a href="preface.html">Preface</a></span></dt><dd><dl><dt><span class="sect1"><a href="preface.html#id2501265">Why Is This Book Necessary?</a></span></dt><dd><dl><dt><span class="sect2"><a href="preface.html#id2498988">Samba 3.0.20 Update Edition</a></span></dt></dl></dd><dt><span class="sect1"><a href="preface.html#id2498874">Prerequisites</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498906">Approach</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498971">Summary of Topics</a></span></dt><dt><span class="sect1"><a href="preface.html#id2550668">Conventions Used</a></span></dt></dl></dd><dt><span class="part"><a href="ExNetworks.html">I. Example Network Configurations</a></span></dt><dd><dl><dt><span class="chapter"><a href="simple.html">1. No-Frills Samba Servers</a></span></dt><dd><dl><dt><span class="sect1"><a href="simple.html#id2550864">Introduction</a></span></dt><dt><span class="sect1"><a href="simple.html#id2550904">Assignment Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="simple.html#id2550946">Drafting Office</a></span></dt><dt><span class="sect2"><a href="simple.html#id2551655">Charity Administration Office</a></span></dt><dt><span class="sect2"><a href="simple.html#AccountingOffice">Accounting Office</a></span></dt></dl></dd><dt><span class="sect1"><a href="simple.html#id2554992">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="small.html">2. Small Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="small.html#id2555462">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555484">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555545">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555593">Technical Issues</a></span></dt><dt><span class="sect2"><a href="small.html#id2555791">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555812">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2557356">Validation</a></span></dt><dt><span class="sect2"><a href="small.html#id2558004">Notebook Computers: A Special Case</a></span></dt><dt><span class="sect2"><a href="small.html#id2558030">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2558104">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="secure.html">3. Secure Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="secure.html#id2558582">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558634">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2558867">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="secure.html#id2559309">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2559348">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#ch4bsc">Basic System Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2560202">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4ptrcfg">Printer Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4valid">Validation</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4appscfg">Application Share Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2564663">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2564725">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="Big500users.html">4. The 500-User Office</a></span></dt><dd><dl><dt><span class="sect1"><a href="Big500users.html#id2565247">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565292">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565398">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565433">Technical Issues</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2565636">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565659">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#ch5-dnshcp-setup">Installation of DHCP, DNS, and Samba Control Files</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566387">Server Preparation: All Servers</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566951">Server-Specific Preparation</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5-procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2570151">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2570210">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="happy.html">5. Making Happy Users</a></span></dt><dd><dl><dt><span class="sect1"><a href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></span></dt><dt><span class="sect1"><a href="happy.html#id2571190">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571288">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2571425">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573760">Political Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573776">Installation Checklist</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2573956">Samba Server Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-ptrcfg">Printer Configuration</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a></span></dt><dt><span class="sect1"><a href="happy.html#id2580803">Miscellaneous Server Preparation Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2580823">Configuring Directory Share Point Roots</a></span></dt><dt><span class="sect2"><a href="happy.html#id2580918">Configuring Profile Directories</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581163">Preparation of Logon Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581274">Assigning User Rights and Privileges</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2581407">Windows Client Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583160">Software Installation</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583195">Roll-out Image Creation</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2583229">Key Points Learned</a></span></dt><dt><span class="sect1"><a href="happy.html#id2583345">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="2000users.html">6. A Distributed 2000-User Network</a></span></dt><dd><dl><dt><span class="sect1"><a href="2000users.html#id2583767">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2583797">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2583865">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2584139">Technical Issues</a></span></dt><dt><span class="sect2"><a href="2000users.html#id2585083">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2585101">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2588260">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2588407">Questions and Answers</a></span></dt></dl></dd></dl></dd><dt><span class="part"><a href="DMSMig.html">II. Domain Members, Updating Samba and Migration</a></span></dt><dd><dl><dt><span class="chapter"><a href="unixclients.html">7. Adding Domain Member Servers and Clients</a></span></dt><dd><dl><dt><span class="sect1"><a href="unixclients.html#id2589266">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589319">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2589354">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589383">Technical Issues</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2590032">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2590132">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></span></dt><dt><span class="sect2"><a href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></span></dt><dt><span class="sect2"><a href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a></span></dt><dt><span class="sect2"><a href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596913">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2596967">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="upgrades.html">8. Updating Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="upgrades.html#id2598126">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2598223">Cautions and Notes</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2599552">Upgrading from Samba 1.x and 2.x to Samba-3</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2600546">Samba-3 to Samba-3 Updates on the Same Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600749">Migrating Samba-3 to a New Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="ntmigration.html">9. Migrating NT4 Domain to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="ntmigration.html#id2601336">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601421">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2601476">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601662">Technical Issues</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2601985">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2602011">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2605017">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2605055">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="nw4migration.html">10. Migrating NetWare Server to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="nw4migration.html#id2606030">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606147">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606260">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606337">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606527">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606536">NetWare Migration Using LDAP Backend</a></span></dt></dl></dd></dl></dd></dl></dd><dt><span class="part"><a href="RefSection.html">III. Reference Section</a></span></dt><dd><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id26146 72">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616162">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618932">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621928">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625407">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Samba-3 by Example</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="next" href="pr01.html" title="About the Cover Artwork"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Samba-3 by Example</th></tr><tr><td width="20%" align="left"> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr></table><hr></div><div class="book" lang="en"><div class="titlepage"><div><div><h1 class="title"><a name="S3bE"></a>Samba-3 by Example</h1></div><div><h2 class="subtitle">Practical Exercises in Successful Samba Deployment</h2></div><div><div class="authorgroup"><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div></div><div><p class="pubdate">July, 2006</p></div></div><hr></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="preface"><a href="pr01.html">About the Cover Artwork</a></span></dt><dt><span class="preface"><a href="pr02.html">Acknowledgments</a></span></dt><dt><span class="preface"><a href="pr03.html">Foreword</a></span></dt><dd><dl><dt><span class="sect1"><a href="pr03.html#id2501076">By John M. Weathersby, Executive Director, OSSI</a></span></dt></dl></dd><dt><span class="preface"><a href="preface.html">Preface</a></span></dt><dd><dl><dt><span class="sect1"><a href="preface.html#id2501265">Why Is This Book Necessary?</a></span></dt><dd><dl><dt><span class="sect2"><a href="preface.html#id2498988">Samba 3.0.20 Update Edition</a></span></dt></dl></dd><dt><span class="sect1"><a href="preface.html#id2498874">Prerequisites</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498906">Approach</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498971">Summary of Topics</a></span></dt><dt><span class="sect1"><a href="preface.html#id2550668">Conventions Used</a></span></dt></dl></dd><dt><span class="part"><a href="ExNetworks.html">I. Example Network Configurations</a></span></dt><dd><dl><dt><span class="chapter"><a href="simple.html">1. No-Frills Samba Servers</a></span></dt><dd><dl><dt><span class="sect1"><a href="simple.html#id2550864">Introduction</a></span></dt><dt><span class="sect1"><a href="simple.html#id2550904">Assignment Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="simple.html#id2550946">Drafting Office</a></span></dt><dt><span class="sect2"><a href="simple.html#id2551655">Charity Administration Office</a></span></dt><dt><span class="sect2"><a href="simple.html#AccountingOffice">Accounting Office</a></span></dt></dl></dd><dt><span class="sect1"><a href="simple.html#id2554992">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="small.html">2. Small Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="small.html#id2555462">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555484">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555545">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555593">Technical Issues</a></span></dt><dt><span class="sect2"><a href="small.html#id2555791">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555812">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2557356">Validation</a></span></dt><dt><span class="sect2"><a href="small.html#id2558004">Notebook Computers: A Special Case</a></span></dt><dt><span class="sect2"><a href="small.html#id2558030">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2558104">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="secure.html">3. Secure Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="secure.html#id2558582">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558634">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2558867">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="secure.html#id2559309">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2559348">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#ch4bsc">Basic System Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2560202">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4ptrcfg">Printer Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4valid">Validation</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4appscfg">Application Share Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2564663">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2564725">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="Big500users.html">4. The 500-User Office</a></span></dt><dd><dl><dt><span class="sect1"><a href="Big500users.html#id2565247">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565292">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565398">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565433">Technical Issues</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2565636">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565659">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#ch5-dnshcp-setup">Installation of DHCP, DNS, and Samba Control Files</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566387">Server Preparation: All Servers</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566951">Server-Specific Preparation</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5-procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2570151">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2570210">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="happy.html">5. Making Happy Users</a></span></dt><dd><dl><dt><span class="sect1"><a href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></span></dt><dt><span class="sect1"><a href="happy.html#id2571190">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571288">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2571425">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573760">Political Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573776">Installation Checklist</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2573956">Samba Server Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-ptrcfg">Printer Configuration</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a></span></dt><dt><span class="sect1"><a href="happy.html#id2580803">Miscellaneous Server Preparation Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2580823">Configuring Directory Share Point Roots</a></span></dt><dt><span class="sect2"><a href="happy.html#id2580918">Configuring Profile Directories</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581163">Preparation of Logon Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581274">Assigning User Rights and Privileges</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2581407">Windows Client Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583160">Software Installation</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583195">Roll-out Image Creation</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2583229">Key Points Learned</a></span></dt><dt><span class="sect1"><a href="happy.html#id2583345">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="2000users.html">6. A Distributed 2000-User Network</a></span></dt><dd><dl><dt><span class="sect1"><a href="2000users.html#id2583767">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2583797">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2583865">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2584139">Technical Issues</a></span></dt><dt><span class="sect2"><a href="2000users.html#id2585083">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2585101">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2588260">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2588407">Questions and Answers</a></span></dt></dl></dd></dl></dd><dt><span class="part"><a href="DMSMig.html">II. Domain Members, Updating Samba and Migration</a></span></dt><dd><dl><dt><span class="chapter"><a href="unixclients.html">7. Adding Domain Member Servers and Clients</a></span></dt><dd><dl><dt><span class="sect1"><a href="unixclients.html#id2589266">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589319">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2589354">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589383">Technical Issues</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2590032">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2590132">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></span></dt><dt><span class="sect2"><a href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></span></dt><dt><span class="sect2"><a href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a></span></dt><dt><span class="sect2"><a href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596913">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2596967">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="upgrades.html">8. Updating Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="upgrades.html#id2598126">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2598223">Cautions and Notes</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2599552">Upgrading from Samba 1.x and 2.x to Samba-3</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2600546">Samba-3 to Samba-3 Updates on the Same Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600749">Migrating Samba-3 to a New Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="ntmigration.html">9. Migrating NT4 Domain to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="ntmigration.html#id2601336">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601421">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2601476">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601662">Technical Issues</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2601985">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2602011">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2605017">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2605055">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="nw4migration.html">10. Migrating NetWare Server to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="nw4migration.html#id2606030">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606147">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606260">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606337">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606527">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606536">NetWare Migration Using LDAP Backend</a></span></dt></dl></dd></dl></dd></dl></dd><dt><span class="part"><a href="RefSection.html">III. Reference Section</a></span></dt><dd><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A. 2 2 GNU General Public License version 3 3 </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id26288 70">A.3 </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A. 4 4 Preamble 5 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 15">A.5 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A. 6 6 TERMS AND CONDITIONS 7 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26290 19">A.7 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A. 8 8 0. Definitions. 9 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26291 11">A.9 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A. 10 10 1. Source Code. 11 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 10">A.11 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A. 12 12 2. Basic Permissions. 13 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26292 49">A.13 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A. 14 14 3. Protecting Users’ Legal Rights From Anti-Circumvention Law. 15 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 290">A.15 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A. 16 16 4. Conveying Verbatim Copies. 17 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26293 17">A.17 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A. 18 18 5. Conveying Modified Source Versions. 19 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26294 12">A.19 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A. 20 20 6. Conveying Non-Source Forms. 21 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26296 02">A.21 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A. 22 22 7. Additional Terms. 23 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26297 38">A.23 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A. 24 24 8. Termination. 25 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629 781">A.25 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A. 26 26 9. Acceptance Not Required for Having Copies. 27 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 01">A.27 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A. 28 28 10. Automatic Licensing of Downstream Recipients. 29 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26298 53">A.29 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A. 30 30 11. Patents. 31 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26 29988">A.31 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A. 32 32 12. No Surrender of Others’ Freedom. 33 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 10">A.33 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A. 34 34 13. Use with the ???TITLE??? Affero General Public License. 35 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26300 39">A.35 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A. 36 36 14. Revised Versions of this License. 37 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 01">A.37 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A. 38 38 15. Disclaimer of Warranty. 39 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 28">A.39 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A. 40 40 16. Limitation of Liability. 41 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 48">A.41 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A. 42 42 17. Interpretation of Sections 15 and 16. 43 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 64">A.43 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A. 44 44 END OF TERMS AND CONDITIONS 45 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id26301 68">A.45 </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A. 46 46 How to Apply These Terms to Your New Programs 47 47 </a></span></dt></dl></dd></dl></dd><dt><span class="glossary"><a href="go01.html">Glossary</a></span></dt><dt><span class="index"><a href="ix01.html">Index</a></span></dt></dl></div><div class="list-of-figures"><p><b>List of Figures</b></p><dl><dt>1.1. <a href="simple.html#charitynet">Charity Administration Office Network</a></dt><dt>1.2. <a href="simple.html#acctingnet2">Accounting Office Network Topology</a></dt><dt>2.1. <a href="small.html#acct2net">Abmas Accounting 52-User Network Topology</a></dt><dt>3.1. <a href="secure.html#ch04net">Abmas Network Topology 130 Users</a></dt><dt>4.1. <a href="Big500users.html#chap05net">Network Topology 500 User Network Using tdbsam passdb backend.</a></dt><dt>5.1. <a href="happy.html#sbehap-LDAPdiag">The Interaction of LDAP, UNIX Posix Accounts and Samba Accounts</a></dt><dt>5.2. <a href="happy.html#chap6net">Network Topology 500 User Network Using ldapsam passdb backend</a></dt><dt>5.3. <a href="happy.html#XP-screen001">Windows XP Professional User Shared Folders</a></dt><dt>6.1. <a href="2000users.html#chap7idres">Samba and Authentication Backend Search Pathways</a></dt><dt>6.2. <a href="2000users.html#ch7singleLDAP">Samba Configuration to Use a Single LDAP Server</a></dt><dt>6.3. <a href="2000users.html#ch7dualLDAP">Samba Configuration to Use a Dual (Fail-over) LDAP Server</a></dt><dt>6.4. <a href="2000users.html#ch7dualadd">Samba Configuration to Use Dual LDAP Databases - Broken - Do Not Use!</a></dt><dt>6.5. <a href="2000users.html#ch7dualok">Samba Configuration to Use Two LDAP Databases - The result is additive.</a></dt><dt>6.6. <a href="2000users.html#chap7net">Network Topology 2000 User Complex Design A</a></dt><dt>6.7. <a href="2000users.html#chap7net2">Network Topology 2000 User Complex Design B</a></dt><dt>7.1. <a href="unixclients.html#ch09openmag">Open Magazine Samba Survey</a></dt><dt>7.2. <a href="unixclients.html#ch9-sambadc">Samba Domain: Samba Member Server</a></dt><dt>7.3. <a href="unixclients.html#ch9-adsdc">Active Directory Domain: Samba Member Server</a></dt><dt>9.1. <a href="ntmigration.html#ch8-migration">Schematic Explaining the net rpc vampire Process</a></dt><dt>9.2. <a href="ntmigration.html#NT4DUM">View of Accounts in NT4 Domain User Manager</a></dt><dt>15.1. <a href="appendix.html#swxpp001">The General Panel.</a></dt><dt>15.2. <a href="appendix.html#swxpp004">The Computer Name Panel.</a></dt><dt>15.3. <a href="appendix.html#swxpp006">The Computer Name Changes Panel</a></dt><dt>15.4. <a href="appendix.html#swxpp007">The Computer Name Changes Panel Domain MIDEARTH</a></dt><dt>15.5. <a href="appendix.html#swxpp008">Computer Name Changes User name and Password Panel</a></dt><dt>15.6. <a href="appendix.html#lam-login">The LDAP Account Manager Login Screen</a></dt><dt>15.7. <a href="appendix.html#lam-config">The LDAP Account Manager Configuration Screen</a></dt><dt>15.8. <a href="appendix.html#lam-user">The LDAP Account Manager User Edit Screen</a></dt><dt>15.9. <a href="appendix.html#lam-group">The LDAP Account Manager Group Edit Screen</a></dt><dt>15.10. <a href="appendix.html#lam-group-mem">The LDAP Account Manager Group Membership Edit Screen</a></dt><dt>15.11. <a href="appendix.html#lam-host">The LDAP Account Manager Host Edit Screen</a></dt><dt>15.12. <a href="appendix.html#imcidealx">The IMC Samba User Account Screen</a></dt><dt>16.1. <a href="primer.html#pktcap01">Windows Me Broadcasts The First 10 Minutes</a></dt><dt>16.2. <a href="primer.html#pktcap02">Windows Me Later Broadcast Sample</a></dt><dt>16.3. <a href="primer.html#hostannounce">Typical Windows 9x/Me Host Announcement</a></dt><dt>16.4. <a href="primer.html#nullconnect">Typical Windows 9x/Me NULL SessionSetUp AndX Request</a></dt><dt>16.5. <a href="primer.html#userconnect">Typical Windows 9x/Me User SessionSetUp AndX Request</a></dt><dt>16.6. <a href="primer.html#XPCap01">Typical Windows XP NULL Session Setup AndX Request</a></dt><dt>16.7. <a href="primer.html#XPCap02">Typical Windows XP User Session Setup AndX Request</a></dt></dl></div><div class="list-of-tables"><p><b>List of Tables</b></p><dl><dt>1. <a href="preface.html#pref-new">Samba Changes 3.0.2 to 3.0.20</a></dt><dt>1.1. <a href="simple.html#acctingnet">Accounting Office Network Information</a></dt><dt>3.1. <a href="secure.html#chap4netid">Abmas.US ISP Information</a></dt><dt>3.2. <a href="secure.html#namedrscfiles">DNS (named) Resource Files</a></dt><dt>4.1. <a href="Big500users.html#ch5-filelocations">Domain: MEGANET, File Locations for Servers</a></dt><dt>5.1. <a href="happy.html#sbehap-privs">Current Privilege Capabilities</a></dt><dt>5.2. <a href="happy.html#oldapreq">Required OpenLDAP Linux Packages</a></dt><dt>5.3. <a href="happy.html#sbehap-bigacct">Abmas Network Users and Groups</a></dt><dt>5.4. <a href="happy.html#proffold">Default Profile Redirections</a></dt><dt>9.1. <a href="ntmigration.html#ch8-vampire">Samba smb.conf Scripts Essential to Samba Operation</a></dt><dt>13.1. <a href="HA.html#ProbList">Effect of Common Problems</a></dt><dt>16.1. <a href="primer.html#capsstats01">Windows Me Startup Broadcast Capture Statistics</a></dt><dt>16.2. <a href="primer.html#capsstats02">Second Machine (Windows 98) Capture Statistics</a></dt></dl></div><div class="list-of-examples"><p><b>List of Examples</b></p><dl><dt>1.1. <a href="simple.html#draft-smbconf">Drafting Office smb.conf File</a></dt><dt>1.2. <a href="simple.html#charity-smbconfnew">Charity Administration Office smb.conf New-style File</a></dt><dt>1.3. <a href="simple.html#charity-smbconf">Charity Administration Office smb.conf Old-style File</a></dt><dt>1.4. <a href="simple.html#MEreg">Windows Me Registry Edit File: Disable Password Caching</a></dt><dt>1.5. <a href="simple.html#acctconf">Accounting Office Network smb.conf Old Style Configuration File</a></dt><dt>2.1. <a href="small.html#initGrps">Script to Map Windows NT Groups to UNIX Groups</a></dt><dt>2.2. <a href="small.html#dhcp01">Abmas Accounting DHCP Server Configuration File /etc/dhcpd.conf</a></dt><dt>2.3. <a href="small.html#acct2conf">Accounting Office Network smb.conf File [globals] Section</a></dt><dt>2.4. <a href="small.html#acct3conf">Accounting Office Network smb.conf File Services and Shares Section</a></dt><dt>3.1. <a href="secure.html#ch4memoryest">Estimation of Memory Requirements</a></dt><dt>3.2. <a href="secure.html#ch4diskest">Estimation of Disk Storage Requirements</a></dt><dt>3.3. <a href="secure.html#ch4natfw">NAT Firewall Configuration Script</a></dt><dt>3.4. <a href="secure.html#promisnet">130 User Network with tdbsam [globals] Section</a></dt><dt>3.5. <a href="secure.html#promisnetsvca">130 User Network with tdbsam Services Section Part A</a></dt><dt>3.6. <a href="secure.html#promisnetsvcb">130 User Network with tdbsam Services Section Part B</a></dt><dt>3.7. <a href="secure.html#ch4initGrps">Script to Map Windows NT Groups to UNIX Groups</a></dt><dt>3.8. <a href="secure.html#prom-dhcp">DHCP Server Configuration File /etc/dhcpd.conf</a></dt><dt>3.9. <a href="secure.html#ch4namedcfg">DNS Master Configuration File /etc/named.conf Master Section</a></dt><dt>3.10. <a href="secure.html#ch4namedvarfwd">DNS Master Configuration File /etc/named.conf Forward Lookup Definition Section</a></dt><dt>3.11. <a href="secure.html#ch4namedvarrev">DNS Master Configuration File /etc/named.conf Reverse Lookup Definition Section</a></dt><dt>3.12. <a href="secure.html#eth1zone">DNS 192.168.1 Reverse Zone File</a></dt><dt>3.13. <a href="secure.html#eth2zone">DNS 192.168.2 Reverse Zone File</a></dt><dt>3.14. <a href="secure.html#abmasbiz">DNS Abmas.biz Forward Zone File</a></dt><dt>3.15. <a href="secure.html#abmasus">DNS Abmas.us Forward Zone File</a></dt><dt>4.1. <a href="Big500users.html#ch5-massivesmb">Server: MASSIVE (PDC), File: /etc/samba/smb.conf</a></dt><dt>4.2. <a href="Big500users.html#ch5-dc-common">Server: MASSIVE (PDC), File: /etc/samba/dc-common.conf</a></dt><dt>4.3. <a href="Big500users.html#ch5-commonsmb">Common Samba Configuration File: /etc/samba/common.conf</a></dt><dt>4.4. <a href="Big500users.html#ch5-bldg1-smb">Server: BLDG1 (Member), File: smb.conf</a></dt><dt>4.5. <a href="Big500users.html#ch5-bldg2-smb">Server: BLDG2 (Member), File: smb.conf</a></dt><dt>4.6. <a href="Big500users.html#ch5-dommem-smb">Common Domain Member Include File: dom-mem.conf</a></dt><dt>4.7. <a href="Big500users.html#massive-dhcp">Server: MASSIVE, File: dhcpd.conf</a></dt><dt>4.8. <a href="Big500users.html#bldg1dhcp">Server: BLDG1, File: dhcpd.conf</a></dt><dt>4.9. <a href="Big500users.html#bldg2dhcp">Server: BLDG2, File: dhcpd.conf</a></dt><dt>4.10. <a href="Big500users.html#massive-nameda">Server: MASSIVE, File: named.conf, Part: A</a></dt><dt>4.11. <a href="Big500users.html#massive-namedb">Server: MASSIVE, File: named.conf, Part: B</a></dt><dt>4.12. <a href="Big500users.html#massive-namedc">Server: MASSIVE, File: named.conf, Part: C</a></dt><dt>4.13. <a href="Big500users.html#abmasbizdns">Forward Zone File: abmas.biz.hosts</a></dt><dt>4.14. <a href="Big500users.html#abmasusdns">Forward Zone File: abmas.biz.hosts</a></dt><dt>4.15. <a href="Big500users.html#bldg12nameda">Servers: BLDG1/BLDG2, File: named.conf, Part: A</a></dt><dt>4.16. <a href="Big500users.html#bldg12namedb">Servers: BLDG1/BLDG2, File: named.conf, Part: B</a></dt><dt>4.17. <a href="Big500users.html#ch5-initgrps">Initialize Groups Script, File: /etc/samba/initGrps.sh</a></dt><dt>5.1. <a href="happy.html#sbehap-dbconf">LDAP DB_CONFIG File</a></dt><dt>5.2. <a href="happy.html#sbehap-slapdconf">LDAP Master Configuration File /etc/openldap/slapd.conf Part A</a></dt><dt>5.3. <a href="happy.html#sbehap-slapdconf2">LDAP Master Configuration File /etc/openldap/slapd.conf Part B</a></dt><dt>5.4. <a href="happy.html#sbehap-nss01">Configuration File for NSS LDAP Support /etc/ldap.conf</a></dt><dt>5.5. <a href="happy.html#sbehap-nss02">Configuration File for NSS LDAP Clients Support /etc/ldap.conf</a></dt><dt>5.6. <a href="happy.html#sbehap-massive-smbconfa">LDAP Based smb.conf File, Server: MASSIVE global Section: Part A</a></dt><dt>5.7. <a href="happy.html#sbehap-massive-smbconfb">LDAP Based smb.conf File, Server: MASSIVE global Section: Part B</a></dt><dt>5.8. <a href="happy.html#sbehap-bldg1-smbconf">LDAP Based smb.conf File, Server: BLDG1</a></dt><dt>5.9. <a href="happy.html#sbehap-bldg2-smbconf">LDAP Based smb.conf File, Server: BLDG2</a></dt><dt>5.10. <a href="happy.html#sbehap-shareconfa">LDAP Based smb.conf File, Shares Section Part A</a></dt><dt>5.11. <a href="happy.html#sbehap-shareconfb">LDAP Based smb.conf File, Shares Section Part B</a></dt><dt>5.12. <a href="happy.html#sbehap-ldifadd">LDIF IDMAP Add-On Load File File: /etc/openldap/idmap.LDIF</a></dt><dt>6.1. <a href="2000users.html#ch7-LDAP-master">LDAP Master Server Configuration File /etc/openldap/slapd.conf</a></dt><dt>6.2. <a href="2000users.html#ch7-LDAP-slave">LDAP Slave Configuration File /etc/openldap/slapd.conf</a></dt><dt>6.3. <a href="2000users.html#ch7-massmbconfA">Primary Domain Controller smb.conf File Part A</a></dt><dt>6.4. <a href="2000users.html#ch7-massmbconfB">Primary Domain Controller smb.conf File Part B</a></dt><dt>6.5. <a href="2000users.html#ch7-massmbconfC">Primary Domain Controller smb.conf File Part C</a></dt><dt>6.6. <a href="2000users.html#ch7-slvsmbocnfA">Backup Domain Controller smb.conf File Part A</a></dt><dt>6.7. <a href="2000users.html#ch7-slvsmbocnfB">Backup Domain Controller smb.conf File Part B</a></dt><dt>7.1. <a href="unixclients.html#ch9-sdmsdc">Samba Domain Member in Samba Domain Using LDAP smb.conf File</a></dt><dt>7.2. <a href="unixclients.html#ch9-ldifadd">LDIF IDMAP Add-On Load File File: /etc/openldap/idmap.LDIF</a></dt><dt>7.3. <a href="unixclients.html#ch9-sdmlcnf">Configuration File for NSS LDAP Support /etc/ldap.conf</a></dt><dt>7.4. <a href="unixclients.html#ch9-sdmnss">NSS using LDAP for Identity Resolution File: /etc/nsswitch.conf</a></dt><dt>7.5. <a href="unixclients.html#ch0-NT4DSDM">Samba Domain Member Server Using Winbind smb.conf File for NT4 Domain</a></dt><dt>7.6. <a href="unixclients.html#ch0-NT4DSCM">Samba Domain Member Server Using Local Accounts smb.conf File for NT4 Domain</a></dt><dt>7.7. <a href="unixclients.html#ch9-adssdm">Samba Domain Member smb.conf File for Active Directory Membership</a></dt><dt>7.8. <a href="unixclients.html#sbe-idmapridex">Example smb.conf File Using idmap_rid</a></dt><dt>7.9. <a href="unixclients.html#sbeunxa">Typical ADS Style Domain smb.conf File</a></dt><dt>7.10. <a href="unixclients.html#sbewinbindex">ADS Membership Using RFC2307bis Identity Resolution smb.conf File</a></dt><dt>7.11. <a href="unixclients.html#ch9-pamwnbdlogin">SUSE: PAM login Module Using Winbind</a></dt><dt>7.12. <a href="unixclients.html#ch9-pamwbndxdm">SUSE: PAM xdm Module Using Winbind</a></dt><dt>7.13. <a href="unixclients.html#ch9-rhsysauth">Red Hat 9: PAM System Authentication File: /etc/pam.d/system-auth Module Using Winbind</a></dt><dt>9.1. <a href="ntmigration.html#sbent4smb">NT4 Migration Samba-3 Server smb.conf Part: A</a></dt><dt>9.2. <a href="ntmigration.html#sbent4smb2">NT4 Migration Samba-3 Server smb.conf Part: B</a></dt><dt>9.3. <a href="ntmigration.html#sbentslapd">NT4 Migration LDAP Server Configuration File: /etc/openldap/slapd.conf Part A</a></dt><dt>9.4. <a href="ntmigration.html#sbentslapd2">NT4 Migration LDAP Server Configuration File: /etc/openldap/slapd.conf Part B</a></dt><dt>9.5. <a href="ntmigration.html#sbrntldapconf">NT4 Migration NSS LDAP File: /etc/ldap.conf</a></dt><dt>9.6. <a href="ntmigration.html#sbentnss">NT4 Migration NSS Control File: /etc/nsswitch.conf (Stage:1)</a></dt><dt>9.7. <a href="ntmigration.html#sbentnss2">NT4 Migration NSS Control File: /etc/nsswitch.conf (Stage:2)</a></dt><dt>10.1. <a href="nw4migration.html#sbeamg">A Rough Tool to Create an LDIF File from the System Account Files</a></dt><dt>10.2. <a href="nw4migration.html#ch8ldap">NSS LDAP Control File /etc/ldap.conf</a></dt><dt>10.3. <a href="nw4migration.html#sbepu2">The PAM Control File /etc/security/pam_unix2.conf</a></dt><dt>10.4. <a href="nw4migration.html#ch8smbconf">Samba Configuration File smb.conf Part A</a></dt><dt>10.5. <a href="nw4migration.html#ch8smbconf2">Samba Configuration File smb.conf Part B</a></dt><dt>10.6. <a href="nw4migration.html#ch8smbconf3">Samba Configuration File smb.conf Part C</a></dt><dt>10.7. <a href="nw4migration.html#ch8smbconf4">Samba Configuration File smb.conf Part D</a></dt><dt>10.8. <a href="nw4migration.html#ch8smbconf5">Samba Configuration File smb.conf Part E</a></dt><dt>10.9. <a href="nw4migration.html#sbersync">Rsync Script</a></dt><dt>10.10. <a href="nw4migration.html#sbexcld">Rsync Files Exclusion List /root/excludes.txt</a></dt><dt>10.11. <a href="nw4migration.html#ch8ideal">Idealx smbldap-tools Control File Part A</a></dt><dt>10.12. <a href="nw4migration.html#ch8ideal2">Idealx smbldap-tools Control File Part B</a></dt><dt>10.13. <a href="nw4migration.html#ch8ideal3">Idealx smbldap-tools Control File Part C</a></dt><dt>10.14. <a href="nw4migration.html#ch8ideal4">Idealx smbldap-tools Control File Part D</a></dt><dt>10.15. <a href="nw4migration.html#ch8kix">Kixtart Control File File: logon.kix</a></dt><dt>10.16. <a href="nw4migration.html#ch8kix2">Kixtart Control File File: main.kix</a></dt><dt>10.17. <a href="nw4migration.html#ch8kix3">Kixtart Control File File: setup.kix, Part A</a></dt><dt>10.18. <a href="nw4migration.html#ch8kix3b">Kixtart Control File File: setup.kix, Part B</a></dt><dt>10.19. <a href="nw4migration.html#ch8kix4">Kixtart Control File File: acct.kix</a></dt><dt>12.1. <a href="DomApps.html#ch10-krb5conf">Kerberos Configuration File: /etc/krb5.conf</a></dt><dt>12.2. <a href="DomApps.html#ch10-smbconf">Samba Configuration File: /etc/samba/smb.conf</a></dt><dt>12.3. <a href="DomApps.html#ch10-etcnsscfg">NSS Configuration File Extract File: /etc/nsswitch.conf</a></dt><dt>12.4. <a href="DomApps.html#etcsquidcfg">Squid Configuration File Extract /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]</a></dt><dt>12.5. <a href="DomApps.html#etcsquid2">Squid Configuration File extract File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]</a></dt><dt>15.1. <a href="appendix.html#ch12SL">A Useful Samba Control Script for SUSE Linux</a></dt><dt>15.2. <a href="appendix.html#ch12RHscript">A Sample Samba Control Script for Red Hat Linux</a></dt><dt>15.3. <a href="appendix.html#loopback">DNS Localhost Forward Zone File: /var/lib/named/localhost.zone</a></dt><dt>15.4. <a href="appendix.html#dnsloopy">DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone</a></dt><dt>15.5. <a href="appendix.html#roothint">DNS Root Name Server Hint File: /var/lib/named/root.hint</a></dt><dt>15.6. <a href="appendix.html#sbehap-ldapreconfa">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh Part A</a></dt><dt>15.7. <a href="appendix.html#sbehap-ldapreconfb">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh Part B</a></dt><dt>15.8. <a href="appendix.html#sbehap-ldapreconfc">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh Part C</a></dt><dt>15.9. <a href="appendix.html#sbehap-ldifpata">LDIF Pattern File Used to Pre-configure LDAP Part A</a></dt><dt>15.10. <a href="appendix.html#sbehap-ldifpatb">LDIF Pattern File Used to Pre-configure LDAP Part B</a></dt><dt>15.11. <a href="appendix.html#lamcfg">Example LAM Configuration File config.cfg</a></dt><dt>15.12. <a href="appendix.html#lamconf">LAM Profile Control File lam.conf</a></dt></dl></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"> </td><td width="20%" align="center"> </td><td width="40%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top"> </td><td width="20%" align="center"> </td><td width="40%" align="right" valign="top"> About the Cover Artwork</td></tr></table></div></body></html> -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/ix01.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Index</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Index</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> </td></tr></table><hr></div><div class="index"><div class="titlepage"><div><div><h2 class="title"><a name="id26308 60"></a>Index</h2></div></div></div><div class="index"><div class="indexdiv"><h3>Symbols</h3><dl><dt>%LOGONSERVER%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>%USERNAME%, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a></dt><dt>%USERPROFILE%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>/data/ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>/etc/cups/mime.convs, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/cups/mime.types, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/dhcpd.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>/etc/exports, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>/etc/group, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/hosts, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>/etc/krb5.conf, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>/etc/ldap.conf, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>/etc/mime.convs, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/mime.types, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/named.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>/etc/nsswitch.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/etc/openldap/slapd.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>/etc/passwd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>/etc/rc.d/boot.local, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>/etc/rc.d/rc.local, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>/etc/resolv.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/etc/samba/secrets.tdb, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>/etc/samba/smbusers, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/shadow, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>/etc/squid/squid.conf, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/syslog.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/etc/xinetd.d, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>/lib/libnss_ldap.so.2, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>/opt/IDEALX/sbin, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/proc/sys/net/ipv4/ip_forward, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>/usr/bin, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/lib/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local/samba/var/locks, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/usr/sbin, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share/samba/swat, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share/swat, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/var/cache/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/var/lib/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/var/log/ldaplogs, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/var/log/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>8-bit, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt></dl></div><div class="indexdiv"><h3></h3><dl><dt>, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="Big500users.html#id2565659">Implementation</a>, <a class="indexterm" href="happy.html#sbehap-ppc">Addition of Machines to the Domain</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a></dt><dd><dl><dt>Domain account, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>logon, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>problem, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>transparent inter-operability, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd></dl></div><div class="indexdiv"><h3>A</h3><dl><dt>abmas-netfw.sh, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>accept, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>accepts liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>access, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>access control, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a>, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Access Control Lists (see ACLs)</dt><dt>access control settings, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>access controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>accessible, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dd><dl><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>account credentials, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>account information, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>account names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>account policies, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>accountable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>accounts</dt><dd><dl><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>machine, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>manage, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>user, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></dd><dt>ACL, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>ACLs, <a class="indexterm" href="happy.html#id2583229">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>acquisitions, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Act!, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>ACT! database, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>Act!Diag, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>Active Directory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2589319">Assignment Tasks</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>authentication, <a class="indexterm" href="DomApps.html#id2617956">Squid Configuration</a></dt><dt>domain, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>management tools, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>realm, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>Replacement, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>tree, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt></dl></dd><dt>active directory, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>AD printer publishing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>ADAM, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>add group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add machine script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>Add Printer Wizard</dt><dd><dl><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>add user script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add user to group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>adduser, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>adequate precautions, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>administrative installation, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>administrative rights, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>administrator, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>ADMT, <a class="indexterm" href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></dt><dt>ADS, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>affordability, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>alarm, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>algorithm, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>allow trusted domains, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>alternative, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>analysis, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>anonymous connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>Apache Web server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>appliance mode, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>application server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>application servers, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>application/octet-stream, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>arp, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>assessment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>assistance, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>assumptions, <a class="indexterm" href="HA.html#id2620832">Key Points Learned</a></dt><dt>authconfig, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>authenticate, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>authenticated, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>authenticated connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>authentication, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dd><dl><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd><dt>authentication process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>authentication protocols, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>authorized location, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>auto-generated SID, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>automatically allocate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>availability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt></dl></div><div class="indexdiv"><h3>B</h3><dl><dt>backends, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Backup, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Backup Domain Controller (see BDC)</dt><dt>bandwidth, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dd><dl><dt>requirements, <a class="indexterm" href="2000users.html#id2584178">User Needs</a></dt></dl></dd><dt>bandwidth calculations, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>BDC, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>benefit, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>best practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bias, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>binary database, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>binary files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>binary package, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>bind interfaces only, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>directed, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>mailslot, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>broadcast messages, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast storms, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>broken, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>broken behavior, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>browse, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>browse master, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>Browse Master, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browse.dat, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Browser Election Service, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browsing, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>budgetted, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug fixes, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug report, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>C</h3><dl><dt>cache, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt><dt>cache directories, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>caching, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>case-sensitive, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>centralized storage, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>character set, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>check samba daemons, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>check-point, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>check-point controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>Checkpoint Controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>chgrp, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>chkconfig, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>chmod, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>choice, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>chown, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>CIFS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>cifsfs, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>clean database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>clients per DC, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Clock skew, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>cluster, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>clustering, <a class="indexterm" href="HA.html#id2618932">Introduction</a>, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>code maintainer, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>codepage, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>collision rates, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>commercial, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>Common Internet File System (see CIFS)</dt><dt>comparison</dt><dd><dl><dt>Active Directory & OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>compat, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>compatible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>compile-time, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>complexities, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>compromise, <a class="indexterm" href="happy.html#id2571190">Introduction</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>computer account, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Computer Management, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>computer name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>condemns, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>conferences, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>configuration files, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>configure.pl, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>connection, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>connectivity, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>consequential risk, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consultant, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>consumer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consumer expects, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>contiguous directory, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>contributions, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>control files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>convmv, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>copy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>corrective action, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>cost, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>cost-benefit, <a class="indexterm" href="nw4migration.html#id2606147">Assignment Tasks</a></dt><dt>country of origin, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>Courier-IMAP, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>credential, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>credentials, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>crippled, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>criticism, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Critics, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Cryptographic, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>CUPS, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dd><dl><dt>queue, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt></dl></dd><dt>cupsd, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>customer expected, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>customers, <a class="indexterm" href="ch14.html">Samba Support</a></dt></dl></div><div class="indexdiv"><h3>D</h3><dl><dt>daemon, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>daemon control, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>data</dt><dd><dl><dt>corruption, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>integrity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>data corruption, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a>, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>data integrity, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a>, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>data storage, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>database, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>database applications, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>DB_CONFIG, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>DCE, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>DDNS (see dynamic DNS)</dt><dt>Debian, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>default installation, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>default password, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>default profile, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Default User, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>defective</dt><dd><dl><dt>cables, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>HUBs, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>switches, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt></dl></dd><dt>defects, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defensible standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defragmentation, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a></dt><dt>delete group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delete user from group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delimiter, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>dependability, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>deployment, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>desired security setting, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>development, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DHCP, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dd><dl><dt>client, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>relay, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>Relay Agent, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>request, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>requests, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>servers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>traffic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>dhcp client validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>DHCP Server, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>DHCP server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>diagnostic, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>diffusion, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital rights, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital sign'n'seal, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digits, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>diligence, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>directory, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dd><dl><dt>Computers container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>People container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>replication, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>schema, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>server, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>synchronization, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>directory tree, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>disable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disaster recovery, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disk image, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>disruptive, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>distributed, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt><dt>distributed domain, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>DMB, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>DMS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>DNS, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>configuration, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Dynamic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>dynamic, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>name lookup, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>SRV records, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>suffix, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></dd><dt>DNS server, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>document the settings, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>documentation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>documented, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Domain, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt></dl></dd><dt>domain</dt><dd><dl><dt>Active Directory, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>controller, <a class="indexterm" href="upgrades.html#id2600964">Replacing a Domain Controller</a></dt><dt>joining, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>trusted, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>Domain accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Administrator, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Domain Controller, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dd><dl><dt>closest, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>domain controller, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>domain controllers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Controllers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Domain Groups</dt><dd><dl><dt>well-known, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt></dl></dd><dt>Domain join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>domain master, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>Domain Master Browser (see DMB)</dt><dt>Domain Member, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dd><dl><dt>authoritative</dt><dd><dl><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>client, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>workstations, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt></dl></dd><dt>domain member</dt><dd><dl><dt>servers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>Domain Member server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Domain Member servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain members, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain name space, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>domain replication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>domain SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Domain SID, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>domain tree, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Domain User Manager, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Domain users, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DOS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>dos2unix, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>down-grade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>drive letters, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>drive mapping, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>dumb printing, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>dump, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>duplicate accounts, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>dynamic DNS, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>E</h3><dl><dt>e-Directory, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Easy Software Products, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>economically sustainable, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>eDirectory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>education, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>election, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>employment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>enable, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>encrypted, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>encrypted password, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>encrypted passwords, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>End User License Agreement (see EULA)</dt><dt>enumerating, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>essential, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>ethereal, <a class="indexterm" href="primer.html#id2625745">Exercises</a></dt><dt>Ethernet switch, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dt>ethernet switch, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>EULA, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>Everyone, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Excel, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>exclusive open, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>experiment, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>export, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>extent, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>External Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>extreme demand, <a class="indexterm" href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></dt></dl></div><div class="indexdiv"><h3>F</h3><dl><dt>fail, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>failed, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>failed join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>failure, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>familiar, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fatal problem, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>fear, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fears, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Fedora, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a></dt><dt>FHS, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>file and print server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>file and print service, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>file caching, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt><dt>File Hierarchy System (see FHS)</dt><dt>file locations, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>file permissions, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>file server</dt><dd><dl><dt>read-only, <a class="indexterm" href="simple.html#id2551026">Dissection and Discussion</a></dt></dl></dd><dt>file servers, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a></dt><dt>file system, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>access control, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>Ext3, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>permissions, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>file system security, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>filter, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>financial responsibility, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>firewall, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>fix, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>flaws, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>flexibility, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>flush</dt><dd><dl><dt>cache memory, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></dd><dt>folder redirection, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>force group, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>force user, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>forced settings, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>foreign, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>foreign SID, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>forwarded, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>foundation members, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Free Standards Group (see FSG)</dt><dt>free support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>front-end, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dd><dl><dt>server, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt></dl></dd><dt>frustration, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>FSG, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>FTP</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd><dt>full control, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615018">Using MS Windows Explorer (File Manager)</a></dt><dt>fully qualified, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>functional differences, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt></dl></div><div class="indexdiv"><h3>G</h3><dl><dt>generation, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>Gentoo, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>getent, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>getfacl, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>getgrnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>getpwnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>getpwnam(), <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>GID, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Goettingen, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>government, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>GPL, <a class="indexterm" href="secure.html#id2564111">Comments Regarding Software Terms of Use</a></dt><dt>group account, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>group management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>group mapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>group membership, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>group names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group policies, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a></dt><dt>Group Policy, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>Group Policy editor, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>Group Policy Objects, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>groupadd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupmem, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>groupmod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>GSS-API, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>guest account, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a>, <a class="indexterm" href="primer.html#chap01conc">Dissection and Discussion</a>, <a class="indexterm" href="primer.html#id2628204">Technical Issues</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>H</h3><dl><dt>hackers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>hardware prices, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>hardware problems, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>Heimdal, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Heimdal Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Heimdal kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>help, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>helper agent, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>hesiod, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>hierarchy of control, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>high availability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>hire, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>HKEY_CURRENT_USER, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>HKEY_LOCAL_MACHINE, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>HKEY_LOCAL_USER, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>host announcement, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a>, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>hostname, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>hosts, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>HUB, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Hybrid, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>hypothetical, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>I</h3><dl><dt>Idealx, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dd><dl><dt>smbldap-tools, <a class="indexterm" href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt></dl></dd><dt>identifiers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>identity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>management, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt></dl></dd><dt>identity management, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Identity Management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Identity management, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>Identity resolution, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Identity resolver, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>IDMAP, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap backend, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>IDMAP backend, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>idmap gid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap uid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap_rid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>IMAP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>import, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>income, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>independent expert, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>inetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>inetOrgPerson, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>inheritance, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>initGrps.sh, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>initial credentials, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>inoperative, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>install, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>installation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>integrate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>integrity, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>inter-domain, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>inter-operability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>interactive help, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>interdomain trusts, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>interfaces, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>intermittent, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>internationalization, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Internet Explorer, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>Internet Information Server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>interoperability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>IP forwarding, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>IPC$, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>iptables, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>IRC, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>isolated, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Italian, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>J</h3><dl><dt>jobs, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>joining a domain, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></div><div class="indexdiv"><h3>K</h3><dl><dt>KDC, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>Heimdal, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>interoperability, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>libraries, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>MIT, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>unspecified fields, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>kerberos, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>Kerberos ticket, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>kinit, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Kixtart, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>klist, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>krb5, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>krb5.conf, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt></dl></div><div class="indexdiv"><h3>L</h3><dl><dt>LAM, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dd><dl><dt>configuration editor, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>configuration file, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>login screen, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>opening screen, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>profile, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>wizard, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt></dl></dd><dt>large domain, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>LDAP, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2573037">Preliminary Advice: Dangers Can Be Avoided</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2583767">Introduction</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>backend, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>database, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>directory, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>initial configuration, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>master/slave</dt><dd><dl><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>preload, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>schema, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>secure, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>updates, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>ldap, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>LDAP Account Manager (see LAM)</dt><dt>LDAP backend, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>LDAP database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>LDAP Interchange Format (see LDIF)</dt><dt>LDAP server, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>LDAP-transfer-LDIF.txt, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>ldap.conf, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapsam, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>ldapsam backend, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapsearch, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>LDIF, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt><dt>leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Lightweight Directory Access Protocol (see LDAP)</dt><dt>limit, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Linux desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>Linux Standards Base (see LSB)</dt><dt>LMB, <a class="indexterm" href="primer.html#id2626005">Findings</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>LMHOSTS, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>load distribution, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Local Group Policy, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>Local Master Announcement, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>Local Master Browser (see LMB)</dt><dt>localhost, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>lock directory, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>locking</dt><dd><dl><dt>Application level, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Client side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Server side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>logging, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>login, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>loglevel, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>logon credentials, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>logon hours, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>logon machines, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon path, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>logon scrip, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>logon script, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2581163">Preparation of Logon Scripts</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon server, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon services, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon time, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>logon traffic, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon.kix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>loopback, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>low performance, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>lower-case, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>lpadmin, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>LSB, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>M</h3><dl><dt>machine, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>machine account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>machine accounts, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>machine secret password, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>MACHINE.SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>mailing list, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>mailing lists, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>managed, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>management, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dd><dl><dt>group, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>User, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>mandatory profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Mandrake, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>mapped drives, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>mapping, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>consistent, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt></dl></dd><dt>Mars_NWE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>material, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>memberUID, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>memory requirements, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>merge, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>merged, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>meta-directory, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>meta-service, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Microsoft Access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft Excel, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft ISA, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>Microsoft Management Console (see MMC)</dt><dt>Microsoft Office, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>Microsoft Outlook</dt><dd><dl><dt>PST files, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>migrate, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>migration, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dd><dl><dt>objectives, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd><dt>Migration speed, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mime type, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>mime types, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>missing RPC's, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>MIT, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>MIT Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>MIT kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>MIT KRB5, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>mixed mode, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>mixed-mode, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>MMC, <a class="indexterm" href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>mobile computing, <a class="indexterm" href="small.html#id2555545">Dissection and Discussion</a></dt><dt>mobility, <a class="indexterm" href="2000users.html#id2584139">Technical Issues</a></dt><dt>modularization, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>modules, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>MS Access</dt><dd><dl><dt>validate, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt></dl></dd><dt>MS Outlook, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>PST file, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>MS Windows Server 2003, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>MS Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>MSDFS, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt><dt>multi-subnet, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>multi-user</dt><dd><dl><dt>access, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>data access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>multiple directories, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>multiple domain controllers, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>multiple group mappings, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mutual assistance, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>My Documents, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>My Network Places, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>mysqlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>N</h3><dl><dt>name resolution, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dd><dl><dt>Defective, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>name resolve order, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>name service switch, <a class="indexterm" href="small.html#id2555812">Implementation</a> (see NSS)</dt><dt>named, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>NAT, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>native, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>net</dt><dd><dl><dt>ads</dt><dd><dl><dt>info, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>status, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>getlocalsid, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>groupmap</dt><dd><dl><dt>add, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>list, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>modify, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt></dl></dd><dt>rpc</dt><dd><dl><dt>info, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>join, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>vampire, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt></dl></dd><dt>setlocalsid, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>NetBIOS, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>name cache, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>name resolution</dt><dd><dl><dt>delays, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Node Type, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></dd><dt>netbios</dt><dd><dl><dt>machine name, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a></dt></dl></dd><dt>netbios forwarding, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>NetBIOS name, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>aliases, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>netbios name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>NETLOGON, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="happy.html#id2581407">Windows Client Configuration</a></dt><dt>netlogon, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Netlogon, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>netmask, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>Netware, <a class="indexterm" href="small.html">Small Office Networking</a></dt><dt>NetWare, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>network</dt><dd><dl><dt>administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>analyzer, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>bandwidth, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>broadcast, <a class="indexterm" href="primer.html#id2625568">Introduction</a></dt><dt>captures, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>collisions, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>load, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>logon scripts, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>management, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>multi-segment, <a class="indexterm" href="happy.html#id2571190">Introduction</a></dt><dt>overload, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>performance, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>routed, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>segment, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>sniffer, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>timeout, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>timeouts, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>trace, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>traffic</dt><dd><dl><dt>observation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>wide-area, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt></dl></dd><dt>Network Address Translation (see NAT)</dt><dt>network administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network attached storage (see NAS)</dt><dt>network bandwidth</dt><dd><dl><dt>utilization, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Network Default Profile, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>network hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>network hygiene, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>network Identities, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>network load factors, <a class="indexterm" href="Big500users.html#id2565398">Dissection and Discussion</a></dt><dt>Network Neighborhood, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network segment, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>network segments, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>network share, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>networking</dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>networking hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>next generation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>NextFreeUnixId, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NFS server, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>NICs, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>NIS, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>nis, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>NIS schema, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS server, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS+, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>nisplus, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>NLM, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>nmap, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>nmbd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>nobody, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>Novell, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>Novell SUSE SLES 9, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NSS, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a> (see same service switch)</dt><dt>nss_ldap, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>nt acl support, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>NT4 registry, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>NTLM, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>NTLM authentication daemon, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>NTLMSSP, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>NTLMSSP_AUTH, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>ntlm_auth, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>NTP, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>NTUSER.DAT, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NULL connection, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>NULL session, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>NULL-Session, <a class="indexterm" href="primer.html#id2628058">Discussion</a></dt></dl></div><div class="indexdiv"><h3>O</h3><dl><dt>objectClass, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>off-site storage, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Open Magazine, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>Open Source, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>openldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>OpenOffice, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>operating profiles, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>oplock break, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>oplocks, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Oplocks</dt><dd><dl><dt>disabled, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></dd><dt>opportunistic</dt><dd><dl><dt>locking, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt></dl></dd><dt>opportunistic locking, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>optimized, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>organizational units, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>OS/2, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Outlook</dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt></dl></dd><dt>Outlook Address Book, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>Outlook Express, <a class="indexterm" href="secure.html#id2559309">Political Issues</a>, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>over-ride, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>over-ride controls, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>over-rule, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615018">Using MS Windows Explorer (File Manager)</a></dt><dt>overheads, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>ownership, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></div><div class="indexdiv"><h3>P</h3><dl><dt>package, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>package names, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>packages, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>PADL, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>PADL LDAP tools, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>PADL Software, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>paid-for support, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>PAM, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>pam_ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>pam_ldap.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>pam_unix2.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dd><dl><dt>use_ldap, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt></dl></dd><dt>parameters, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>passdb backend, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>passdb.tdb, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>passwd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>password</dt><dd><dl><dt>backend, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>password caching, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>password change, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>password length, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>payroll, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>pdbedit, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>PDC, <a class="indexterm" href="Big500users.html#id2565292">Assignment Tasks</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>PDC/BDC ratio, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>PDF, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>performance, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a>, <a class="indexterm" href="HA.html#id2618932">Introduction</a>, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>performance degradation, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Perl, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>permission, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>permissions, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>excessive, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>group, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>user, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></dd><dt>Permissions, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>permits, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>permitted group, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>PHP, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>PHP4, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>pile-driver, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>ping, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>pitfalls, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Pluggable Authentication Modules (see PAM)</dt><dt>policy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>poor performance, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>POP3, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>Posix, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>POSIX, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Posix accounts, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Posix ACLs, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>PosixAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>posixAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postfix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postscript, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>powers, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>precaution, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>presence and leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>price paid, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>primary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>principals, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>print filter, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>print queue, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>print spooler, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a></dt><dt>Print Test Page, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>printcap name, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>printer validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>printers</dt><dd><dl><dt>Advanced, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Default Settings, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>General, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Properties, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Security, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Sharing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>printing, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dd><dl><dt>drag-and-drop, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>dumb, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>point-n-click, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt></dl></dd><dt>privacy, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Privilege Attribute Certificates (see PAC)</dt><dt>privilege controls, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>privileged pipe, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>privileges, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>problem report, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>problem resolution, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>product defects, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>professional support, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>profile</dt><dd><dl><dt>default, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>mandatory, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>roaming, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>profile path, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>profile share, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>profiles, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>profiles share, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>programmer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>project, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>project maintainers, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Properties, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>proprietary, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protected, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protection, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protocol</dt><dd><dl><dt>negotiation, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>protocol analysis, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>provided services, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>proxy, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>PST file, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>public specifications, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>purchase support, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>Q</h3><dl><dt>Qbasic, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>qualified problem, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>R</h3><dl><dt>RAID, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>RAID controllers, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>Raw Print Through, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw printing, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>Rbase, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>rcldap, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>realm, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>recognize, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>record locking, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>recursively, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Red Hat, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>Red Hat Fedora Linux, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Red Hat Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="simple.html#AccountingOffice">Accounting Office</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>redirected folders, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>refereed standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>regedit, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>regedt32, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dd><dl><dt>keys</dt><dd><dl><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>SECURITY, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd></dl></dd><dt>registry change, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Registry Editor, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry hacks, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>registry keys, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>reimburse, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>rejected, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>rejoin, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>reliability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt><dt>remote announce, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>remote browse sync, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>remote procedure call (see RPC)</dt><dt>replicate, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>replicated, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>requesting payment, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>resilient, <a class="indexterm" href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></dt><dt>resolution, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>resolve, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>response, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>responsibility, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>responsible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>restrict anonymous, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>restricted export, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Restrictive security, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>reverse DNS, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>rfc2307bis, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a></dt><dt>RID, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>risk, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>road-map, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>published, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>roaming profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>roaming profiles, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>routed network, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>router, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>routers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>RPC, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>rpc, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>rpcclient, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>RPM, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dd><dl><dt>install, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>rpm, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>RPMs, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>rpms, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>rsync, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>rsyncd.conf, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>run-time control files, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>S</h3><dl><dt>safe-guards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>samba, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>Samba, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Samba accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>samba cluster, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>samba control script, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>Samba Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Samba Domain server, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Samba RPM Packages, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>Samba Tea, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>sambaDomainName, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>sambaGroupMapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaSAMAccount, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>SambaSamAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>sambaSamAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaXP conference, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>SAN, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>SAS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>scalability, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>scalable, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>schannel, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>schema, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>scripts, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>secondary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>secret, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>secrets.tdb, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>secure account password, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>secure connections, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>secure networking, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>secure networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dd><dl><dt>identifier, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>share mode, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>user mode, <a class="indexterm" href="simple.html#id2553821">Dissection and Discussion</a></dt></dl></dd><dt>Security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Security Account Manager (see SAM)</dt><dt>security controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security descriptors, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>security fixes, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security updates, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SerNet, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>server</dt><dd><dl><dt>domain member, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>stand-alone, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>service, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dd><dl><dt>smb</dt><dd><dl><dt>start, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a></dt></dl></dd></dl></dd><dt>Service Packs, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>services provided, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>session setup, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>Session Setup, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></dt><dt>SessionSetUpAndX, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>set primary group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>setfacl, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>severely degrade, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>SFU, <a class="indexterm" href="unixclients.html#id2596287">IDMAP, Active Directory, and MS Services for UNIX 3.5</a></dt><dt>SGID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>shadow-utils, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Share Access Controls, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>share ACLs, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share definition, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Share Definition</dt><dd><dl><dt>Controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt></dl></dd><dt>share definition controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share level access controls, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share level ACL, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Share Permissions, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>shared resource, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>shares, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SID, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt><dt>side effects, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>Sign'n'seal, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>silent return, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>simple, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>Single Sign-On (see SSO)</dt><dt>slapcat, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>slapd, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>slapd.conf, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>slow logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>slow network, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>slurpd, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>smart printing, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>SMB, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>SMB passwords, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>SMB/CIFS, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>smbclient, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>smbd, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dd><dl><dt>location of files, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></dd><dt>smbfs, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbldap-groupadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-groupmod, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-passwd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-populate, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>smbldap-tools updating, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>smbldap-useradd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>smbldap-usermod, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbmnt, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbmount, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbpasswd, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>smbumnt, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbumount, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>SMTP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>snap-shot, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>socket address, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>socket options, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>solve, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>source code, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>SPNEGO, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>SQL, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Squid, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617956">Squid Configuration</a></dt><dt>squid, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Squid proxy, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>SRVTOOLS.EXE, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>SSL, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>stand-alone server, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>starting CUPS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting dhcpd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dd><dl><dt>nmbd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>smbd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>winbindd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt></dl></dd><dt>startingCUPS, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>startup script, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>sticky bit, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>storage capacity, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>strategic, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>strategy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>straw-man, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>strict sync, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>stripped, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>strong cryptography, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>subscription, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>SUID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>Sun ONE Identity Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>super daemon, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>support, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>survey, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>SUSE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>SUSE Enterprise Linux Server, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>SUSE Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>SWAT, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>sync always, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>synchronization, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>synchronize, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>synchronized, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>syslog, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>system level logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>system security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>T</h3><dl><dt>tattooing, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>TCP/IP, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>tdbdump, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>tdbsam, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>testparm, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>ticket, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>time server, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>Tivoli Directory Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>TLS, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>token, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>tool, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>TOSHARG2, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>track record, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>traffic collisions, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>transaction processing, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>transactional, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>transfer, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>translate, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>traverse, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>tree, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Tree Connect, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></dt><dt>trust account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>trusted computing, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Trusted Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>trusted domains, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>trusted third-party, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>trusting, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>turn-around time, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>U</h3><dl><dt>UDP</dt><dd><dl><dt>broadcast, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt></dl></dd><dt>UID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>un-join, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>unauthorized activities, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>UNC name, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>unencrypted, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>Unicast, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>unicode, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Universal Naming Convention (see UNC name)</dt><dt>UNIX, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt></dl></dd><dt>UNIX accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>UNIX/Linux server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unix2dos, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>unknown, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unsupported software, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>update, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>updates, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>updating smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>upgrade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>uppercase, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>user</dt><dd><dl><dt>management, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>user account, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>User and Group Controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>user credentials, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>user errors, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user groups, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>user identities, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>user logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>User Manager, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>User Mode, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>useradd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>userdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>usermod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>username, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>username map, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>UTF-8, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>utilities, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>V</h3><dl><dt>valid users, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>validate, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>validated, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>validation, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>vampire, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>vendor, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>vendors, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>VFS modules, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>virus, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>VPN, <a class="indexterm" href="2000users.html#id2583797">Assignment Tasks</a></dt><dt>vulnerabilities, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>W</h3><dl><dt>wbinfo, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>weakness, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>web</dt><dd><dl><dt>caching, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>proxying, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt></dl></dd><dt>Web</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dd><dl><dt>access, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt></dl></dd></dl></dd><dt>Web browsers, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>WebClient, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>WHATSNEW.txt, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></dt><dt>white-pages, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>wide-area, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>wide-area network, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>winbind, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589354">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a></dt><dt>Winbind, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>winbind trusted domains only, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>winbind use default domain, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>winbindd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>winbindd_cache.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>winbindd_idmap.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Windows, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>NT, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>Windows 2000 ACLs, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>Windows 2003 Serve, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows 200x ACLs, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Windows accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Windows ACLs, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Windows Address Book, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Windows ADS Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>Windows clients, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Windows Explorer, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>Windows explorer, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Windows security identifier (see SID)</dt><dt>Windows Servers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows Services for UNIX (see SUS)</dt><dt>Windows XP, <a class="indexterm" href="small.html#id2555484">Assignment Tasks</a></dt><dt>WINS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>name resolution, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>server, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt></dl></dd><dt>WINS server, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>WINS serving, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins support, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins.dat, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Wireshark, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>wireshark, <a class="indexterm" href="primer.html#id2625745">Exercises</a></dt><dt>Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>workgroup, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a></dt><dt>Workgroup Announcement, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>workstation, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>wrapper, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>write lock, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></div><div class="indexdiv"><h3>X</h3><dl><dt>xinetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>XML, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>xmlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>Y</h3><dl><dt>YaST, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>Yellow Pages, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>yellow pages (see NIS)</dt></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> </td></tr><tr><td width="40%" align="left" valign="top">Glossary </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> </td></tr></table></div></body></html>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Index</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Index</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> </td></tr></table><hr></div><div class="index"><div class="titlepage"><div><div><h2 class="title"><a name="id2630895"></a>Index</h2></div></div></div><div class="index"><div class="indexdiv"><h3>Symbols</h3><dl><dt>%LOGONSERVER%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>%USERNAME%, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a></dt><dt>%USERPROFILE%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>/data/ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>/etc/cups/mime.convs, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/cups/mime.types, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/dhcpd.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>/etc/exports, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>/etc/group, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/hosts, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>/etc/krb5.conf, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>/etc/ldap.conf, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>/etc/mime.convs, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/mime.types, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/named.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>/etc/nsswitch.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/etc/openldap/slapd.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>/etc/passwd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>/etc/rc.d/boot.local, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>/etc/rc.d/rc.local, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>/etc/resolv.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/etc/samba/secrets.tdb, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>/etc/samba/smbusers, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/shadow, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>/etc/squid/squid.conf, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/syslog.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/etc/xinetd.d, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>/lib/libnss_ldap.so.2, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>/opt/IDEALX/sbin, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/proc/sys/net/ipv4/ip_forward, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>/usr/bin, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/lib/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local/samba/var/locks, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/usr/sbin, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share/samba/swat, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share/swat, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/var/cache/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/var/lib/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/var/log/ldaplogs, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/var/log/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>8-bit, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt></dl></div><div class="indexdiv"><h3></h3><dl><dt>, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="Big500users.html#id2565659">Implementation</a>, <a class="indexterm" href="happy.html#sbehap-ppc">Addition of Machines to the Domain</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a></dt><dd><dl><dt>Domain account, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>logon, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>problem, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>transparent inter-operability, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd></dl></div><div class="indexdiv"><h3>A</h3><dl><dt>abmas-netfw.sh, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>accept, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>accepts liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>access, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>access control, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a>, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Access Control Lists (see ACLs)</dt><dt>access control settings, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>access controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>accessible, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dd><dl><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>account credentials, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>account information, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>account names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>account policies, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>accountable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>accounts</dt><dd><dl><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>machine, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>manage, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>user, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></dd><dt>ACL, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>ACLs, <a class="indexterm" href="happy.html#id2583229">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>acquisitions, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Act!, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>ACT! database, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>Act!Diag, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>Active Directory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2589319">Assignment Tasks</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>authentication, <a class="indexterm" href="DomApps.html#id2617976">Squid Configuration</a></dt><dt>domain, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>management tools, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>realm, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>Replacement, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>tree, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt></dl></dd><dt>active directory, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>AD printer publishing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>ADAM, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>add group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add machine script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>Add Printer Wizard</dt><dd><dl><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>add user script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add user to group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>adduser, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>adequate precautions, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>administrative installation, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>administrative rights, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>administrator, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>ADMT, <a class="indexterm" href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></dt><dt>ADS, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>affordability, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>alarm, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>algorithm, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>allow trusted domains, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>alternative, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>analysis, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>anonymous connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>Apache Web server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>appliance mode, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>application server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>application servers, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>application/octet-stream, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>arp, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>assessment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>assistance, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>assumptions, <a class="indexterm" href="HA.html#id2620859">Key Points Learned</a></dt><dt>authconfig, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>authenticate, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>authenticated, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>authenticated connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>authentication, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dd><dl><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd><dt>authentication process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>authentication protocols, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>authorized location, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>auto-generated SID, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>automatically allocate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>availability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt></dl></div><div class="indexdiv"><h3>B</h3><dl><dt>backends, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Backup, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Backup Domain Controller (see BDC)</dt><dt>bandwidth, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dd><dl><dt>requirements, <a class="indexterm" href="2000users.html#id2584178">User Needs</a></dt></dl></dd><dt>bandwidth calculations, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>BDC, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>benefit, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>best practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bias, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>binary database, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>binary files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>binary package, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>bind interfaces only, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>directed, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>mailslot, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>broadcast messages, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast storms, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>broken, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>broken behavior, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>browse, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>browse master, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>Browse Master, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browse.dat, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Browser Election Service, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browsing, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>budgetted, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug fixes, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug report, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>C</h3><dl><dt>cache, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt><dt>cache directories, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>caching, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>case-sensitive, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>centralized storage, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>character set, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>check samba daemons, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>check-point, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>check-point controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>Checkpoint Controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>chgrp, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>chkconfig, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>chmod, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>choice, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>chown, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>CIFS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>cifsfs, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>clean database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>clients per DC, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Clock skew, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>cluster, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>clustering, <a class="indexterm" href="HA.html#id2618959">Introduction</a>, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>code maintainer, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>codepage, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>collision rates, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>commercial, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>Common Internet File System (see CIFS)</dt><dt>comparison</dt><dd><dl><dt>Active Directory & OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>compat, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>compatible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>compile-time, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>complexities, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>compromise, <a class="indexterm" href="happy.html#id2571190">Introduction</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>computer account, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Computer Management, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>computer name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>condemns, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>conferences, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>configuration files, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>configure.pl, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>connection, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>connectivity, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>consequential risk, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consultant, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>consumer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consumer expects, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>contiguous directory, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>contributions, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>control files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>convmv, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>copy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>corrective action, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>cost, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>cost-benefit, <a class="indexterm" href="nw4migration.html#id2606147">Assignment Tasks</a></dt><dt>country of origin, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>Courier-IMAP, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>credential, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>credentials, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>crippled, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>criticism, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Critics, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Cryptographic, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>CUPS, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dd><dl><dt>queue, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt></dl></dd><dt>cupsd, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>customer expected, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>customers, <a class="indexterm" href="ch14.html">Samba Support</a></dt></dl></div><div class="indexdiv"><h3>D</h3><dl><dt>daemon, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>daemon control, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>data</dt><dd><dl><dt>corruption, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>integrity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>data corruption, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a>, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>data integrity, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a>, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>data storage, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>database, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>database applications, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>DB_CONFIG, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>DCE, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>DDNS (see dynamic DNS)</dt><dt>Debian, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>default installation, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>default password, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>default profile, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Default User, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>defective</dt><dd><dl><dt>cables, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>HUBs, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>switches, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt></dl></dd><dt>defects, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defensible standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defragmentation, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a></dt><dt>delete group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delete user from group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delimiter, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>dependability, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>deployment, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>desired security setting, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>development, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DHCP, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dd><dl><dt>client, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>relay, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>Relay Agent, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>request, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>requests, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>servers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>traffic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>dhcp client validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>DHCP Server, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>DHCP server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>diagnostic, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>diffusion, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital rights, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital sign'n'seal, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digits, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>diligence, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>directory, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dd><dl><dt>Computers container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>People container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>replication, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>schema, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>server, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>synchronization, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>directory tree, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>disable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disaster recovery, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disk image, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>disruptive, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>distributed, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt><dt>distributed domain, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>DMB, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>DMS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>DNS, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>configuration, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Dynamic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>dynamic, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>name lookup, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>SRV records, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>suffix, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></dd><dt>DNS server, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>document the settings, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>documentation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>documented, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Domain, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt></dl></dd><dt>domain</dt><dd><dl><dt>Active Directory, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>controller, <a class="indexterm" href="upgrades.html#id2600964">Replacing a Domain Controller</a></dt><dt>joining, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>trusted, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>Domain accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Administrator, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Domain Controller, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dd><dl><dt>closest, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>domain controller, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>domain controllers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Controllers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Domain Groups</dt><dd><dl><dt>well-known, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt></dl></dd><dt>Domain join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>domain master, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>Domain Master Browser (see DMB)</dt><dt>Domain Member, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dd><dl><dt>authoritative</dt><dd><dl><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>client, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>workstations, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt></dl></dd><dt>domain member</dt><dd><dl><dt>servers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>Domain Member server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Domain Member servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain members, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain name space, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>domain replication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>domain SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Domain SID, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>domain tree, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Domain User Manager, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Domain users, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DOS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>dos2unix, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>down-grade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>drive letters, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>drive mapping, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>dumb printing, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>dump, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>duplicate accounts, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>dynamic DNS, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>E</h3><dl><dt>e-Directory, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Easy Software Products, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>economically sustainable, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>eDirectory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>education, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>election, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>employment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>enable, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>encrypted, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>encrypted password, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>encrypted passwords, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>End User License Agreement (see EULA)</dt><dt>enumerating, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>essential, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>ethereal, <a class="indexterm" href="primer.html#id2625769">Exercises</a></dt><dt>Ethernet switch, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dt>ethernet switch, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>EULA, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>Everyone, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Excel, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>exclusive open, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>experiment, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>export, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>extent, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>External Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>extreme demand, <a class="indexterm" href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></dt></dl></div><div class="indexdiv"><h3>F</h3><dl><dt>fail, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>failed, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>failed join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>failure, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>familiar, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fatal problem, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>fear, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fears, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Fedora, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a></dt><dt>FHS, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>file and print server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>file and print service, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>file caching, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt><dt>File Hierarchy System (see FHS)</dt><dt>file locations, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>file permissions, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>file server</dt><dd><dl><dt>read-only, <a class="indexterm" href="simple.html#id2551026">Dissection and Discussion</a></dt></dl></dd><dt>file servers, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a></dt><dt>file system, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>access control, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>Ext3, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>permissions, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>file system security, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>filter, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>financial responsibility, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>firewall, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>fix, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>flaws, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>flexibility, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>flush</dt><dd><dl><dt>cache memory, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></dd><dt>folder redirection, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>force group, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>force user, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>forced settings, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>foreign, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>foreign SID, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>forwarded, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>foundation members, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Free Standards Group (see FSG)</dt><dt>free support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>front-end, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dd><dl><dt>server, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt></dl></dd><dt>frustration, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>FSG, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>FTP</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd><dt>full control, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615027">Using MS Windows Explorer (File Manager)</a></dt><dt>fully qualified, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>functional differences, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt></dl></div><div class="indexdiv"><h3>G</h3><dl><dt>generation, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>Gentoo, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>getent, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>getfacl, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>getgrnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>getpwnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>getpwnam(), <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>GID, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Goettingen, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>government, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>GPL, <a class="indexterm" href="secure.html#id2564111">Comments Regarding Software Terms of Use</a></dt><dt>group account, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>group management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>group mapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>group membership, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>group names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group policies, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a></dt><dt>Group Policy, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>Group Policy editor, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>Group Policy Objects, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>groupadd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupmem, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>groupmod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>GSS-API, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>guest account, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a>, <a class="indexterm" href="primer.html#chap01conc">Dissection and Discussion</a>, <a class="indexterm" href="primer.html#id2628227">Technical Issues</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>H</h3><dl><dt>hackers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>hardware prices, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>hardware problems, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>Heimdal, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Heimdal Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Heimdal kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>help, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>helper agent, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>hesiod, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>hierarchy of control, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>high availability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>hire, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>HKEY_CURRENT_USER, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>HKEY_LOCAL_MACHINE, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>HKEY_LOCAL_USER, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>host announcement, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a>, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>hostname, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>hosts, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>HUB, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Hybrid, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>hypothetical, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>I</h3><dl><dt>Idealx, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dd><dl><dt>smbldap-tools, <a class="indexterm" href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt></dl></dd><dt>identifiers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>identity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>management, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt></dl></dd><dt>identity management, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Identity Management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Identity management, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>Identity resolution, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Identity resolver, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>IDMAP, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap backend, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>IDMAP backend, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>idmap gid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap uid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap_rid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>IMAP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>import, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>income, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>independent expert, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>inetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>inetOrgPerson, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>inheritance, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>initGrps.sh, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>initial credentials, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>inoperative, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>install, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>installation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>integrate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>integrity, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>inter-domain, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>inter-operability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>interactive help, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>interdomain trusts, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>interfaces, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>intermittent, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>internationalization, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Internet Explorer, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>Internet Information Server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>interoperability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>IP forwarding, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>IPC$, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>iptables, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>IRC, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>isolated, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Italian, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>J</h3><dl><dt>jobs, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>joining a domain, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></div><div class="indexdiv"><h3>K</h3><dl><dt>KDC, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>Heimdal, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>interoperability, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>libraries, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>MIT, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>unspecified fields, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>kerberos, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>Kerberos ticket, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>kinit, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Kixtart, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>klist, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>krb5, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>krb5.conf, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt></dl></div><div class="indexdiv"><h3>L</h3><dl><dt>LAM, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dd><dl><dt>configuration editor, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>configuration file, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>login screen, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>opening screen, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>profile, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>wizard, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt></dl></dd><dt>large domain, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>LDAP, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2573037">Preliminary Advice: Dangers Can Be Avoided</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2583767">Introduction</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>backend, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>database, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>directory, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>initial configuration, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>master/slave</dt><dd><dl><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>preload, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>schema, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>secure, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>updates, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>ldap, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>LDAP Account Manager (see LAM)</dt><dt>LDAP backend, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>LDAP database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>LDAP Interchange Format (see LDIF)</dt><dt>LDAP server, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>LDAP-transfer-LDIF.txt, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>ldap.conf, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapsam, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>ldapsam backend, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>ldapsearch, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>LDIF, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt><dt>leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Lightweight Directory Access Protocol (see LDAP)</dt><dt>limit, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Linux desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>Linux Standards Base (see LSB)</dt><dt>LMB, <a class="indexterm" href="primer.html#id2626028">Findings</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>LMHOSTS, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>load distribution, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Local Group Policy, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>Local Master Announcement, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>Local Master Browser (see LMB)</dt><dt>localhost, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>lock directory, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>locking</dt><dd><dl><dt>Application level, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Client side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Server side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>logging, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>login, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>loglevel, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>logon credentials, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>logon hours, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>logon machines, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon path, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>logon scrip, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>logon script, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2581163">Preparation of Logon Scripts</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon server, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon services, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon time, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>logon traffic, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon.kix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>loopback, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>low performance, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>lower-case, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>lpadmin, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>LSB, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>M</h3><dl><dt>machine, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>machine account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>machine accounts, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>machine secret password, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>MACHINE.SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>mailing list, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>mailing lists, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>managed, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>management, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dd><dl><dt>group, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>User, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>mandatory profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Mandrake, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>mapped drives, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>mapping, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>consistent, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt></dl></dd><dt>Mars_NWE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>material, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>memberUID, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>memory requirements, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>merge, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>merged, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>meta-directory, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>meta-service, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Microsoft Access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft Excel, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft ISA, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>Microsoft Management Console (see MMC)</dt><dt>Microsoft Office, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>Microsoft Outlook</dt><dd><dl><dt>PST files, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>migrate, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>migration, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dd><dl><dt>objectives, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd><dt>Migration speed, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mime type, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>mime types, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>missing RPC's, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>MIT, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>MIT Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>MIT kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>MIT KRB5, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>mixed mode, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>mixed-mode, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>MMC, <a class="indexterm" href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>mobile computing, <a class="indexterm" href="small.html#id2555545">Dissection and Discussion</a></dt><dt>mobility, <a class="indexterm" href="2000users.html#id2584139">Technical Issues</a></dt><dt>modularization, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>modules, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>MS Access</dt><dd><dl><dt>validate, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt></dl></dd><dt>MS Outlook, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>PST file, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>MS Windows Server 2003, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>MS Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>MSDFS, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt><dt>multi-subnet, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>multi-user</dt><dd><dl><dt>access, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>data access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>multiple directories, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>multiple domain controllers, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>multiple group mappings, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mutual assistance, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>My Documents, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>My Network Places, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>mysqlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>N</h3><dl><dt>name resolution, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dd><dl><dt>Defective, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>name resolve order, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>name service switch, <a class="indexterm" href="small.html#id2555812">Implementation</a> (see NSS)</dt><dt>named, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>NAT, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>native, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>net</dt><dd><dl><dt>ads</dt><dd><dl><dt>info, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>status, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>getlocalsid, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>groupmap</dt><dd><dl><dt>add, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>list, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>modify, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt></dl></dd><dt>rpc</dt><dd><dl><dt>info, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>join, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>vampire, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt></dl></dd><dt>setlocalsid, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>NetBIOS, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>name cache, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>name resolution</dt><dd><dl><dt>delays, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Node Type, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></dd><dt>netbios</dt><dd><dl><dt>machine name, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a></dt></dl></dd><dt>netbios forwarding, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>NetBIOS name, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>aliases, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>netbios name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>NETLOGON, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="happy.html#id2581407">Windows Client Configuration</a></dt><dt>netlogon, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Netlogon, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>netmask, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>Netware, <a class="indexterm" href="small.html">Small Office Networking</a></dt><dt>NetWare, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>network</dt><dd><dl><dt>administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>analyzer, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>bandwidth, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>broadcast, <a class="indexterm" href="primer.html#id2625592">Introduction</a></dt><dt>captures, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>collisions, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>load, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>logon scripts, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>management, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>multi-segment, <a class="indexterm" href="happy.html#id2571190">Introduction</a></dt><dt>overload, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>performance, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>routed, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>segment, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>sniffer, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>timeout, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>timeouts, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>trace, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>traffic</dt><dd><dl><dt>observation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>wide-area, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt></dl></dd><dt>Network Address Translation (see NAT)</dt><dt>network administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network attached storage (see NAS)</dt><dt>network bandwidth</dt><dd><dl><dt>utilization, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Network Default Profile, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>network hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>network hygiene, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>network Identities, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>network load factors, <a class="indexterm" href="Big500users.html#id2565398">Dissection and Discussion</a></dt><dt>Network Neighborhood, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network segment, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>network segments, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>network share, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>networking</dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>networking hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>next generation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>NextFreeUnixId, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NFS server, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>NICs, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>NIS, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>nis, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>NIS schema, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS server, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS+, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>nisplus, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>NLM, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>nmap, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>nmbd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>nobody, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>Novell, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>Novell SUSE SLES 9, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NSS, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a> (see same service switch)</dt><dt>nss_ldap, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>nt acl support, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>NT4 registry, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>NTLM, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>NTLM authentication daemon, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>NTLMSSP, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>NTLMSSP_AUTH, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>ntlm_auth, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>NTP, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>NTUSER.DAT, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NULL connection, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>NULL session, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>NULL-Session, <a class="indexterm" href="primer.html#id2628081">Discussion</a></dt></dl></div><div class="indexdiv"><h3>O</h3><dl><dt>objectClass, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>off-site storage, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Open Magazine, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>Open Source, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>openldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>OpenOffice, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>operating profiles, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>oplock break, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>oplocks, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Oplocks</dt><dd><dl><dt>disabled, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></dd><dt>opportunistic</dt><dd><dl><dt>locking, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt></dl></dd><dt>opportunistic locking, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>optimized, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>organizational units, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>OS/2, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Outlook</dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt></dl></dd><dt>Outlook Address Book, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>Outlook Express, <a class="indexterm" href="secure.html#id2559309">Political Issues</a>, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>over-ride, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>over-ride controls, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>over-rule, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615027">Using MS Windows Explorer (File Manager)</a></dt><dt>overheads, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>ownership, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></div><div class="indexdiv"><h3>P</h3><dl><dt>package, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>package names, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>packages, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>PADL, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>PADL LDAP tools, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>PADL Software, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>paid-for support, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>PAM, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>pam_ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>pam_ldap.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>pam_unix2.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dd><dl><dt>use_ldap, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt></dl></dd><dt>parameters, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>passdb backend, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>passdb.tdb, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>passwd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>password</dt><dd><dl><dt>backend, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>password caching, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>password change, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>password length, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>payroll, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>pdbedit, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>PDC, <a class="indexterm" href="Big500users.html#id2565292">Assignment Tasks</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>PDC/BDC ratio, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>PDF, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>performance, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a>, <a class="indexterm" href="HA.html#id2618959">Introduction</a>, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>performance degradation, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Perl, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>permission, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>permissions, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>excessive, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>group, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>user, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></dd><dt>Permissions, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>permits, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>permitted group, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>PHP, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>PHP4, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>pile-driver, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>ping, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>pitfalls, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Pluggable Authentication Modules (see PAM)</dt><dt>policy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>poor performance, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>POP3, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>Posix, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>POSIX, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Posix accounts, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Posix ACLs, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>PosixAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>posixAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postfix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postscript, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>powers, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>precaution, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>presence and leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>price paid, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>primary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>principals, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>print filter, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>print queue, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>print spooler, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a></dt><dt>Print Test Page, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>printcap name, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>printer validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>printers</dt><dd><dl><dt>Advanced, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Default Settings, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>General, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Properties, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Security, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Sharing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>printing, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dd><dl><dt>drag-and-drop, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>dumb, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>point-n-click, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt></dl></dd><dt>privacy, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Privilege Attribute Certificates (see PAC)</dt><dt>privilege controls, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>privileged pipe, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>privileges, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>problem report, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>problem resolution, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>product defects, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>professional support, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>profile</dt><dd><dl><dt>default, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>mandatory, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>roaming, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>profile path, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>profile share, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>profiles, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>profiles share, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>programmer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>project, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>project maintainers, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Properties, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>proprietary, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protected, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protection, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protocol</dt><dd><dl><dt>negotiation, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>protocol analysis, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>provided services, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>proxy, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>PST file, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>public specifications, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>purchase support, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>Q</h3><dl><dt>Qbasic, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>qualified problem, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>R</h3><dl><dt>RAID, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>RAID controllers, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>Raw Print Through, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw printing, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>Rbase, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>rcldap, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>realm, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>recognize, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>record locking, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>recursively, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Red Hat, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>Red Hat Fedora Linux, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Red Hat Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="simple.html#AccountingOffice">Accounting Office</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>redirected folders, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>refereed standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>regedit, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>regedt32, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dd><dl><dt>keys</dt><dd><dl><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>SECURITY, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd></dl></dd><dt>registry change, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Registry Editor, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry hacks, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>registry keys, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>reimburse, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>rejected, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>rejoin, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>reliability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt><dt>remote announce, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>remote browse sync, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>remote procedure call (see RPC)</dt><dt>replicate, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>replicated, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>requesting payment, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>resilient, <a class="indexterm" href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></dt><dt>resolution, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>resolve, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>response, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>responsibility, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>responsible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>restrict anonymous, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>restricted export, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Restrictive security, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>reverse DNS, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>rfc2307bis, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a></dt><dt>RID, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>risk, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>road-map, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>published, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>roaming profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>roaming profiles, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>routed network, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>router, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>routers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>RPC, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>rpc, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>rpcclient, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>RPM, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dd><dl><dt>install, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>rpm, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>RPMs, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>rpms, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>rsync, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>rsyncd.conf, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>run-time control files, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>S</h3><dl><dt>safe-guards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>samba, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>Samba, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Samba accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>samba cluster, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>samba control script, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>Samba Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Samba Domain server, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Samba RPM Packages, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>Samba Tea, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>sambaDomainName, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>sambaGroupMapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaSAMAccount, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>SambaSamAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>sambaSamAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaXP conference, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>SAN, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>SAS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>scalability, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>scalable, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>schannel, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>schema, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>scripts, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>secondary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a></dt><dt>secret, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>secrets.tdb, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>secure account password, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>secure connections, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>secure networking, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>secure networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dd><dl><dt>identifier, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>share mode, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>user mode, <a class="indexterm" href="simple.html#id2553821">Dissection and Discussion</a></dt></dl></dd><dt>Security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Security Account Manager (see SAM)</dt><dt>security controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security descriptors, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>security fixes, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security updates, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SerNet, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>server</dt><dd><dl><dt>domain member, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>stand-alone, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>service, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dd><dl><dt>smb</dt><dd><dl><dt>start, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a></dt></dl></dd></dl></dd><dt>Service Packs, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>services provided, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>session setup, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>Session Setup, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></dt><dt>SessionSetUpAndX, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>set primary group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>setfacl, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>severely degrade, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>SFU, <a class="indexterm" href="unixclients.html#id2596287">IDMAP, Active Directory, and MS Services for UNIX 3.5</a></dt><dt>SGID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>shadow-utils, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Share Access Controls, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>share ACLs, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share definition, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Share Definition</dt><dd><dl><dt>Controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt></dl></dd><dt>share definition controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share level access controls, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share level ACL, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Share Permissions, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>shared resource, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>shares, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SID, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt><dt>side effects, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>Sign'n'seal, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>silent return, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>simple, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>Single Sign-On (see SSO)</dt><dt>slapcat, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>slapd, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>slapd.conf, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>slow logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>slow network, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>slurpd, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>smart printing, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>SMB, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>SMB passwords, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>SMB/CIFS, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>smbclient, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>smbd, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dd><dl><dt>location of files, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></dd><dt>smbfs, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbldap-groupadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-groupmod, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-passwd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-populate, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>smbldap-tools updating, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>smbldap-useradd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>smbldap-usermod, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbmnt, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbmount, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbpasswd, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>smbumnt, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbumount, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>SMTP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>snap-shot, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>socket address, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>socket options, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>solve, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>source code, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>SPNEGO, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>SQL, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Squid, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617976">Squid Configuration</a></dt><dt>squid, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Squid proxy, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>SRVTOOLS.EXE, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>SSL, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>stand-alone server, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>starting CUPS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting dhcpd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dd><dl><dt>nmbd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>smbd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>winbindd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt></dl></dd><dt>startingCUPS, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>startup script, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>sticky bit, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>storage capacity, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>strategic, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>strategy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>straw-man, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>strict sync, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>stripped, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>strong cryptography, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>subscription, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>SUID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>Sun ONE Identity Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>super daemon, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>support, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>survey, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>SUSE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>SUSE Enterprise Linux Server, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>SUSE Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>SWAT, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>sync always, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>synchronization, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>synchronize, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>synchronized, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>syslog, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>system level logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>system security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>T</h3><dl><dt>tattooing, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>TCP/IP, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>tdbdump, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>tdbsam, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>testparm, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>ticket, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>time server, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>Tivoli Directory Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>TLS, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>token, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>tool, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>TOSHARG2, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>track record, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>traffic collisions, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>transaction processing, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>transactional, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>transfer, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>translate, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>traverse, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>tree, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Tree Connect, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></dt><dt>trust account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>trusted computing, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Trusted Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>trusted domains, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>trusted third-party, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>trusting, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>turn-around time, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>U</h3><dl><dt>UDP</dt><dd><dl><dt>broadcast, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt></dl></dd><dt>UID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>un-join, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>unauthorized activities, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>UNC name, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>unencrypted, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>Unicast, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>unicode, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Universal Naming Convention (see UNC name)</dt><dt>UNIX, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt></dl></dd><dt>UNIX accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>UNIX/Linux server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unix2dos, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>unknown, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unsupported software, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>update, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>updates, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>updating smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>upgrade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>uppercase, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>user</dt><dd><dl><dt>management, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>user account, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>User and Group Controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>user credentials, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>user errors, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user groups, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>user identities, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>user logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>User Manager, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>User Mode, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>useradd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>userdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>usermod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>username, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>username map, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>UTF-8, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>utilities, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>V</h3><dl><dt>valid users, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>validate, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>validated, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>validation, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>vampire, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>vendor, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>vendors, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>VFS modules, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>virus, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>VPN, <a class="indexterm" href="2000users.html#id2583797">Assignment Tasks</a></dt><dt>vulnerabilities, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>W</h3><dl><dt>wbinfo, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>weakness, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>web</dt><dd><dl><dt>caching, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>proxying, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt></dl></dd><dt>Web</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dd><dl><dt>access, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt></dl></dd></dl></dd><dt>Web browsers, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>WebClient, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>WHATSNEW.txt, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></dt><dt>white-pages, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>wide-area, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>wide-area network, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>winbind, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589354">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a></dt><dt>Winbind, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>winbind trusted domains only, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>winbind use default domain, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>winbindd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>winbindd_cache.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>winbindd_idmap.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Windows, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>NT, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>Windows 2000 ACLs, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>Windows 2003 Serve, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows 200x ACLs, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Windows accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Windows ACLs, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Windows Address Book, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Windows ADS Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>Windows clients, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Windows Explorer, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>Windows explorer, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Windows security identifier (see SID)</dt><dt>Windows Servers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows Services for UNIX (see SUS)</dt><dt>Windows XP, <a class="indexterm" href="small.html#id2555484">Assignment Tasks</a></dt><dt>WINS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>name resolution, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>server, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt></dl></dd><dt>WINS server, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>WINS serving, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins support, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins.dat, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Wireshark, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>wireshark, <a class="indexterm" href="primer.html#id2625769">Exercises</a></dt><dt>Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>workgroup, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a></dt><dt>Workgroup Announcement, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>workstation, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>wrapper, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>write lock, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></div><div class="indexdiv"><h3>X</h3><dl><dt>xinetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>XML, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>xmlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>Y</h3><dl><dt>YaST, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>Yellow Pages, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>yellow pages (see NIS)</dt></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> </td></tr><tr><td width="40%" align="left" valign="top">Glossary </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> </td></tr></table></div></body></html> -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/kerberos.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 11. Active Directory, Kerberos, and Security</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="RefSection.html" title="Part III. Reference Section"><link rel="next" href="DomApps.html" title="Chapter 12. Integrating Additional Services"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 11. Active Directory, Kerberos, and Security</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="RefSection.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="DomApps.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="kerberos"></a>Chapter 11. Active Directory, Kerberos, and Security</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id26146 72">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></div><p><a class="indexterm" name="id2610549"></a>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 11. Active Directory, Kerberos, and Security</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="RefSection.html" title="Part III. Reference Section"><link rel="next" href="DomApps.html" title="Chapter 12. Integrating Additional Services"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 11. Active Directory, Kerberos, and Security</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="RefSection.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="DomApps.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="kerberos"></a>Chapter 11. Active Directory, Kerberos, and Security</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></div><p><a class="indexterm" name="id2610549"></a> 2 2 By this point in the book, you have been exposed to many Samba-3 features and capabilities. 3 3 More importantly, if you have implemented the examples given, you are well on your way to becoming … … 527 527 Microsoft Office files (Word and Excel) to a network drive. Here is the typical sequence: 528 528 </p><div class="orderedlist"><ol type="1"><li><p> 529 A user opens a Wor kdocument from a network drive. The file was owned by user <code class="constant">janetp</code>529 A user opens a Word document from a network drive. The file was owned by user <code class="constant">janetp</code> 530 530 and [users], and was set read/write-enabled for everyone. 531 A user opens a Word document from a network drive. The file was owned by user <code class="constant">janetp</code> 532 and <code class="constant">users</code>, and was set read/write-enabled for everyone. 531 533 </p></li><li><p> 532 534 File changes and edits are made. … … 543 545 want to know when this “<span class="quote">bug</span>” will be fixed. The fact is, this is not a bug in Samba at all. 544 546 Here is the real sequence of what happens in this case. 545 </p><p><a class="indexterm" name="id26144 30"></a><a class="indexterm" name="id2614438"></a><a class="indexterm" name="id2614446"></a>547 </p><p><a class="indexterm" name="id2614440"></a><a class="indexterm" name="id2614448"></a><a class="indexterm" name="id2614456"></a> 546 548 When the user saves a file, MS Word creates a new (temporary) file. This file is naturally owned 547 549 by the user who creates the file (<code class="constant">billc</code>) and has the permissions that follow … … 561 563 simple steps to create a share in which all files will consistently be owned by the same user and the 562 564 same group: 563 </p><div class="procedure"><a name="id2614 493"></a><p class="title"><b>Procedure 11.2. Using Directory Permissions to Force File User and Group Ownership</b></p><ol type="1"><li><p>565 </p><div class="procedure"><a name="id2614502"></a><p class="title"><b>Procedure 11.2. Using Directory Permissions to Force File User and Group Ownership</b></p><ol type="1"><li><p> 564 566 Change your share definition so that it matches this pattern: 565 567 </p><pre class="screen"> … … 569 571 read only = No 570 572 </pre><p> 571 </p></li><li><p><a class="indexterm" name="id26145 19"></a><a class="indexterm" name="id2614530"></a>573 </p></li><li><p><a class="indexterm" name="id2614528"></a><a class="indexterm" name="id2614539"></a> 572 574 Set consistent user and group permissions recursively down the directory tree as shown here: 573 575 </p><pre class="screen"> 574 576 <code class="prompt">root# </code> chown -R janetp.users /usr/data/finance 575 577 </pre><p> 576 </p></li><li><p><a class="indexterm" name="id26145 62"></a>578 </p></li><li><p><a class="indexterm" name="id2614571"></a> 577 579 Set the files and directory permissions to be read/write for owner and group, and not accessible 578 580 to others (everyone), using the following command: … … 580 582 <code class="prompt">root# </code> chmod ug+rwx,o-rwx /usr/data/finance 581 583 </pre><p> 582 </p></li><li><p><a class="indexterm" name="id2614 591"></a>584 </p></li><li><p><a class="indexterm" name="id2614600"></a> 583 585 Set the SGID (supergroup) bit on all directories from the top down. This means all files 584 586 can be created with the permissions of the group set on the directory. It means all users … … 590 592 </pre><p> 591 593 592 </p></li><li><p><a class="indexterm" name="id26146 31"></a><a class="indexterm" name="id2614639"></a><a class="indexterm" name="id2614647"></a>594 </p></li><li><p><a class="indexterm" name="id2614641"></a><a class="indexterm" name="id2614649"></a><a class="indexterm" name="id2614657"></a> 593 595 Make sure all users that must have read/write access to the directory have 594 596 <code class="constant">finance</code> group membership as their primary group, 595 597 for example, the group they belong to in <code class="filename">/etc/passwd</code>. 596 </p></li></ol></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26146 72"></a>Managing Windows 200x ACLs</h3></div></div></div><p><a class="indexterm" name="id2614679"></a><a class="indexterm" name="id2614687"></a><a class="indexterm" name="id2614695"></a><a class="indexterm" name="id2614703"></a>598 </p></li></ol></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2614682"></a>Managing Windows 200x ACLs</h3></div></div></div><p><a class="indexterm" name="id2614688"></a><a class="indexterm" name="id2614696"></a><a class="indexterm" name="id2614704"></a><a class="indexterm" name="id2614712"></a> 597 599 Samba must translate Windows 2000 ACLs to UNIX POSIX ACLs. This has some interesting side effects because 598 600 there is not a one-to-one equivalence between them. The as-close-as-possible ACLs match means … … 602 604 There are two possible ways to set ACLs on UNIX/Linux file systems from a Windows network workstation, 603 605 either via File Manager or via the Microsoft Management Console (MMC) Computer Management interface. 604 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26147 27"></a>Using the MMC Computer Management Interface</h4></div></div></div><div class="procedure"><ol type="1"><li><p>606 </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2614736"></a>Using the MMC Computer Management Interface</h4></div></div></div><div class="procedure"><ol type="1"><li><p> 605 607 From a Windows 200x/XP Professional workstation, log on to the domain using the Domain Administrator 606 608 account (on Samba domains, this is usually the account called <code class="constant">root</code>). … … 617 619 </p></li><li><p> 618 620 In the left panel, click <span class="guimenu">Computer Management (FRODO)</span> → <span class="guimenuitem">[+] Shared Folders</span> → <span class="guimenuitem">Shares</span>. 619 </p></li><li><p><a class="indexterm" name="id261491 0"></a><a class="indexterm" name="id2614918"></a><a class="indexterm" name="id2614925"></a><a class="indexterm" name="id2614933"></a>621 </p></li><li><p><a class="indexterm" name="id2614919"></a><a class="indexterm" name="id2614927"></a><a class="indexterm" name="id2614935"></a><a class="indexterm" name="id2614943"></a> 620 622 In the right panel, double-click on the share on which you wish to set/edit ACLs. This 621 623 brings up the Properties panel. Click the <span class="guimenu">Security</span> tab. It is best … … 624 626 functionality under the <code class="constant">Permissions</code> tab can be utilized with respect 625 627 to a Samba domain server. 626 </p></li><li><p><a class="indexterm" name="id26149 73"></a><a class="indexterm" name="id2614981"></a>628 </p></li><li><p><a class="indexterm" name="id2614982"></a><a class="indexterm" name="id2614990"></a> 627 629 You may now edit/add/remove access control settings. Be very careful. Many problems have been 628 630 created by people who decided that everyone should be rejected but one particular group should … … 633 635 When you are done with editing, close all panels by clicking through the <span class="guimenu">OK</span> 634 636 buttons until the last panel closes. 635 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26150 18"></a>Using MS Windows Explorer (File Manager)</h4></div></div></div><p>637 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615027"></a>Using MS Windows Explorer (File Manager)</h4></div></div></div><p> 636 638 The following alternative method may be used from a Windows workstation. In this example we work 637 639 with a domain called <code class="constant">MEGANET</code>, a server called <code class="constant">MASSIVE</code>, and a … … 641 643 Click <span class="guimenu">Start</span> → <span class="guimenuitem">[right-click] My Computer</span> → <span class="guimenuitem">Explore</span> → <span class="guimenuitem">[left panel] [+] My Network Places</span> → <span class="guimenuitem">[+] Entire Network</span> → <span class="guimenuitem">[+] Microsoft Windows Network</span> → <span class="guimenuitem">[+] Meganet</span> → <span class="guimenuitem">[+] Massive</span> → <span class="guimenuitem">[right-click] Apps</span> → <span class="guimenuitem">Properties</span> → <span class="guimenuitem">Security</span> → <span class="guimenuitem">Advanced</span>. This opens a panel that has four tabs. Only the functionality under the 642 644 <code class="constant">Permissions</code> tab can be utilized for a Samba domain server. 643 </p></li><li><p><a class="indexterm" name="id26151 42"></a><a class="indexterm" name="id2615150"></a>645 </p></li><li><p><a class="indexterm" name="id2615152"></a><a class="indexterm" name="id2615160"></a> 644 646 You may now edit/add/remove access control settings. Be very careful. Many problems have been 645 647 created by people who decided that everyone should be rejected but one particular group should … … 650 652 When you are done with editing, close all panels by clicking through the <span class="guimenu">OK</span> 651 653 buttons until the last panel closes. 652 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26151 89"></a>Setting Posix ACLs in UNIX/Linux</h4></div></div></div><p><a class="indexterm" name="id2615196"></a><a class="indexterm" name="id2615204"></a>654 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615198"></a>Setting Posix ACLs in UNIX/Linux</h4></div></div></div><p><a class="indexterm" name="id2615205"></a><a class="indexterm" name="id2615213"></a> 653 655 Yet another alternative method for setting desired security settings on the shared resource files and 654 656 directories can be achieved by logging into UNIX/Linux and setting POSIX ACLs directly using command-line … … 673 675 other::r-x 674 676 </pre><p> 675 </p></li><li><p><a class="indexterm" name="id26152 78"></a>677 </p></li><li><p><a class="indexterm" name="id2615287"></a> 676 678 You want to add permission for <code class="constant">AppsMgrs</code> to enable them to 677 679 manage the applications (apps) share. It is important to set the ACL recursively … … 696 698 </pre><p> 697 699 This confirms that the change of POSIX ACL permissions has been effective. 698 </p></li><li><p><a class="indexterm" name="id26153 34"></a><a class="indexterm" name="id2615341"></a><a class="indexterm" name="id2615349"></a><a class="indexterm" name="id2615357"></a><a class="indexterm" name="id2615365"></a>700 </p></li><li><p><a class="indexterm" name="id2615343"></a><a class="indexterm" name="id2615351"></a><a class="indexterm" name="id2615359"></a><a class="indexterm" name="id2615367"></a><a class="indexterm" name="id2615375"></a> 699 701 It is highly recommended that you read the online manual page for the <code class="literal">setfacl</code> 700 702 and <code class="literal">getfacl</code> commands. This provides information regarding how to set/read the default 701 703 ACLs and how that may be propagated through the directory tree. In Windows ACLs terms, this is the equivalent 702 704 of setting <code class="constant">inheritance</code> properties. 703 </p></li></ol></div></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2615 399"></a>Key Points Learned</h3></div></div></div><p>705 </p></li></ol></div></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2615408"></a>Key Points Learned</h3></div></div></div><p> 704 706 The mish-mash of issues were thrown together into one chapter because it seemed like a good idea. 705 707 Looking back, this chapter could be broken into two, but it's too late now. It has been done. 706 708 The highlights covered are as follows: 707 </p><div class="itemizedlist"><ul type="disc"><li><p><a class="indexterm" name="id26154 16"></a><a class="indexterm" name="id2615424"></a><a class="indexterm" name="id2615432"></a><a class="indexterm" name="id2615440"></a>709 </p><div class="itemizedlist"><ul type="disc"><li><p><a class="indexterm" name="id2615426"></a><a class="indexterm" name="id2615434"></a><a class="indexterm" name="id2615442"></a><a class="indexterm" name="id2615450"></a> 708 710 Winbind honors and does not override account controls set in Active Directory. 709 711 This means that password change, logon hours, and so on, are (or soon will be) enforced … … 711 713 change is enforced. At this time, if logon hours expire, the user is not forcibly 712 714 logged off. That may be implemented at some later date. 713 </p></li><li><p><a class="indexterm" name="id26154 59"></a><a class="indexterm" name="id2615467"></a>715 </p></li><li><p><a class="indexterm" name="id2615468"></a><a class="indexterm" name="id2615476"></a> 714 716 Sign'n'seal (plus schannel support) has been implemented in Samba-3. Beware of potential 715 717 problems acknowledged by Microsoft as having been fixed but reported by some as still 716 718 possibly an open issue. 717 </p></li><li><p><a class="indexterm" name="id26154 83"></a><a class="indexterm" name="id2615491"></a><a class="indexterm" name="id2615498"></a><a class="indexterm" name="id2615506"></a>719 </p></li><li><p><a class="indexterm" name="id2615492"></a><a class="indexterm" name="id2615500"></a><a class="indexterm" name="id2615508"></a><a class="indexterm" name="id2615516"></a> 718 720 The combination of Kerberos 5, plus OpenLDAP, plus Samba, cannot replace Microsoft 719 721 Active Directory. The possibility to do this is not planned in the current Samba-3 … … 724 726 the four key methodologies was reviewed with specific reference to example deployment 725 727 techniques. 726 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26155 33"></a>Questions and Answers</h2></div></div></div><p>727 </p><div class="qandaset"><dl><dt> <a href="kerberos.html#id26155 49">728 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2615543"></a>Questions and Answers</h2></div></div></div><p> 729 </p><div class="qandaset"><dl><dt> <a href="kerberos.html#id2615558"> 728 730 Does Samba-3 require the Sign'n'seal registry hacks needed by Samba-2? 729 </a></dt><dt> <a href="kerberos.html#id26156 19">731 </a></dt><dt> <a href="kerberos.html#id2615629"> 730 732 Does Samba-3 support Active Directory? 731 </a></dt><dt> <a href="kerberos.html#id26156 50">733 </a></dt><dt> <a href="kerberos.html#id2615660"> 732 734 When Samba-3 is used with Active Directory, is it necessary to run mixed-mode operation, as was 733 735 necessary with Samba-2? 734 </a></dt><dt> <a href="kerberos.html#id26156 89">736 </a></dt><dt> <a href="kerberos.html#id2615698"> 735 737 Is it safe to set share-level access controls in Samba? 736 </a></dt><dt> <a href="kerberos.html#id26157 18">738 </a></dt><dt> <a href="kerberos.html#id2615728"> 737 739 Is it mandatory to set share ACLs to get a secure Samba-3 server? 738 </a></dt><dt> <a href="kerberos.html#id2615 795">740 </a></dt><dt> <a href="kerberos.html#id2615804"> 739 741 The valid users did not work on the [homes]. 740 742 Has this functionality been restored yet? 741 </a></dt><dt> <a href="kerberos.html#id26158 61">743 </a></dt><dt> <a href="kerberos.html#id2615870"> 742 744 Is the bias against use of the force user and force group 743 745 really warranted? 744 </a></dt><dt> <a href="kerberos.html#id26159 24">746 </a></dt><dt> <a href="kerberos.html#id2615934"> 745 747 The example given for file and directory access control forces all files to be owned by one 746 748 particular user. I do not like that. Is there any way I can see who created the file? 747 </a></dt><dt> <a href="kerberos.html#id26159 72">749 </a></dt><dt> <a href="kerberos.html#id2615982"> 748 750 In the book, “The Official Samba-3 HOWTO and Reference Guide”, you recommended use 749 751 of the Windows NT4 Server Manager (part of the SRVTOOLS.EXE) utility. Why 750 752 have you mentioned only the use of the Windows 200x/XP MMC Computer Management utility? 751 </a></dt><dt> <a href="kerberos.html#id26160 39">753 </a></dt><dt> <a href="kerberos.html#id2616048"> 752 754 I tried to set valid users = @Engineers, but it does not work. My Samba 753 755 server is an Active Directory domain member server. Has this been fixed now? 754 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id26155 49"></a><a name="id2615551"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615554"></a><a class="indexterm" name="id2615562"></a>756 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2615558"></a><a name="id2615561"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615564"></a><a class="indexterm" name="id2615572"></a> 755 757 Does Samba-3 require the <code class="constant">Sign'n'seal</code> registry hacks needed by Samba-2? 756 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26155 82"></a><a class="indexterm" name="id2615589"></a><a class="indexterm" name="id2615597"></a>758 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615591"></a><a class="indexterm" name="id2615599"></a><a class="indexterm" name="id2615607"></a> 757 759 No. Samba-3 fully supports <code class="constant">Sign'n'seal</code> as well as <code class="constant">schannel</code> 758 760 operation. The registry change should not be applied when Samba-3 is used as a domain controller. 759 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26156 19"></a><a name="id2615622"></a></td><td align="left" valign="top"><p>761 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615629"></a><a name="id2615631"></a></td><td align="left" valign="top"><p> 760 762 Does Samba-3 support Active Directory? 761 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26156 32"></a>763 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615642"></a> 762 764 Yes. Samba-3 can be a fully participating native mode Active Directory client. Samba-3 does not 763 765 provide Active Directory services. It cannot be used to replace a Microsoft Active Directory 764 766 server implementation. Samba-3 can function as an Active Directory client (workstation) toolkit, 765 767 and it can function as an Active Directory domain member server. 766 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26156 50"></a><a name="id2615653"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615656"></a>768 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615660"></a><a name="id2615662"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615665"></a> 767 769 When Samba-3 is used with Active Directory, is it necessary to run mixed-mode operation, as was 768 770 necessary with Samba-2? 769 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26156 72"></a>771 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615682"></a> 770 772 No. Samba-3 can be used with NetBIOS over TCP/IP disabled, just as can be done with Windows 200x 771 773 Server and 200x/XPPro client products. It is no longer necessary to run mixed-mode operation, 772 774 because Samba-3 can join a native Windows 2003 Server ADS domain. 773 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26156 89"></a><a name="id2615691"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615694"></a>775 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615698"></a><a name="id2615701"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615704"></a> 774 776 Is it safe to set share-level access controls in Samba? 775 777 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> … … 777 779 very mature technology. Not enough sites make use of this powerful capability, neither on 778 780 Windows server or with Samba servers. 779 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26157 18"></a><a name="id2615720"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615724"></a>781 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615728"></a><a name="id2615730"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615733"></a> 780 782 Is it mandatory to set share ACLs to get a secure Samba-3 server? 781 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26157 39"></a><a class="indexterm" name="id2615747"></a><a class="indexterm" name="id2615755"></a><a class="indexterm" name="id2615764"></a><a class="indexterm" name="id2615772"></a>783 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615749"></a><a class="indexterm" name="id2615757"></a><a class="indexterm" name="id2615765"></a><a class="indexterm" name="id2615773"></a><a class="indexterm" name="id2615781"></a> 782 784 No. Samba-3 honors UNIX/Linux file system security, supports Windows 200x ACLs, and provides 783 785 means of securing shares through share definition controls in the <code class="filename">smb.conf</code> file. The additional 784 786 support for share-level ACLs is like frosting on the cake. It adds to security but is not essential 785 787 to it. 786 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615 795"></a><a name="id2615797"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615800"></a>788 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615804"></a><a name="id2615806"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615810"></a> 787 789 The <em class="parameter"><code>valid users</code></em> did not work on the <em class="parameter"><code>[homes]</code></em>. 788 790 Has this functionality been restored yet? 789 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26158 28"></a>791 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615837"></a> 790 792 Yes. This was fixed in Samba-3.0.2. The use of this parameter is strongly recommended as a safeguard 791 793 on the <em class="parameter"><code>[homes]</code></em> meta-service. The correct way to specify this is: 792 794 <a class="link" href="smb.conf.5.html#VALIDUSERS" target="_top">valid users = %S</a>. 793 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26158 61"></a><a name="id2615863"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615866"></a><a class="indexterm" name="id2615874"></a><a class="indexterm" name="id2615882"></a>795 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615870"></a><a name="id2615872"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615876"></a><a class="indexterm" name="id2615883"></a><a class="indexterm" name="id2615891"></a> 794 796 Is the bias against use of the <em class="parameter"><code>force user</code></em> and <em class="parameter"><code>force group</code></em> 795 797 really warranted? 796 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26159 09"></a>798 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615918"></a> 797 799 There is no bias. There is a determination to recommend the right tool for the task at hand. 798 800 After all, it is better than putting users through performance problems, isn't it? 799 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26159 24"></a><a name="id2615926"></a></td><td align="left" valign="top"><p>801 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615934"></a><a name="id2615936"></a></td><td align="left" valign="top"><p> 800 802 The example given for file and directory access control forces all files to be owned by one 801 803 particular user. I do not like that. Is there any way I can see who created the file? 802 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26159 39"></a>804 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615948"></a> 803 805 Sure. You do not have to set the SUID bit on the directory. Simply execute the following command 804 806 to permit file ownership to be retained by the user who created it: … … 808 810 Note that this required no more than removing the <code class="constant">u</code> argument so that the 809 811 SUID bit is not set for the owner. 810 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26159 72"></a><a name="id2615974"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615978"></a>812 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615982"></a><a name="id2615984"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615987"></a> 811 813 In the book, “<span class="quote">The Official Samba-3 HOWTO and Reference Guide</span>”, you recommended use 812 814 of the Windows NT4 Server Manager (part of the <code class="filename">SRVTOOLS.EXE</code>) utility. Why 813 815 have you mentioned only the use of the Windows 200x/XP MMC Computer Management utility? 814 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id26160 06"></a><a class="indexterm" name="id2616013"></a>816 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2616015"></a><a class="indexterm" name="id2616023"></a> 815 817 Either tool can be used with equal effect. There is no benefit of one over the other, except that 816 818 the MMC utility is present on all Windows 200x/XP systems and does not require additional software … … 818 820 Samba-controlled domain, the only tool that permits that is the NT4 Domain User Manager, which 819 821 is provided as part of the <code class="filename">SRVTOOLS.EXE</code> utility. 820 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26160 39"></a><a name="id2616041"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2616044"></a><a class="indexterm" name="id2616052"></a><a class="indexterm" name="id2616060"></a>822 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2616048"></a><a name="id2616051"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2616054"></a><a class="indexterm" name="id2616062"></a><a class="indexterm" name="id2616070"></a> 821 823 I tried to set <em class="parameter"><code>valid users = @Engineers</code></em>, but it does not work. My Samba 822 824 server is an Active Directory domain member server. Has this been fixed now? -
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/primer.html
r231 r272 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 16. Networking Primer</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"><link rel="next" href="apa.html" title="Appendix A. GNU General Public License version 3"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 16. Networking Primer</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="primer"></a>Chapter 16. Networking Primer</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="primer.html#id26254 07">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></div><p>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 16. Networking Primer</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"><link rel="next" href="apa.html" title="Appendix A. GNU General Public License version 3"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 16. Networking Primer</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="primer"></a>Chapter 16. Networking Primer</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></div><p> 2 2 You are about to use the equivalent of a microscope to look at the information 3 3 that runs through the veins of a Windows network. We do more to observe the information than … … 9 9 Samba can be configured with a minimum of complexity. Simplicity should be mastered 10 10 before you get too deeply into complexities. Let's get moving: we have work to do. 11 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26254 07"></a>Requirements and Notes</h2></div></div></div><p>11 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625430"></a>Requirements and Notes</h2></div></div></div><p> 12 12 Successful completion of this primer requires two Microsoft Windows 9x/Me Workstations 13 13 as well as two Microsoft Windows XP Professional Workstations, each equipped with an Ethernet … … 17 17 on a quiet network where there is no other traffic. It is best to use a dedicated hub 18 18 with only the machines under test connected at the time of the exercises. 19 </p><p><a class="indexterm" name="id26254 28"></a>19 </p><p><a class="indexterm" name="id2625451"></a> 20 20 Wireshark (formerly Ethereal) has become the network protocol analyzer of choice for many network administrators. 21 21 You may find more information regarding this tool from the … … 37 37 that is used to monitor traffic; this would not allow you to complete the projects. 38 38 </p></div><p> 39 <a class="indexterm" name="id2625 497"></a>39 <a class="indexterm" name="id2625520"></a> 40 40 Do not worry too much if you do not have access to all this equipment; network captures 41 41 from the exercises are provided on the enclosed CD-ROM. This makes it possible to dive directly 42 42 into the analytical part of the exercises if you so desire. 43 </p><p><a class="indexterm" name="id26255 13"></a><a class="indexterm" name="id2625524"></a>43 </p><p><a class="indexterm" name="id2625536"></a><a class="indexterm" name="id2625547"></a> 44 44 Please do not be alarmed at the use of a high-powered analysis tool (Wireshark) in this 45 45 primer. We expose you only to a minimum of detail necessary to complete … … 55 55 <a class="link" href="primer.html#chap01qa" title="Questions and Answers">“Questions and Answers”</a> also provides useful information 56 56 that may help you to avoid significantly time-consuming networking problems. 57 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26255 68"></a>Introduction</h2></div></div></div><p>57 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625592"></a>Introduction</h2></div></div></div><p> 58 58 The purpose of this chapter is to create familiarity with key aspects of Microsoft Windows 59 59 network computing. If you want a solid technical grounding, do not gloss over these exercises. 60 60 The points covered are recurrent issues on the Samba mailing lists. 61 </p><p><a class="indexterm" name="id2625 583"></a>61 </p><p><a class="indexterm" name="id2625606"></a> 62 62 You can see from these exercises that Windows networking involves quite a lot of network 63 63 broadcast traffic. You can look into the contents of some packets, but only to see … … 75 75 Edition</em></span> (TOSHARG2) Chapter 9, “<span class="quote">Network Browsing,</span>” and Chapter 3, 76 76 “<span class="quote">Server Types and Security Modes.</span>” 77 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26256 29"></a>Assignment Tasks</h3></div></div></div><p><a class="indexterm" name="id2625636"></a>77 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625652"></a>Assignment Tasks</h3></div></div></div><p><a class="indexterm" name="id2625659"></a> 78 78 You are about to witness how Microsoft Windows computer networking functions. The 79 79 exercises step through identification of how a client machine establishes a … … 81 81 each other (i.e., how browsing works) and how the two key types of user identification 82 82 (share mode security and user mode security) are affected. 83 </p><p><a class="indexterm" name="id26256 53"></a>83 </p><p><a class="indexterm" name="id2625676"></a> 84 84 The networking protocols used by MS Windows networking when working with Samba 85 85 use TCP/IP as the transport protocol. The protocols that are specific to Windows 86 86 networking are encapsulated in TCP/IP. The network analyzer we use (Wireshark) 87 87 is able to show you the contents of the TCP/IP packets (or messages). 88 </p><div class="procedure"><a name="chap01tasks"></a><p class="title"><b>Procedure 16.1. Diagnostic Tasks</b></p><ol type="1"><li><p><a class="indexterm" name="id2625 686"></a><a class="indexterm" name="id2625697"></a><a class="indexterm" name="id2625705"></a>88 </p><div class="procedure"><a name="chap01tasks"></a><p class="title"><b>Procedure 16.1. Diagnostic Tasks</b></p><ol type="1"><li><p><a class="indexterm" name="id2625709"></a><a class="indexterm" name="id2625720"></a><a class="indexterm" name="id2625728"></a> 89 89 Examine network traces to witness SMB broadcasts, host announcements, 90 90 and name resolution processes. … … 96 96 Review traces of network logons for a Windows 9x/Me client as well as 97 97 a domain logon for a Windows XP Professional client. 98 </p></li></ol></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id26257 45"></a>Exercises</h2></div></div></div><p>99 <a class="indexterm" name="id26257 53"></a>98 </p></li></ol></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625769"></a>Exercises</h2></div></div></div><p> 99 <a class="indexterm" name="id2625776"></a> 100 100 You are embarking on a course of discovery. The first part of the exercise requires 101 101 two MS Windows 9x/Me systems. We called one machine <code class="constant">WINEPRESSME</code> and the … … 112 112 Choose a workgroup name (MIDEARTH) for each exercise. 113 113 </p><p> 114 <a class="indexterm" name="id26258 42"></a>114 <a class="indexterm" name="id2625866"></a> 115 115 The network captures provided on the CD-ROM included with this book were captured using <code class="constant">Ethereal</code> 116 116 version <code class="literal">0.10.6</code>. A later version suffices without problems (i.e. you should be using Wireshark), but an earlier version may not … … 120 120 that can be derived from this book really does warrant your taking sufficient time to practice each exercise with 121 121 care and attention to detail. 122 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26258 71"></a>Single-Machine Broadcast Activity</h3></div></div></div><p>122 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625894"></a>Single-Machine Broadcast Activity</h3></div></div></div><p> 123 123 In this section, we start a single Windows 9x/Me machine, then monitor network activity for 30 minutes. 124 </p><div class="procedure"><a name="id2625 882"></a><p class="title"><b>Procedure 16.2. Monitoring Windows 9x Steps</b></p><ol type="1"><li><p>124 </p><div class="procedure"><a name="id2625906"></a><p class="title"><b>Procedure 16.2. Monitoring Windows 9x Steps</b></p><ol type="1"><li><p> 125 125 Start the machine from which network activity will be monitored (using <code class="literal">Wireshark</code>). 126 126 Launch <code class="literal">Wireshark</code>, click … … 139 139 Analyze the capture. Identify each discrete message type that was captured. Note what transport protocol 140 140 was used. Identify the timing between messages of identical types. 141 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26260 05"></a>Findings</h4></div></div></div><p>141 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626028"></a>Findings</h4></div></div></div><p> 142 142 The summary of the first 10 minutes of the packet capture should look like <a class="link" href="primer.html#pktcap01" title="Figure 16.1. Windows Me Broadcasts The First 10 Minutes">“Windows Me Broadcasts The First 10 Minutes”</a>. 143 143 A screenshot of a later stage of the same capture is shown in <a class="link" href="primer.html#pktcap02" title="Figure 16.2. Windows Me Later Broadcast Sample">“Windows Me Later Broadcast Sample”</a>. 144 </p><div class="figure"><a name="pktcap01"></a><p class="title"><b>Figure 16.1. Windows Me Broadcasts The First 10 Minutes</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture.png" width="216" alt="Windows Me Broadcasts The First 10 Minutes"></div></div></div><br class="figure-break"><div class="figure"><a name="pktcap02"></a><p class="title"><b>Figure 16.2. Windows Me Later Broadcast Sample</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture2.png" width="226.8" alt="Windows Me Later Broadcast Sample"></div></div></div><br class="figure-break"><p><a class="indexterm" name="id26261 22"></a><a class="indexterm" name="id2626134"></a>144 </p><div class="figure"><a name="pktcap01"></a><p class="title"><b>Figure 16.1. Windows Me Broadcasts The First 10 Minutes</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture.png" width="216" alt="Windows Me Broadcasts The First 10 Minutes"></div></div></div><br class="figure-break"><div class="figure"><a name="pktcap02"></a><p class="title"><b>Figure 16.2. Windows Me Later Broadcast Sample</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture2.png" width="226.8" alt="Windows Me Later Broadcast Sample"></div></div></div><br class="figure-break"><p><a class="indexterm" name="id2626145"></a><a class="indexterm" name="id2626157"></a> 145 145 Broadcast messages observed are shown in <a class="link" href="primer.html#capsstats01" title="Table 16.1. Windows Me Startup Broadcast Capture Statistics">“Windows Me Startup Broadcast Capture Statistics”</a>. 146 146 Actual observations vary a little, but not by much. … … 148 148 first to ensure that its name would not result in a name clash, and second to establish its 149 149 presence with the Local Master Browser (LMB). 150 </p><div class="table"><a name="capsstats01"></a><p class="title"><b>Table 16.1. Windows Me Startup Broadcast Capture Statistics</b></p><div class="table-contents"><table summary="Windows Me Startup Broadcast Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">WINEPRESSME<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME<03></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME<20></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1d></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1e></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1b></td><td align="center">Qry</td><td align="center">84</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">__MSBROWSE__</td><td align="center">Reg</td><td align="center">8</td><td align="left">Registered after winning election to Browse Master</td></tr><tr><td align="left">JHT<03></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 x 2. This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">2</td><td align="left">Observed at 10 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Get Backup List Request</td><td align="center">Qry</td><td align="center">12</td><td align="left">6 x 2 early in startup, 0.5 sec apart</td></tr><tr><td align="left">Browser Election Request</td><td align="center">Ann</td><td align="center">10</td><td align="left">5 x 2 early in startup</td></tr><tr><td align="left">Request Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">4</td><td align="left">Early in startup</td></tr></tbody></table></div></div><br class="table-break"><p><a class="indexterm" name="id2626 480"></a><a class="indexterm" name="id2626488"></a>150 </p><div class="table"><a name="capsstats01"></a><p class="title"><b>Table 16.1. Windows Me Startup Broadcast Capture Statistics</b></p><div class="table-contents"><table summary="Windows Me Startup Broadcast Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">WINEPRESSME<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME<03></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME<20></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1d></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1e></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1b></td><td align="center">Qry</td><td align="center">84</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">__MSBROWSE__</td><td align="center">Reg</td><td align="center">8</td><td align="left">Registered after winning election to Browse Master</td></tr><tr><td align="left">JHT<03></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 x 2. This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">2</td><td align="left">Observed at 10 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Get Backup List Request</td><td align="center">Qry</td><td align="center">12</td><td align="left">6 x 2 early in startup, 0.5 sec apart</td></tr><tr><td align="left">Browser Election Request</td><td align="center">Ann</td><td align="center">10</td><td align="left">5 x 2 early in startup</td></tr><tr><td align="left">Request Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">4</td><td align="left">Early in startup</td></tr></tbody></table></div></div><br class="table-break"><p><a class="indexterm" name="id2626504"></a><a class="indexterm" name="id2626512"></a> 151 151 From the packet trace, it should be noted that no messages were propagated over TCP/IP; 152 152 all messages employed UDP/IP. When steady-state operation has been achieved, there is a cycle 153 153 of various announcements, re-election of a browse master, and name queries. These create 154 154 the symphony of announcements by which network browsing is made possible. 155 </p><p><a class="indexterm" name="id26265 06"></a>155 </p><p><a class="indexterm" name="id2626529"></a> 156 156 For detailed information regarding the precise behavior of the CIFS/SMB protocols, 157 157 refer to the book “<span class="quote">Implementing CIFS: The Common Internet File System,</span>” … … 160 160 At this time, the machine you used to capture the single-system startup trace should still be running. 161 161 The objective of this task is to identify the interaction of two machines in respect to broadcast activity. 162 </p><div class="procedure"><a name="id26265 42"></a><p class="title"><b>Procedure 16.3. Monitoring of Second Machine Activity</b></p><ol type="1"><li><p>162 </p><div class="procedure"><a name="id2626565"></a><p class="title"><b>Procedure 16.3. Monitoring of Second Machine Activity</b></p><ol type="1"><li><p> 163 163 On the machine from which network activity will be monitored (using <code class="literal">Wireshark</code>), 164 164 launch <code class="literal">Wireshark</code> and click … … 177 177 Analyze the capture trace, taking note of the transport protocols used, the types of messages observed, 178 178 and what interaction took place between the two machines. Leave both machines running for the next task. 179 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26266 58"></a>Findings</h4></div></div></div><p>179 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626681"></a>Findings</h4></div></div></div><p> 180 180 <a class="link" href="primer.html#capsstats02" title="Table 16.2. Second Machine (Windows 98) Capture Statistics">“Second Machine (Windows 98) Capture Statistics”</a> summarizes capture statistics observed. As in the previous case, 181 181 all announcements used UDP/IP broadcasts. Also, as was observed with the last example, the second … … 185 185 “<span class="quote">Implementing CIFS: The Common Internet File System.</span>” 186 186 </p><div class="table"><a name="capsstats02"></a><p class="title"><b>Table 16.2. Second Machine (Windows 98) Capture Statistics</b></p><div class="table-contents"><table summary="Second Machine (Windows 98) Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">MILGATE98<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">MILGATE98<03></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">MILGATE98<20></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<00></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1d></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1e></td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH<1b></td><td align="center">Qry</td><td align="center">18</td><td align="left">900 sec apart at stable operation</td></tr><tr><td align="left">JHT<03></td><td align="center">Reg</td><td align="center">2</td><td align="left">This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement MILGATE98</td><td align="center">Ann</td><td align="center">14</td><td align="left">Every 120 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">6</td><td align="left">900 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">6</td><td align="left">Insufficient detail to determine frequency</td></tr></tbody></table></div></div><br class="table-break"><p> 187 <a class="indexterm" name="id26269 40"></a>188 <a class="indexterm" name="id26269 47"></a>189 <a class="indexterm" name="id26269 54"></a>187 <a class="indexterm" name="id2626964"></a> 188 <a class="indexterm" name="id2626971"></a> 189 <a class="indexterm" name="id2626978"></a> 190 190 Observation of the contents of Host Announcements, Domain/Workgroup Announcements, 191 191 and Local Master Announcements is instructive. These messages convey a significant 192 192 level of detail regarding the nature of each machine that is on the network. An example 193 193 dissection of a Host Announcement is given in <a class="link" href="primer.html#hostannounce" title="Figure 16.3. Typical Windows 9x/Me Host Announcement">“Typical Windows 9x/Me Host Announcement”</a>. 194 </p><div class="figure"><a name="hostannounce"></a><p class="title"><b>Figure 16.3. Typical Windows 9x/Me Host Announcement</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/HostAnnouncment.png" width="221.4" alt="Typical Windows 9x/Me Host Announcement"></div></div></div><br class="figure-break"></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26270 19"></a>Simple Windows Client Connection Characteristics</h3></div></div></div><p>194 </p><div class="figure"><a name="hostannounce"></a><p class="title"><b>Figure 16.3. Typical Windows 9x/Me Host Announcement</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/HostAnnouncment.png" width="221.4" alt="Typical Windows 9x/Me Host Announcement"></div></div></div><br class="figure-break"></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627042"></a>Simple Windows Client Connection Characteristics</h3></div></div></div><p> 195 195 The purpose of this exercise is to discover how Microsoft Windows clients create (establish) 196 196 connections with remote servers. The methodology involves analysis of a key aspect of how 197 197 Windows clients access remote servers: the session setup protocol. 198 </p><div class="procedure"><a name="id26270 33"></a><p class="title"><b>Procedure 16.4. Client Connection Exploration Steps</b></p><ol type="1"><li><p>198 </p><div class="procedure"><a name="id2627056"></a><p class="title"><b>Procedure 16.4. Client Connection Exploration Steps</b></p><ol type="1"><li><p> 199 199 Configure a Windows 9x/Me machine (MILGATE98) with a share called <code class="constant">Stuff</code>. 200 200 Create a <em class="parameter"><code>Full Access</code></em> control password on this share. … … 217 217 Save the captured data in case it is needed for later analysis. 218 218 </p></li><li><p> 219 <a class="indexterm" name="id26271 64"></a>219 <a class="indexterm" name="id2627187"></a> 220 220 From the top of the packets captured, scan down to locate the first packet that has 221 221 interpreted as <code class="constant">Session Setup AndX, User: anonymous; Tree Connect AndX, 222 222 Path: \\MILGATE98\IPC$</code>. 223 </p></li><li><p><a class="indexterm" name="id2627 183"></a><a class="indexterm" name="id2627191"></a>223 </p></li><li><p><a class="indexterm" name="id2627206"></a><a class="indexterm" name="id2627214"></a> 224 224 In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request, 225 225 and Tree Connect AndX Request</code>. Examine both operations. Identify the name of … … 231 231 that was targeted at the <code class="constant">\\MILGATE98\IPC$</code> service. 232 232 </p></li><li><p> 233 <a class="indexterm" name="id26272 36"></a>234 <a class="indexterm" name="id26272 42"></a>233 <a class="indexterm" name="id2627259"></a> 234 <a class="indexterm" name="id2627266"></a> 235 235 Dissect this packet as per the previous one. This packet should have a password length 236 236 of 24 (characters) and should have a password field, the contents of which is a 237 237 long hexadecimal number. Observe the name in the Account field. This is a User Mode 238 238 session setup packet. 239 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26272 56"></a>Findings and Comments</h4></div></div></div><p>240 <a class="indexterm" name="id26272 65"></a>241 The <code class="constant">IPC$</code> share serves a vital purpose<sup>[<a name="id26272 76" href="#ftn.id2627276" class="footnote">15</a>]</sup>239 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2627280"></a>Findings and Comments</h4></div></div></div><p> 240 <a class="indexterm" name="id2627288"></a> 241 The <code class="constant">IPC$</code> share serves a vital purpose<sup>[<a name="id2627299" href="#ftn.id2627299" class="footnote">15</a>]</sup> 242 242 in SMB/CIFS-based networking. A Windows client connects to this resource to obtain the list of 243 243 resources that are available on the server. The server responds with the shares and print queues that … … 245 245 username and a <code class="constant">NULL</code> password. 246 246 </p><p> 247 <a class="indexterm" name="id2627 296"></a>247 <a class="indexterm" name="id2627320"></a> 248 248 The two packets examined are material evidence of how Windows clients may 249 249 interoperate with Samba. Samba requires every connection setup to be authenticated using … … 252 252 account. 253 253 </p><p> 254 <a class="indexterm" name="id26273 16"></a><a class="indexterm" name="id2627322"></a>255 <a class="indexterm" name="id26273 31"></a>254 <a class="indexterm" name="id2627339"></a><a class="indexterm" name="id2627345"></a> 255 <a class="indexterm" name="id2627354"></a> 256 256 Samba has a special name for the <code class="constant">NULL</code>, or empty, user account: 257 257 it calls it the <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account</a>. The … … 262 262 <a class="link" href="primer.html#nullconnect" title="Figure 16.4. Typical Windows 9x/Me NULL SessionSetUp AndX Request">“Typical Windows 9x/Me NULL SessionSetUp AndX Request”</a>. 263 263 </p><div class="figure"><a name="nullconnect"></a><p class="title"><b>Figure 16.4. Typical Windows 9x/Me NULL SessionSetUp AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/NullConnect.png" width="221.4" alt="Typical Windows 9x/Me NULL SessionSetUp AndX Request"></div></div></div><br class="figure-break"><p> 264 <a class="indexterm" name="id26274 16"></a>265 <a class="indexterm" name="id26274 23"></a>266 <a class="indexterm" name="id26274 30"></a>264 <a class="indexterm" name="id2627439"></a> 265 <a class="indexterm" name="id2627446"></a> 266 <a class="indexterm" name="id2627453"></a> 267 267 When a UNIX/Linux system does not have a <code class="constant">nobody</code> user account 268 268 (<code class="filename">/etc/passwd</code>), the operation of the <code class="constant">NULL</code> … … 272 272 is shown in <a class="link" href="primer.html#userconnect" title="Figure 16.5. Typical Windows 9x/Me User SessionSetUp AndX Request">“Typical Windows 9x/Me User SessionSetUp AndX Request”</a>. 273 273 </p><div class="figure"><a name="userconnect"></a><p class="title"><b>Figure 16.5. Typical Windows 9x/Me User SessionSetUp AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/UserConnect.png" width="221.4" alt="Typical Windows 9x/Me User SessionSetUp AndX Request"></div></div></div><br class="figure-break"><p> 274 <a class="indexterm" name="id26275 07"></a>274 <a class="indexterm" name="id2627530"></a> 275 275 The User Mode connection packet contains the account name and the domain name. 276 276 The password is provided in Microsoft encrypted form, and its length is shown 277 277 as 24 characters. This is the length of Microsoft encrypted passwords. 278 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26275 21"></a>Windows 200x/XP Client Interaction with Samba-3</h3></div></div></div><p>278 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627544"></a>Windows 200x/XP Client Interaction with Samba-3</h3></div></div></div><p> 279 279 By now you may be asking, “<span class="quote">Why did you choose to work with Windows 9x/Me?</span>” 280 280 </p><p> … … 291 291 a domain member of either a Samba-controlled domain or a Windows NT4 or 200x Active Directory domain. 292 292 Here we do not provide details for how to configure this, as full coverage is provided earlier in this book. 293 </p><div class="procedure"><a name="id26275 64"></a><p class="title"><b>Procedure 16.5. Steps to Explore Windows XP Pro Connection Set-up</b></p><ol type="1"><li><p>293 </p><div class="procedure"><a name="id2627587"></a><p class="title"><b>Procedure 16.5. Steps to Explore Windows XP Pro Connection Set-up</b></p><ol type="1"><li><p> 294 294 Start your domain controller. Also, start the Wireshark monitoring machine, launch Wireshark, 295 295 and then wait for the next step to complete. … … 320 320 in this chapter. 321 321 </p></li><li><p> 322 <a class="indexterm" name="id2627 790"></a>323 <a class="indexterm" name="id2627 797"></a>322 <a class="indexterm" name="id2627813"></a> 323 <a class="indexterm" name="id2627820"></a> 324 324 From the top of the packets captured, scan down to locate the first packet that has 325 325 interpreted as <code class="constant">Session Setup AndX Request, NTLMSSP_AUTH</code>. 326 326 </p></li><li><p> 327 <a class="indexterm" name="id26278 17"></a>328 <a class="indexterm" name="id26278 24"></a>329 <a class="indexterm" name="id26278 31"></a>327 <a class="indexterm" name="id2627840"></a> 328 <a class="indexterm" name="id2627847"></a> 329 <a class="indexterm" name="id2627854"></a> 330 330 In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request</code>. 331 331 Expand the packet decode information, beginning at the <code class="constant">Security Blob:</code> … … 339 339 has been decoded as <code class="constant">Session Setup AndX Request, NTLMSSP_AUTH</code>. 340 340 </p></li><li><p> 341 <a class="indexterm" name="id2627 893"></a>341 <a class="indexterm" name="id2627917"></a> 342 342 In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request</code>. 343 343 Expand the packet decode information, beginning at the <code class="constant">Security Blob:</code> … … 350 350 password and then the NT (case-preserving) password hash. 351 351 </p></li><li><p> 352 <a class="indexterm" name="id26279 55"></a>353 <a class="indexterm" name="id26279 62"></a>352 <a class="indexterm" name="id2627978"></a> 353 <a class="indexterm" name="id2627985"></a> 354 354 The passwords are 24-character hexadecimal numbers. This packet confirms that this is a User Mode 355 355 session setup packet. 356 </p></li></ol></div><div class="figure"><a name="XPCap01"></a><p class="title"><b>Figure 16.6. Typical Windows XP NULL Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-NullConnection.png" width="270" alt="Typical Windows XP NULL Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="figure"><a name="XPCap02"></a><p class="title"><b>Figure 16.7. Typical Windows XP User Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-UserConnection.png" width="270" alt="Typical Windows XP User Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id26280 58"></a>Discussion</h4></div></div></div><p><a class="indexterm" name="id2628065"></a>356 </p></li></ol></div><div class="figure"><a name="XPCap01"></a><p class="title"><b>Figure 16.6. Typical Windows XP NULL Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-NullConnection.png" width="270" alt="Typical Windows XP NULL Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="figure"><a name="XPCap02"></a><p class="title"><b>Figure 16.7. Typical Windows XP User Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-UserConnection.png" width="270" alt="Typical Windows XP User Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2628081"></a>Discussion</h4></div></div></div><p><a class="indexterm" name="id2628088"></a> 357 357 This exercise demonstrates that, while the specific protocol for the Session Setup AndX is handled 358 358 in a more sophisticated manner by recent MS Windows clients, the underlying rules or principles … … 361 361 technology server (one using Windows NT4/200x or Samba). It also demonstrates that an authenticated 362 362 connection must be made before resources can be used. 363 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628 089"></a>Conclusions to Exercises</h3></div></div></div><p>363 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628113"></a>Conclusions to Exercises</h3></div></div></div><p> 364 364 In summary, the following points have been established in this chapter: 365 365 </p><div class="itemizedlist"><ul type="disc"><li><p> … … 380 380 databases in concurrent deployment. Refer to <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 10, “<span class="quote">Account Information Databases.</span>” 381 381 </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="chap01conc"></a>Dissection and Discussion</h2></div></div></div><p> 382 <a class="indexterm" name="id2628 177"></a>382 <a class="indexterm" name="id2628200"></a> 383 383 The exercises demonstrate the use of the <code class="constant">guest</code> account, the way that 384 384 MS Windows clients and servers resolve computer names to a TCP/IP address, and how connections … … 388 388 the Microsoft knowledgebase article 389 389 <a class="ulink" href="http://support.microsoft.com/support/kb/articles/Q102/78/8.asp" target="_top">Q102878.</a> 390 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id26282 04"></a>Technical Issues</h3></div></div></div><p>391 <a class="indexterm" name="id26282 12"></a>390 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628227"></a>Technical Issues</h3></div></div></div><p> 391 <a class="indexterm" name="id2628235"></a> 392 392 Network browsing involves SMB broadcast announcements, SMB enumeration requests, 393 393 connections to the <code class="constant">IPC$</code> share, share enumerations, and SMB connection … … 397 397 The questions and answers given in this section are designed to highlight important aspects of Microsoft 398 398 Windows networking. 399 </p><div class="qandaset"><dl><dt> <a href="primer.html#id26282 58">399 </p><div class="qandaset"><dl><dt> <a href="primer.html#id2628281"> 400 400 What is the significance of the MIDEARTH<1b> type query? 401 </a></dt><dt> <a href="primer.html#id26283 04">401 </a></dt><dt> <a href="primer.html#id2628328"> 402 402 What is the significance of the MIDEARTH<1d> type name registration? 403 </a></dt><dt> <a href="primer.html#id2628 378">403 </a></dt><dt> <a href="primer.html#id2628402"> 404 404 What is the role and significance of the <01><02>__MSBROWSE__<02><01> 405 405 name registration? 406 </a></dt><dt> <a href="primer.html#id26284 11">406 </a></dt><dt> <a href="primer.html#id2628434"> 407 407 What is the significance of the MIDEARTH<1e> type name registration? 408 </a></dt><dt> <a href="primer.html#id26284 42">408 </a></dt><dt> <a href="primer.html#id2628465"> 409 409 410 410 What is the significance of the guest account in smb.conf? 411 </a></dt><dt> <a href="primer.html#id26285 20">411 </a></dt><dt> <a href="primer.html#id2628543"> 412 412 Is it possible to reduce network broadcast activity with Samba-3? 413 </a></dt><dt> <a href="primer.html#id26286 29">413 </a></dt><dt> <a href="primer.html#id2628652"> 414 414 Can I just use plain-text passwords with Samba? 415 </a></dt><dt> <a href="primer.html#id26287 16">415 </a></dt><dt> <a href="primer.html#id2628739"> 416 416 What parameter in the smb.conf file is used to enable the use of encrypted passwords? 417 </a></dt><dt> <a href="primer.html#id26287 57">417 </a></dt><dt> <a href="primer.html#id2628780"> 418 418 Is it necessary to specify encrypt passwords = Yes 419 419 when Samba-3 is configured as a domain member? 420 </a></dt><dt> <a href="primer.html#id2628 789">420 </a></dt><dt> <a href="primer.html#id2628812"> 421 421 Is it necessary to specify a guest account when Samba-3 is configured 422 422 as a domain member server? 423 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id26282 58"></a><a name="id2628260"></a></td><td align="left" valign="top"><p>423 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2628281"></a><a name="id2628283"></a></td><td align="left" valign="top"><p> 424 424 What is the significance of the MIDEARTH<1b> type query? 425 425 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 426 <a class="indexterm" name="id26282 72"></a>427 <a class="indexterm" name="id2628 282"></a>426 <a class="indexterm" name="id2628296"></a> 427 <a class="indexterm" name="id2628305"></a> 428 428 This is a broadcast announcement by which the Windows machine is attempting to 429 429 locate a Domain Master Browser (DMB) in the event that it might exist on the network. 430 430 Refer to <span class="emphasis"><em>TOSHARG2,</em></span> Chapter 9, Section 9.7, “<span class="quote">Technical Overview of Browsing,</span>” 431 431 for details regarding the function of the DMB and its role in network browsing. 432 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26283 04"></a><a name="id2628306"></a></td><td align="left" valign="top"><p>432 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628328"></a><a name="id2628330"></a></td><td align="left" valign="top"><p> 433 433 What is the significance of the MIDEARTH<1d> type name registration? 434 434 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 435 <a class="indexterm" name="id26283 19"></a>436 <a class="indexterm" name="id26283 28"></a>435 <a class="indexterm" name="id2628342"></a> 436 <a class="indexterm" name="id2628351"></a> 437 437 This name registration records the machine IP addresses of the LMBs. 438 438 Network clients can query this name type to obtain a list of browser servers from the … … 452 452 </p></li><li><p> 453 453 The IP address of the LMB on the local segment 454 </p></li></ul></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628 378"></a><a name="id2628381"></a></td><td align="left" valign="top"><p>454 </p></li></ul></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628402"></a><a name="id2628404"></a></td><td align="left" valign="top"><p> 455 455 What is the role and significance of the <01><02>__MSBROWSE__<02><01> 456 456 name registration? 457 457 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 458 <a class="indexterm" name="id2628 396"></a>458 <a class="indexterm" name="id2628419"></a> 459 459 This name is registered by the browse master to broadcast and receive domain announcements. 460 460 Its scope is limited to the local network segment, or subnet. By querying this name type, 461 461 master browsers on networks that have multiple domains can find the names of master browsers 462 462 for each domain. 463 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26284 11"></a><a name="id2628413"></a></td><td align="left" valign="top"><p>463 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628434"></a><a name="id2628436"></a></td><td align="left" valign="top"><p> 464 464 What is the significance of the MIDEARTH<1e> type name registration? 465 465 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 466 <a class="indexterm" name="id26284 25"></a>466 <a class="indexterm" name="id2628449"></a> 467 467 This name is registered by all browse masters in a domain or workgroup. The registration 468 468 name type is known as the Browser Election Service. Master browsers register themselves 469 469 with this name type so that DMBs can locate them to perform cross-subnet 470 470 browse list updates. This name type is also used to initiate elections for Master Browsers. 471 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26284 42"></a><a name="id2628444"></a></td><td align="left" valign="top"><p>472 <a class="indexterm" name="id26284 48"></a>471 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628465"></a><a name="id2628467"></a></td><td align="left" valign="top"><p> 472 <a class="indexterm" name="id2628471"></a> 473 473 What is the significance of the <em class="parameter"><code>guest account</code></em> in smb.conf? 474 474 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> … … 483 483 or there must be an entry in the <code class="filename">smb.conf</code> file with a valid UNIX account, such as 484 484 <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account = ftp</a>. 485 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26285 20"></a><a name="id2628522"></a></td><td align="left" valign="top"><p>485 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628543"></a><a name="id2628545"></a></td><td align="left" valign="top"><p> 486 486 Is it possible to reduce network broadcast activity with Samba-3? 487 487 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 488 <a class="indexterm" name="id26285 34"></a>489 <a class="indexterm" name="id26285 40"></a>488 <a class="indexterm" name="id2628557"></a> 489 <a class="indexterm" name="id2628564"></a> 490 490 Yes, there are two ways to do this. The first involves use of WINS (See <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 9, 491 491 Section 9.5, “<span class="quote">WINS The Windows Inter-networking Name Server</span>”); the … … 493 493 a correctly configured DNS server (see <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 9, Section 9.3, “<span class="quote">Discussion</span>”). 494 494 </p><p> 495 <a class="indexterm" name="id26285 72"></a>496 <a class="indexterm" name="id2628 579"></a>497 <a class="indexterm" name="id2628 588"></a>495 <a class="indexterm" name="id2628595"></a> 496 <a class="indexterm" name="id2628602"></a> 497 <a class="indexterm" name="id2628611"></a> 498 498 The use of WINS reduces network broadcast traffic. The reduction is greatest when all network 499 499 clients are configured to operate in <em class="parameter"><code>Hybrid Mode</code></em>. This can be effected through … … 503 503 Use of SMB without NetBIOS is possible only on Windows 200x/XP Professional clients and servers, as 504 504 well as with Samba-3. 505 </p></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id26286 29"></a><a name="id2628631"></a></td><td align="left" valign="top"><p>505 </p></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628652"></a><a name="id2628654"></a></td><td align="left" valign="top"><p> 506 506 Can I just use plain-text passwords with Samba? 507 507 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> … … 526 526 PDC/BDC to provide Windows user and group accounts, the <em class="parameter"><code>idmap uid, idmap gid</code></em> ranges 527 527 set in the <code class="filename">smb.conf</code> file provide the local UID/GIDs needed for local identity management purposes. 528 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26287 16"></a><a name="id2628718"></a></td><td align="left" valign="top"><p>528 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628739"></a><a name="id2628741"></a></td><td align="left" valign="top"><p> 529 529 What parameter in the <code class="filename">smb.conf</code> file is used to enable the use of encrypted passwords? 530 530 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 531 531 The parameter in the <code class="filename">smb.conf</code> file that controls this behavior is known as <em class="parameter"><code>encrypt 532 532 passwords</code></em>. The default setting for this in Samba-3 is <code class="constant">Yes (Enabled)</code>. 533 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id26287 57"></a><a name="id2628759"></a></td><td align="left" valign="top"><p>533 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628780"></a><a name="id2628782"></a></td><td align="left" valign="top"><p> 534 534 Is it necessary to specify <a class="link" href="smb.conf.5.html#ENCRYPTPASSWORDS" target="_top">encrypt passwords = Yes</a> 535 535 when Samba-3 is configured as a domain member? 536 536 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p> 537 537 No. This is the default behavior. 538 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628 789"></a><a name="id2628791"></a></td><td align="left" valign="top"><p>538 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628812"></a><a name="id2628814"></a></td><td align="left" valign="top"><p> 539 539 Is it necessary to specify a <em class="parameter"><code>guest account</code></em> when Samba-3 is configured 540 540 as a domain member server? … … 544 544 necessary to provide a <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account = an_account</a>, 545 545 where <code class="constant">an_account</code> is a valid local UNIX user account. 546 </p></td></tr></tbody></table></div></div><div class="footnotes"><br><hr width="100" align="left"><div class="footnote"><p><sup>[<a name="ftn.id26272 76" href="#id2627276" class="para">15</a>] </sup>TOSHARG2, Sect 4.5.1</p></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="RefSection.html">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 15. A Collection of Useful Tidbits </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Appendix A.546 </p></td></tr></tbody></table></div></div><div class="footnotes"><br><hr width="100" align="left"><div class="footnote"><p><sup>[<a name="ftn.id2627299" href="#id2627299" class="para">15</a>] </sup>TOSHARG2, Sect 4.5.1</p></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="RefSection.html">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 15. A Collection of Useful Tidbits </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Appendix A. 547 547 GNU General Public License version 3 548 548 </td></tr></table></div></body></html>
Note:
See TracChangeset
for help on using the changeset viewer.